My Courses
-

ShadowRay 2.0 Takes Advantage of an Unresolved Ray Vulnerability to Create a Self-Replicating GPU Cryptomining Botnet.
Oligo Security has issued a warning regarding ongoing attacks that exploit a two-year-old security flaw in the Ray open-source artificial intelligence (AI) framework. This vulnerability allows infected clusters with NVIDIA GPUs to be transformed into a self-replicating cryptocurrency mining botnet, known as ShadowRay 2.0. The attack primarily takes advantage of a critical missing authentication bug…
-

Hackers connected to Iran analyzed ship AIS data just days before a missile strike attempt occurred in the real world.
Threat actors with ties to Iran have increasingly engaged in cyber warfare to facilitate and enhance physical, real-world attacks, a trend identified by Amazon as cyber-enabled kinetic targeting. This development indicates a blurring of lines between state-sponsored cyber attacks and kinetic warfare, prompting the need for a new category of warfare, as highlighted in a…
-

Vulnerability in WordPress Backup Plugin Leaves 800,000 Sites Open to Remote Code Execution Exploits
A critical vulnerability in the WPvivid Backup & Migration WordPress plugin allows unauthenticated attackers to upload files and execute code on the server, potentially leading to full site takeover. This issue, tracked as CVE-2026-1357, has been assigned a severity score of 9.8 (Critical) and affects all plugin versions up to and including 0.9.123. A fix…
-

KillSec ransomware targeting healthcare IT systems
The KillSec ransomware strain has quickly emerged as a significant threat to healthcare IT infrastructures across Latin America and beyond. First identified in early September 2025, KillSec operators have exploited compromised software supply chain relationships to deploy their malicious payloads at scale. Initial signs of compromise were detected when several Brazilian healthcare providers reported unusual…
-

HiddenGh0st, Winos, and kkRAT using SEO strategies and GitHub pages
Chinese-speaking users have become the primary target of a malicious search engine optimisation (SEO) poisoning campaign. This campaign employs fake software sites to distribute malware, posing significant risks to unsuspecting individuals. According to Fortinet FortiGuard Labs researcher Pei Han Liao, the attackers have manipulated search rankings by utilising SEO plugins. They have also registered lookalike…
-

Runtime visibility indispensable in cloud-native security
The security landscape for cloud-native applications is undergoing a significant transformation as Containers, Kubernetes, and Serverless technologies become the standard for modern enterprises. This shift accelerates delivery but also expands the attack surface in ways that traditional security models struggle to address. As adoption increases, so does complexity, with security teams tasked to monitor sprawling…
-

Cursor AI Code Editor getting hammered through compromised repositories
A security vulnerability has been identified in the AI-powered code editor Cursor, which could allow code execution when a maliciously crafted repository is opened. This issue arises from the default disabling of an important security feature known as Workspace Trust. According to Oasis Security, Cursor’s configuration permits VS Code-style tasks to auto-execute upon opening a…
-

Chinese APT group infiltrated Philippine military with EggStreme fileless malware
An advanced persistent threat (APT) group from China has been linked to the compromise of a military company based in the Philippines, employing a previously undocumented fileless malware framework known as EggStreme. This sophisticated multi-stage toolset facilitates persistent and low-profile espionage by injecting malicious code directly into memory and utilising DLL sideloading to execute payloads.…


