My Courses
-

AI Safety Measures Criticized: Cisco’s Demonstration Reveals Vulnerabilities in AI Systems
Cisco’s latest jailbreak method has unveiled significant vulnerabilities in AI systems, particularly highlighting how easily sensitive data can be extracted from chatbots trained on proprietary or copyrighted content. This demonstration raises critical concerns about the effectiveness of current AI guardrails, as it exposes the potential for malicious actors to exploit these weaknesses. The implications of…
-

The United States has declared a funding allocation of $100 million aimed at enhancing cybersecurity for state, local, and tribal governments.
The Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Emergency Management Agency (FEMA) have announced two significant grants exceeding $100 million aimed at enhancing cybersecurity for state, local, and tribal governments. These funds are intended to bolster the cybersecurity posture of various governmental entities, enabling them to better protect critical infrastructure and sensitive data…
-

A recent malware attack is utilizing LNK files to deploy the REMCOS backdoor on Windows systems.
In recent weeks, cybersecurity teams have detected a rise in malicious campaigns that exploit Windows shortcut (LNK) files to deploy sophisticated backdoors. These attacks cleverly disguise LNK shortcuts as harmless documents or folders, taking advantage of Windows’ default setting that hides known file extensions to mislead users. When executed, the shortcut silently invokes PowerShell with…
-

CNCERT has alleged that U.S. intelligence agencies are targeting Chinese military-industrial entities.
Since mid-2022, Chinese military-industrial networks have been subjected to highly sophisticated cyber intrusions attributed to US intelligence agencies. These campaigns exploited previously unknown vulnerabilities to install stealthy malware, maintain prolonged access, and exfiltrate sensitive defence data. The initial identification of these intrusions followed an NSA breach at Northwestern Polytechnical University, with subsequent incidents uncovered by…
-

Researchers took advantage of kernelCTF instances on Google and a zero-day vulnerability in Debian 12.
Researchers have successfully exploited CVE-2025-38001, a previously unknown Use-After-Free (UAF) vulnerability in the Linux Hierarchical Fair Service Curve (HFSC) queuing discipline. This exploit allowed them to compromise all Google kernelCTF instances, including Long-Term Support (LTS), Container-Optimised OS (COS), and mitigation environments, as well as fully patched Debian 12 systems. Their efforts resulted in an estimated…
-

Guide for Preventing Man-in-the-Middle Attacks
Some of the most devastating cyberattacks do not rely on brute force but instead succeed through stealth. These quiet intrusions often go unnoticed until long after the attacker has disappeared. Among the most insidious are Man-in-the-Middle (MITM) attacks, where criminals exploit weaknesses in communication protocols to silently position themselves between two unsuspecting parties. Fortunately, protecting…
-

Critical Vulnerability in Squid Allows Remote Code Execution by Attackers
A critical security vulnerability has been identified in Squid Web Proxy Cache, allowing attackers to execute remote code via a heap buffer overflow in URN (Uniform Resource Name) handling. This vulnerability, tracked as CVE-2025-54574, impacts all Squid versions prior to 6.4 and has been rated with a critical severity level due to its potential for…
-

Cybercriminals are leveraging artificial intelligence to develop a harmful NPM package that can deplete your cryptocurrency wallet.
Cybercriminals have significantly advanced their attack strategies by utilising artificial intelligence to develop a malicious NPM package that disguises itself as a legitimate development tool while covertly draining cryptocurrency wallets. The package, named @Kodane/Patch-Manager, claims to be an “NPM Registry Cache Manager” that offers features like licence validation and registry optimisation. However, it conceals a…
-

A surge in exploitation efforts by threat actors can serve as a preliminary warning of emerging cyber vulnerabilities.
Cybersecurity researchers have identified a significant pattern that could transform how organisations prepare for emerging threats. Their comprehensive analysis indicates that spikes in malicious attacker activity against enterprise edge technologies serve as reliable early warning signals for new vulnerability disclosures. This provides defenders with a critical window of opportunity to bolster their defences before zero-day…
-

Cybersecurity M&A Summary: 44 Transactions Reported in July 2025
In July 2025, the cybersecurity sector witnessed a significant surge in merger and acquisition (M&A) activity, with a total of 44 deals announced. This wave of M&A reflects the growing demand for advanced security solutions as organisations increasingly prioritise their digital defence strategies. Major players in the industry are actively seeking to enhance their capabilities…
