My Courses

  • DOJ charges 22-year-old accused RapperBot botmaster

    DOJ charges 22-year-old accused RapperBot botmaster

    A 22-year-old man from Oregon, Ethan Foltz, has been charged with allegedly developing and managing a distributed denial-of-service (DDoS)-for-hire botnet known as RapperBot. The U.S. Department of Justice (DoJ) reported that this botnet has been responsible for large-scale DDoS attacks targeting victims in over 80 countries since at least 2021. Foltz faces one count of…

  • Apache ActiveMQ exploit allows DripDropper installation on Linux cloud systems

    Apache ActiveMQ exploit allows DripDropper installation on Linux cloud systems

    Threat actors are exploiting a nearly two-year-old security flaw in Apache ActiveMQ to gain persistent access to cloud Linux systems and deploy malware known as DripDropper. In a surprising twist, these unknown attackers have been observed patching the exploited vulnerability after securing initial access, thereby preventing further exploitation by other adversaries and evading detection, according…

  • AWS Trusted Advisor vulnerability hides public S3 buckets

    AWS Trusted Advisor vulnerability hides public S3 buckets

    AWS’s Trusted Advisor tool is designed to alert customers about the public exposure of their S3 storage buckets. However, recent findings by Fog Security researchers indicate that this tool can be manipulated to report buckets as not exposed, even when they are. Amazon S3 offers various access protection mechanisms, including IAM users, roles, and policies,…

  • FBI alleges Russian APT group exploiting old Cisco vulnerability (CVE-2018-0171)

    FBI alleges Russian APT group exploiting old Cisco vulnerability (CVE-2018-0171)

    Russian state-sponsored hackers, identified as Static Tundra, have been actively exploiting a seven-year-old vulnerability in Cisco devices, specifically CVE-2018-0171. This critical flaw allows attackers to gain unauthorised access to affected systems, posing significant risks to organisations that have not patched their devices. The FBI has issued warnings regarding this ongoing campaign, highlighting the persistent nature…

  • Git version 2.51: Getting ready for the future by incorporating SHA-256.

    Git version 2.51: Getting ready for the future by incorporating SHA-256.

    Git 2.51 has been released, continuing the ongoing effort to modernise the version control system. This update introduces several technical enhancements, with a significant focus on bolstering cryptographic security through the support of SHA-256. Since its inception in 2005, Git has relied on SHA-1, which has become increasingly vulnerable to collision attacks, rendering it unsuitable…

  • VPN applications for Android, widely utilized by millions of users, are secretly maintaining connections and are vulnerable to security issues.

    VPN applications for Android, widely utilized by millions of users, are secretly maintaining connections and are vulnerable to security issues.

    A recent study by researchers from Arizona State University and Citizen Lab has revealed that three families of Android VPN apps, collectively boasting over 700 million downloads on Google Play, are secretly interconnected. Virtual Private Networks (VPNs) are often promoted as tools for enhancing user privacy and securing internet traffic. However, the consumer VPN landscape…

  • United Kingdom government withdraws Apple backdoor request

    United Kingdom government withdraws Apple backdoor request

    The U.K. government has reportedly abandoned its plans to compel Apple to weaken encryption protections and implement a backdoor that would allow access to the encrypted data of U.S. citizens. U.S. Director of National Intelligence Tulsi Gabbard stated on X that the U.S. government had collaborated with its U.K. partners over recent months to safeguard…

  • URL-based and QR code phishing increasing

    URL-based and QR code phishing increasing

    Cybercriminals are increasingly employing advanced social engineering techniques and AI-generated content to create malicious URLs that are difficult for users to identify, according to Proofpoint. URL-based threats have become the dominant form of cyber threats, manifesting through emails, text messages, and collaboration apps. Attackers are not only impersonating trusted brands but are also abusing legitimate…

  • CISOs must consider potential risks before hastily adopting AI technologies.

    CISOs must consider potential risks before hastily adopting AI technologies.

    Organisations are increasingly investing in cloud, AI, and emerging technologies, yet their infrastructure and security strategies often lag behind. A recent Unisys survey of 1,000 senior executives reveals a misalignment between business and IT leaders regarding the necessary preparations for the next wave of technology. From a security perspective, the findings raise concerns about the…

  • AI browsers scammed by PromptFix attacks run malicious hidden prompts

    AI browsers scammed by PromptFix attacks run malicious hidden prompts

    Cybersecurity researchers have unveiled a new prompt injection technique known as PromptFix. This method deceives a generative artificial intelligence (GenAI) model by embedding malicious instructions within a fake CAPTCHA check on a web page. Guardio Labs describes this technique as an “AI-era take on the ClickFix scam.” The attack demonstrates how AI-driven browsers, such as…