A report by the Government Accountability Office (GAO) has criticized the Department of Health and Human Services (HHS) for failing to implement several recommended cybersecurity measures. The GAO found that the HHS had not adequately monitored the healthcare sector’s implementation of ransomware mitigation and failed to track adoption of certain practices. The report also stated that HHS lacks full awareness of the sector’s cybersecurity practices, risking misallocation of resources.

New Malware Loaders Use Call Stack Spoofing, GitHub C2, and .NET Reactor for Stealth
An updated version of a malware loader, known as Hijack Loader, has been discovered with new features aimed at evading detection and maintaining persistence. The