My Courses
-

HeartCrypt’s EDR Killer Tools called ‘AVKiller’ are currently being utilized in ransomware attacks.
Cybersecurity teams have recently faced a significant threat from a novel payload known as “AVKiller,” which has been observed disabling endpoint defences to facilitate ransomware deployment. First detected in mid-2024, this tool utilises the HeartCrypt packer-as-a-service to obscure its true functionality, allowing it to bypass traditional static signature checks. Attackers typically deliver AVKiller through a…
-

1.2 million healthcare devices and systems have had their data exposed online, putting patient records in jeopardy of being compromised.
New research by European cybersecurity company Modat has revealed that over 1.2 million internet-connected healthcare devices and systems are exposed, endangering patient data. The findings highlight significant vulnerabilities across the globe, particularly in regions such as the United States (174K+), South Africa (172K+), and Australia (111K+). The research, conducted using Modat’s unique internet scanning platform,…
-

Zero-Day Vulnerabilities in HashiCorp Vault Allow Attackers to Execute Code Remotely
In early August 2025, security researchers uncovered a series of critical zero-day vulnerabilities in HashiCorp Vault, a widely adopted secrets management solution. These vulnerabilities, which include authentication bypasses, policy enforcement inconsistencies, and audit-log abuse, create end-to-end attack paths that can lead to remote code execution (RCE) on Vault servers. Initial findings from manual code reviews…
-

Techniques for Preventing Python Supply Chain Attacks
The Python ecosystem, powered by the Python Package Index (PyPI), has become a cornerstone for modern software development. From machine learning libraries to web frameworks, developers can integrate powerful tools with a single pip install command. But this convenience comes with risk: the open-source supply chain is increasingly being targeted by attackers. Python supply chain…
-

Gemini compromised through a prompt injection in a Google Calendar invitation
Artificial intelligence assistants are becoming deeply integrated into our digital lives. From managing emails to controlling smart home devices, AI tools like Google’s Gemini are designed for convenience. But as researchers recently demonstrated, this convenience comes with a hidden cost: an expanded attack surface that cybercriminals are eager to exploit. The Exploit: Prompt Injection via…
-

A critical flaw in HTTP/1.1 has put millions of websites at risk of being seized by malicious actors.
A critical vulnerability in the HTTP/1.1 protocol poses a significant threat to tens of millions of websites, enabling potential hostile takeovers through sophisticated desynchronization attacks. This fundamental flaw creates extreme ambiguity regarding the boundaries of requests, allowing attackers to manipulate web traffic and compromise entire infrastructures. The vulnerability exposes millions of websites to data theft…
-

Microsoft has revealed a vulnerability in Exchange Server that allows for discreet access to cloud services in hybrid configurations.
Microsoft has issued an advisory regarding a high-severity security vulnerability affecting on-premise versions of Exchange Server, identified as CVE-2025-53786, which has a CVSS score of 8.0. This flaw could enable an attacker with administrative access to an on-premises Exchange server to escalate privileges within the connected cloud environment, particularly in hybrid deployments where Exchange Server…
-

CISA Issues Urgent Advisory Calling on Federal Agencies to Fix Exchange Server Flaw by Monday.
The Cybersecurity and Infrastructure Security Agency (CISA) has issued an emergency advisory mandating all Federal Civilian Executive Branch agencies to urgently address a newly identified vulnerability in Microsoft Exchange, tracked as CVE-2025-53786, by 9:00 AM EDT on Monday, August 11, 2025. This vulnerability allows attackers with administrative access to an on-premises Exchange server to move…
-

The ‘DarkWeb’ firmware for Flipper Zero circumvents rolling code security systems used by several leading car manufacturers.
A new custom firmware for the Flipper Zero multi-tool device poses a significant threat to vehicle security by reportedly bypassing the rolling code systems used in many modern cars. Demonstrations from the YouTube channel “Talking Sasquach” indicate that this firmware, which is circulating on the dark web, can clone a vehicle’s keyfob with just a…
-

WhatsApp has removed 6.8 million accounts associated with harmful activities.
WhatsApp has successfully dismantled 6.8 million accounts linked to fraudulent activities in the first half of 2024, marking a significant escalation in its battle against organized cybercrime. This takedown operation, announced by parent company Meta, specifically targeted scam centres operating across Southeast Asia that exploit forced labour to execute sophisticated fraud schemes aimed at global…
