My Courses
-

Counterfeit PDF editing software downloads TamperedChef malware
Cybersecurity researchers have uncovered a sophisticated cybercrime campaign that employs malvertising techniques to redirect victims to fraudulent websites, ultimately delivering a new information stealer known as TamperedChef. The primary aim of this campaign is to entice users into downloading and installing a trojanised PDF editor, specifically the AppSuite PDF Editor, which is embedded with the…
-

Visual Studio Code vulnerability allows deleted extension takeover
Cybersecurity researchers have uncovered a significant loophole in the Visual Studio Code Marketplace that enables threat actors to reuse names of previously removed extensions. Software supply chain security firm ReversingLabs made this discovery after identifying a malicious extension named “ahbanC.shiba,” which operates similarly to two other flagged extensions, “ahban.shiba” and “ahban.cychelloworld.” All three extensions function…
-

Git vulnerability CVE-2025-48384 allows remote code execution
CVE-2025-48384 is a recently patched vulnerability in the widely used distributed revision control system Git, which is currently being exploited by attackers. The US Cybersecurity and Infrastructure Security Agency (CISA) confirmed the exploitation of this flaw and added it to its Known Exploited Vulnerabilities catalog. This vulnerability arises from a mismatch in how Git reads…
-

Over 300,000 Plex Media Server installations remain susceptible to exploitation due to CVE-2025-34158
Over 300,000 internet-facing Plex Media Server instances remain vulnerable to the critical CVE-2025-34158, despite a fix being issued earlier this month. Plex Media Server (PMS) allows users to transform their Windows, Linux, or macOS computers, as well as network-attached storage devices, into personal media servers. This software organises movies, music, photos, and other media, enabling…
-

ShadowSilk attacks Asia-Pacific government targets via Telegram bots
A threat activity cluster known as ShadowSilk has been linked to a new wave of attacks targeting government entities in Central Asia and the Asia-Pacific (APAC) region. According to Group-IB, nearly three dozen victims have been identified, primarily focusing on data exfiltration. The hacking group exhibits toolset and infrastructural overlaps with other threat actors, including…
-

Energy industry needs to be vigilant about cyberattacks
The energy sector remains a significant target for cybercriminals, with power outages posing threats to economic stability and public safety. The rising demand for electricity, driven by technological advancements and digital growth, exacerbates the sector’s vulnerabilities. Artificial Intelligence is a major contributor to this demand, with Goldman Sachs predicting a 160% increase in data centre…
-

AI agents vulnerable to prompt injection via image scaling attacks
Researchers have uncovered a significant vulnerability in popular AI systems, demonstrating that these technologies can be manipulated into executing malicious instructions concealed within images. This technique, known as a prompt injection via image scaling attack, allows attackers to embed harmful commands in seemingly innocuous visuals. By exploiting the way AI interprets and processes images, malicious…



