My Courses
-

CISA has issued a warning regarding vulnerabilities in D-Link products that are currently being exploited in attacks.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a new alert, adding three vulnerabilities affecting D-Link devices to its Known Exploited Vulnerabilities (KEV) Catalog. This inclusion indicates that these flaws are actively exploited by malicious cyber actors, posing significant threats to networks. The vulnerabilities impact several D-Link products, specifically CVE-2020-25078, which affects D-Link…
-

Over 10,000 harmful TikTok Shop websites are targeting users to obtain login details and distribute malware.
A sophisticated cybercriminal campaign known as “ClickTok” has emerged as a significant threat to TikTok Shop users globally. Researchers have identified over 10,000 malicious domains aimed at stealing user credentials and deploying advanced spyware. This campaign marks a notable escalation in e-commerce-focused cyberattacks, merging traditional phishing techniques with innovative malware distribution to exploit the rising…
-

The Compliance Checklist for Network Security: 25 Controls That Are Mapped and Prepared for Auditing
Following new SEC rules announced on July 26, 2023, U.S. public companies are required to disclose any cybersecurity incident deemed ‘material’ within four business days of that determination. This requirement became effective for most companies on December 15, 2023. The average global cost of a data breach surged to $4.88 million in 2024, with significant…
-

How to Obtain Real-Time Indicators of Compromise from Incidents in 15,000 Security Operations Centers.
Cybersecurity is fundamentally about staying one step ahead of potential threats. The security of business assets relies heavily on proactive threat detection and rapid response, which are powered by high-quality data. Every security system and service, from network monitoring to incident response and analytics, depends on continuous data feeds to operate effectively. Effective cybersecurity is…
-

How Poor Certificate Management Creates Vulnerabilities for Phishing and Man-in-the-Middle Attacks
SSL Certificates are ubiquitous, utilised across websites, APIs, mobile applications, internal tools, and CI/CD pipelines. While most teams recognise their significance, they often fail to manage them effectively. Certificates are typically overlooked until a failure occurs. If they expire, are misused, or lack proper monitoring, they become prime targets for attackers. A minor error in…
-

A newly identified MCPoison attack utilizes the Cursor IDE’s MCP validation process to run arbitrary commands within the system.
A critical vulnerability in Cursor IDE, an increasingly popular AI-powered development environment, allows for persistent remote code execution through the manipulation of the Model Context Protocol (MCP) system. This vulnerability, tracked as CVE-2025-54136 and referred to as “MCPoison,” exploits a flaw in trust validation that enables attackers to execute arbitrary commands on developer machines without…
-

Microsoft’s Project Ire independently reverse engineers software to detect malware.
Microsoft has introduced Project Ire, an innovative prototype that leverages autonomous AI technology to analyse software files for potential malicious content. This advanced AI agent is designed to autonomously reverse engineer software, enabling it to identify and assess threats effectively. By utilising sophisticated algorithms, Project Ire can dissect various software components, providing a comprehensive evaluation…
-

A vulnerability in the Cursor AI Code Editor allows for remote code execution (RCE) by swapping in a malicious MCP file after it has been approved.
Cybersecurity researchers have identified a significant security vulnerability in the AI-powered code editor Cursor, which could lead to remote code execution. This flaw, designated as CVE-2025-54136 with a CVSS score of 7.2, has been dubbed MCPoison by Check Point Research. The vulnerability exploits a peculiarity in how Cursor manages modifications to Model Context Protocol (MCP)…
-

Google’s August update addresses two Qualcomm vulnerabilities that have been actively exploited.
Google has released critical security updates to address multiple vulnerabilities in Android, including two Qualcomm bugs identified as actively exploited. The vulnerabilities, CVE-2025-21479 (CVSS score: 8.6) and CVE-2025-27038 (CVSS score: 7.5), were disclosed by Qualcomm in June 2025, alongside CVE-2025-21480 (CVSS score: 8.6). CVE-2025-21479 pertains to an incorrect authorisation vulnerability in the Graphics component, potentially…

