shutterstock_490960141-1

Industry News: ESG5

    86% of Companies Report Network Disruption Amid Remote Work Shift

    2020-04-29

    DARKReading: The global shift to remote work has caused a level of network disruption in 86% of companies, a new study shows. Of the organizations surveyed, 41% said they experienced moderate disruptions to network security practices, 23% saw major disruptions, and 22% said disruptions were minimal.

    Read more...

    Why Cyber-security and Governance Should Go Hand in Hand

    2020-04-23

    The Asset ESG Forum: Ongoing worldwide lockdown measures have made working from home the norm, thus increasing the chances of being exposed to cyber-attacks and practices such as phishing - fraudulent messages that resemble e-mails from trusted sources.

    Read more...

    Zoom Users Top 300 Mln Despite Growing Ban List, Shares Hit Record

    2020-04-22

    Reuters: Zoom video conferencing app’s user base grew by another 50% to 300 million in the last three weeks, as the company fought to quell a backlash around security and safety that has seen a number of governments and firms ban its applications.

    Read more...

    Cybersecurity Risks Set to Soar

    2020-04-21

    ETFExpress: The virus has debilitated regions, and decimated sectors with an unparalleled level of speed and ferocity. Its impact on companies and business models has been indiscriminate, hurting particularly those companies with weaker or under-developed digital underpinnings. Stronger players have had to shock themselves into emergency measures designed to prevent discontinuity. Companies have had to learn how to operate remotely, and virtually. And billions of people are now working from home and adjusting to virtual workplaces thanks to teleconferencing services like Zoom and Microsoft Teams. 

    Read more...

    Know Your Breach: Zoom

    The target: Zoom, a popular videoconferencing service

    The take: More than 500,000 username/password combinations, along with personal meeting URLs and HostKeys for active Zoom accounts were found currently for sale on the dark web.

    The attack vector: Security researchers suspect that the list was not stolen from Zoom directly, but was rather compiled through ‘password stuffing’ attacks – where e-mail/password combinations from past breaches are tried against different sites and services. Attackers take previously breached username/password combinations and cycle through login attempts using the breached credentials – the successful combinations are compiled and sold.

    This incident highlights a few key issues – namely, for individuals, the risks inherent in password re-use: this incident confirms that at least 500,000 active Zoom users are still re-using known compromised passwords, which attackers can use to gain control of their other accounts.

    Institutionally, it highlights reputational issues – while this particular list of credentials was not exposed directly by Zoom, attackers are using the service’s popularity to market the list, and it gives the appearance of being yet another in a string of recent security incidents the videoconferencing service has had to answer for.

    Read more...

    North Korea Hacking Threatens U.S. and Global Financial System: U.S. Officials

    2020-04-15

    Reuters: U.S. government officials warned on April 15, 2020 about the threat of North Korean hackers, calling particular attention to banking and other financial services.

    Read more...

    Cybercrime May Be the World's Third-Largest Economy by 2021

    2020-04-13

    Dark Reading: As organizations go digital, so does crime. Today, cybercrime is a massive business in its own right, and criminals everywhere are clamoring to get a piece of the action as companies and consumers invest trillions to stake their claim in the digital universe.

    Read more...

    Axonius Nabs $58M for its Cybersecurity-focused Network Asset Management Platform

    2020-03-31

    Tech Crunch: As companies get to grips with a wider (and, lately, more enforced) model of remote working, a startup that provides a platform to help track and manage all the devices that are accessing networked services — an essential component of cybersecurity policy — has raised a large round of growth funding.

    Read more...

    This Attack is the Most Common Threat You Will Face

    2020-03-26

    ZDNet: Almost half of businesses have experienced a cyberattack or data breach in the past year – and almost all of the organisations that know they've been on the receiving end of attacks have reported being targeted by phishing and other fraudulent emails as the volume of these attacks continues to rise.

    Read more...

    10 Ways Hackers are Using Automation to Boost Their Attacks

    2020-03-25

    ZDNet: Automation is something businesses in almost every sector are familiar with, as part of their efforts to make systems more efficient. It's something that the cybersecurity industry is increasingly using, with automated data collection and processing playing an ever-growing role in protecting against data breaches and cyberattacks.

    Read more...

    About Castle Hall Diligence

    Castle Hall helps investors build comprehensive due diligence programs across hedge fund, private equity and long only portfolios More →

    Subscribe to Cyber Updates