My Courses
-

Akira ransomware attackers actively exploiting SonicWall SSL VPN
Threat actors associated with the Akira ransomware group have intensified their focus on SonicWall devices for initial access. Cybersecurity firm Rapid7 reported a notable increase in intrusions involving SonicWall appliances, particularly following a resurgence of Akira ransomware activity since late July 2025. SonicWall disclosed that the SSL VPN activity targeting its firewalls exploited a year-old…
-

Counterfeit Madgicx Plus and SocialMetrics extensions hijacking Meta business accounts
Cybersecurity researchers have revealed two new campaigns that distribute fake browser extensions through malicious advertisements and counterfeit websites to steal sensitive data. The first campaign, identified by Bitdefender, promotes a fraudulent “Meta Verified” browser extension called SocialMetrics Pro, which falsely claims to unlock the blue check badge for Facebook and Instagram profiles. At least 37…
-

AsyncRAT Takes Advantage of ConnectWise ScreenConnect to Capture Credentials and Cryptocurrency
Cybersecurity researchers have revealed a new campaign that exploits ConnectWise ScreenConnect, a legitimate Remote Monitoring and Management (RMM) software, to deploy a fileless loader that delivers a Remote Access Trojan (RAT) known as AsyncRAT. According to a report from LevelBlue shared with The Hacker News, attackers utilise ScreenConnect to gain remote access and execute a…
-

CHILLYHELL macOS Backdoor and ZynorRAT remote access trojan threat to all operating systems
Cybersecurity researchers have identified two new malware families, including a modular Apple macOS backdoor named CHILLYHELL and a Go-based Remote Access Trojan (RAT) called ZynorRAT, which can target both Windows and Linux systems. An analysis from Jamf Threat Labs indicates that CHILLYHELL is written in C++ and designed for Intel architectures. This malware is attributed…
-

New phishing tool Salty2FA bypasses two-factor authentication
Phishing-as-a-Service (PhaaS) platforms continue to evolve, providing attackers with faster and cheaper methods to infiltrate corporate accounts. Researchers at ANY.RUN have identified a new threat: Salty2FA, a phishing kit engineered to circumvent various two-factor authentication (2FA) methods and evade traditional security measures. This kit has already been detected in campaigns across the United States and…
-

Cryptojacking attack using TOR infiltrates misconfigured Docker APIs
Cybersecurity researchers have identified a new variant of a previously disclosed campaign that exploits the TOR network for cryptojacking attacks aimed at exposed Docker APIs. Akamai, which uncovered this recent activity last month, indicated that the campaign is designed to prevent other actors from accessing the Docker API over the internet. These findings build upon…
-

Chinese agents reportedly posed as US congressman to transmit malware
China’s APT41 has been implicated in a sophisticated cyber espionage operation, where they impersonated U.S. Representative John Moolenaar to distribute malicious emails. These emails were aimed at trade groups in an effort to gather sensitive information ahead of critical U.S.-China trade negotiations. The operation highlights the increasing threat posed by state-sponsored hackers, particularly as geopolitical…
-

GitHub workflow breaches impact multiple repositories
A supply chain attack known as GhostAction has emerged, allowing threat actors to infiltrate systems and steal sensitive information. This sophisticated attack has particularly targeted GitHub workflows, affecting hundreds of repositories and compromising thousands of secrets. By exploiting vulnerabilities within these workflows, attackers have been able to gain unauthorised access to critical data, raising significant…


