SIEM as a Service
Erlang/OTP SSH RCE Vulnerability

PoC Exploit Released for Erlang/OTP SSH Remote Code Execution Vulnerability

A critical remote code execution vulnerability in Erlang/OTP's SSH implementation has security teams scrambling to patch affected systems after researchers confirmed the development of a proof-of-concept exploit. The vulnerability, tracked as CVE-2025-32433 and assigned...
Threat Modeling

Why Threat Modeling Should Be Part of Every Security Program

In today's hyperconnected business environment, security teams face unprecedented challenges protecting organizational assets against increasingly sophisticated threats. Threat modeling stands out as a structured methodology that helps organizations systematically identify, evaluate, and prioritize potential security...
The Future of GRC

The Future of GRC – Integrating ESG, Cyber, and Regulatory Risk

The future of GRC (Governance, Risk, and Compliance) is being reshaped as organizations navigate complex challenges at the crossroads of sustainability, digital security, and regulatory oversight. Traditional GRC frameworks that treated these domains as separate...
Hackers Weaponize MMC Script to Deploy MysterySnail RAT Malware

Hackers Weaponize MMC Script to Deploy MysterySnail RAT Malware

A sophisticated cyberespionage campaign leveraging malicious Microsoft Management Console (MMC) scripts to deploy the stealthy MysterySnail remote access trojan (RAT).  First identified in 2021 during an investigation into the CVE-2021-40449 zero-day vulnerability, MysterySnail RAT had...
Cybersecurity Cooperation With Russia

China Plans to Strengthen Its Cybersecurity Cooperation With Russia

Chinese Ambassador to Russia Zhang Hanhui has officially announced Beijing's intention to strengthen strategic cooperation with Moscow in cybersecurity, signaling a significant expansion of the two nations' digital partnership.  The announcement comes as both countries...
Harvest Ransomware Attack

Harvest Ransomware Attack – Details of the Data Breach Released

Harvest SAS, a leading French fintech company specializing in wealth management software, has fallen victim to a sophisticated ransomware attack.  The ransomware attack was first detected on February 27, 2025, but Harvest publicly disclosed the...
Erlang/OTP SSH Vulnerability

Critical Erlang/OTP SSH Vulnerability Allows Unauthenticated Remote Code Execution

A critical vulnerability in the Erlang/Open Telecom Platform (OTP) SSH implementation that allows attackers to execute arbitrary code without authentication.  The flaw, tracked as CVE-2025-32433, has been assigned the maximum CVSS score of 10.0, indicating...
Threat Actors Attacking Content Creators

Threat Actors Attacking Content Creators With Fake AI Tools to Hijack Their Devices

Cybercriminals are capitalizing on the explosive growth of generative AI tools, deploying sophisticated campaigns that impersonate popular software like CapCut, Adobe Express, and Canva to distribute malware and hijack devices. ESET warns that content...
Oracle Cloud Compromise

CISA Warns of Credential Risks Linked to Oracle Cloud Compromise

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a high-priority advisory following reports of unauthorized access to a legacy Oracle Cloud environment.  While Oracle disputes claims of a significant breach, CISA warns that the...
Critical PHP’s extract() Function Vulnerability

Critical PHP’s extract() Function Vulnerability Allows Arbitrary Code Execution

A critical vulnerability in PHP's extract() function enables attackers to trigger memory corruption that can lead to arbitrary native code execution across multiple PHP versions.  The vulnerability stems from a memory management issue that can...
SIEM as a Service

Recent Posts