My Courses
-

Operational Technology (OT) networks are being extensively targeted due to vulnerabilities found in Erlang/OTP.
The recently patched Erlang/OTP flaw, identified as CVE-2025-32433, has been actively exploited since early May, shortly after its discovery. This vulnerability has raised significant concerns, particularly as it has been targeted in widespread attacks against Operational Technology (OT) networks. Security experts have noted that the exploitation of this flaw poses serious risks to organisations relying…
-

Citrix NetScaler vulnerability CVE-2025-6543 actively exploited in crucial industries
The Dutch National Cyber Security Centre (NCSC-NL) has issued a warning regarding cyber attacks that exploit a recently disclosed critical security vulnerability affecting Citrix NetScaler ADC products. This vulnerability, identified as CVE-2025-6543, has a CVSS score of 9.2 and can lead to unintended control flow and denial-of-service (DoS) when the devices are configured as a…
-

Researchers have observed a significant increase in remote code execution (RCE) exploits targeting the Erlang/OTP SSH protocol, with 70% of these attacks aimed at operational technology (OT) firewalls.
Malicious actors have been exploiting a critical security flaw in the Erlang/Open Telecom Platform (OTP) SSH, identified as CVE-2025-32433, which has a CVSS score of 10.0. This vulnerability, a missing authentication issue, allows attackers with network access to execute arbitrary code on affected Erlang/OTP SSH servers without requiring credentials. The flaw was patched in April…
-

Balancing trust and risk in AI: Anticipating hallucinations before they occur.
Recent physics-based research indicates that large language models possess the capability to predict when their responses may be inaccurate or misleading. This breakthrough could significantly enhance trust, risk management, and security in AI-driven systems. By enabling these models to identify potential “hallucinations” in their outputs before they occur, developers and users can better navigate the…
-

Deficiencies in the dealership systems of a leading automotive manufacturer facilitated car hacking and the theft of personal information.
A researcher has revealed significant vulnerabilities in a platform utilised by over 1,000 dealerships across the United States, highlighting how these flaws could have been exploited to hack into vehicles. This alarming discovery raises concerns about the security of automotive systems and the potential for unauthorised access to personal data. The researcher’s findings indicate that…
-

Russian hackers took advantage of a WinRAR zero-day vulnerability to launch attacks in Europe and Canada.
WinRAR has addressed the critical vulnerability identified as CVE-2025-8088, a zero-day flaw that was actively exploited by the Russian hacking group RomCom. This vulnerability posed significant risks to various sectors, including financial, defence, manufacturing, and logistics companies across Europe and Canada. The exploitation of this zero-day vulnerability allowed attackers to infiltrate systems, potentially leading to…
-

RomCom hackers are utilizing a zero-day vulnerability in WinRAR to conduct specific targeted attacks.
ESET researchers have identified a previously unknown vulnerability in WinRAR, which has been exploited in the wild by the Russia-aligned group RomCom. Users of WinRAR and its related components, including the Windows versions of its command line tools, UnRAR.dll, or the portable UnRAR source code, are urged to update to the latest release immediately. ESET…
-

Despite increases in breaches and budgets, the safety of healthcare systems has not improved.
A new report from Resilience highlights a growing cyber crisis in the U.S. healthcare sector, where ransomware attacks, vendor compromises, and human error are causing widespread disruption. In 2023, breaches exposed 168 million records, and the first half of 2025 has already seen extortion demands reaching as high as $4 million. Despite significant investments in…
-

Penetration testing has become a fundamental component of the strategy for Chief Information Security Officers (CISOs).
Security leaders are re-evaluating their cybersecurity strategies as digital supply chains grow and Generative AI becomes integral to critical systems. A recent survey by Emerald Research, involving 225 security leaders, revealed that 68% are apprehensive about the risks associated with third-party software and components. While most respondents claim to meet regulatory requirements, 60% acknowledge that…

