My Courses
-

Cybercriminals are exploiting SVG files by embedding harmful JavaScript to deploy malware on Windows systems.
Cybercriminals have started to exploit Scalable Vector Graphics (SVG) files as advanced attack vectors, turning seemingly innocuous image files into powerful phishing tools capable of executing malicious JavaScript on Windows systems. This emerging threat takes advantage of the XML-based structure of SVG files, allowing attackers to embed and execute harmful scripts when these files are…
-

SocGholish malware is distributed through advertising tools and provides access to various groups such as LockBit and Evil Corp.
The threat actors behind the SocGholish malware have been observed utilising Traffic Distribution Systems (TDSs) such as Parrot TDS and Keitaro TDS to filter and redirect unsuspecting users to dubious content. The core of their operation revolves around a sophisticated Malware-as-a-Service (MaaS) model, where infected systems are sold as initial access points to other cybercriminal…
-

WhatsApp developers are facing threats from malicious npm packages that come with a remote kill switch.
Two malicious npm packages, identified as Naya-Flore and Nvlore-Hsc, have emerged as sophisticated threats targeting WhatsApp developers through a remote-controlled destruction mechanism capable of wiping development systems entirely. These packages masquerade as legitimate WhatsApp socket libraries while harbouring a devastating kill switch that can execute system-wide file deletion with a single command. Published by npm…
-

SonicWall has verified that there are no new zero-day vulnerabilities in SSLVPN, stating that the recent ransomware attack is associated with an older vulnerability.
SonicWall has officially addressed concerns regarding a potential new zero-day vulnerability in its Secure Sockets Layer Virtual Private Network (SSLVPN) products. In a statement to Cybersecurity News, the company confirmed that recent ransomware attacks are not due to a new flaw but are linked to a previously identified and patched vulnerability, specifically CVE-2024-40766. This vulnerability…
-

The ScarCruft hacker group has initiated a new malware campaign that utilizes Rust programming language and the PubNub service.
The North Korean state-sponsored Advanced Persistent Threat (APT) group ScarCruft has initiated a sophisticated malware campaign aimed at South Korean users, utilising a deceptive postal-code update notice as bait. This attack signifies a notable advancement in ScarCruft’s operational capabilities, as it marks the first recorded deployment of ransomware alongside their traditional espionage tools. The campaign…
-

Recent “Ghost Calls” attacks exploit web conferencing tools for secret command and control operations.
A sophisticated new attack technique known as “Ghost Calls” exploits web conferencing platforms to establish covert command and control (C2) channels. Presented by Adam Crosser from Praetorian at Black Hat USA 2025, this groundbreaking research reveals how attackers can leverage the TURN protocol and legitimate conferencing infrastructure to bypass network security measures. The TURNt tool…
-

A total of 6,500 Axis servers are found to have the Remoting Protocol open, with 4,000 of them located in the United States susceptible to potential exploits.
Cybersecurity researchers have identified multiple security vulnerabilities in video surveillance products from Axis Communications that could potentially lead to takeover attacks. These flaws allow for pre-authentication remote code execution on the Axis Device Manager, a server responsible for configuring and managing camera fleets, as well as on the Axis Camera Station, the client software used…



