Darktrace: 96% of Phishing Attacks in 2024 Exploited Trusted Domains

Darktrace: 96% of Phishing Attacks in 2024 Exploited Trusted Domains

Threat actors are increasingly targeting trusted business platforms such as Dropbox, SharePoint, and QuickBooks in their phishing email campaigns and leveraging legitimate domains to bypass security measures, a new report released today has found. By embedding sender addresses or payload links within legitimate domains, attackers evade traditional detection methods and deceive unsuspecting users. According to Darktrace’s Annual Threat Report 2024, the authors detected more than 30.4 million phishing emails, reinforcing phishing as the preferred attack…

Read More

IT Leaders Fear AI-Driven Cybersecurity Costs Will Soar

IT Leaders Fear AI-Driven Cybersecurity Costs Will Soar

IT leaders are concerned about the rocketing costs of cyber security tools, which are being inundated with AI features. Meanwhile, hackers are largely eschewing AI, as there are relatively few discussions about how they could use it posted on cyber crime forums. Featured Partners: Artificial Intelligence (AI) Software 1 New Relic Visit website Optimize your business operations with New Relic’s comprehensive observability platform. Designed for multi-dimensional enterprises, it provides real-time insights and robust application performance…

Read More

Cyber Attack Severity Rating System Established in U.K.

Cyber Attack Severity Rating System Established in U.K.

A new rating system in the U.K. will classify the severity of cyberattacks on a scale from one to five, aiming to provide businesses and policymakers with more precise insights into the impact of cyber threats. The Cyber Monitoring Centre, an independent nonprofit organisation of industry experts, will assess incidents in real time and publish results for free. The system is designed to be easily understood, similar to the Saffir-Simpson hurricane scale, which categorises hurricanes…

Read More

Ransomware Payments Decreased by 35% in 2024

Ransomware Payments Decreased by 35% in 2024

Ransomware payments took an unexpected plunge in 2024, dropping 35% to approximately $813.55 million — despite payouts surpassing $1 billion for the first time in 2023. The decline was largely driven by a series of successful law enforcement takedowns and improved cyber hygiene, which enabled more victims to refuse payment, according to blockchain platform Chainalysis. The drop came as a surprise, considering the upward trend seen earlier in the year. In fact, ransomware actors extorted…

Read More

Sophos Acquires Secureworks for $859 Million | TechRepublic

Sophos Acquires Secureworks for 9 Million | TechRepublic

Sophos has completed its $859 million acquisition of managed cyber security services provider Secureworks in an all-cash transaction. It now claims to be the “leading pure-play” provider of Managed Detection and Response Services, supporting more than 28,000 global organisations. Secureworks is an Atlanta, U.S.-based cybersecurity company that focuses on threat detection, response, and managed security services. Its acquisition will build out Sophos’ security operations platform for mitigating cyber attacks. “The open and scalable platform helps…

Read More

U.K. Announces 'World-First' Cyber Code of Practice

U.K. Announces 'World-First' Cyber Code of Practice

The U.K. government has introduced its “world-first” AI Cyber Code of Practice for companies developing AI systems. The voluntary framework outlines 13 principles designed to mitigate risks such as AI-driven cyberattacks, system failures, and data vulnerabilities. The voluntary code applies to developers, system operators, and data custodians at organisations that create, deploy, or manage AI systems. AI vendors that only sell models or components fall under other relevant guidelines. “From securing AI systems against hacking…

Read More

Top cybersecurity conferences in 2025

Top cybersecurity conferences in 2025

All around the world, security leaders gather to network and share findings from their respective organizations. Security magazine highlights a few upcoming cybersecurity conferences in 2025. Africa CISO Summit Nairobi, Kenya March 19 — 20, 2025 The Africa CISO Summit 2025 is a unique gathering that convenes over 200 of the continent’s foremost cybersecurity leaders, decision-makers, and innovators. This March, Nairobi will host an exclusive forum designed to address the pressing challenges faced by the…

Read More

Phishing Emails in Australia Rise by 30%

Phishing Emails in Australia Rise by 30%

The number of phishing emails received by Australians surged by 30% last year, new research by security firm Abnormal Security has found. Cybercriminals have increasingly targeted the Asia-Pacific region, partly because it is becoming a larger player in critical industries like data centres and telecoms. For APAC as a whole, credential phishing attacks rose by 30.5% between 2023 and 2024, according to the research. New Zealand saw a 30% rise, while for Japan and Singapore,…

Read More

GhostGPT: New Chatbot for Malware Creation, Scams

GhostGPT: New Chatbot for Malware Creation, Scams

Security researchers have discovered a new malicious chatbot advertised on cybercrime forums. GhostGPT generates malware, business email compromise scams, and more material for illegal activities. The chatbot likely uses a wrapper to connect to a jailbroken version of OpenAI’s ChatGPT or another large language model, the Abnormal Security experts suspect. Jailbroken chatbots have been instructed to ignore their safeguards to prove more useful to criminals. Must-read security coverage What is GhostGPT? The security researchers found…

Read More

UK Considers Banning Ransomware Payments

UK Considers Banning Ransomware Payments

The U.K. government is considering banning ransomware payments to make critical industries “unattractive targets for criminals.” It would apply to all public sector bodies and critical national infrastructure, which includes NHS trusts, schools, local councils, and data centres. Currently, all government departments nationwide are banned from paying cyber criminals to decrypt their data or prevent it from being leaked. This rule intends to protect the services and infrastructure the British public relies on from financial…

Read More
1 2 3 130