Cybercrimes tend to increase during the holiday season, as malicious actors take advantage of the increased employee travel and distractions that are more common during the holiday season. To help protect from cyberattacks during the busy holiday season, the FBI and CISA compiled several recommendations that employees can take now to prevent from these kinds of attacks.
Read More
On August 20th, 2024, the SEC announced that it settled charges against Equiniti Trust Company LLC (formerly American Stock & Trust Company, LLC) due to failing to ensure client securities and funds were protected from theft. Equiniti Trust Company LLC (“Equiniti”) incurred two cyber incidents from 2022 to 2023 that resulted in the loss of more than $6.6 million of client funds.
In March, the U.S. Department of Treasury has released its newest report, Managing Artificial Intelligence- Specific Cybersecurity Risks in the Financial Services Sector. The report, which was mandated by Executive Order 14110, Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence, outlines the current state of AI as it relates to the financial industry, as well as best practices for managing and utilizing AI, largely in relation to growing fraud and cybersecurity threats associated with AI.
The SEC announced on Monday that it settled charges against two investment advisers, Delphia (USA) Inc. and Global Predictions Inc., for making false and misleading statements about their purported use of artificial intelligence (AI), according to a SEC press release. This is the first time the SEC has fined investment advisers for false and misleading statements about their use of AI.
Last week, the National Institute of Standards and Technology (NIST) released version 2.0 of its widely used Cybersecurity Framework (CSF), its landmark guidance document for reducing cybersecurity risk. This is the first major update since the framework was initially launched in 2014 to help organizations understand, mitigate, and communicate cybersecurity-related risks.
An active phishing campaign using individualized phishing lures is targeting senior corporate accounts in Microsoft Azure environments, according to researchers from Proofpoint, a company that provides cybersecurity products and software.