My Courses
-

A ransomware assault targeting a phone repair and insurance firm resulted in damages totaling millions.
The sudden emergence of Royal Ransomware in early 2023 marked a significant escalation in cyber threats targeting service providers across Europe. Attackers exploited unpatched VPN and remote-desktop gateways, initiating brute-force and credential-stuffing campaigns to breach perimeter defences. Once inside, the malware deployed a custom encryption engine that utilised AES-256 for file encryption and RSA-4096 to…
-

The vulnerabilities in Nvidia Triton represent a significant threat to AI models.
Nvidia has addressed over a dozen vulnerabilities in its Triton Inference Server, a critical component for deploying AI models. These vulnerabilities pose significant risks to AI systems, potentially compromising their integrity and functionality. The patches released by Nvidia aim to enhance the security of the Triton Inference Server, ensuring that AI applications remain robust against…
-

SonicWall VPNs are being actively targeted due to a zero-day vulnerability that allows attackers to circumvent multi-factor authentication (MFA) and install ransomware.
A likely zero-day vulnerability in SonicWall’s Secure Mobile Access (SMA) VPNs and firewall appliances is currently being exploited in the wild, allowing attackers to bypass multi-factor authentication (MFA) and deploy ransomware within hours of breaching the system. Security firms such as Huntress, Arctic Wolf, and Sophos have reported a significant increase in high-severity incidents targeting…
-

A novel Python-based PXA stealer distributed through Telegram has reportedly compromised 200,000 unique passwords alongside numerous credit card details.
A sophisticated new cybercriminal campaign has emerged, utilising a Python-based information stealer known as PXA Stealer to orchestrate one of the most extensive data theft operations observed in recent months. The malware, which first surfaced in late 2024, has evolved into a highly evasive multi-stage operation that has successfully compromised over 4,000 unique victims across…
-

Vulnerabilities in NVIDIA Triton allow unauthenticated attackers to run code and take control of AI servers.
A newly disclosed set of security flaws in NVIDIA’s Triton Inference Server for Windows and Linux, an open-source platform for running artificial intelligence (AI) models at scale, poses significant risks to susceptible servers. According to Wiz researchers Ronen Shustin and Nir Ohfeld, when these vulnerabilities are chained together, they could allow a remote, unauthenticated attacker…
-

A newly discovered LegalPwn attack leverages Gemini, ChatGPT, and various other AI tools to execute harmful code by manipulating disclaimers.
A new attack method known as “LegalPwn” has been identified, exploiting the tendency of AI models to comply with legal-sounding text. This sophisticated prompt injection technique, revealed by Pangea AI Security, manipulates large language models (LLMs) into executing malicious code by embedding harmful instructions within seemingly legitimate legal disclaimers, copyright notices, and terms of service.…
-

Vietnamese cybercriminals have employed the PXA Stealer tool to target 4,000 IP addresses, successfully compromising 200,000 passwords worldwide.
Cybersecurity researchers have identified a new wave of campaigns distributing a Python-based information stealer known as PXA Stealer. This malicious activity is believed to be orchestrated by Vietnamese-speaking cybercriminals who monetise the stolen data through a subscription-based underground ecosystem that automates resale and reuse via Telegram APIs. A joint report by Beazley Security and SentinelOne…
-

A vulnerability in FUJIFILM printers could allow attackers to initiate a Denial of Service (DoS) condition.
A critical security vulnerability, tracked as CVE-2025-48499, has been identified in multiple FUJIFILM printer models, including various DocuPrint and Apeos series. This vulnerability allows attackers to trigger denial-of-service (DoS) conditions by sending malicious network packets, resulting in printers freezing and requiring manual rebooting. The issue arises from an out-of-bounds write condition in the printer’s buffer…
-

Mozilla has issued a warning regarding phishing attacks aimed at the accounts of add-on developers.
Mozilla has issued an urgent security alert to its developer community due to a sophisticated phishing campaign targeting AMO (Addons.Mozilla.Org) accounts. The company’s security team, led by Scott DeVaney, reported on August 1, 2025, that cybercriminals are actively attempting to compromise developer credentials through deceptive emails that claim account updates are necessary to maintain access…

