My Courses
-

Cybercriminals have the ability to alter BitLocker registry keys through WMI, enabling them to run harmful code as if they were an interactive user.
A novel lateral movement technique has emerged that exploits BitLocker’s Component Object Model (COM) functionality to execute malicious code on target systems. This technique, demonstrated through the BitLockMove proof-of-concept tool, signifies a sophisticated evolution in lateral movement tactics that bypasses traditional detection mechanisms while leveraging legitimate Windows components. BitLocker, Microsoft’s full disk encryption feature designed…
-

THE BIGGEST Bitcoin HACK EVER, WORTH $3.5 BILLION, HAS BEEN DISCOVERED
The largest cryptocurrency hack ever recorded involved the theft of 127,426 BTC from the Chinese mining pool LuBian in December 2020. At the time of the theft, the stolen Bitcoin was valued at approximately $3.5 billion, but it has since appreciated to an estimated $14.5 billion based on current market valuations. This revelation comes nearly…
-

A data breach at Northwest Radiologists has affected 350,000 residents of Washington.
Northwest Radiologists has reported a significant data breach that has compromised the personal information of approximately 350,000 residents of Washington State. This incident, which occurred in January 2025, raises serious concerns about the security of sensitive data held by healthcare providers. Affected individuals may face risks such as identity theft and fraud, prompting Northwest Radiologists…
-

Multiple security flaws have been fixed in the AI Code Editor named Cursor.
Recent security findings have revealed that attackers could exploit vulnerabilities in the AI Code Editor Cursor by silently modifying sensitive MCP files. This manipulation could trigger the execution of arbitrary code without requiring any user approval, posing a significant risk to users and their data. The potential for such exploitation highlights the urgent need for…
-

Vulnerability in the NestJS Framework Allows Attackers to Run Arbitrary Code on Developers’ Machines.
A critical security vulnerability has been identified in the NestJS framework’s development tools, specifically within the @nestjs/devtools-integration package. This flaw, designated as CVE-2025-54782, allows remote code execution (RCE) attacks, enabling malicious websites to execute arbitrary code on developers’ local machines. The vulnerability arises from an unsafe JavaScript sandbox and inadequate Cross-Origin Resource Sharing (CORS) validation,…
-

A vulnerability in the AI-powered Cursor IDE allows for the execution of remote code without requiring any interaction from the user.
A severe vulnerability in the popular AI-powered code editor Cursor IDE, known as “CurXecute,” has been identified, allowing attackers to execute arbitrary code on developers’ machines without any user interaction. This vulnerability, tracked as CVE-2025-54135, has a high severity score of 8.6 and affects all versions of Cursor IDE prior to 1.3. The flaw exploits…
-

Illumina, a leading company in gene sequencing, has agreed to pay $9.8 million to settle issues related to product vulnerabilities.
Illumina, a leading gene sequencing company, has agreed to pay $9.8 million to resolve allegations that its products supplied to the US government were compromised by cybersecurity vulnerabilities. The settlement comes in response to concerns that these flaws could potentially jeopardise sensitive data and operations within government agencies. By addressing these accusations, Illumina aims to…
-

The PlayPraetor Android Trojan has infected over 11,000 devices by using counterfeit Google Play pages and advertisements on Meta.
Cybersecurity researchers have identified a new Android remote access trojan (RAT) named PlayPraetor, which has already infected over 11,000 devices, predominantly in Portugal, Spain, France, Morocco, Peru, and Hong Kong. The botnet’s rapid expansion, now exceeding 2,000 new infections weekly, is attributed to aggressive campaigns targeting Spanish and French speakers, marking a strategic shift from…
-

APT37 Cybercriminals Utilize JPEG Images to Target Windows Systems Exploiting “mspaint.exe”
A sophisticated new wave of cyberattacks attributed to North Korea’s notorious APT37 (Reaper) group is leveraging advanced malware hidden within JPEG image files to compromise Microsoft Windows systems. This development signals a dangerous evolution in evasion tactics and fileless attack techniques. Security researchers at Genians Security Center (GSC) have recently identified a new variant of…

