Menu
Sign In
shutterstock_490960141-1

Industry News: ESG5

    Know Your Breach: Hertz

    The Target: ​Car rental giant Hertz

    The Take: The stolen data varies by region, but largely includes Hertz customer names, dates of birth, contact information, driver’s licenses, payment card information, and workers’ compensation claims. Hertz said a smaller number of customers had their Social Security numbers taken in the breach, along with other government-issued identification numbers.

    The Vector: The company attributed the breach to a vendor, software maker Cleo, which last year was at the center of a mass-hacking campaign by a prolific Russia-linked ransomware gang. Hertz is one of dozens of companies that used Cleo’s software at the time of their data thefts. The Clop ransomware gang claimed last year to have exploited a zero-day vulnerability in Cleo’s widely used enterprise file transfer products, which allow companies to share large sets of sensitive data over the internet. By breaching these systems, the hackers stole reams of data from Cleo’s corporate customers.

    This breach is critical reminder that zero-day exploits do happen, and furthermore that patching software in a timely, effective manner is a key component of ensuring customer data is protected. Ensuring third-party vendors are deploying patches and fixes in accordance with a firm’s cybersecurity policy is an important step in an overall robust security posture.

    Read more...

    CISOs No Closer To Containing Shadow AI’s Skyrocketing Data Risks

    2025-04-17

    CSO Online: Generative AI’s many benefits come with the drawback of data security risks, primarily through shadow AI use and the leakage of sensitive information.

    Read more...

    Bill Extends Cyber Threat Info-Sharing Between Public, Private Sector

    2025-04-16

    Cybersecurity Dive: Two federal lawmakers today introduced a bipartisan bill that preserves key regulation that facilitates the sharing of cyber-threat data between private companies and the federal government.

    Read more...

    CISA Extends Funding to Ensure 'No Lapse in Critical CVE Services'

    2025-04-16

    Bleeping Computer: CISA says the U.S. government has extended MITRE's funding to ensure no continuity issues with the critical Common Vulnerabilities and Exposures (CVE) program.

    Read more...

    Ex-CISA Chief Chris Krebs Leaving SentinelOne Following Trump Pressure

    2025-04-16

    Investing.com: Christopher Krebs, whom President Donald Trump fired as head of the Cybersecurity and Infrastructure Security Agency in 2020, said he is leaving cybersecurity company SentinelOne following pressure from the White House.

    Read more...

    Cybersecurity Funding Ticks Up Despite Slow Deal Flow

    2025-04-15

    Crunchbase: After successive quarters of decline, venture funding to cybersecurity startups nudged up in the first quarter — and could see even more investment after having the largest acquisition of a private, venture-backed company ever.

    Read more...

    C-suite Disconnect on Cybersecurity Threatens Business Value and Resilience, EY Study Finds

    2025-04-14

    PR Newswire: New research from Ernst & Young LLP highlights significant financial risks posed by today's evolving cybersecurity threat landscape, with alarming disconnects across the C-suite on exposure levels, threat sources and more. 

    Read more...

    Report: OCC Hack Prompts Information Sharing Limits From Big Banks

    2025-04-14

    PYMNTS.com: A Bloomberg report says that JPMorgan Chase and Bank of New York Mellon have scaled back electronic information sharing with the Office of the Comptroller of the Currency (OCC) following a significant breach of the regulator’s email system.

    Read more...

    Know Your Breach: Sensata Technologies

    The Target: ​Sensata Technologies is an industrial technology company that develops, manufactures, and sells a wide range of sensors and sensor-rich solutions, as well as electrical protection components and systems.

    The Take: A preliminary investigation with assistance from external cybersecurity experts confirmed that the hackers have exfiltrated data from the company network.

    The Vector: Data theft is a common tactic used by ransomware actors to extort victims, increase pressure to pay a ransom, and create legal and regulatory complexities. Currently, Sensata is still determining what files were stolen in the attack and will notify impacted individuals and regulatory authorities as needed, based on the results of its investigation.

    This breach is a stark reminder of how strong authentication controls are in an overall robust cybersecurity posture, and that good password hygiene plays a pivotal role in protection.

    Read more...

    Treasury Department Bank Regulator Discloses Major Hack

    2025-04-09

    Cybersecurity Dive: Attackers gained access to emails containing sensitive government data related to financial institutions in a cyberattack on the Department of the Treasury’s Office of the Comptroller of the Currency (OCC), in what the agency characterized as a “major incident.”

    Read more...

    About Castle Hall Diligence

    Castle Hall helps investors build comprehensive due diligence programs across hedge fund, private equity and long only portfolios More →

    Subscribe to Cyber Updates