shutterstock_490960141-1

Industry News: ESG5

    DraftKings Warns Data of 67K People Was Exposed In Account Hacks

    2022-12-19

    Bleeping Computer: Sports betting company DraftKings revealed last week that more than 67,000 customers had their personal information exposed following a credential attack in November.

    Read more...

    Know Your Breach: Uber

    The Target: Uber, a U.S based ride-service company.

    The Take: Exposure of sensitive company information including: IT Asset reports, Windows domain login names and email addresses, and Active Directory information. 

    The Vector:  The data was stolen through a breach in a third-party provider, Teqtivity, using compromised employee credentials. These were used to gain access to an AWS backup server.

    This breach is a stark reminder of how authentication controls are in an overall robust cybersecurity posture, and more critically, ensuring these controls are in place on all third-party vendors which have access to a firm’s data. The information stolen in this attack could lead to highly targeted phishing campaigns against Uber. Regular vendor assessments are a key component in cybersecurity.

    Read more...

    US Begins Seizure of 48 DDoS-for-hire Services Following Global Investigation

    2022-12-15

    ITPro: The US' Department of Justice (DoJ) has begun the seizure of 48 DDoS-for-hire services and brought criminal charges against six individuals involved.

    Read more...

    Challenges with Data Weaken Cybersecurity Posture for Government Agencies

    2022-12-14

    Business Wire: Public sector organizations are more likely to struggle with leveraging data to detect and prevent threats than their private sector counterparts (63% to 49%), ultimately affecting their cybersecurity readiness. That’s according to a survey commissioned by Splunk Inc. (NASDAQ: SPLK), the data platform leader for security and observability.

    Read more...

    The Cybersecurity Industry Doesn't Have a Stress Problem — It Has a Leadership Problem

    2022-12-13

    Dark Reading: Around the world, employees have been experiencing extreme stress due to the ongoing pandemic, business disruption, and the faster pace of work. 

    Read more...

    Cybersecurity Startup Snyk Valued at $7.4 Bln After Latest Funding

    2022-12-12

    Reuters: Cybersecurity start-up Snyk Ltd said it had raised $196.5 million in Series G funding, led by Qatar Investment Authority, which is at a lower valuation of $7.4 billion.

    Read more...

    Play Ransomware Claims Attack on Belgium City of Antwerp

    2022-12-12

    Bleeping Computer: Digipolis, the IT company responsible for managing Antwerp's IT systems, suffered a ransomware attack that disrupted the city's IT, email, and phone services.

    Read more...

    California Probes Cyberattack Against State’s Finance Department

    2022-12-12

    Yahoo Finance: California’s finance department has been hit by a cybersecurity attack, and a notorious ransomware group is claiming responsibility.

    Read more...

    Why Employee-Targeted Digital Risks Are The Next Frontier Of Enterprise Cybersecurity

    2022-12-12

    Forbes: The story of cybersecurity is a constant progression of new ways to defeat new threats, from thought experiments to mainstream best practices. It started with the earliest antivirus software, which began as an experiment and progressed to being a necessity.

    Read more...

    Know Your Breach: VEVOR

    The Target: Vevor, a California-based online retailer.

    The Take: 1.1 billion records across two databases of Personally Identifiable Information including: first and last name, partial credit card numbers, transaction IDs, order and refund information, home addresses, and email addresses. Internal Vevor account admin names and plaintext passwords were also exposed, as well as IP addresse, ports, and pathways.

    The Vector: A misconfigured data server was left open and unsecured, meaning anyone with an internet connection could have viewed and downloaded the data.

    This breach is critical reminder that authentication controls are an important piece in an overall robust cybersecurity posture and furthermore, that when admin credentials are exposed, dangerous pivot attacks may follow as attackers use these to move into a firm’s other platforms. Multi-factor authentication and password length and complexity rules are effective strategies to mitigate these kinds of breaches to protect a firm’s data.

    Read more...

    About Castle Hall Diligence

    Castle Hall helps investors build comprehensive due diligence programs across hedge fund, private equity and long only portfolios More →

    Subscribe to Cyber Updates