Interim Attack Prevention Guide

Some of the most devastating cyberattacks do not rely on brute force and instead succeed through stealth. These quiet intrusions often become unnoticed until much later after the attacker disappears. The most insidious is the man-in-the-middle (MITM) attack, where criminals exploit weaknesses in their communication protocols to quietly position themselves between two unsuspecting parties. Fortunately, […]

Shadow’s Wild West

Everyone is the current IT decision maker. Organizational employees can install the plugin in just one click. There is no need to complete the team first. It’s great for productivity, but it’s a serious problem for your security attitude. When the floodgates for Saas and Ai were opened, it was not only democratized, its safety […]

Board-Level Cybersecurity Risk Communication Certification for CISOs

aaron heath Medical School Chief Information Security Officer (CISO) and Cyber ​​Security Advisor Aaron Heath is the Chief Information Security Officer (CISO) and Cyber ​​Security Advisor at the Medical University of South Carolina (MUSC). He started his career in the IT field and moved to the Information Security Department at MUSC in 2014. With a […]

CISO board-level cybersecurity risk communication certification

Aaron Heath Chief Information Security Officer (CISO) and Cybersecurity Counsel of Medical College Aaron Heath is Chief Information Security Officer (CISO) and Cybersecurity Advisor at the South Carolina Medical College (MUSC). He began his career in 2014 before moving to MUSC’s information security. In a legal background, his expertise includes incident response, forensic medicine and […]

PlayPraetor Android Trojan infects over 11,000 devices via fake Google Play pages and meta ads

Cybersecurity researchers have discovered a new Android remote access trojan (rat) called PlayPraetor, which infected more than 11,000 devices, mainly in Portugal, Spain, France, Morocco, Peru, and Hong Kong. “The rapid growth of botnets, which is currently over 2,000 new infections per week, is driven by an aggressive campaign focused on Spanish and French speakers, […]

Remove Otter AI from your organization

Earlier this year, the popular AI Notebook Taker, known as Otter AI, rolled out a new expansion model that led to explosive growth in account creation across multiple Nudge Security customers, including one large company that discovered 800 new account sign-ups within 90 days. ‍ For SaaS companies looking to expand their footprint through product-driven […]

CL-STA-0969 installs secret malware on telecom networks during 10 months of spying

Southeast Asian telecommunications organizations are targeted by state-sponsored threat actors known as CL-STA-0969, promoting remote control over compromised networks. Palo Alto Networks Unit 42 said it observed multiple incidents in the region between February and November 2024, including those intended for critical communications infrastructure. Attacks are characterized by using several tools that allow remote access, […]

New “Pest” PAM Backdoor exposes critical Linux systems to silent qualification theft

August 2, 2025Ravi LakshmananThreat detection / SSH security Cybersecurity researchers have flagged a plague called the previously undocumented Linux backdoor, which has managed to avoid detection for a year. “The implant is built as a malicious PAM (pluggable authentication module) that allows attackers to quietly bypass system authentication and gain permanent SSH access,” said Pierre-Henri […]

Akira ransomware exploits Sonic Wall VPN with zero-day attacks on fully patched devices

August 2, 2025Ravi LakshmananVulnerability/Zero Day SonicWall SSL VPN devices have been subject to Akira ransomware attacks as part of a new surge in activity observed in late July 2025. “The reviewed intrusions have observed multiple ransomware intrusions in a short period of time, each including VPN access via Sonicwall SSL VPN,” said Julian Tuin, a […]

Cursor AI code editor fixed the flaw that allows attackers to execute commands via SlackMCP

Cybersecurity researchers have revealed the current high-patch, high-level security flaws of Cursor, a popular artificial intelligence (AI) code editor, which could lead to remote code execution. The vulnerability tracked as CVE-2025-54135 (CVSS score: 8.6) is addressed in version 1.3, released on July 29, 2025. It is called Curxecute by AIM Labs, which previously disclosed echo […]