My Courses
-

Healthcare cybersecurity risks increasing – especially password management
In 2025, healthcare organisations are confronting a significant rise in password security risks. Recent data from the HIMSS Cybersecurity Survey indicates that 74% of these organisations experienced at least one major security incident in the past year. More than half of the respondents, specifically 52%, anticipate an increase in their IT budgets for 2025. Notably,…
-

Pharmaceutical company Inotiv hit by ransomware attack
Inotiv, a pharmaceutical company, has officially notified the Securities and Exchange Commission (SEC) about a significant disruption to its business operations following a ransomware attack. Hackers successfully compromised and encrypted Inotiv’s internal systems, leading to operational challenges that have impacted the company’s ability to function effectively. The breach has raised concerns regarding data security and…
-

Regional Australian councils expose confidential information due to Workhorse vulnerability
The Cyber Emergency Response Team Coordination Center (CERT/CC) has revealed critical information exposure vulnerabilities in a Workhorse Software application, which is widely utilised by numerous cities and towns across Australia. Despite the release of patches intended to address these security flaws, sensitive data remains at risk due to inadequate remediation efforts. The vulnerabilities could potentially…
-

SAP Netweaver exploits CVE-2025-31324 and CVE-2025-42999 publicly released
A working exploit that concatenates two critical SAP Netweaver vulnerabilities, CVE-2025-31324 and CVE-2025-42999, has been made public by VX Underground, as warned by Onapsis security researchers. This exploit was allegedly released on a Telegram channel associated with a collective of three established cybercrime groups: Scattered Spider, ShinyHunters, and LAPSUS$. Earlier this year, CVE-2025-31324, a missing…
-

North Korean hackers target diplomats via GitHub spearphishing attack
North Korean threat actors have been linked to a coordinated cyber espionage campaign targeting diplomatic missions in South Korea between March and July 2025. This campaign involved at least 19 spear-phishing emails that impersonated trusted diplomatic contacts, aiming to lure embassy staff and foreign ministry personnel with convincing meeting invites, official letters, and event invitations.…
-

Hacktivist sentenced to 20 months imprisonment in UK.
Al-Tahery Al-Mashriky, a member of the Yemen Cyber Army, has been implicated in a series of hacking incidents targeting various websites. These actions were part of broader hacktivist campaigns aimed at promoting political agendas through digital disruption. The group has gained notoriety for defacing websites, which has raised significant concerns about cybersecurity and the implications…
-

Gambling tech company Bragg hit by cyberattack
Bragg Gaming Group recently reported that hackers gained access to its internal systems over the weekend. Despite this breach, the company confirmed that its operations remained unaffected. The cyberattack has raised concerns within the industry, but Bragg Gaming Group has assured stakeholders that it is taking the necessary steps to enhance its cybersecurity measures. The…
-

Microsoft Analyzes PipeMagic Modular Backdoor
PipeMagic, a sophisticated modular malware framework that masquerades as a ChatGPT application, offers cybercriminals persistent access and unparalleled flexibility. This malicious software is designed to adapt and evolve, allowing attackers to maintain control over compromised systems while evading detection. Microsoft has conducted an in-depth analysis of PipeMagic, revealing its capabilities to integrate various modules that…
-

Interconnected SAP exploits allow remote code execution
A new exploit has emerged that combines two critical, now-patched security flaws in SAP NetWeaver, posing significant risks to organisations regarding system compromise and data theft. This exploit chains together CVE-2025-31324, which has a CVSS score of 10.0 for a missing authorisation check, and CVE-2025-42999, rated at 9.1 for insecure deserialization. SAP addressed these vulnerabilities…

