My Courses

  • The Importance of Security Culture in Reducing Cyber Risk

    The Importance of Security Culture in Reducing Cyber Risk

    After two decades of developing increasingly sophisticated security architectures, organisations are confronting a critical reality: tools and technologies alone cannot sufficiently mitigate cyber risk. As technology stacks have advanced, attackers have shifted their focus from infrastructure vulnerabilities to exploiting human behaviour. Recent data from Verizon’s Data Breach Investigations Report indicates that nearly 60% of all…

  • Microsoft Windows vulnerability used to distribute PipeMagic RansomExx malware

    Microsoft Windows vulnerability used to distribute PipeMagic RansomExx malware

    Cybersecurity researchers have revealed the exploitation of a now-patched security flaw in Microsoft Windows by threat actors to deploy the PipeMagic malware in RansomExx ransomware attacks. These attacks leverage CVE-2025-29824, a privilege escalation vulnerability affecting the Windows Common Log File System (CLFS), which Microsoft addressed in April 2025. Kaspersky and BI.ZONE reported that PipeMagic, first…

  • Chinese APT groups targeting Taiwanese web hosting companies

    Chinese APT groups targeting Taiwanese web hosting companies

    The Chinese APT UAT-7237 has been actively targeting Taiwanese web infrastructure, aiming for long-term access to high-value entities. This sophisticated cyber threat has focused on web hosting firms in Taiwan, exploiting vulnerabilities to infiltrate networks and gather sensitive information. By maintaining a persistent presence within these infrastructures, UAT-7237 seeks to compromise critical data and gain…

  • Noodlophile malware operation using copyright-related phishing tactics

    Noodlophile malware operation using copyright-related phishing tactics

    The Noodlophile malware campaign, which has been active for over a year, is employing sophisticated spear-phishing emails to target enterprises in the U.S., Europe, Baltic countries, and the Asia-Pacific (APAC) region. According to Morphisec researcher Shmuel Uzan, these emails masquerade as copyright infringement notices and are customised with reconnaissance-derived details, such as specific Facebook Page…

  • New NIST guide explains how to detect morphed images

    New NIST guide explains how to detect morphed images

    Face morphing software has the capability to blend two individuals’ photos into a single image, enabling potential identity fraud at secure locations such as buildings, airports, and borders. These morphed images can deceive facial recognition systems, allowing one person to impersonate another. The software is widely accessible, with morphs easily created using mobile applications, desktop…

  • How security teams are currently utilizing AI.

    How security teams are currently utilizing AI.

    Artificial Intelligence (AI) is transitioning from a proof-of-concept phase into everyday security operations within Security Operations Centres (SOCs). It is now employed to reduce alert noise, assist analysts during investigations, and accelerate incident response. What was once considered experimental technology is beginning to yield measurable results for Chief Information Security Officers (CISOs). While machine learning…

  • Workday data breach linked to Salesforce hack

    Workday data breach linked to Salesforce hack

    Workday has reportedly become one of the latest major companies to have its Salesforce instances compromised by hackers. This incident appears to be part of a broader trend, as numerous organisations have experienced similar breaches targeting their Salesforce environments. The implications of this data breach are significant, raising concerns about the security of sensitive information…

  • New 5G vulnerability bypasses need for malicious base station

    New 5G vulnerability bypasses need for malicious base station

    Researchers have unveiled a novel 5G attack known as Sni5Gect, which poses significant security risks by enabling attackers to sniff traffic and disrupt network operations. This innovative attack method is particularly concerning as it circumvents the need for a malicious base station, making it easier for cybercriminals to exploit vulnerabilities within the 5G infrastructure. By…

  • Cofense Vision 3.0 detects how users interact with phishing messages

    Cofense Vision 3.0 detects how users interact with phishing messages

    Cofense has launched Vision 3.0, the latest enhancement to its Phishing Threat Detection and Response (PDR) platform, which significantly improves incident response times. This new version provides security teams with detailed visibility into user interactions with phishing emails that bypass perimeter defences. Building on the existing “Who Opened” feature, the updated “Who Clicked” functionality allows…