My Courses
-

Croatian research institute targeted by ToolShell ransomware attack
The Ruđer Bošković Institute (RBI), the largest Croatian science and technology research institute, confirmed that it was among “at least 9,000 institutions worldwide” targeted by a ransomware attack exploiting Microsoft SharePoint “ToolShell” vulnerabilities on Thursday, July 31, 2025. The attack compromised part of the network related to the Institute’s administrative and professional services, resulting in…
-

Microsoft has addressed the “BadSuccessor” Kerberos vulnerability identified as CVE-2025-53779.
In August 2025, Microsoft released security updates addressing over 100 vulnerabilities across its products, including a significant relative path traversal flaw in Windows Kerberos (CVE-2025-53779). This vulnerability, identified by Akamai researcher Yuval Gordon, allows an authorised attacker to elevate privileges over a network as part of a BadSuccessor attack. It exploits the delegated Managed Service…
-

Manpower has reported that a data breach resulting from a ransomware attack has affected 140,000 individuals.
In January, the RansomHub ransomware group executed a significant cyberattack on the staffing and recruiting firm Manpower, resulting in a substantial data breach. This incident has reportedly impacted approximately 140,000 individuals, raising serious concerns about the security of sensitive information. Manpower has confirmed that the breach involved the theft of personal data, which could potentially…
-

New Zoom and Xerox security updates address privilege escalation and remote code execution (RCE)
Zoom and Xerox have recently addressed significant security vulnerabilities in their respective software products, which could potentially lead to privilege escalation and remote code execution. The vulnerability affecting Zoom Clients for Windows, identified as CVE-2025-49457 with a CVSS score of 9.6, involves an untrusted search path that may allow unauthenticated users to escalate privileges via…
-

AWS CISO explains cloud-native security
In a recent interview with Help Net Security, Amy Herzog, CISO at AWS, elaborates on the concept of cloud-native security, which provides scalable and flexible protection that aligns with cloud development practices. She defines cloud-native security as a combination of security controls and processes that operate in harmony with cloud functionalities. This approach is API-driven…
-

Adobe patches 60+ security flaws in 13 products
Adobe has released critical security updates addressing over 60 vulnerabilities across 13 of its products, including Adobe Commerce, Substance, InDesign, FrameMaker, and Dimension. These updates are essential for safeguarding users against potential exploits that could compromise their systems and data. The vulnerabilities range in severity, with some classified as critical, highlighting the importance of timely…
-

Fortinet and Ivanti issue new security updates
Fortinet and Ivanti have announced the release of new security advisories as part of their August 2025 Patch Tuesday updates. These updates address critical vulnerabilities that could potentially expose systems to cyber threats. Fortinet has detailed several patches aimed at enhancing the security of its products, ensuring that users are protected against emerging risks. Similarly,…
-

PS1Bot malware executes multi-stage attacks
Cybersecurity researchers have identified a new malvertising campaign aimed at infecting victims with a sophisticated multi-stage malware framework known as PS1Bot. This malware features a modular design, enabling the delivery of various modules that execute a range of malicious activities on compromised systems, including information theft, keylogging, reconnaissance, and establishing persistent access. Cisco Talos researchers,…
-

N-able N-Central vulnerabilities actively exploited (CISA)
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) recently added two security vulnerabilities affecting N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog, highlighting evidence of active exploitation. N-able N-central is a Remote Monitoring and Management (RMM) platform tailored for Managed Service Providers (MSPs), enabling efficient management and security of clients’ Windows, Apple, and Linux…

