My Courses
-

Akira and Lynx ransomware are targeting Managed Service Providers (MSPs) by exploiting stolen login credentials and existing vulnerabilities.
Two sophisticated ransomware operations, Akira and Lynx, have emerged as significant threats to Managed Service Providers (MSPs) and small businesses. These ransomware-as-a-service (RaaS) groups have collectively compromised over 365 organisations, showcasing their effectiveness in targeting high-value infrastructure providers that serve multiple clients. Since its emergence in 2022, the Akira ransomware group has evolved into one…
-

Trend Micro has released patches for vulnerabilities in Apex One that were being exploited in the wild.
Trend Micro has swiftly addressed two critical zero-day vulnerabilities in its Apex One security solution, which may have been actively exploited by Chinese threat actors. These vulnerabilities posed significant risks, potentially allowing unauthorised access and manipulation of systems protected by Apex One. The urgency of the patch highlights the ongoing threat landscape and the need…
-

PLoB: A Framework for Behavioral Fingerprinting to Detect Malicious Login Attempts.
Splunk researchers have developed an innovative system designed to fingerprint post-logon behaviour, leveraging artificial intelligence to detect subtle signals indicative of potential intrusions. This framework, known as PLoB (Post-Logon Behaviour), aims to enhance security measures by identifying malicious logins that traditional methods may overlook. By analysing user actions after they have logged in, the system…
-

Malicious actors exploit smart contracts to siphon over $900,000 from user cryptocurrency wallets.
In early 2024, a sophisticated campaign emerged, revealing that cybercriminals were distributing malicious Ethereum smart contracts disguised as lucrative trading bots. These weaponised contracts utilised Web3 development platforms like Remix to lure victims into deploying code that ostensibly executed arbitrage strategies, only to redirect deposited funds into wallets controlled by attackers. Rather than conducting legitimate…






