My Courses

  • Counterfeit PDF editing software downloads TamperedChef malware

    Counterfeit PDF editing software downloads TamperedChef malware

    Cybersecurity researchers have uncovered a sophisticated cybercrime campaign that employs malvertising techniques to redirect victims to fraudulent websites, ultimately delivering a new information stealer known as TamperedChef. The primary aim of this campaign is to entice users into downloading and installing a trojanised PDF editor, specifically the AppSuite PDF Editor, which is embedded with the…

  • Visual Studio Code vulnerability allows deleted extension takeover

    Visual Studio Code vulnerability allows deleted extension takeover

    Cybersecurity researchers have uncovered a significant loophole in the Visual Studio Code Marketplace that enables threat actors to reuse names of previously removed extensions. Software supply chain security firm ReversingLabs made this discovery after identifying a malicious extension named “ahbanC.shiba,” which operates similarly to two other flagged extensions, “ahban.shiba” and “ahban.cychelloworld.” All three extensions function…

  • s1ngularity Nx attack exposes GitHub credentials

    s1ngularity Nx attack exposes GitHub credentials

    The maintainers of the Nx build system have issued a warning regarding a supply chain attack that enabled attackers to publish malicious versions of the widely used npm package and its auxiliary plugins. These compromised versions contained code designed to scan users’ file systems, collect sensitive credentials, and post this information to GitHub as repositories…

  • Git vulnerability CVE-2025-48384 allows remote code execution

    Git vulnerability CVE-2025-48384 allows remote code execution

    CVE-2025-48384 is a recently patched vulnerability in the widely used distributed revision control system Git, which is currently being exploited by attackers. The US Cybersecurity and Infrastructure Security Agency (CISA) confirmed the exploitation of this flaw and added it to its Known Exploited Vulnerabilities catalog. This vulnerability arises from a mismatch in how Git reads…

  • Over 300,000 Plex Media Server installations remain susceptible to exploitation due to CVE-2025-34158

    Over 300,000 Plex Media Server installations remain susceptible to exploitation due to CVE-2025-34158

    Over 300,000 internet-facing Plex Media Server instances remain vulnerable to the critical CVE-2025-34158, despite a fix being issued earlier this month. Plex Media Server (PMS) allows users to transform their Windows, Linux, or macOS computers, as well as network-attached storage devices, into personal media servers. This software organises movies, music, photos, and other media, enabling…

  • ShadowSilk attacks Asia-Pacific government targets via Telegram bots

    ShadowSilk attacks Asia-Pacific government targets via Telegram bots

    A threat activity cluster known as ShadowSilk has been linked to a new wave of attacks targeting government entities in Central Asia and the Asia-Pacific (APAC) region. According to Group-IB, nearly three dozen victims have been identified, primarily focusing on data exfiltration. The hacking group exhibits toolset and infrastructural overlaps with other threat actors, including…

  • Energy industry needs to be vigilant about cyberattacks

    Energy industry needs to be vigilant about cyberattacks

    The energy sector remains a significant target for cybercriminals, with power outages posing threats to economic stability and public safety. The rising demand for electricity, driven by technological advancements and digital growth, exacerbates the sector’s vulnerabilities. Artificial Intelligence is a major contributor to this demand, with Goldman Sachs predicting a 160% increase in data centre…

  • AI agents vulnerable to prompt injection via image scaling attacks

    AI agents vulnerable to prompt injection via image scaling attacks

    Researchers have uncovered a significant vulnerability in popular AI systems, demonstrating that these technologies can be manipulated into executing malicious instructions concealed within images. This technique, known as a prompt injection via image scaling attack, allows attackers to embed harmful commands in seemingly innocuous visuals. By exploiting the way AI interprets and processes images, malicious…

  • ShadowCaptcha distributing ransomware & cryptominers via compromised WordPress sites

    ShadowCaptcha distributing ransomware & cryptominers via compromised WordPress sites

    A new large-scale cybercrime campaign, codenamed ShadowCaptcha, has been identified, exploiting over 100 compromised WordPress sites. This campaign, first detected in August 2025 by the Israel National Digital Agency, directs unsuspecting visitors to fake CAPTCHA verification pages using the ClickFix social engineering tactic. Researchers Shimi Cohen, Adi Pick, Idan Beit Yosef, Hila David, and Yaniv…

  • HOOK Android Trojan incorporates ransomware overlays & 107 remote commands

    HOOK Android Trojan incorporates ransomware overlays & 107 remote commands

    Cybersecurity researchers have identified a new variant of an Android banking trojan named HOOK, which incorporates ransomware-style overlay screens to display extortion messages. A key feature of this variant is its ability to deploy a full-screen ransomware overlay designed to pressure victims into making ransom payments. Zimperium zLabs researcher Vishnu Pratapagiri noted that this overlay…