learn more
<https://castlehalldiligence.com>
shutterstock_490960141-1

Industry News: ESG5

Business Leaders Must Take Urgent Action to Counter Ransomware Threat, White House Warns in Memo

2021-06-03

CNBC: The Biden administration is urging corporate executives and business leaders to take immediate steps to prepare for ransomware attacks, warning in a new memo that cybercriminals are shifting from stealing data to disrupting core operations.

Read more...

FireEye is Selling its Products Business and Name for $1.2 Billion

2021-06-02

CNBC: The U.S. cybersecurity firm said the sale will split Mandiant Solutions, its cyber forensics unit, from its cloud security, network and email products.

Read more...

Why a Culture of Silence and Driving Mistakes Underground is Bad for Everyone

2021-06-02

ZDNet: Cybersecurity works best when people know that their corporate information security team will be sympathetic to mistakes. That's because, if someone suspects they may have clicked a phishing link or fallen victim to a cyberattack, they're much more likely to be open about it – and that helps the whole organisation stay secure against malicious hackers.

Read more...

Two-Thirds of Organizations Plan to Improve Their Cybersecurity in the Wake of Devastating Ransomware Attacks

2021-06-02

KnowBe4: With 81% of organizations believing ransomware attacks will become more prevalent in the second half of 2021, nearly everyone is preparing for the worst to come.

Read more...

Security Leaders More Concerned About Legal Settlements Than Regulatory Fines

2021-06-01

Help Net Security: An overwhelming 90% of security leaders are concerned about group legal settlements following a serious data breach, compared to 85% who are worried about regulatory fines, Egress reveals.

Read more...

Reserve Bank Moves to Address Cyber Vulnerability After KPMG Report

2021-05-31

RNZ: A report by consultancy KPMG has uncovered shortcomings in the Reserve Bank's data protection practices, which resulted in it becoming a victim of a cyber-attack on the third-party file-sharing application it used to share and store information.

Read more...

Know Your Breach: Bergen Logistics

The target: Bergen Logistics, a U.S based fulfillment provider.

The take: Personally Identifiable Information including: names, sur names, city, zip code, addresses, order numbers, email addresses, plain-text passwords to customer accounts.

The attack vector: An unsecured Elasticsearch database server was left online, meaning anyone with an internet connection was able to connect and download the data.

The exposure of personal information can lead to highly targeted phishing and fraud attacks. More critical was how this firm stored their customer account passwords in plain text on the server with no encryption or protections. Ensuring credentials are adequately and appropriately protected through encryption is an integral part of maintaining a robust cybersecurity posture.

Read more...

US Pipelines Ordered to Increase Cyber Defenses After Hack

2021-05-27

Yahoo Finance: U.S. pipeline operators will be required for the first time to conduct a cybersecurity assessment under a Biden administration directive in response to the ransomware hack that disrupted gas supplies in several states this month.

Read more...

Canada Post Says 950,000 Customers Exposed in Data Breach

2021-05-27

Yahoo Finance: Canada's national mail carrier says a malware attack on one of its suppliers has impacted 44 of its biggest corporate customers across the country, and potentially up to nearly one million people.

Read more...

Japanese Government Agencies Suffer Data Breaches After Fujitsu Hack

2021-05-27

Bleeping Computer: Offices of multiple Japanese agencies were breached via Fujitsu's "ProjectWEB" information sharing tool. Fujitsu states that attackers gained unauthorized access to projects that used ProjectWEB, and stole some customer data.

Read more...