My Courses

  • DDoS attacks act as tools for political leverage and chaos

    DDoS attacks act as tools for political leverage and chaos

    In the first half of 2025, there were 8,062,971 DDoS attacks globally, with the EMEA region experiencing the highest volume at 3.2 million attacks, according to Netscout. Peak attack speeds reached an alarming 3.12 Tbps and 1.5 Gpps. These attacks have evolved from mere disruption tools into precise instruments of geopolitical influence, capable of targeting…

  • The US Cybersecurity Agency has highlighted a vulnerability in Wi-Fi range extenders that is currently being exploited.

    The US Cybersecurity Agency has highlighted a vulnerability in Wi-Fi range extenders that is currently being exploited.

    The Cybersecurity and Infrastructure Security Agency (CISA) has identified a significant vulnerability in the TP-Link TL-WA855RE Wi-Fi range extender, which allows attackers to reset and hijack the devices. This flaw poses a serious risk to users, as it can lead to unauthorised access to their networks. CISA has urged individuals still using these discontinued extenders…

  • Malicious actors using HexStrike AI to create Citrix exploits

    Malicious actors using HexStrike AI to create Citrix exploits

    Threat actors are attempting to exploit a newly released artificial intelligence (AI) offensive security tool called HexStrike AI, which is designed to automate reconnaissance and vulnerability discovery. HexStrike AI is marketed as an AI-driven security platform aimed at enhancing authorised red teaming operations, bug bounty hunting, and capture the flag (CTF) challenges. The open-source platform…

  • Cloudflare successfully thwarts unprecedented DDoS attack

    Cloudflare successfully thwarts unprecedented DDoS attack

    A recent wave of Distributed Denial of Service (DDoS) attacks persisted for several weeks, characterised by a massive User Datagram Protocol (UDP) flood. This unprecedented assault originated from multiple Internet of Things (IoT) devices and cloud service providers, showcasing the vulnerabilities inherent in these technologies. The scale of the attack was staggering, reaching a record-breaking…

  • How a background in gaming can benefit a career in cybersecurity

    How a background in gaming can benefit a career in cybersecurity

    Many people may not realise that playing video games can contribute to a career in cybersecurity. The skills acquired through gaming, although seemingly unrelated at first, can be highly beneficial in this field. With over 3 billion gamers globally, there exists a significant talent pool that companies could tap into for cybersecurity roles. Organisations struggling…

  • WhatsApp Zero-day vulnerabilities utilised for iOS attacks

    WhatsApp Zero-day vulnerabilities utilised for iOS attacks

    A critical vulnerability identified as CVE-2025-55177 has been exploited in conjunction with a zero-day flaw affecting iOS and macOS systems. This exploitation is believed to be part of a series of suspected spyware attacks targeting Apple users. The security breach highlights the increasing sophistication of cyber threats, particularly those aimed at popular platforms like WhatsApp.…

  • Silver Fox using WatchDog driver to distribute ValleyRAT malware

    Silver Fox using WatchDog driver to distribute ValleyRAT malware

    The threat actor known as Silver Fox has exploited a previously unknown vulnerable driver associated with WatchDog Anti-Malware in a Bring Your Own Vulnerable Driver (BYOVD) attack. This attack aims to disable security solutions on compromised hosts. The vulnerable driver, “amsdk.sys” (version 1.0.600), is a 64-bit, validly signed Windows kernel device driver built on the…

  • Nodemailer imitator nodejs-smtp clips Atomic and Exodus wallets

    Nodemailer imitator nodejs-smtp clips Atomic and Exodus wallets

    Cybersecurity researchers have uncovered a malicious npm package named Nodejs-Smtp, which stealthily injects harmful code into desktop applications for cryptocurrency wallets such as Atomic and Exodus on Windows systems. This package, uploaded in April 2025 by a user named “nikotimon,” impersonates the legitimate email library Nodemailer, featuring identical taglines, page styling, and README descriptions. Despite…

  • Ukrainian group FDN3 initiates large-scale brute-force attacks against SSL VPN and RDP systems.

    Ukrainian group FDN3 initiates large-scale brute-force attacks against SSL VPN and RDP systems.

    Cybersecurity researchers have identified a Ukrainian IP network, FDN3 (AS211736), as being involved in extensive brute-force and password spraying campaigns targeting SSL VPN and RDP devices during June and July 2025. According to a report from French cybersecurity firm Intrinsec, FDN3 is believed to be part of a larger abusive infrastructure that includes two other…

  • Android Droppers distributing banking trojans, SMS stealers and spyware

    Android Droppers distributing banking trojans, SMS stealers and spyware

    Cybersecurity researchers are highlighting a significant shift in the Android malware landscape, where dropper apps, traditionally used to deliver banking trojans, are now also distributing simpler forms of malware such as SMS stealers and basic spyware. These campaigns are being propagated through dropper apps that masquerade as government or banking applications in India and other…