My Courses
-

The Cursor AI Code Editor has addressed a vulnerability that permitted attackers to execute commands through prompt injection.
Cybersecurity researchers have identified and disclosed a critical security vulnerability in Cursor, a widely used AI code editor, which could lead to remote code execution (RCE). This vulnerability, designated as CVE-2025-54135 with a CVSS score of 8.6, has been patched in version 1.3 released on July 29, 2025. Codenamed CurXecute by Aim Labs, the flaw…
-

A new backdoor called ‘Plague’ has emerged that compromises critical Linux systems, allowing for covert theft of credentials.
Cybersecurity researchers have identified a previously undocumented Linux backdoor known as Plague, which has successfully evaded detection for over a year. This malicious implant functions as a Pluggable Authentication Module (PAM), allowing attackers to silently bypass system authentication and maintain persistent SSH access. Pluggable Authentication Modules are a suite of shared libraries that manage user…
-

CL-STA-0969 Deploys Hidden Malware in Telecommunications Infrastructures Throughout a 10-Month Intelligence Gathering Operation.
Telecommunications organisations in Southeast Asia have been targeted by a state-sponsored threat actor known as CL-STA-0969, which aims to facilitate remote control over compromised networks. Palo Alto Networks Unit 42 reported multiple incidents in the region, including one that specifically targeted critical telecommunications infrastructure between February and November 2024. The attacks are characterised by the…
-

Cyber risk management company Safe has secured $70 million in funding.
Cyber risk management firm Safe has successfully raised $70 million in Series C funding to enhance its innovative approach to cyber risk management through the development of specialised AI agents. This significant investment will enable Safe to further advance its technology, providing organisations with more effective tools to identify, assess, and mitigate cyber threats. The…
-

According to Microsoft, Russian cyberspies are conducting AitM attacks on foreign embassies located in Moscow.
Russian state-sponsored Advanced Persistent Threat (APT) group Secret Blizzard has been implicated in sophisticated ISP-level Attack-in-the-Middle (AitM) operations targeting foreign embassies in Moscow. According to a report by Microsoft, these cyber espionage activities have enabled the group to infiltrate diplomatic devices with malware, posing significant risks to sensitive communications and data. The AitM attacks leverage…
-

Microsoft Enhances .NET Bounty Program – Increases Max Reward to $40,000
Microsoft has announced an increase in the rewards for its .NET Bounty Program, now offering up to $40,000 for valid and complete reports that detail remote code execution or elevation of privilege vulnerabilities. This significant boost aims to encourage security researchers to identify and report critical bugs within the .NET framework. By enhancing the financial…
-

Gen Z Targeted: Cybercriminals Turn Their Attention to Tech-Savvy Young Professionals
As cybercriminals increasingly target Generation Z, companies must consider treating this demographic as a distinct attack surface. Gen Z, known for their digital savviness, often lacks the experience to recognise sophisticated cyber threats, making them particularly vulnerable. This age group is frequently engaged with various online platforms, which can expose them to phishing attacks, social…
-

What is Information Security (InfoSec)?
Information security, commonly known as InfoSec, involves the strategies and measures implemented to safeguard sensitive business information from unauthorized access, alteration, disruption, or destruction. This field is essential for maintaining the confidentiality, integrity, and availability of data. Cybersecurity vs. Information Security: While both terms are often used interchangeably, they have distinct meanings. Cybersecurity is a…
