Menu
Sign In
shutterstock_490960141-1

Industry News: ESG5

    Bybit Hack Exposes Multi-Sig Security Flaws as Industry Reevaluates Protections

    2025-02-24

    Wealth Professional: Bybit, one of the largest cryptocurrency exchanges, suffered a US$1.5bn security breach that has since triggered US$5.5bn in outflows.

    Read more...

    Tech Investment Firm Insight Partners Discloses Data Breach

    2025-02-19

    Cybersecurity Dive: Insight Partners suffered a data breach in January stemming from what it described as “a sophisticated social engineering attack.” In a statement the private equity and venture capital firm said it initially detected unauthorized access to “certain Insight information systems” on Jan. 16. 

    Read more...

    What A New Presidency Means For Global Cybersecurity—And For SMEs

    2025-02-19

    Forbes: As a cybersecurity leader dedicated to safeguarding small- and medium-sized enterprises (SMEs) from cyber threats, the shifting sands of the cybersecurity landscape are always top-of-mind.

    Read more...

    Palo Alto Networks Warns Firewall Vulnerability Is Under Active Exploitation

    2025-02-18

    Cybersecurity Dive: Palo Alto Networks confirmed that a high severity vulnerability, listed as CVE-2025-0108, in its PAN-OS management web interface was being exploited by attackers in the wild.

    Read more...

    Fintech Giant Finastra Notifies Victims of October Data Breach

    2025-02-17

    Bleeping Computer: Financial technology giant Finastra is notifying victims of a data breach after their personal information was stolen by unknown attackers who first breached its systems in October 2024.

    Read more...

    Know Your Breach: HPE

    The Target: Hewlett Packard Enterprise, an American multinational information technology company.

     The Take: A breach notification filing with the state of Massachusetts indicated that Social Security numbers, driver’s license numbers and credit/debit card numbers were compromised in the attack.

     The Vector: HPE was notified on Dec. 12, 2023, that a suspected nation-state threat group had breached its Office 365 email environment. An investigation revealed that starting in May 2023, Midnight Blizzard actors accessed emails and pilfered data from mailboxes “belonging to individuals in our cybersecurity, go-to-market, business segments, and other functions.”

     As phishing actors continue to explore every potential abuse opportunity on legitimate service providers, novel security gaps constantly threaten to expose users to severe risks. It is essential not to rely solely on email protection solutions, and also scrutinize every email that lands on your inbox, look for inconsistencies, and double-check all claims made in those messages.

    Read more...

    Thoma Bravo-Backed SailPoint Set for US Market  Comeback After Over Two Years

    2025-02-13

    Yahoo Finance/Reuters: Thoma Bravo-backed cybersecurity firm SailPoint will start trading on the Nasdaq, returning to the U.S. stock market more than two years after it went private.

    Read more...

    Ransomware Gangs Shifting Tactics to Evade Enterprise Defenses

    2025-02-12

    Cybersecurity Dive: Huntress found that ransomware gangs are broadly using the kinds of advanced tactics and techniques that were first tested on large organizations, such as tampering or disabling cybersecurity products.

    Read more...

    Buyout Firms Vie For Cybersecurity Firm Trend Micro, Sources Say

    2025-02-12

    Yahoo Finance/Reuters: Bain Capital, Advent International and EQT AB are among the private equity firms competing to acquire Japanese cybersecurity firm Trend Micro, which has a market value of 1.32 trillion yen ($8.54 billion), according to people familiar with the matter.

    Read more...

    Trump to Nominate Sean Cairncross as National Cyber Director

    2025-02-12

    Cybersecurity Dive: President Donald Trump plans to nominate Sean Cairncross, a former official at the Republican National Committee, as the next national cyber director, according to a list of planned nominees obtained by Cybersecurity Dive. 

    Read more...

    About Castle Hall Diligence

    Castle Hall helps investors build comprehensive due diligence programs across hedge fund, private equity and long only portfolios More →

    Subscribe to Cyber Updates