My Courses
-

IRGC-affiliated hacking groups are launching attacks on specific financial institutions, government entities, and media organizations.
During the 12-day conflict between Israel and Iran in June 2025, a sophisticated network of Iranian-linked cyber threat actors launched coordinated digital operations against critical infrastructure sectors worldwide. This campaign showcased unprecedented coordination between military operations and state-sponsored cyberattacks, targeting financial institutions, government agencies, and media organisations across multiple countries. The cyber offensive involved a…
-

Advanced DevilsTongue Windows spyware monitors users around the world.
The emergence of DevilsTongue signifies a notable advancement in mercenary spyware capabilities, employing sophisticated Windows-based techniques to infiltrate high-value targets globally. First detected in campaigns dating back to 2019, this modular malware aggressively exploits zero-day browser vulnerabilities and weaponised documents to gain initial access. Once deployed, it establishes a covert presence, exfiltrating sensitive data from…
-

Weaknesses in Rockwell Arena Simulation allow attackers to run harmful code from a distance.
Rockwell Automation has disclosed three critical memory corruption vulnerabilities in its Arena® Simulation software, which could enable threat actors to execute arbitrary code remotely on affected systems. The vulnerabilities, identified as CVE-2025-7025, CVE-2025-7032, and CVE-2025-7033, carry a high CVSS 4.0 base score of 8.4 and affect all versions 16.20.09 and prior. Discovered internally during routine…
-

CAPTCHAgeddon – A New ClickFix Attack Uses Phony CAPTCHA to Distribute Malware
A sophisticated new malware campaign, known as “ClickFix,” has emerged, weaponising fake CAPTCHA verification pages to deceive users into executing malicious PowerShell commands. This campaign marks a significant evolution in browser-based attack methodologies, representing a next-generation mutation of traditional fake browser update scams that were prevalent throughout 2024. Victims encounter what appears to be a…
-

Vulnerabilities in CyberArk Conjur have led to the exposure of sensitive enterprise information.
CyberArk has addressed multiple vulnerabilities within its Conjur platform that posed significant risks, allowing for unauthenticated remote code execution. These vulnerabilities could potentially be exploited in a chain reaction, leading to severe security breaches and the exposure of enterprise secrets. The timely patching of these issues underscores CyberArk’s commitment to maintaining robust security measures for…
-

SpyCloud Improves Its Investigations Solution by Incorporating AI-Driven Insights – Transforming the Analysis of Insider Threats and Cybercrime.
SpyCloud, a leader in identity threat protection, announced a significant enhancement to its SaaS Investigations solution on August 6th, 2025. The integration of advanced AI-powered insights aims to empower security teams with finished intelligence derived from billions of breach, malware, and phishing records. This new capability builds on the foundation of SpyCloud’s industry-leading IDLink identity…
-

A newly discovered vulnerability in Microsoft Exchange Server allows attackers to acquire administrative privileges.
A critical security vulnerability in Microsoft Exchange Server hybrid deployments has been disclosed, allowing attackers with on-premises administrative access to escalate privileges to cloud environments without easily detectable traces. This vulnerability, tracked as CVE-2025-53786, was officially documented by Microsoft on August 6, 2025, following a demonstration by security researcher Dirk-Jan Mollema at the Black Hat…
-

Leading enterprise AI assistants are susceptible to misuse, which could lead to data theft and manipulation.
Zenity has revealed significant vulnerabilities in major AI assistants, including ChatGPT, Copilot, Cursor, Gemini, and Salesforce Einstein. These AI tools can be manipulated through specially crafted prompts, leading to potential data theft and manipulation. The findings highlight the ease with which malicious actors can exploit these systems, raising concerns about the security measures in place…


