My Courses
-

A recent report shows that AI has reduced the workloads for virtual Chief Information Security Officers (vCISOs) by 68%, responding to the increasing demands from small and medium-sized businesses (SMBs).
As the volume and sophistication of cyber threats continue to escalate, cybersecurity has become essential for businesses of all sizes. Small and Medium-sized Businesses (SMBs) are increasingly turning to Virtual Chief Information Security Officer (vCISO) services to navigate these challenges and meet compliance demands. A recent report by Cynomi reveals that 79% of Managed Service…
-

Trend Micro has verified that critical vulnerabilities in Apex One on-premise systems are being actively exploited.
Trend Micro has announced mitigations for critical security vulnerabilities in the on-premise versions of Apex One Management Console, which have reportedly been exploited in the wild. The vulnerabilities, identified as CVE-2025-54948 and CVE-2025-54987, both received a CVSS score of 9.4 and are classified as management console command injection and remote code execution flaws. According to…
-

CERT-UA alerts about malware attacks delivered through HTA files, utilizing court summons as bait.
The Computer Emergency Response Team of Ukraine (CERT-UA) has issued a warning regarding cyber attacks conducted by a threat actor known as UAC-0099. This group is targeting government agencies, defence forces, and enterprises within the defence-industrial complex in Ukraine. The attacks primarily utilise phishing emails as an initial compromise vector, delivering various malware families, including…
-

CISA has included three D-Link vulnerabilities in its Known Exploited Vulnerabilities (KEV) Catalog due to indications of ongoing exploitation.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) recently added three significant security vulnerabilities affecting D-Link routers to its Known Exploited Vulnerabilities (KEV) catalog, following evidence of active exploitation. These high-severity vulnerabilities, identified as CVE-2020-25078, CVE-2020-25079, and CVE-2020-40799, stem from 2020 and 2022. CVE-2020-25078, with a CVSS score of 7.5, allows for remote administrator password…
-

CISA has published two advisories addressing vulnerabilities and exploits related to Industrial Control Systems (ICS).
On August 5, 2025, the Cybersecurity and Infrastructure Security Agency (CISA) issued two urgent advisories regarding critical vulnerabilities in Industrial Control Systems (ICS) that could severely impact the manufacturing and energy sectors. The advisories highlight significant security flaws in products from Mitsubishi Electric and Tigo Energy, with the latter’s vulnerabilities allowing for remote exploitation, while…
-

AI is revolutionizing the field of cybersecurity adversarial testing, according to the insights of the founder of Pentera.
In 2015, the founder of a cybersecurity testing software company envisioned the necessity of automated penetration testing, a concept that faced initial scepticism. Today, with over 1,200 enterprise customers and thousands of users, this vision has been validated. However, the founder acknowledges that the current achievements are merely the foundation for future advancements. The emergence…
-

Numerous Dell laptops are at risk of being compromised, allowing unauthorized access and ongoing malware infections.
A wide range of vulnerabilities, collectively known as “ReVault,” affects millions of Dell laptops utilised by government agencies, cybersecurity professionals, and enterprises globally. These vulnerabilities specifically target the Broadcom BCM5820X security chip embedded in Dell’s ControlVault3 firmware, creating opportunities for attackers to steal passwords and biometric data while maintaining persistent access to compromised systems. More…
-

The frequency of cyber attacks targeting AI infrastructure is increasing, with significant vulnerabilities being identified.
Cybercriminals have increasingly targeted high-value infrastructure that supports the training, tuning, and serving of modern artificial intelligence models. Over the past six months, incident-response teams have identified a new malware family, provisionally named “ShadowInit.” This malware specifically targets GPU clusters, model-serving gateways, and orchestration pipelines within large language model (LLM) deployments. Unlike previous crypto-mining campaigns,…
-

Microsoft is hosting the Zero Day Quest Hacking Contest, offering rewards that can reach as high as $5 million.
Microsoft has announced the return of its groundbreaking Zero Day Quest, the largest public hacking event in history, offering unprecedented bounty rewards of up to $5 million for high-impact security research. Building on last year’s successful $4 million initiative, this enhanced program underscores Microsoft’s commitment to collaborative security through responsible vulnerability disclosure and community engagement.…
-

The U.S. Treasury has issued a warning regarding cryptocurrency ATMs contributing to illegal activities.
The U.S. Department of the Treasury’s Financial Crimes Enforcement Network (FinCEN) has issued a significant warning regarding the misuse of Convertible Virtual Currency (CVC) kiosks by criminal organisations. Released on August 4, 2025, the advisory underscores how these cryptocurrency ATMs, intended for legitimate users, have become major conduits for fraudulent activities and money laundering. FinCEN…
