My Courses

  • Docker vulnerability (CVE-2025-9074) allows container escape, assigned CVSS of 9.3

    Docker vulnerability (CVE-2025-9074) allows container escape, assigned CVSS of 9.3

    Docker has released critical fixes for a significant security vulnerability affecting the Docker Desktop application for Windows and macOS. This flaw, identified as CVE-2025-9074, has a CVSS score of 9.3 out of 10.0 and has been addressed in version 4.44.3. The vulnerability allows a malicious container to access the Docker Engine and launch additional containers…

  • Diplomats targeted by UNC6384 through captive portal hijacking

    Diplomats targeted by UNC6384 through captive portal hijacking

    A China-nexus threat actor known as UNC6384 has been linked to a series of attacks aimed at diplomats in Southeast Asia and various global entities to further Beijing’s strategic interests. This multi-stage attack chain employs sophisticated social engineering techniques, including valid code signing certificates, an Adversary-in-the-Middle (AitM) attack, and indirect execution methods to avoid detection.…

  • Phishing Attack Employs UpCrypter in Fraudulent Voicemail Emails to Distribute RAT Payloads.

    Phishing Attack Employs UpCrypter in Fraudulent Voicemail Emails to Distribute RAT Payloads.

    Cybersecurity researchers have identified a new phishing campaign that employs fake voicemails and purchase orders to distribute a malware loader known as UpCrypter. The campaign utilises “carefully crafted emails to deliver malicious URLs linked to convincing phishing pages,” according to Fortinet FortiGuard Labs researcher Cara Lin. These phishing pages are designed to entice recipients into…

  • Transparent Tribe spear-phishing Indian government using weaponised desktop shortcuts

    Transparent Tribe spear-phishing Indian government using weaponised desktop shortcuts

    The advanced persistent threat (APT) actor known as Transparent Tribe has been observed targeting both Windows and BOSS (Bharat Operating System Solutions) Linux systems with malicious Desktop shortcut files in attacks aimed at Indian Government entities. Initial access is achieved through spear-phishing emails, as reported by CYFIRMA. Linux BOSS environments are specifically targeted via weaponised…

  • MixShell malware spreading through US supply chains via contact forms

    MixShell malware spreading through US supply chains via contact forms

    Cybersecurity researchers have raised alarms about a sophisticated social engineering campaign targeting supply chain-critical manufacturing companies with a stealthy in-memory malware known as MixShell. Codenamed ZipLine by Check Point Research, this campaign diverges from traditional phishing tactics by initiating contact through a company’s public ‘Contact Us’ form. Attackers manipulate employees into engaging in seemingly professional…

  • Reasons Behind SIEM Rule Failures and Solutions: Lessons Learned from 160 Million Attack Simulations

    Reasons Behind SIEM Rule Failures and Solutions: Lessons Learned from 160 Million Attack Simulations

    Security Information and Event Management (SIEM) systems serve as essential tools for detecting suspicious activities within enterprise networks, enabling organisations to identify and respond to potential attacks in real time. However, the recent Picus Blue Report 2025, which analysed over 160 million real-world attack simulations, revealed a concerning statistic: organisations are only detecting 1 out…

  • Is an SSH brute-force Go module stealing your credentials?

    Is an SSH brute-force Go module stealing your credentials?

    Cybersecurity researchers have identified a malicious Go module, dubbed “golang-random-ip-ssh-bruteforce,” which masquerades as a brute-force tool for SSH but is designed to covertly exfiltrate credentials to its creator. According to Socket researcher Kirill Boychenko, upon the first successful login, the module transmits the target IP address, username, and password to a hard-coded Telegram bot controlled…

  • Robust MLSecOps vital for managing vulnerabilities

    Robust MLSecOps vital for managing vulnerabilities

    Organisations that fail to adapt their security programs while implementing Artificial Intelligence (AI) risk exposure to a range of both traditional and emerging threats. MLSecOps addresses this critical gap in security by integrating AI and Machine Learning (ML) development with stringent security protocols. Establishing a robust MLSecOps foundation is vital for proactively mitigating vulnerabilities and…

  • AI Agents have hidden security flaws

    AI Agents have hidden security flaws

    In a recent interview with Help Net Security, Jacob Ideskog, the Chief Technology Officer of Curity, highlighted the significant risks that AI agents pose to organisations. He expressed concern that the industry is “sleepwalking” into a security crisis as these agents become increasingly integrated into enterprise systems. Ideskog noted that AI agents and other non-human…

  • Lightweight LLMs decrease incident response time using decision theoretic planning

    Lightweight LLMs decrease incident response time using decision theoretic planning

    Researchers from the University of Melbourne and Imperial College London have developed a novel method for enhancing incident response planning using Large Language Models (LLMs), with a particular emphasis on minimising the risk of hallucinations. Their approach utilises a smaller, fine-tuned LLM in conjunction with retrieval-augmented generation and decision-theoretic planning. The method addresses the prevalent…