Safeguarding Client Accounts Against Credential Compromise

OCIE issues a new alert: “Credential Stuffing”

Yesterday The Office and Compliance Inspections and Examinations (“OCIE”) issued an alert about safeguarding client accounts against credential compromise that highlighted the issue of “credential stuffing attacks“. Credential stuffing is a type of cyber attack where many compromised user credentials are tried against systems to gain unauthorized access, using automated means. Over the past few […]

Internet DNS

Critical Wormable Vulnerability Affecting Windows DNS Servers

Critical Wormable Vulnerability Affecting Windows DNS Servers On July 14, 2020 Microsoft publicly disclosed a critical vulnerability affecting Windows DNS Server. https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1350 As a reminder DNS (Domain Naming System) servers are used primarily to resolve IP addresses. DNS is used for locating and identifying computer services and devices on the internet, such as email servers, […]

Breacking New Alert - Ocie issues cybersecurity alert.

OCIE issues a new Cybersecurity: Ransomware Alert

Today the OCIE issued a Ransomware Alert, highlighting an uptick in sophisticated social engineering and other cyber campaigns, designed to infiltrate the networks of financial institutions to access sensitive information and/or to deploy ransomware. As a reminder, ransomware actors typically demand monetary payment for the return of data. We can spend time regurgitating what was […]

Work From Home Asset Management

Technology, security, and privacy in a Work From Home (WFH) environment

Will Work From Home (WFH) be an Alternative Asset Management Firm’ new norm? Firstly, let me address the question that comes to mind after reading the title, this isn’t just another article about how COVID-19 has affected us………now keep reading. I’m not writing this article to express my opinion about whether WFH is good or […]

Phishing scam private equity

Three UK-based Private Equity firms lose 1.3 million dollars to cyber criminals

  The team at Check Point identified that cyber criminals – dubbed the Florentine Banker – targeted three Private Equity firms and stole over $1.3 million dollars, with only about half the money recovered. The cyber criminals launched an email spear-phishing campaign targeting executives, and other high-profile employees in an attempt to gain access to […]

Elteni Zoom Vulnerability

Are you considering fleeing Zoom? Don’t be so quick to do so.

Zoom has been under the spotlight over the past few weeks due to privacy and security issues. They were served with a class-action lawsuit over its data sharing practices, and come under scrutiny from the New York Attorney General’s Office. Headlines like this may make you want to “Zoom” for the hills, but hit the […]

Work From Home

Have you considered the work from home risks?

Have you made the decision to allow employees to work from home or are you still contemplating the idea? If work from home is or will be the preferred method for the unforeseeable future, there are some things you should do to maintain your compliance and security posture. Here are some risks you should be […]

CDPwn – Cisco patches 5 critical vulnerabilities

CDPwn – Cisco patches 5 critical vulnerabilities that affect millions of devices.

Five critical vulnerabilities found in various implementations of the Cisco Discovery Protocol (CDP) could allow attackers on a local network to take over enterprise devices, as discovered by IoT security company Armis. (It is important to note that attacks can not be performed remotely and requires attackers to have access to internal networks.) CDP is […]

Elteni OCIE Observations - Hedge Funds, Private Equity, RIA, Asset Management

The SEC’s OCIE Releases Their Observations From Examinations

On January 27, 2020 the Securities and Exchange Commission Commission’s Office of Compliance Inspections and Examinations issued examination observations related to cybersecurity and operational resiliency practices undertaken by market participants. We reviewed this alert and simplified it into major points that are easily digestible. The OCIE provided the following observations: Governance and Risk Management Senior leadership is […]

1 2 3