My Courses
-

SmartLoader malware spread through GitHub repositories
Cybersecurity researchers have identified a sophisticated malware distribution campaign that exploits GitHub repositories, masquerading as legitimate software projects. The SmartLoader malware has been strategically deployed across various repositories, leveraging users’ trust in the popular code-sharing platform to infiltrate systems globally. This malicious campaign specifically targets individuals searching for game cheats, software cracks, and automation tools…
-

Cybercriminals using CrossC2 to extend Cobalt Strike beacons to Linux and macOS
Japan’s CERT Coordination Centre (JPCERT/CC) reported on Thursday that it observed incidents involving a command-and-control (C2) framework known as CrossC2. This framework is designed to enhance the functionality of Cobalt Strike across various platforms, including Linux and Apple macOS. The agency detected this activity between September and December 2024, targeting multiple countries, including Japan, through…
-

Weaknesses in the Xerox Print Orchestration Product allow remote code execution
Xerox has addressed critical security vulnerabilities in its FreeFlow Core, specifically Path Traversal and XML External Entity (XXE) injection flaws that could allow unauthenticated remote code execution. These vulnerabilities posed significant risks, enabling potential attackers to exploit the system without requiring any form of authentication. By successfully executing these attacks, malicious actors could gain unauthorised…
-

Canadian House of Commons targeted by SharePoint Toolshell cyberattack
A cyberattack targeted the Canadian House of Commons on August 9, 2025, when threat actors exploited a recently disclosed Microsoft vulnerability to gain unauthorised access to sensitive employee information. This breach highlights the escalating cybersecurity challenges faced by Canada’s government institutions amid a growing threat landscape. An internal email obtained by CBC News revealed that…
-

Apache Tomcat vulnerabilities allow Denial of Service (DoS) attacks
A critical security vulnerability has been discovered in Apache Tomcat’s HTTP/2 implementation, enabling attackers to launch severe denial-of-service (DoS) attacks against web servers. This vulnerability, designated as CVE-2025-48989 and referred to as the “Made You Reset” attack, affects multiple versions of the widely used Java servlet container, posing significant risks to web applications globally. Rated…
-

Android malware targeting banking applications through NFC relay scams and call hijacking
Cybersecurity researchers have identified a new Android trojan named PhantomCard, which exploits Near-Field Communication (NFC) technology to execute relay attacks aimed at facilitating fraudulent transactions targeting banking customers in Brazil. According to ThreatFabric, PhantomCard relays NFC data from a victim’s banking card to the fraudster’s device and is based on Chinese-originating NFC relay malware-as-a-service. The…
-

MadeYouReset vulnerability in HTTP2 facilitates large-scale DDoS attacks
A new Distributed Denial of Service (DDoS) attack vector has emerged, exploiting flaws in HTTP/2 implementations. This vulnerability, dubbed ‘MadeYouReset’, has drawn comparisons to the previously known Rapid Reset attack. By leveraging these HTTP/2 weaknesses, attackers can orchestrate massive DDoS attacks that overwhelm targeted servers. The implications of this vulnerability are significant, as it allows…
-

Bypassing Passkey Login through Manipulation of the WebAuthn Process
Researchers at the enterprise browser security firm SquareX have demonstrated a significant vulnerability in passkey security systems. They revealed that an attacker could impersonate a legitimate user by manipulating the WebAuthn process, effectively bypassing the security measures designed to protect user accounts. This manipulation raises serious concerns about the integrity of passkey authentication, which is…
-

Hackers using specialized phishing tools for downgrade attacks on FIDO authentication
A sophisticated new threat vector has emerged that could undermine one of the most trusted authentication methods in cybersecurity. FIDO-based passkeys, long considered the gold standard for phishing-resistant authentication, are now facing a potentially devastating attack technique that forces users to downgrade to less secure authentication methods. This attack exploits a critical vulnerability in FIDO…
-

AI-assisted SOC boosts efficiency and cuts investigation time
Security operations have never been a 9-to-5 job. For Security Operations Centre (SOC) analysts, the day often begins and ends deep in a queue of alerts, chasing down what frequently turns out to be false positives or switching between multiple tools to piece together context. The work is repetitive, time-consuming, and high-stakes, leaving SOCs under…
