My Courses
-

Remote hiring fraud increasing quickly
What if the star engineer that an organisation just hired is actually an attacker in disguise? This scenario is not about phishing; it involves infiltration through the onboarding process. Meet “Jordan from Colorado,” who possesses a strong resume, convincing references, a clean background check, and a digital footprint that checks out. On their first day,…
-

MystRodX backdoor uses DNS and ICMP triggers for covert manipulation
Cybersecurity researchers have recently unveiled a sophisticated backdoor known as MystRodX, which is designed to capture sensitive data from compromised systems. Implemented in C++, MystRodX boasts features such as file management, port forwarding, reverse shell, and socket management. According to QiAnXin XLab, this backdoor distinguishes itself from typical variants through its exceptional stealth and flexibility.…
-

Can AI agents identify threats that your Security Operations Center overlooks?
A new research project called NetMoniAI demonstrates how AI agents could transform network monitoring and security. Developed by a team at Texas Tech University, the framework integrates distributed monitoring at the edge with AI-driven analysis at the centre. Although still in the research stage, it provides Chief Information Security Officers (CISOs) with insights into the…
-

Iranian cybercriminals compromise over 100 diplomatic email accounts
An Iran-nexus group has been linked to a “coordinated” and “multi-wave” spear-phishing campaign targeting embassies and consulates across Europe and other regions globally. This activity has been attributed to Iranian-aligned operators associated with a group known as Homeland Justice, as reported by Israeli cybersecurity company Dream. The campaign involved sending emails that disguised legitimate diplomatic…
-

BruteForceAI: New AI-powered Github tool
BruteForceAI is an innovative penetration testing tool that leverages Large Language Models (LLMs) to enhance the execution of brute-force attacks. Unlike traditional methods that require extensive manual setup, BruteForceAI automatically analyses HTML content to detect login form selectors, streamlining the attack preparation process. This tool is designed to simulate realistic human behaviour while conducting multi-threaded…
-

Connected vehicles are intelligent, user-friendly, and vulnerable to cyberattack
Consumers are increasingly concerned about vulnerabilities in their vehicles, which significantly impacts their purchasing behaviour and brand loyalty, according to RunSafe Security. Modern vehicles operate on over 100 million lines of code, surpassing that of most fighter jets, yet they often lack adequate cybersecurity measures. While innovations such as over-the-air (OTA) updates and smartphone integration…
-

Fake npm packages stealing Ethereum wallet keys
A new set of four malicious packages has been discovered in the NPM package registry, designed to steal cryptocurrency wallet credentials from Ethereum developers. These packages masquerade as legitimate cryptographic utilities and Flashbots MEV infrastructure while secretly exfiltrating private keys and mnemonic seeds to a Telegram bot controlled by the threat actor. Socket researcher Kush…
-

TAG-150 creates CastleRAT using Python and C, broadening the capabilities of CastleLoader malware.
The threat actor known as TAG-150 is behind the malware-as-a-service (MaaS) framework and loader called CastleLoader, as well as a remote access trojan (RAT) named CastleRAT. CastleRAT is available in both Python and C variants, with its core functionalities including the collection of system information, downloading and executing additional payloads, and executing commands via CMD…


