My Courses
-

Apple releases fix for CVE-2025-43300 zero-day vulnerability
Apple has released critical security updates to address a zero-day vulnerability impacting iOS, iPadOS, and macOS, which has reportedly been exploited in the wild. The flaw, tracked as CVE-2025-43300, is an out-of-bounds write vulnerability within the ImageIO framework that could lead to memory corruption when processing malicious images. In an advisory, Apple acknowledged that this…
-

AI boosts ransomware impacts
Ransomware continues to pose a significant threat to large and medium-sized businesses, with numerous ransomware gangs leveraging artificial intelligence for automation, according to Acronis. From January to June 2025, the number of publicly reported ransomware victims surged by 70% compared to the same period in 2023 and 2024. February emerged as the most severe month,…
-

Chinese hacker groups Murky, Genesis, and Glacial Panda targeting cloud computing and telecommunications
Cybersecurity researchers have raised alarms about the malicious activities of a China-nexus cyber espionage group known as Murky Panda, which exploits trusted relationships in the cloud to infiltrate enterprise networks. According to a report by CrowdStrike, this adversary has demonstrated a significant capability to rapidly weaponise N-day and zero-day vulnerabilities, often gaining initial access to…
-

Automation is transforming how penetration testing services are provided.
Pentesting remains one of the most effective methods for identifying real-world security weaknesses before adversaries can exploit them. However, as the threat landscape has evolved, the delivery of pentest results has not kept pace. Most organisations still depend on traditional reporting methods, such as static PDFs, emailed documents, and spreadsheet-based tracking. These outdated workflows introduce…
-

Increasing municipal infrastructure hacking risk
A small-town water system, a county hospital, and a local school district may not appear to be front-line targets in global conflict, yet they are increasingly vulnerable to cyber attacks. These organisations face daily threats, ranging from ransomware to foreign adversaries probing for weaknesses. The implications of these attacks can extend to national security, disrupting…
-

OSINT helps financial institutions combat money laundering
Open Source Intelligence (OSINT) tools play a crucial role in helping financial firms combat money laundering by revealing complex networks and ownership structures. Money launderers frequently utilise layered networks of offshore entities and shell companies to obscure the true Ultimate Beneficial Owner (UBO) of a company. The manual process of identifying UBOs can be laborious…
-

Commvault pre-auth exploit chain allows remote code execution
Commvault has released critical updates to address four security vulnerabilities that could be exploited for remote code execution on affected instances. The vulnerabilities, identified in Commvault versions prior to 11.36.60, include CVE-2025-57788 (CVSS score: 6.9), which allows unauthenticated attackers to execute API calls without user credentials; CVE-2025-57789 (CVSS score: 5.3), which enables remote attackers to…
-

QuirkyLoader distributes Agent Tesla, AsyncRAT, Snake Keylogger and other malware
Cybersecurity researchers have revealed a new malware loader named QuirkyLoader, which has been actively delivering various next-stage payloads, including information stealers and remote access trojans, through email spam campaigns since November 2024. Notable malware families distributed via QuirkyLoader include Agent Tesla, AsyncRAT, Formbook, Masslogger, Remcos RAT, Rhadamanthys Stealer, and Snake Keylogger. IBM X-Force reported that…


