{"id":19620,"date":"2024-09-09T09:29:01","date_gmt":"2024-09-09T13:29:01","guid":{"rendered":"https:\/\/www.elteni.com\/?p=19620"},"modified":"2024-09-09T09:29:01","modified_gmt":"2024-09-09T13:29:01","slug":"2024-september-newsletter","status":"publish","type":"post","link":"https:\/\/www.elteni.com\/insights\/?p=19620","title":{"rendered":"2024 September Newsletter"},"content":{"rendered":"<h1>ELTENI&#8217;S CYBER SCOOP<\/h1>\n<h3>Latest News<\/h3>\n<p>In this newsletter, we highlight a new CISA incident reporting tool, how to identify a Business Email Compromise and additional developments on the National Public Data breach.<\/p>\n<h1>REGULATORY CORNER<\/h1>\n<p><strong>CISA Launches New Portal to Improve Cyber Reporting<\/strong><\/p>\n<p><em>The Portal is a secure platform with enhanced functionality for cyber incident reporting, including integration with login.gov credentials. The portal\u2019s enhanced functionality includes the ability to save and update reports, share submitted reports with colleagues or clients for third-party reporting, and search and filter reports. A new collaboration feature allows users to engage in informal discussions with CISA.<\/em><\/p>\n<h3>Notes<\/h3>\n<p>As cyber incidents become increasingly common, the saying rings true: &#8220;it&#8217;s not if, but when.&#8221; Therefore, it&#8217;s crucial to be prepared to document and report incidents as they occur. Doing so not only meets regulatory requirements but also ensures an efficient and effective response and remediation. Tools that assist in accurately reporting incidents and provide a channel for collaboration are valuable, especially given the complexity and abundance of information on reporting requirements, which can make compliance confusing.<\/p>\n<p><a href=\"https:\/\/www.cisa.gov\/news-events\/news\/cisa-launches-new-portal-improve-cyber-reporting\">CISA Launches New Portal to Improve Cyber Reporting | CISA<\/a><\/p>\n<h1>ENFORCEMENT NEWS<\/h1>\n<p><strong>SEC Charges Transfer Agent Equiniti Trust Co. with Failing to Protect Client Funds Against Cyber Intrusions<\/strong><\/p>\n<p><em>The Securities and Exchange Commission today announced settled charges against New York-based registered transfer agent Equiniti Trust Company LLC, formerly known as American Stock Transfer &amp; Trust Company LLC, for failing to assure that client securities and funds were protected against theft or misuse.\u00a0 <\/em><em>\u201cAmerican Stock Transfer failed to provide the safeguards necessary to protect its clients\u2019 funds and securities from the types of cyber intrusions that have become a near-constant threat to companies and the markets,\u201d said Monique C. Winkler, Director of the SEC\u2019s San Francisco Regional Office.<\/em><\/p>\n<h3>Notes<\/h3>\n<p>Beyond the fines and reputational damage faced by Equiniti, this incident also had a significant financial impact on their clients. This judgment underscores the SEC&#8217;s commitment to enforcing cybersecurity regulations for entities under its jurisdiction, ensuring that they implement adequate security controls and practices to protect client assets and information. It highlights the necessity for regulated entities to take a proactive approach in building and managing a robust cybersecurity program that evolves to meet the demands of an ever-changing threat landscape. Continuous improvement and adaptation are essential in maintaining compliance and safeguarding client trust in today&#8217;s environment.<\/p>\n<p><a href=\"https:\/\/www.sec.gov\/newsroom\/press-releases\/2024-101\">SEC Charges Transfer Agent Equiniti Trust Co. with Failing to Protect Client Funds Against Cyber Intrusions | SEC<\/a><\/p>\n<h1>CYBER NEWS<\/h1>\n<p><u><a href=\"https:\/\/www.wired.com\/story\/how-to-spot-business-email-compromise-scam\/\">How to spot a Business Email Compromise Scam | Wired<\/a><\/u><\/p>\n<p>Business email compromise (BEC) scams are a big deal. The con artists behind this criminal enterprise will cold-email you, pretending to be someone you work with, in order to gain access to money or information. You might get an email that appears to be from your company&#8217;s CEO asking you to quickly do something like buy gift cards, or you might get an email that looks like it&#8217;s from an employee at your company asking you to change their direct deposit information. The scam itself can take a lot of forms, but the end goal is to somehow siphon money away from you or the business you work for.<\/p>\n<p><a href=\"https:\/\/krebsonsecurity.com\/2024\/08\/national-public-data-published-its-own-passwords\/\">National Public Data Published Its Own Passwords | Krebs on Security<\/a><\/p>\n<p>New details are emerging about a breach at National Public Data (NPD), a consumer data broker that recently spilled hundreds of millions of Americans\u2019 Social Security Numbers, addresses, and phone numbers online. KrebsOnSecurity has learned that another NPD data broker which shares access to the same consumer records inadvertently published the passwords to its back-end database in a file that was freely available from its homepage.<\/p>\n<p><u><a href=\"https:\/\/www.securityweek.com\/major-backdoor-in-millions-of-rfid-cards-allows-instant-cloning\/\">Major Backdoor in Millions of RFID Cards Allows Instant Cloning | Security Week<\/a><\/u><\/p>\n<p>The backdoor, documented in a research paper by Quarkslab researcher Philippe Teuwen, allows the instantaneous cloning of RFID smart cards used to open office doors and hotel rooms around the world.<\/p>\n<p><u><a href=\"https:\/\/www.securityweek.com\/google-warns-of-exploited-chrome-vulnerability\/\">Google Warns of Exploited Chrome Vulnerability | Security Week<\/a><\/u><\/p>\n<p>Essentially, if the victim visits a compromised or malicious web page, the vulnerability could allow the attacker to execute code or access sensitive information. \u00a0Google notes in its updated advisory that the in-the-wild exploitation of the security defect was reported after the browser update was released, but did not make it clear whether the flaw was exploited as a zero-day.<\/p>\n<h1>DECODE THE TERMS<\/h1>\n<p><strong>DLP &#8211; <\/strong>Data Loss Prevention (DLP) is a security tool that stops unauthorized access, sharing, or loss of sensitive information. It monitors and controls data movement to ensure it stays within the organization, protecting personal data, financial records, and intellectual property. DLP helps keep important information safe and secure.<\/p>\n<p><strong>EDR \u2013 <\/strong>Endpoint Detection and Response (EDR) is a security tool that monitors and analyzes activity on devices like computers, phones, and servers to detect and respond to cyber threats. It helps identify suspicious behavior, such as malware or unauthorized access, and provides tools to investigate and stop the threats before they cause damage, keeping the organization&#8217;s devices and data safe.<\/p>\n<p><strong>MITM \u2013 <\/strong>A Man-in-the-Middle (MITM) attack is when a hacker secretly intercepts and potentially alters the communication between two parties, like a user and a website, without either party knowing. The attacker can eavesdrop on the conversation, steal sensitive information like passwords or credit card details, or manipulate the data being exchanged. It\u2019s like someone secretly listening to and tampering with a private conversation.<\/p>\n<p><strong>VPN \u2013 <\/strong>A Virtual Private Network (VPN) is a tool that creates a secure, private connection between your device and the internet. It hides your online activity and location, making it harder for hackers, advertisers, or anyone else to see what you\u2019re doing or track you. It&#8217;s like a private, encrypted tunnel that keeps your data safe and protects your privacy while you&#8217;re online.<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>ELTENI&#8217;S CYBER SCOOP Latest News In this newsletter, we highlight a new CISA incident reporting tool, how to identify a Business Email Compromise and additional developments on the [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":19621,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[114,67,134,113,68,3,133,135,101,102,103,18,140,136,47,17,25,106,137,89,138,90,127,19],"tags":[],"class_list":["post-19620","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-alternative-asset-management","category-awareness","category-breaches","category-business-email-compromise","category-cloud","category-cyber","category-finra","category-ftc","category-hackers","category-hedge-fund","category-investment-adviser","category-microsoft","category-newsletter","category-nydfs","category-ocie","category-password","category-pii","category-private-equity","category-private-funds","category-regulatory","category-rules","category-sec","category-technology","category-vulnerability"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>2024 September Newsletter - Insights<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.elteni.com\/insights\/?p=19620\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"2024 September Newsletter - Insights\" \/>\n<meta property=\"og:description\" content=\"ELTENI&#8217;S CYBER SCOOP Latest News In this newsletter, we highlight a new CISA incident reporting tool, how to identify a Business Email Compromise and additional developments on the [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.elteni.com\/insights\/?p=19620\" \/>\n<meta property=\"og:site_name\" content=\"Insights\" \/>\n<meta property=\"article:published_time\" content=\"2024-09-09T13:29:01+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.elteni.com\/insights\/wp-content\/uploads\/2024\/09\/September-Newsletter-Thumbnail.png\" \/>\n\t<meta property=\"og:image:width\" content=\"814\" \/>\n\t<meta property=\"og:image:height\" content=\"1057\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"dtuck\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"dtuck\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=19620#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=19620\"},\"author\":{\"name\":\"dtuck\",\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/#\\\/schema\\\/person\\\/14c8aed9360eb93e744ed177fab3c94b\"},\"headline\":\"2024 September Newsletter\",\"datePublished\":\"2024-09-09T13:29:01+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=19620\"},\"wordCount\":972,\"image\":{\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=19620#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/wp-content\\\/uploads\\\/2024\\\/09\\\/September-Newsletter-Thumbnail.png\",\"articleSection\":[\"Alternative Asset Management\",\"Awareness\",\"Breaches\",\"Business Email Compromise\",\"Cloud\",\"Cyber\",\"FINRA\",\"FTC\",\"Hackers\",\"Hedge Fund\",\"Investment Adviser\",\"Microsoft\",\"Newsletter\",\"NYDFS\",\"OCIE\",\"Password\",\"PII\",\"Private Equity\",\"Private Funds\",\"Regulatory\",\"Rules\",\"SEC\",\"Technology\",\"Vulnerability\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=19620\",\"url\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=19620\",\"name\":\"2024 September Newsletter - Insights\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=19620#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=19620#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/wp-content\\\/uploads\\\/2024\\\/09\\\/September-Newsletter-Thumbnail.png\",\"datePublished\":\"2024-09-09T13:29:01+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/#\\\/schema\\\/person\\\/14c8aed9360eb93e744ed177fab3c94b\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=19620#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=19620\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=19620#primaryimage\",\"url\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/wp-content\\\/uploads\\\/2024\\\/09\\\/September-Newsletter-Thumbnail.png\",\"contentUrl\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/wp-content\\\/uploads\\\/2024\\\/09\\\/September-Newsletter-Thumbnail.png\",\"width\":814,\"height\":1057},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=19620#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.elteni.com\\\/insights\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"2024 September Newsletter\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/#website\",\"url\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/\",\"name\":\"Insights\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/#\\\/schema\\\/person\\\/14c8aed9360eb93e744ed177fab3c94b\",\"name\":\"dtuck\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/?s=96&d=mm&r=g\",\"caption\":\"dtuck\"},\"url\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?author=3\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"2024 September Newsletter - Insights","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.elteni.com\/insights\/?p=19620","og_locale":"en_US","og_type":"article","og_title":"2024 September Newsletter - Insights","og_description":"ELTENI&#8217;S CYBER SCOOP Latest News In this newsletter, we highlight a new CISA incident reporting tool, how to identify a Business Email Compromise and additional developments on the [&hellip;]","og_url":"https:\/\/www.elteni.com\/insights\/?p=19620","og_site_name":"Insights","article_published_time":"2024-09-09T13:29:01+00:00","og_image":[{"width":814,"height":1057,"url":"https:\/\/www.elteni.com\/insights\/wp-content\/uploads\/2024\/09\/September-Newsletter-Thumbnail.png","type":"image\/png"}],"author":"dtuck","twitter_card":"summary_large_image","twitter_misc":{"Written by":"dtuck","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.elteni.com\/insights\/?p=19620#article","isPartOf":{"@id":"https:\/\/www.elteni.com\/insights\/?p=19620"},"author":{"name":"dtuck","@id":"https:\/\/www.elteni.com\/insights\/#\/schema\/person\/14c8aed9360eb93e744ed177fab3c94b"},"headline":"2024 September Newsletter","datePublished":"2024-09-09T13:29:01+00:00","mainEntityOfPage":{"@id":"https:\/\/www.elteni.com\/insights\/?p=19620"},"wordCount":972,"image":{"@id":"https:\/\/www.elteni.com\/insights\/?p=19620#primaryimage"},"thumbnailUrl":"https:\/\/www.elteni.com\/insights\/wp-content\/uploads\/2024\/09\/September-Newsletter-Thumbnail.png","articleSection":["Alternative Asset Management","Awareness","Breaches","Business Email Compromise","Cloud","Cyber","FINRA","FTC","Hackers","Hedge Fund","Investment Adviser","Microsoft","Newsletter","NYDFS","OCIE","Password","PII","Private Equity","Private Funds","Regulatory","Rules","SEC","Technology","Vulnerability"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.elteni.com\/insights\/?p=19620","url":"https:\/\/www.elteni.com\/insights\/?p=19620","name":"2024 September Newsletter - Insights","isPartOf":{"@id":"https:\/\/www.elteni.com\/insights\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.elteni.com\/insights\/?p=19620#primaryimage"},"image":{"@id":"https:\/\/www.elteni.com\/insights\/?p=19620#primaryimage"},"thumbnailUrl":"https:\/\/www.elteni.com\/insights\/wp-content\/uploads\/2024\/09\/September-Newsletter-Thumbnail.png","datePublished":"2024-09-09T13:29:01+00:00","author":{"@id":"https:\/\/www.elteni.com\/insights\/#\/schema\/person\/14c8aed9360eb93e744ed177fab3c94b"},"breadcrumb":{"@id":"https:\/\/www.elteni.com\/insights\/?p=19620#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.elteni.com\/insights\/?p=19620"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.elteni.com\/insights\/?p=19620#primaryimage","url":"https:\/\/www.elteni.com\/insights\/wp-content\/uploads\/2024\/09\/September-Newsletter-Thumbnail.png","contentUrl":"https:\/\/www.elteni.com\/insights\/wp-content\/uploads\/2024\/09\/September-Newsletter-Thumbnail.png","width":814,"height":1057},{"@type":"BreadcrumbList","@id":"https:\/\/www.elteni.com\/insights\/?p=19620#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.elteni.com\/insights"},{"@type":"ListItem","position":2,"name":"2024 September Newsletter"}]},{"@type":"WebSite","@id":"https:\/\/www.elteni.com\/insights\/#website","url":"https:\/\/www.elteni.com\/insights\/","name":"Insights","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.elteni.com\/insights\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/www.elteni.com\/insights\/#\/schema\/person\/14c8aed9360eb93e744ed177fab3c94b","name":"dtuck","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/?s=96&d=mm&r=g","caption":"dtuck"},"url":"https:\/\/www.elteni.com\/insights\/?author=3"}]}},"_links":{"self":[{"href":"https:\/\/www.elteni.com\/insights\/index.php?rest_route=\/wp\/v2\/posts\/19620","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.elteni.com\/insights\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.elteni.com\/insights\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.elteni.com\/insights\/index.php?rest_route=\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.elteni.com\/insights\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=19620"}],"version-history":[{"count":0,"href":"https:\/\/www.elteni.com\/insights\/index.php?rest_route=\/wp\/v2\/posts\/19620\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.elteni.com\/insights\/index.php?rest_route=\/wp\/v2\/media\/19621"}],"wp:attachment":[{"href":"https:\/\/www.elteni.com\/insights\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=19620"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.elteni.com\/insights\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=19620"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.elteni.com\/insights\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=19620"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}