Security News > 2025 > February

PCI DSS 4.0 Mandates DMARC By 31st March 2025
2025-02-20 11:21

The payment card industry has set a critical deadline for businesses handling cardholder data or processing payments- by March 31, 2025, DMARC implementation will be mandatory! This requirement...

Cybercriminals Use Eclipse Jarsigner to Deploy XLoader Malware via ZIP Archives
2025-02-20 11:12

A malware campaign distributing the XLoader malware has been observed using the DLL side-loading technique by making use of a legitimate application associated with the Eclipse Foundation. "The...

Darcula PhaaS can now auto-generate phishing kits for any brand
2025-02-20 11:00

The Darcula phishing-as-a-service (PhaaS) platform is preparing to release its third major version, with one of the highlighted features, the ability to create do-it-yourself phishing kits to...

Hackers pose as employers to steal crypto, login credentials
2025-02-20 10:00

Since early 2024, ESET researchers have been tracking DeceptiveDevelopment, a series of malicious campaigns linked to North Korea-aligned operators. Disguising themselves as software development...

Microsoft's End of Support for Exchange 2016 and 2019: What IT Teams Must Do Now
2025-02-20 10:00

For decades, Microsoft Exchange has been the backbone of business communications, powering emailing, scheduling and collaboration for organizations worldwide. Whether deployed on-premises or in...

Ghost ransomware crew continues to haunt IT depts with scarily bad infosec
2025-02-20 08:41

FBI and CISA issue reminder - deep sigh - about the importance of patching and backups The operators of Ghost ransomware continue to claim victims and score payments, but keeping the crooks at bay...

New NailaoLocker ransomware used against EU healthcare orgs
2025-02-20 08:00

A previously undocumented ransomware payload named NailaoLocker has been spotted in attacks targeting European healthcare organizations between June and October 2024. [...]

Medusa ransomware gang demands $2M from UK private health services provider
2025-02-20 07:34

2.3 TB held to ransom as biz formerly known as Virgin Care tells us it's probing IT 'security incident' Exclusive HCRG Care Group, a private health and social services provider, has seemingly...

Unknown and unsecured: The risks of poor asset visibility
2025-02-20 05:30

In this Help Net Security interview, Juliette Hudson, CTO of CybaVerse, discusses why asset visibility remains a critical cybersecurity challenge. She explains how to maintain security without...

300% increase in endpoint malware detections
2025-02-20 05:00

The third quarter of 2024 saw a dramatic shift in the types of malware detected at network perimeters, according to a new WatchGuard report. The report’s key findings include a 300% increase...