My Courses
-

Parallel-Poisoned Web Attack presents poisoned web pages to AI web bots
AI agents can be manipulated into executing malicious actions by websites that remain concealed from regular users, as discovered by JFrog AI architect Shaked Zychlinski. This innovative method enables attackers to inject prompts or instructions into these autonomous AI-powered assistants, effectively hijacking their behaviour for nefarious purposes. Indirect prompt-injection poisoning attacks, where harmful instructions are…
-

SAP S/4HANA vulnerability CVE-2025-42957 actively exploited
A critical security vulnerability affecting SAP S/4HANA, an Enterprise Resource Planning (ERP) software, has been actively exploited in the wild. The command injection vulnerability, identified as CVE-2025-42957 with a CVSS score of 9.9, was addressed by SAP in its recent monthly updates. According to the NIST National Vulnerability Database (NVD), this flaw allows an attacker…
-

AI-driven supply chain attack using model namespace reuse
A critical AI supply chain vulnerability known as Model Namespace Reuse has emerged, posing significant risks to major tech companies like Google and Microsoft. This issue enables attackers to deploy malicious AI models, which can lead to unauthorised code execution within affected systems. By exploiting this vulnerability, cybercriminals can manipulate the AI supply chain, potentially…
-

Importance of the CVE matrix for cybersecurity
The industry operates under the influence of Common Vulnerabilities and Exposures (CVE). Each security update released by various vendors addresses specific software flaws that could be exploited. These publicly acknowledged flaws are assigned a CVE designator along with associated parameters such as type, severity, and CVSS score. These parameters are crucial for assessing the risk…
-

Hidden SVG files launch base64-encoded phishing sites
Cybersecurity researchers have identified a new malware campaign that utilises Scalable Vector Graphics (SVG) files in phishing attacks, impersonating the Colombian judicial system. According to VirusTotal, these SVG files are distributed via email and are designed to execute an embedded JavaScript payload. This payload decodes and injects a Base64-encoded HTML phishing page that masquerades as…
-

File security risks increasing due to insider threats, malware, and AI
Breaches related to file access are increasingly common, leading to significant financial repercussions for many organisations. Over the past two years, numerous companies have experienced multiple file-related incidents, resulting in losses that can reach millions. The consequences of these breaches often include the theft of customer data, diminished productivity, and the exposure of intellectual property.…
-

GhostRedirector compromises Windows servers utilizing Rungan backdoor and Gamshen IIS module
Cybersecurity researchers have uncovered a previously undocumented threat cluster known as GhostRedirector, which has compromised at least 65 Windows servers, primarily located in Brazil, Thailand, and Vietnam. According to Slovak cybersecurity company ESET, the attacks have resulted in the deployment of a passive C++ backdoor named Rungan and a native Internet Information Services (IIS) module…
-

Russian cyberespionage group APT28 targets NATO member firms with Outlook “NotDoor” backdoor
The Russian state-sponsored hacking group known as APT28 has been linked to a new Microsoft Outlook backdoor called NotDoor, which has been used in attacks against various companies across NATO member countries. NotDoor functions as a Visual Basic for Applications (VBA) macro designed to monitor incoming emails for specific trigger words. When such an email…
-

USA and allies advocating Software Bill of Materials (SBOMs)
The adoption of Software Bill of Materials (SBOM) is set to significantly enhance software supply chain security, thereby reducing risks and costs associated with vulnerabilities. As the United States and its allies advocate for the implementation of SBOMs, the initiative aims to provide a clearer view of the components within software products. This transparency is…

