My Courses
-

Leaked Credentials Increase by 160%: Exploits Utilized by Attackers
When an organisation’s credentials are leaked, the immediate consequences are often not visible, yet the long-term impact can be significant. Many real-world cyber breaches start with something deceptively simple: a username and password. According to Verizon’s 2025 Data Breach Investigations Report, leaked credentials accounted for 22% of breaches in 2024, surpassing phishing and software exploitation.…
-

A data breach at Columbia University has affected 860,000 individuals.
Columbia University has recently fallen victim to a significant cyberattack, resulting in the theft of personal information belonging to approximately 860,000 individuals, including students, applicants, and employees. The breach has raised serious concerns about data security and privacy, as sensitive information may now be in the hands of malicious actors. University officials are currently investigating…
-

Bouygues, a French telecommunications company, has reported that a data breach has impacted 6.4 million of its customers.
French Telecom Firm Bouygues has recently fallen victim to a significant cyberattack, leading to the compromise of personal information belonging to approximately 6.4 million customers. The breach has raised serious concerns regarding data security and privacy, as sensitive information may have been accessed by unauthorised individuals. Bouygues has acknowledged the incident and is currently investigating…
-

GreedyBear has swindled $1 million in cryptocurrency by employing over 150 harmful Firefox wallet extensions.
A newly discovered campaign, dubbed GreedyBear, has leveraged over 150 malicious extensions in the Firefox marketplace, designed to impersonate popular cryptocurrency wallets and steal more than $1 million in digital assets. The published browser add-ons masquerade as MetaMask, TronLink, Exodus, and Rabby Wallet, among others, as reported by Koi Security researcher Tuval Admoni. What makes…
-

ChatGPT-5 Launch: Discover the Latest Features of the Next-Gen AI Assistant
OpenAI has officially launched ChatGPT-5, a new generation of its AI agent that introduces a sophisticated, unified system designed to be faster, more intelligent, and significantly more useful for real-world applications. This release represents a substantial evolution from its predecessors, featuring a suite of models tailored for various tasks and complexities. At the core of…
-

Recent techniques for lateral movement within Active Directory have emerged that circumvent authentication measures and enable data exfiltration.
At Black Hat USA 2025, Dirk-Jan Mollema unveiled sophisticated attack vectors that exploit hybrid Active Directory and Microsoft Entra ID environments, revealing how attackers can achieve complete tenant compromise through previously unknown lateral movement techniques. These methods expose critical vulnerabilities in Microsoft’s authentication infrastructure, allowing unauthorized access to Exchange Online, SharePoint, and Entra ID without…
-

Cybercriminals are utilizing legitimate drivers to disable antivirus programs and weaken the security measures of a system.
In a sophisticated campaign first observed in October 2024, attackers have begun leveraging a legitimate driver to disable antivirus software across compromised networks. By abusing the ThrottleStop.sys driver—originally designed by TechPowerUp to manage CPU throttling—the malware gains kernel-level memory access to terminate security processes at will. Initial access is most often achieved through stolen RDP…
-

Organizations Alerted to Security Flaw in Microsoft Exchange Hybrid Setup
CISA and Microsoft have recently issued critical advisories regarding CVE-2025-53786, a high-severity vulnerability that poses a significant risk of privilege escalation in cloud environments. This flaw primarily affects Microsoft Exchange Hybrid Deployments, which are commonly used by organisations to integrate on-premises and cloud-based email services. The vulnerability could potentially allow attackers to gain elevated privileges,…
-

Recent HTTP request smuggling attacks have affected content delivery networks (CDNs), large organizations, and millions of websites.
A recent wave of HTTP Request Smuggling attacks has exploited vulnerabilities in HTTP/1.1, significantly impacting numerous websites, including those of major organisations and Content Delivery Networks (CDNs). These desynchronisation attacks have allowed malicious actors to manipulate the way web servers process requests, leading to potential data breaches and security risks for millions of users. Researchers…
-

Nvidia has stated that its chips do not contain any backdoors, kill switches, or spyware.
Nvidia Corporation has issued a strong statement asserting that its Graphics Processing Units (GPUs) contain no backdoors, kill switches, or spyware. This declaration directly addresses growing concerns from policymakers regarding potential hardware-based control mechanisms. The semiconductor giant categorically rejects proposals from some industry observers and government officials advocating for mandatory remote disable capabilities in critical…
