Chinese government agencies are paying an APT, masked as a legitimate company, to spy on foreign and domestic targets of political interest.
Follow Dark Reading:
 February 23, 2024
LATEST SECURITY NEWS & COMMENTARY
iSoon's Secret APT Status Exposes China's Foreign Hacking Machinations
Chinese government agencies are paying an APT, masked as a legitimate company, to spy on foreign and domestic targets of political interest.
Pharmacy Delays Across US Blamed on Nation-State Hackers
Healthcare tech provider Change Healthcare says a suspected nation-state threat actor breached its systems, causing pharmacy transaction delays nationwide.
Hubris May Have Contributed to Downfall of Ransomware Kingpin LockBit
The most prolific ransomware group in recent years was on the decline at the time of its takedown, security researchers say.
Zero-Click Apple Shortcuts Vulnerability Allows Silent Data Theft
Vulnerability CVE-2024-23204, affecting Apple's popular Shortcuts app, suggests a critical need for ongoing security awareness in the macOS and iOS ecosystem.
NSA Cybersecurity Director Rob Joyce to Retire
His retirement will go into effect on March 31, concluding 34 years of service to the National Security Agency.
Iran-Backed Charming Kitten Stages Fake Webinar Platform to Ensnare Targets
The latest ploy by the APT also known as Charming Cypress targets policy experts in the Middle East, Europe, and the US.
4 Key Steps to Reevaluate Your Cybersecurity Priorities
Amid a spike in attacks, now is a good time for brands to strengthen their cybersecurity strategy.
(Sponsored Article) Transform Your Security Operations Center With AI
Attackers aren't slowing down and are using new methods to infiltrate orgs. To limit their impact, automation in the SOC is more critical now than ever.
MORE NEWS / MORE COMMENTARY
HOT TOPICS
Critical Vulnerability in VMware vSphere Plug-in Allows Session Hijacking
Admins are urged to remove vSphere's vulnerable Enhanced Authentication Plug-in, which was discontinued nearly three years ago but is still widely in use.

'Lucifer' Botnet Turns Up the Heat on Apache Hadoop Servers
More than 3,000 unique attacks hitting Hadoop and Druid honeypots in just the past month indicate an attacker testing phase, portending fire and brimstone to come.

How CISOs Balance Business Growth, Security in Cyber-Threat Landscape
Collaboration, care, and proactive planning need to be part of CISO toolboxes as worsening threat environments become the new normal. CISOs need to adjust processes so business innovation can continue.

MORE
PRODUCTS & RELEASES
EDITORS' CHOICE
Critical ConnectWise RMM Bug Poised for Exploitation Avalanche
Two days after disclosure, most instances of the remote desktop tool remain unpatched, while cyberattackers have started in-the-wild exploitation — and researchers warn it could get ugly, fast.
LATEST FROM THE EDGE

10 Security Metrics Categories CISOs Should Present to the Board
Boards of directors don't care about a security program's minute technical details. They want to see how key performance indicators are tracked and used.
LATEST FROM DR TECHNOLOGY

Insurers Use Claims Data to Recommend Cybersecurity Technologies
Policy holders using certain technologies — such as managed detection and response (MDR) services, Google Workspace, and email security gateways — gain premium discounts from cyber insurers.
LATEST FROM DR GLOBAL

Russian Cyberattackers Launch Multiphase PsyOps Campaign
Operation Texonto spanned several months, using various Russian propaganda lures and spear-phishing to misinform and trick users into giving up Microsoft 365 credentials.
WEBINARS
WHITE PAPERS
FEATURED REPORTS
View More Dark Reading Reports >>
Dark Reading Daily
-- Published By Dark Reading
Informa Tech Holdings LLC | Registered in the United States
with number 7418737 | 605 Third Ave., 22nd Floor, New York, New York 10158, USA
To opt-out of any future Dark Reading Daily Newsletter emails, please respond here.
Thoughts about this newsletter? Give us feedback.
Keep This Newsletter Out Of Your SPAM Folder
Don't let future editions go missing. Take a moment to add the newsletter's address to your anti-spam white list:
If you're not sure how to do that, ask your administrator or ISP. Or check your anti-spam utility's documentation.
We take your privacy very seriously. Please review our Privacy Statement.