My Courses

  • Considering Browsers as a Vulnerability Target: Reevaluating Security for Scattered Spider

    Considering Browsers as a Vulnerability Target: Reevaluating Security for Scattered Spider

    As enterprises increasingly transition their operations to web-based platforms, security teams encounter a rising array of cyber challenges. Over 80% of security incidents now stem from web applications accessed through browsers like Chrome, Edge, and Firefox. One particularly agile adversary, Scattered Spider, has focused its efforts on compromising sensitive data within these browsers. Known also…

  • ScarCruft’s “Operation HanKook Phantom” targeting South Korean academics with RokRAT malware

    ScarCruft’s “Operation HanKook Phantom” targeting South Korean academics with RokRAT malware

    Cybersecurity researchers have identified a new phishing campaign orchestrated by the North Korea-linked hacking group known as ScarCruft (also referred to as APT37), aimed at delivering a malware called RokRAT. This operation, dubbed Operation HanKook Phantom by Seqrite Labs, appears to target individuals affiliated with the National Intelligence Research Association, including academics, former government officials,…

  • Velociraptor forensic tool used for command and control tunneling

    Velociraptor forensic tool used for command and control tunneling

    Cybersecurity researchers have highlighted a recent cyber attack involving the deployment of Velociraptor, an open-source endpoint monitoring and digital forensic tool, by unknown threat actors. This incident exemplifies the ongoing misuse of legitimate software for malicious purposes. According to the Sophos Counter Threat Unit Research Team, the attackers utilised Velociraptor to download and execute Visual…

  • Abandoned Sogou Zhuyin update server compromised and repurposed for Taiwan espionage operation

    Abandoned Sogou Zhuyin update server compromised and repurposed for Taiwan espionage operation

    An abandoned update server linked to the Input Method Editor (IME) software Sogou Zhuyin was exploited by threat actors in an espionage campaign that delivered various malware families, including C6DOOR and GTELAM. This campaign, identified in June 2025 and codenamed TAOTH by Trend Micro researchers Nick Dai and Pierre Lee, primarily targeted users in Eastern…

  • Amazon disrupts APT29 watering hole attack using Microsoft Device Code Authentication

    Amazon disrupts APT29 watering hole attack using Microsoft Device Code Authentication

    On Friday, Amazon reported that it had identified and disrupted an opportunistic watering hole campaign orchestrated by the Russia-linked APT29 actors, aimed at intelligence gathering. The campaign involved compromised websites that redirected visitors to malicious infrastructure, designed to deceive users into authorising attacker-controlled devices through Microsoft’s device code authentication flow, as stated by Amazon’s Chief…

  • FreePBX servers exploited by zero-day vulnerability

    FreePBX servers exploited by zero-day vulnerability

    The Sangoma FreePBX Security Team has issued a critical advisory regarding an actively exploited zero-day vulnerability affecting FreePBX systems with an exposed Administrator Control Panel (ACP) on the public internet. FreePBX, an open-source private branch exchange (PBX) platform built on Asterisk, is widely utilised by businesses, call centres, and service providers for managing voice communications.…

  • Storm-0501 utilizes Entra ID to extract and erase Azure data during hybrid cloud attacks

    Storm-0501 utilizes Entra ID to extract and erase Azure data during hybrid cloud attacks

    The financially motivated threat actor known as Storm-0501 has been observed refining its tactics to conduct data exfiltration and extortion attacks targeting cloud environments. Unlike traditional on-premises ransomware, where the threat actor typically deploys malware to encrypt critical files across endpoints within the compromised network and then negotiates for a decryption key, cloud-based ransomware introduces…

  • First AI-driven ransomware leveraging OpenAI model

    First AI-driven ransomware leveraging OpenAI model

    ESET, a cybersecurity company, has disclosed the discovery of an artificial intelligence (AI)-powered ransomware variant codenamed PromptLock. Written in Golang, this newly identified strain utilises the gpt-oss:20b model from OpenAI locally via the Ollama API to generate malicious Lua scripts in real-time. The open-weight language model was released by OpenAI earlier this month. PromptLock leverages…

  • Anthropic AI used for cybercrime

    Anthropic AI used for cybercrime

    A new report from Anthropic reveals that criminals are increasingly using AI to manage various aspects of their operations. The findings indicate that AI is now integrated throughout the entire attack cycle, encompassing reconnaissance, malware development, fraud, and extortion. This report is based on actual cases where Anthropic’s models were misused, providing a unique perspective…