Tech Republic

100+ Hiring Kits Ready for Download

With the pace of business life moving quickly and relentlessly, it’s prudent for HR personnel to seek ways to save time. You could spend hours writing a hiring kit yourself, but consider how much your time is worth. It’s probable that you want to spend your efforts on finding the right candidate, not on the actual writing process. Each of our hiring kits contains a salary range, desirable skills, job description, interview questions and a job ad. Subscribe to TechRepublic Premium and get access to 100+ ready-made hiring kits. Just download a hiring kit and customize it to fit your company’s needs. Best of all, we’re constantly adding to our library. As technology changes, we publish new kits and update existing ones. Whether you need a CTO, social media analyst, or cloud engineer, we’ve got you covered. A sample of TechRepublic Premium’s hiring kits Members get access to all our policies, glossaries, and more In addition to all our hiring kits, TechRepublic Premium members get access to all our other great resources, including policies, glossaries, checklists, and features. source

100+ Hiring Kits Ready for Download Read More »

MWC 2025: Nothing Shows Off Its Phone (3A) Line

Image: Nothing Like last year, the London-based independent smartphone company Nothing announced a new model during Mobile World Congress. The Phone (3A) line continues Nothing’s trend of distinct visual design with modernized cameras and an artificial intelligence feature: Essential Space. Two models make up the Phone (3A) line: (3A) and (3A) Pro. The basic (3A) model costs $379; it can be preordered starting March 4, shipping March 11. The (3A) Pro model costs $459; it can be ordered starting March 11, shipping March 25. UK-based Nothing phone has limited U.S. availability To get a Nothing phone in the U.S., you’ll need to be enrolled in the company’s beta program, which has been in place since the (2A) line and provides the same unit that can be purchased globally. Beta program users are encouraged to participate in community forums and provide feedback. Compatibility with U.S. phone carriers can be limited, and 5G is generally not supported. Nothing phones are compatible with global networks worldwide. Mobility must-reads Phone (3A) line has impressive specs and design Both models of the Phone (3A) have 12 GB of RAM and 256 GB of storage. Both models boast 6.77 inches of screen space. The Pro offers a premium camera with a 3x periscope telephoto lens compared to the base model’s 2x zoom. The battery life supports up to 26 hours of YouTube video. The Nothing OS 3.1 operating system is based on Android 15 and comes with three years of Android updates. Nothing’s distinct rear lights sync with applications The geometric design is intended to have more of “a sense of sophistication” compared to its predecessor. The Nothing phone’s geometric design and prominent ring around the cameras will likely have your friends asking what kind of phone you have. The “Glyph” interface, as Nothing calls the ring of lights around the camera, enable an interface unlike anything on a mainstream smartphone: Those lights can indicate notifications, go off in conjunction with alarms, sync up to music, or indicate a countdown when taking a picture. Essential Space organizes your content with AI Inside the Nothing (3A) line sits a Qualcomm Snapdragon 7s Gen 3 5G processor built on TSMC’s 4nm process. A Hexagon Tensor Accelerator AI engine enables the Essential Space function. This unique function has a designated button to take you to a panel including personalized suggestions, summaries, or to-dos. Nothing said the AI function is “coming soon” – for now, the Essential Space will be populated by screenshots or photos you’ll choose manually. Voice memos can be paired with the screenshots in order to take notes of what about that moment inspired you. The AI portion can generate a to-do list, including time slots, from natural language if you tell it what you need to do. The Nothing company said a meeting transcription function, including the ability to recognize individual speakers and generate to-do lists from transcripts, is coming soon to Essential Space. source

MWC 2025: Nothing Shows Off Its Phone (3A) Line Read More »

5 Best Accounting Software for E-commerce 2025

In selecting the best accounting software for e-commerce businesses, I recommend one that can sync transactions between the e-commerce platform and accounting software, track multi-channel sales, reconcile payments, handle sales tax, and automate COGS and returns for accurate reporting. With that in mind, here are the software that made it to my list: Acumatica Cloud ERP Employees per Company Size Micro (0-49), Small (50-249), Medium (250-999), Large (1,000-4,999), Enterprise (5,000+) Any Company Size Any Company Size Features Accounts Receivable/Payable, API, Departmental Accounting, and more QuickBooks Employees per Company Size Micro (0-49), Small (50-249), Medium (250-999), Large (1,000-4,999), Enterprise (5,000+) Micro (0-49 Employees), Small (50-249 Employees), Medium (250-999 Employees), Large (1,000-4,999 Employees) Micro, Small, Medium, Large Features API, General Ledger, Inventory Management Quicken Business & Personal Employees per Company Size Micro (0-49), Small (50-249), Medium (250-999), Large (1,000-4,999), Enterprise (5,000+) Micro (0-49 Employees) Micro Features Accounts Receivable/Payable, Invoicing / Billing, Mobile Capabilities, and more Quick comparison of the best accounting software for e-commerce Monthly price My overall rating (out of 5) Accounting features rating (out of 5) E-commerce features rating (out of 5) QuickBooks Online $35 to $235 4.4 4.7 4.0 Xero $20 to $80 4.2 4.7 3.6 Zoho Books $0 to $240 4.1 4.8 3.3 Sage Intacct Custom 3.9 5.0 3.2 Wave $0 or $16 3.3 3.3 1.6 Rating: 5 (Excellent); 4 (Very Good); 3 (Good); 2 (Fair); 1 (Poor). For a detailed explanation, check my methodology below. QuickBooks Online: Best overall Image: QuickBooks Online My rating: 4.4 out of 5 QuickBooks Online leads my roundup of the best e-commerce accounting software, primarily because it offers direct integrations with Shopify and BigCommerce. While platforms like Amazon, eBay, and Squarespace lack native QuickBooks connections, they sync seamlessly through third-party connectors like A2X, Zapier, and Webgility — all of which integrate well with QuickBooks Online. Beyond its powerful features, QuickBooks is widely used across the US. This makes it an ideal choice if you’re looking to outsource bookkeeping to independent CPAs or firms specializing in e-commerce accounting. Pricing Simple Start: $35 per month for one seat Essentials: $65 per month for two users Plus: $99 per month for five seats Advanced: $235 per month for 25 users You can try QuickBooks Online free for 30 days or get a 50% discount for three months if you sign up right away. My evaluation QuickBooks Online earns high marks for both accounting and e-commerce functionality. Its strength in accounting is expected, given its versatility, but what stands out is its e-commerce adaptability. While not an e-commerce platform itself, QuickBooks Online integrates directly and via third-party apps with major e-commerce platforms. The built-in Mailchimp integration within Intuit also makes abandoned cart email automation seamless. Moreover, it did well in ecommerce features due to its strong integrations and automation but lost points for lacking built-in abandoned cart tracking and advanced marketplace reporting. While it syncs with Shopify, Amazon, and eBay, multi-channel sellers may need third-party apps like A2X for detailed revenue attribution and reconciliation. Despite this, it remains a top choice for small or midsize businesses. The main drawback of QuickBooks Online is scalability, as it limits the number of seats to a maximum of 25. If you need more users, Xero might be the better option. But if you need more seats and have outgrown QuickBooks, I highly recommend Sage Intacct. Read our QuickBooks Online review Pros and cons Pros Cons Syncs seamlessly with Shopify and BigCommerce Tracks COGS accurately with inventory management integrations Reconciles payments from Stripe, PayPal, and other processors with minimal manual work Provides detailed financial reports with sales channel breakdowns Lacks native abandoned cart revenue tracking and attribution Requires third-party apps for advanced e-commerce analytics Charges extra for multicurrency transactions Struggles with high transaction volumes, leading to occasional slowdowns Xero: Best for growing companies with multicurrency needs Image: Xero My rating: 4.2 out of 5 Xero is my pick for growing companies because it provides unlimited seats in all plans. On top of that, it offers outstanding features in multicurrency transactions, making it a great pick for e-commerce businesses with international transactions. It also integrates with Shopify, Amazon, WooCommerce, BigCommerce, and more via third-party apps like A2X, Webgility, and Synder. These integrations automate sales data syncing, tax calculations, and COGS tracking. Its bank feeds and automatic reconciliation streamline payment processing from Stripe, PayPal, and other gateways, reducing manual work. Pricing Early: $20 per month (limited to 20 invoices and five bills) Growing: $47 per month Established: $80 per month Get 90% off for three months when you sign up, or try a plan for 30 days and pay the regular rate after the trial. My evaluation Xero goes head-to-head with QuickBooks Online but stands out for scalability and global e-commerce support. Unlike QuickBooks, it allows unlimited users, making it ideal for growing businesses needing access for accountants, finance teams, and e-commerce managers. Another key advantage is its multicurrency support. It automatically converts transactions in over 160 currencies with real-time exchange rates, which is essential for international sales on platforms like Amazon, Shopify, and eBay. However, Xero didn’t score as high in e-commerce features because its integration options and reporting capabilities aren’t as polished. The platform’s editor lacks flexibility, making it frustrating to customize reports or streamline workflows for e-commerce businesses. Additionally, Xero is less popular in the US, where QuickBooks Online dominates the market. Many US CPAs and bookkeepers are QuickBooks ProAdvisors, making QuickBooks Online ideal for businesses wanting to outsource their bookkeeping. Read our review of Xero Pros and cons Pros Cons Syncs with Shopify, Amazon, eBay, and other platforms via third-party apps Supports multicurrency transactions and automatic exchange rate updates Automates sales tax tracking and integrates with Avalara for compliance Provides customizable financial reports with multi-channel tracking Limits automation for high-volume e-commerce businesses Charges extra for multicurrency functionality Lacks native integration for abandoned cart revenue tracking Zoho Books: Best for automation and customization Image: Zoho Books My rating: 4.1 out of 5 Zoho Books is tightly integrated within

5 Best Accounting Software for E-commerce 2025 Read More »

Apple’s Rumored 1st Foldable iPhone: Price, Features & Release Date

Image: Ming-Chi Kuo Apple is reportedly working on a foldable smartphone, according to analyst Ming-Chi Kuo, who shared details on March 5. Kuo works for TF International Securities and gathers information from Apple’s suppliers in Asia. He claimed the device will feature a 7.8-inch inner display that folds vertically, without a visible crease, along with a 5.5-inch outer display. The phone is expected to retail between $2,000 and $2,500. Despite the premium price tag, Kuo said Apple’s fanbase is unlikely to be deterred, and the company predicts the foldable phone will “generate strong replacement demand” as long as the quality lives up to expectations. For comparison, the larger variant of the iPhone 16 Pro Max costs $1,199. Must-read Apple coverage Foldable iPhone rumored to come out in 2026 Foldable phones are eye-catching, but the hinge can break under strain, making them more likely to need repair than a flat model. Apple’s hinge will be made of stainless steel and titanium alloy, Kuo said. Mass production is reportedly scheduled for 2026, with a second-generation model potentially launching the following year. Apple continues to expand its generative AI features, and the foldable phone is expected to be a key part of this strategy. Its larger, split-screen design could enable new AI-driven experiences, such as having an AI chatbot on one screen and a map open on the other, Kuo said. SEE: The new MacBook Air has a price tag $100 less than its predecessor. Face ID unlikely due to design constraints On the other hand, Kuo also suggested that Face ID probably won’t work on the foldable phone because of mechanical constraints related to the phone’s thickness (4.5–4.8mm when unfolded). Instead, Apple is expected to integrate Touch ID into the side button. The device will reportedly feature a single front-facing camera that works whether the phone is open or closed, while a rear-facing camera remains enclosed within the folded panels. Apple faces tough competition in the foldable market Apple is entering a foldable phone market already dominated by Google and Samsung. The Google Pixel 9 Pro Fold, with its horizontal or book-like shape, sold for $1,799. Samsung makes a foldable phone (the Galaxy Z Fold 6) and a flip phone (the Galaxy Z Flip 6). Meanwhile, Motorola is also hanging on to its retro cred with the 2024 Razr line. source

Apple’s Rumored 1st Foldable iPhone: Price, Features & Release Date Read More »

New MacBook Air Brings the M4 Chip and a $100 Lower Price Tag

The MacBook Air comes in a new color: sky blue. Image: Apple. The Apple “Air” rumors we’ve been hearing turned out to apply to both a new iPad Air and a MacBook Air. On March 5, Apple revealed the new MacBook Air comes with its in-house M4 chip, 16 GB of unified memory, and Apple Intelligence with macOS Sequoia. The M4 offers a 10-core CPU, up to 10-core GPU, and support for up to 32 GB of unified memory. The new MacBook Air starts at $999 — pretty low for a Mac and $100 less than the previous generation MacBook Air — for the 13-inch version, while the 15-inch version costs $1,199. It can hook to two 6K external displays. The new 13- and 15-inch MacBook Air are available to pre-order today, with availability beginning March 12. “With a new lower starting price of $999, MacBook Air delivers more value to consumers than ever before, making this the perfect moment to upgrade or experience the Mac for the first time,” said Greg Joswiak, Apple’s senior vice president of Worldwide Marketing, in a press release. SEE: Pre-order Apple’s New iPad Air With Powerful M3 Chip and AI Now Must-read Apple coverage New Mac Studio offers options of 36 GB or 96 GB of memory Apple has also refreshed its professional desktop computer, Mac Studio. Powered by the M3 Ultra chip, plus an up to 16 TB SSD storage, Mac Studio maintains Apple’s place in the high-performance workstation market. The Mac Studio comes in two versions: one with the M3 Ultra for $1,999 or with the M4 Max for $3,999. The more expensive version raises the stats from 36 GB of memory and 512 GB of storage to 96 GB of memory and 1 TB of storage. The Mac Studio box can power professional productivity. Image: Apple Apple M3 Ultra can support half a terabyte of memory Apple’s newest and most powerful chip, the M3 Ultra, will appear in the Mac Studio Pro desktop starting March 12. “M3 Ultra is the pinnacle of our scalable system-on-a-chip architecture, aimed specifically at users who run the most heavily threaded and bandwidth-intensive applications,” Johny Srouji, Apple’s senior vice president of Hardware Technologies, said in a press release. The M3 Ultra starts at 96 GB of memory, and can be configured up to 512 GB. Apple said the chip is optimized for graphics professionals, including those working in 3D rendering, visual effects, and AI. Additional storage options include up to 16 TB of ultrafast SSD storage. SEE: Apple is taking the UK government to court over their request for a backdoor into encrypted iCloud data. Apple’s own UltraFusion packaging architecture enables connecting two M3 Max dies, with over 10,000 high-speed connections for low latency and high bandwidth. The M3 Ultra also includes: A Thunderbolt 5 with 120 Gb/s data transfer speeds, more than 2x the bandwidth per port compared to Thunderbolt 4. A 32-core CPU with 24 performance cores and eight efficiency cores. An 80-core GPU, the largest in Apple’s history. A dynamic caching, hardware-accelerated mesh shading, and ray tracing for gaming, game development, and other professional graphics work.  A 32-core Neural Engine for machine learning and the Apple Intelligence generative AI. 800GB/s of memory bandwidth. Secure enclave, an isolated subsystem for sensitive user data. Along with the other features designed for AI, the M3 Ultra can run large language models up to 600 billion parameters on device. source

New MacBook Air Brings the M4 Chip and a $100 Lower Price Tag Read More »

5 Best Squarespace Alternatives in 2025

Squarespace is a solid choice for building websites, but it’s not the best fit for everyone. While its design templates are polished, and its interface is beginner-friendly, it has notable limitations — especially when it comes to pricing, customization, and flexibility. If you need deeper integrations, better performance, or a more cost-effective hosting solution, Squarespace may not be the right tool for you. After evaluating key factors like performance, security, ease of use, and pricing, I’ve identified the five best Squarespace alternatives for 2025. Each option on this list offers something that Squarespace doesn’t — whether that’s stronger WordPress integration, better scalability, or a lower entry price. By the end of this guide, you’ll know which best Squarespace alternative suits your needs. 1 Zoho Sprints Employees per Company Size Micro (0-49), Small (50-249), Medium (250-999), Large (1,000-4,999), Enterprise (5,000+) Any Company Size Any Company Size Features Burn-down Charts, Epics, Kanban, and more 2 NordLayer Employees per Company Size Micro (0-49), Small (50-249), Medium (250-999), Large (1,000-4,999), Enterprise (5,000+) Small (50-249 Employees), Medium (250-999 Employees), Large (1,000-4,999 Employees), Enterprise (5,000+ Employees) Small, Medium, Large, Enterprise 3 NinjaOne Employees per Company Size Micro (0-49), Small (50-249), Medium (250-999), Large (1,000-4,999), Enterprise (5,000+) Small (50-249 Employees), Medium (250-999 Employees), Large (1,000-4,999 Employees), Enterprise (5,000+ Employees) Small, Medium, Large, Enterprise Features Monitoring, Patch Management Top Squarespace alternatives Provider Overall Rating Best For Starting Price Performance Ease of Use Security Notable Features DreamHost 4.23 Best Overall $4.95/mo 4.79 4.69 4.82 WordPress integration, performance Hostinger 4.19 Best Budget Option $1.99/mo 3.75 4.69 4.46 Affordable, good support GoDaddy 3.72 Best for Ease of Use $7.99/mo 3.33 3.75 4.46 Domain management, simple setup ScalaHosting 3.91 Best for Security $12.95/mo 3.33 4.06 4.64 Security features, performance Bluehost 3.60 Best for WordPress $2.95/mo 3.54 4.06 3.93 WordPress-focused DreamHost: Best overall Squarespace alternative Image: DreamHost Dreamhost pros & cons Pros: Excellent uptime and performance User-friendly control panel Good customer support Cons: Slightly higher pricing on renewal Limited third-party integrations DreamHost is an excellent alternative to Squarespace, offering robust performance, great security, and strong WordPress integration. Unlike Squarespace, DreamHost provides more control over customization while maintaining ease of use. Why I chose DreamHost DreamHost is the best among Squarespace alternatives because it delivers superior performance (4.79/5) and security (4.82/5) at a competitive price. Unlike Squarespace, which prioritizes ease of use over customization, DreamHost gives users far more control over their website — especially for those who want to use WordPress. While Squarespace limits advanced configurations, DreamHost allows for complete site ownership, custom plugins, and deep backend modifications, making it a more flexible choice for developers and businesses with growing needs. DreamHost excels in server performance and reliability, making it the best option for websites that prioritize speed and uptime. While Scala Hosting offers strong security features, DreamHost balances security with ease of use, making it more accessible for users who need a powerful yet manageable hosting solution. If you’re looking for a platform that delivers both customization and high-end performance, DreamHost is the strongest alternative to Squarespace. Dreamhost pricing Plan Type DreamHost Starting Price Key Features Shared Hosting $4.95/month for the first 3 months, then $7.99/month after 1 website, free domain, AI website builder, free WordPress migrations, 97-day money-back guarantee Managed WordPress $19.95/month for the first 3 months, then $23.99/month after Free priority site migration, WordPress installer, 2 weeks of backups, unlimited email VPS Hosting $15.00/month for the first 3 months, then $37.99 /month after (for the basic VPS tier) Unlimited websites, 24/7 support, 2 GB RAM, 2 vCPU Cores Dedicated Hosting Starts at $165/month Root Access, local MySQL database server, Ubuntu, Server Monitoring, DDoS Protection Standout features of Bluehost Optimized WordPress Hosting: Officially recommended by WordPress.org, with one-click installation and automatic updates. Industry-Leading Security: Free SSL, domain privacy, daily backups, and built-in malware protection. 100% Uptime Guarantee: Unlike Squarespace, DreamHost offers a formal uptime SLA with compensation for downtime. Scalable VPS & Dedicated Hosting: More advanced hosting options for growing businesses that need greater control. Unlimited Bandwidth & Storage: Most plans include unlimited traffic and SSD storage, unlike Squarespace’s tiered limits. DreamHost top integrations DreamHost supports a wide range of integrations, strongly emphasizing WordPress and open-source flexibility. Unlike Squarespace, which has a closed ecosystem, DreamHost allows users to install custom plugins, third-party apps, and advanced developer tools. It integrates seamlessly with WooCommerce for e-commerce, Jetpack for security and performance, and Google Workspace for business email and productivity. However, it lacks native drag-and-drop website builders like Squarespace, so users looking for a no-code experience may need to install Elementor or other WordPress page builders separately. Hostinger: Best budget Squarespace alternative Image: Hostinger Hostinger pros & cons Pros: Cheapest option with good performance Easy setup for beginners Great customer support Cons: Limited advanced features Fewer integrations than other providers Why I chose Hostinger Hostinger is the best budget-friendly alternative to Squarespace, offering some of the lowest hosting prices without compromising performance or ease of use. While Squarespace’s cheapest plan starts at $16 per month, Hostinger’s hosting plans start at just $1.99 per month for a single website. This makes it better than Squarespace in that regard — granted you don’t really need an overly-fancy, all-in-one solution; which is what most small businesses really need. Compared to DreamHost, Hostinger isn’t quite as powerful in terms of performance (3.75/5 vs. DreamHost’s 4.79/5), but it still delivers fast loading speeds and solid uptime at a fraction of the cost. It also edges out GoDaddy when it comes to value, offering better pricing and unlimited free SSL certificates. However, it has some limitations — fewer third-party integrations than DreamHost and a less robust support system than ScalaHosting — but Hostinger is the strongest choice for users prioritizing affordability. Hostinger pricing Plan Type Price (48-month term) Renewal Price Key Features Single $1.99/month $3.99/month 1 website, 50GB SSD storage, free SSL, managed WordPress Premium $2.99/month $7.99/month 100 websites, 100GB SSD, free domain, unlimited bandwidth Business $3.99/month $8.99/month 200GB SSD, daily backups, enhanced performance Cloud Startup $9.99/month $19.99/month 300

5 Best Squarespace Alternatives in 2025 Read More »

Salesforce Drops DEI Commitments, Reframes Equality as Legal Compliance

Image: Creative Commons Salesforce has effectively eliminated diversity hiring targets. The company removed specific hiring goals, including ones to increase the representation of women and minority groups, and the term “diversity” from its latest annual report, filed Wednesday. The move comes on the heels of a series of executive orders from President Donald Trump calling for the removal of diversity, equity, and inclusion (DEI) programs across the federal government and private sector. The San Francisco-based company is one of the U.S. government’s largest software vendors. What’s hot at TechRepublic A shift in tone Salesforce included a section titled “Equality, Diversity and Inclusion” in previous annual reports to outline initiatives aimed at building a more diverse workforce. Last year’s filing reaffirmed equality as a core value, emphasizing the company’s commitment to fostering an inclusive environment where employees could thrive. However, the latest report marks a shift in tone. The section was renamed “Equality,” with all references to DEI initiatives removed. Instead of detailing diversity efforts, the company now highlights its compliance with equal-pay and anti-discrimination laws across its global operations. The latest filing, presents equality as a matter of federal compliance, positioning legal adherence as the basis for maintaining an inclusive workplace. CEO Benioff has supported social issues Salesforce CEO Marc Benioff has long been vocal about social issues and expressed support for LGBTQ+ employees. “If someone is going to come after our employees and discriminate against them in any way,” he told Axios last month, “we will do everything we can to help them.” Benioff advocated for a tax increase in San Francisco so the city could fund initiatives to help the homeless, and threatened to withdraw investments from Indiana after the state passed a law permitting anti-gay discrimination on religious grounds, Bloomberg reported. Salesforce joins Amazon, Meta, Google, Target, and Walmart, among other companies that have also rolled back DEI initiatives. Last week, Apple announced it may adjust its DEI policies in response to changing legal and political measures. Several of Trump’s executive DEI orders have been challenged in court. source

Salesforce Drops DEI Commitments, Reframes Equality as Legal Compliance Read More »

DoJ Busts Alleged Global Hacking-for-Hire Network

Image: BirgitKorber, Getty Images/iStockphoto The Justice Department has charged 12 Chinese nationals for their alleged involvement in global hacker-for-hire activities. According to court documents, targets included the U.S. Treasury Department, journalists, and religious organisations. The attacks aimed to steal data and suppress free speech. The indictment names two officers of China’s Ministry of Public Security, eight employees of a private company known as both Anxun Information Technology and i-Soon, and two members of the hacking group Advanced Persistent Threat 27. All remain at large. “The Department of Justice will relentlessly pursue those who threaten our cybersecurity by stealing from our government and our people,” said Sue J. Bai, head of the department’s National Security Division, in a press release. “Today, we are exposing the Chinese government agents directing and fostering indiscriminate and reckless attacks against computers and networks worldwide, as well as the enabling companies and individual hackers that they have unleashed. We will continue to fight to dismantle this ecosystem of cyber mercenaries and protect our national security.” Must-read security coverage i-Soon was hired by the government officials to carry out attacks in the U.S. and abroad The two government officers allegedly hired i-Soon employees as freelance hackers between 2016 and 2023 to steal data while obscuring their involvement. They broke into email accounts, cellphones, servers, and websites of both specific and speculated victims. i-Soon’s U.S.-based targets included a religious group critical of the Chinese government, a China-focused human rights group, news organisations opposing the Chinese Communist Party or delivering uncensored news to Asia, a state research university, a New York State Assembly representative linked to a religious group banned in China, and multiple government departments. Beyond targeting political opponents, i-Soon operated as a profit-driven cyber mercenary firm. Non-U.S. targets included a religious leader and their office, a Hong Kong newspaper opposed to the Chinese government, and the foreign ministries of Taiwan, India, South Korea, and Indonesia. The Attorney’s Office of the Southern District of New York says that these targets were either of interest because of their criticism of the Chinese government or because of their communication with the U.S. i-Soon allegedly conducted hacking operations both at the request of Chinese intelligence agencies and independently, selling stolen data to them. It trained Ministry of Public Security employees in hacking independently and sold various cyber tools, including phishing, password-cracking, and system infiltration software. Its platforms targeted email, social media, and operating systems, with one tool specifically designed to hijack Twitter (now X) accounts. Using this tool, hackers could send victims phishing links that, once opened, granted them access to the account, bypassing security measures. They could then manipulate public opinion by sending, deleting, liking, and forwarding Tweets. i-Soon, which had more than 100 employees at times, is thought to have generated tens of millions of dollars for the Chinese government, charging between approximately $10,000 and $75,000 for each email inbox it successfully exploited. In addition to charges, the JusticeDepartment has seized several primary internet domains used by i-Soon to advertise its business, including ecoatmosphere.org, newyorker.cloud, heidrickjobs.com, and maddmail.site. Two APT27 members sold stolen data to the government via i-Soon and other organisations The APT27 members, Yin “YKC” Kecheng, 38, and Zhou “Coldface” Shuai, 45, also sold stolen data to organisations with links to the Chinese government, including i-Soon, over a period of years. They allegedly targeted U.S. defense contractors, technology firms, government agencies — including the Treasury — local governments, law firms, healthcare systems, and foreign ministries in Asia, resulting in millions of dollars in damages. Between August 2013 and December 2024, they used advanced hacking techniques, including scanning for zero-day vulnerabilities and installing malware such as web shells to maintain persistent access to victim networks. They stole credentials and used hop-point servers to exfiltrate data while utilising encrypted VPNs and VPS accounts to conceal their activities. Yin allegedly openly discussed his desire to target American victims, telling an associate he wanted to “mess with the American military” and “break into a big target” so that he could earn enough money to buy a car. He was also previously sanctioned for his role in hacking the Treasury Department in late 2024. Along with the individuals’ charges, the U.S. Attorney’s Office of the District of Columbia has seized the Virtual Private Server account and internet domains that facilitated their criminal activities. Rewards of up to $2 million each are now available for information leading to the arrests and convictions of Yin and Zhou. Separately, the Justice Department is offering up to $10 million for information leading to the identification or location of any person who engages in malicious cyber activities against U.S. critical infrastructure while acting under the direction of a foreign government. source

DoJ Busts Alleged Global Hacking-for-Hire Network Read More »

Develop Excel Skills From Basics to AI Integration With This $35 Course Bundle

TL;DR: Streamline your daily workflow with the latest Excel features, thanks to The Complete Microsoft Excel Training Bundle for just $34.99. Many people believe Excel is nothing more than a program for faster number crunching, but that is not the case. When you develop advanced Excel skills, you become far more valuable as a professional. Even if you have no Excel experience whatsoever, The Complete Microsoft Excel Training Bundle offers the information you need, and it’s currently on sale for only $34.99. Even with only the most basic computer literacy, you can start with the beginner-friendly Excel training course; it will introduce you to the program and help you understand how it works and how to navigate the interface. You will learn to use all its most common features, including formulas, functions, and formatting. Since you can never have too many AI tools, you can move on to the Using Excel with ChatGPT class even if you have no experience with ChatGPT. If you already have basic Excel skills or after you’ve learned them, the Microsoft Excel: 25 Must-Know Formulas & Functions module is a great next step. Former students have loved this course, giving it an impressive rating of 4.8 out of 5 stars. This course demonstrates essential functions that allow you to efficiently analyze data, streamline calculations, and even automate tasks. Next, you can develop valuable data visualization skills in the Excel Data Analysis module, learning all about charts and graphs; that will prepare you for the Excel Pivot Tables, Pivot Charts, Slicers, and Timelines course, which dives deep into all those tools. Even more advanced features such as PowerPivot and PowerQuery are covered. Two more modules take you through other advanced features: Excel VLOOKUP, XLOOKUP, Match, and Index and then Learn Filtering Techniques in Microsoft Excel. This bundle was created by Apex Learning, an innovative online education platform offering well-planned training and valuable resources. It also provides learners with all the support they need. Get The Complete Microsoft Excel Training Bundle for just $34.99, a 75% discount off the regular $140 retail price. StackSocial prices are subject to change. source

Develop Excel Skills From Basics to AI Integration With This $35 Course Bundle Read More »

Exposed and Vulnerable: Hidden Risks in European Enterprise IT Assets

Europe is on a march to expand its digital operations to keep apace with the growth rate seen in the US and China. This effort is not only scaling up the continent’s enterprise IT landscape but also introducing new layers of complexity. In 2022 alone, the EU poured €127 billion into digital-related investments to boost recovery and resilience plans after COVID-19. However, as businesses grow to meet these ambitions and a changed work culture Post Covid, they often end up with a fragmented IT infrastructure. Especially with multi-location enterprises, this decentralization makes it harder to track and monitor IT assets, including websites, databases, APIs, BYO- and IoT devices. Poor visibility over these public-facing systems increases the chance for weak and unmonitored entry points, expands attack surface and makes organizations more vulnerable to cyber threats. How much do these overlooked digital assets weaken enterprise cyber resilience in Europe, and what role does External Attack Surface Management (EASM) play in addressing this challenge? Europe’s IT Assets Face Growing Security Gaps Exposed IT assets, unknown vulnerabilities, lack of supervision, weak monitoring, and stolen credentials are some of the most threatening cybersecurity concerns of many businesses in Europe, according to several reports. Outpost24’s study, which examined the attack surface security of over 19,000 assets across key French industries, showed that over 20% of identified security risks were critical or high. The pharmaceutical industry had the most critical vulnerabilities (25.4%), while the transport sector saw nearly half of its known exploitable vulnerabilities (49.5%) ranked critical or very high. Financial institutions, despite having stronger malware defenses, recorded the highest number of leaked credentials on the dark web. The situation is just as alarming in the DACH region, where a review of 20,000 assets exposed significant gaps. Healthcare organizations faced the highest percentage of critical security risks (23.2%), while 43.53% of financial sector web servers had encryption misconfigurations, leaving sensitive data exposed. This growing vulnerability in IT infrastructure suggests a lack of proper tracking and monitoring of digital assets used by companies. Unfortunately, this is the type of IT environment bad actors like to pounce on at any time, any day. The Real Threat is Not in the Number of IT Assets but in Their Weaknesses For large businesses, cybersecurity risks aren’t just a matter of scale. While they have more employees and internet-connected devices than smaller companies, the real danger lies in the vulnerabilities within their infrastructure. A vast workforce increases the risk of human error, which, according to Proofpoint’s 2024 Voice of the CISO report, is responsible for 74% of all cyber breaches. But beyond human error, large enterprises rely on complex supply chains involving numerous suppliers and partners, making them prime targets for attacks like those that hit Equifax and SolarWinds. A World Economic Forum and Accenture survey found that 54% of large organizations view supply chain security as the biggest barrier to cyber resilience. Also creating multiple entry points for attackers is the challenge of managing a broad network of public-facing IT assets, such as websites, database servers, APIs, cloud services, ports, and IoT devices. The number of external IT assets is not really the problem, but the amount of weaknesses that go unnoticed over time. A recent Outpost24 Benelux EASM benchmark report shows that over 18% of observed IT assets had critical or high-risk vulnerabilities. More than 20% of analyzed web servers displayed different levels of errors, which suggests signs of misconfigurations that attackers can exploit. If untackled, the sheer depth of these threats can lead to financial losses, operational disruptions, and reputational damage. IBM’s 2024 Cost of a Data Breach Report found that breaches involving shadow IT increased costs by 10% to an average of $4.88 million. GDPR violations can lead to fines of up to €20 million or 4% of global revenue, especially if data breaches go unreported due to poor tracking and management of IT components. This situation requires businesses to step up their attack surface management efforts in a way that helps them to continuously monitor and secure their public-facing assets. The Role of External Attack Surface Management (EASM) External Attack Surface Management (EASM) keeps organizations on the front foot by providing continuous visibility into their public-facing IT components. Outpost24’s EASM solution offers 24/7/365 asset discovery, and risk prioritization, as well as passively scans IP addresses, websites, ports and DNS to detect new vulnerabilities in known and unknown assets quickly. EASM helps to reduce vulnerabilities by closing visibility gaps; a key concern highlighted by industry research from firms like ESG and Forrester. One of the biggest challenges enterprises face is prioritizing risks effectively. To address this, Outpost24 leverages AI-powered tools and Cyber Threat Intelligence Feeds to assess domain ownership as well as vulnerability criticality and exploitability in order to help security teams focus on real threats rather than wasting time on assets that do not play a business-critical role. It outperforms competitors by scanning more frequently, covering all ports, and integrating new threat detection methods faster. Findings from the Benelux report point to the need for European enterprises to adopt robust EASM strategies while emphasizing that automated and continuous monitoring is now a necessity to address shadow IT and secure critical business assets. Pairing EASM with continuous penetration testing in one flexible package ensures organizations balance breadth and depth in their cybersecurity efforts while strengthening their overall security posture. Conclusion The scale of your IT environment should not be a liability. It should be a testament to the growth of your organization. However, you need an effective EASM solution to maintain control over your IT infrastructure. Outpost24 offers a holistic approach to external attack surface management that enables you to track IT assets, control shadow IT, and gain the visibility necessary to defend against emerging threats. You can get started by getting a free attack surface analysis today. source

Exposed and Vulnerable: Hidden Risks in European Enterprise IT Assets Read More »