My Courses

  • Akira ransomware attackers actively exploiting SonicWall SSL VPN

    Akira ransomware attackers actively exploiting SonicWall SSL VPN

    Threat actors associated with the Akira ransomware group have intensified their focus on SonicWall devices for initial access. Cybersecurity firm Rapid7 reported a notable increase in intrusions involving SonicWall appliances, particularly following a resurgence of Akira ransomware activity since late July 2025. SonicWall disclosed that the SSL VPN activity targeting its firewalls exploited a year-old…

  • Counterfeit Madgicx Plus and SocialMetrics extensions hijacking Meta business accounts

    Counterfeit Madgicx Plus and SocialMetrics extensions hijacking Meta business accounts

    Cybersecurity researchers have revealed two new campaigns that distribute fake browser extensions through malicious advertisements and counterfeit websites to steal sensitive data. The first campaign, identified by Bitdefender, promotes a fraudulent “Meta Verified” browser extension called SocialMetrics Pro, which falsely claims to unlock the blue check badge for Facebook and Instagram profiles. At least 37…

  • AsyncRAT Takes Advantage of ConnectWise ScreenConnect to Capture Credentials and Cryptocurrency

    AsyncRAT Takes Advantage of ConnectWise ScreenConnect to Capture Credentials and Cryptocurrency

    Cybersecurity researchers have revealed a new campaign that exploits ConnectWise ScreenConnect, a legitimate Remote Monitoring and Management (RMM) software, to deploy a fileless loader that delivers a Remote Access Trojan (RAT) known as AsyncRAT. According to a report from LevelBlue shared with The Hacker News, attackers utilise ScreenConnect to gain remote access and execute a…

  • CHILLYHELL macOS Backdoor and ZynorRAT remote access trojan threat to all operating systems

    CHILLYHELL macOS Backdoor and ZynorRAT remote access trojan threat to all operating systems

    Cybersecurity researchers have identified two new malware families, including a modular Apple macOS backdoor named CHILLYHELL and a Go-based Remote Access Trojan (RAT) called ZynorRAT, which can target both Windows and Linux systems. An analysis from Jamf Threat Labs indicates that CHILLYHELL is written in C++ and designed for Intel architectures. This malware is attributed…

  • APT41 hackers targeting US trade officials as talks with China approach

    APT41 hackers targeting US trade officials as talks with China approach

    The House Select Committee on China has issued a formal advisory regarding an ongoing series of targeted cyber espionage campaigns linked to the People’s Republic of China (PRC). These campaigns aim to compromise organisations and individuals involved in U.S.–China trade policy and diplomacy, including U.S. government agencies, business organisations, law firms, think tanks, and at…

  • Cryptojacking attack using TOR infiltrates misconfigured Docker APIs

    Cryptojacking attack using TOR infiltrates misconfigured Docker APIs

    Cybersecurity researchers have identified a new variant of a previously disclosed campaign that exploits the TOR network for cryptojacking attacks aimed at exposed Docker APIs. Akamai, which uncovered this recent activity last month, indicated that the campaign is designed to prevent other actors from accessing the Docker API over the internet. These findings build upon…

  • GPUGate malware using Google Ads and counterfeit GitHub commits

    GPUGate malware using Google Ads and counterfeit GitHub commits

    Cybersecurity researchers have uncovered a sophisticated malware campaign that utilises paid advertisements on search engines like Google to deliver malware to unsuspecting users searching for popular tools such as GitHub Desktop. This campaign introduces a novel twist to traditional malvertising by embedding a GitHub commit into a page URL, which contains altered links that redirect…

  • Chinese agents reportedly posed as US congressman to transmit malware

    Chinese agents reportedly posed as US congressman to transmit malware

    China’s APT41 has been implicated in a sophisticated cyber espionage operation, where they impersonated U.S. Representative John Moolenaar to distribute malicious emails. These emails were aimed at trade groups in an effort to gather sensitive information ahead of critical U.S.-China trade negotiations. The operation highlights the increasing threat posed by state-sponsored hackers, particularly as geopolitical…

  • GitHub workflow breaches impact multiple repositories

    GitHub workflow breaches impact multiple repositories

    A supply chain attack known as GhostAction has emerged, allowing threat actors to infiltrate systems and steal sensitive information. This sophisticated attack has particularly targeted GitHub workflows, affecting hundreds of repositories and compromising thousands of secrets. By exploiting vulnerabilities within these workflows, attackers have been able to gain unauthorised access to critical data, raising significant…