Not Just Banks: Why iGaming, Crypto Platforms and Shipping Companies in Cyprus Now Need Penetration Testing Too

Ask most Cyprus businesses which sectors get real cybersecurity scrutiny from regulators, and the answer is almost always “banks and investment firms.” That stopped being accurate a while ago. Between MiCA, the National Betting Authority’s licensing regime, IMO shipping cyber requirements, and the Central Bank of Cyprus’s oversight of electronic money institutions, several sectors that used to sit outside financial-grade regulation are now squarely inside it, each with its own testing expectations that a generic vulnerability scan does not come close to covering.

This guide covers what each of these sectors actually needs tested, why the risk profile is different from a standard business website, and what “in scope” really means if you operate a crypto platform, an iGaming site, a shipping company, or an EMI out of Cyprus.

Read More

DORA, NIS2 and CySEC ICT Risk: What Cyprus Financial Firms Actually Need to Test in 2026

If you run a Cyprus Investment Firm, a bank, an insurer, or any other regulated financial business on the island, you are very likely staring at three overlapping cybersecurity obligations right now: DORA, NIS2, and CySEC’s own ICT risk circulars. Each one has its own legal basis, its own regulator, and its own idea of what “tested” actually means. None of them is satisfied by an annual vulnerability scan, and confusing the three, or assuming one covers the others, is the single most common compliance gap we see when we scope a penetration test for a Cyprus financial firm.

This guide walks through what each framework actually requires, who is in scope, how often testing has to happen, and what a penetration test that satisfies DORA, NIS2, and CySEC actually looks like in practice.

Read More

KREMLIN Malware Forges Chrome and Edge Integrity Checks to Steal Banking Sessions

A newly documented malware operation named KREMLIN is quietly rewriting the rules of browser-based credential theft, and despite the name, it has nothing to do with Russian state activity. Researchers tracking the campaign have identified 1,515 infected systems, with 98.75 percent of them located in Brazil, all compromised through a technique that does something most users would assume is impossible: it installs a browser extension on Chrome and Edge that the victim never approved, never saw in a permissions prompt, and cannot easily find by browsing their installed extensions list. The malware’s operators have been refining this approach since at least May 2025, and the most recent evolution of the campaign, which shifted parts of its infrastructure onto Ethereum smart contracts in May 2026, shows just how far attackers are willing to go to keep a credential-theft operation alive against modern defenses.

Read More

Researchers Used Claude to Breach OpenAI in 72 Hours: Inside the Hacktron AI Exploit Chain

On September 18, 2026, a small independent research team called Hacktron AI publicly disclosed something that would have sounded like science fiction two years ago: they used Anthropic’s Claude model to build a working exploit chain, breach OpenAI’s own infrastructure, take over employee accounts, and reach an internal GitHub repository, all within 72 hours. OpenAI confirmed the incident, patched the underlying flaws, and paid a $6,500 bug bounty. No production systems or sensitive user data were exposed. But the story that matters here is not really about OpenAI’s patch cycle. It is about what happens when an AI model becomes a genuinely capable member of the offensive security team, and what that means for every organization that has not yet stress-tested its own defenses against that reality.

Read More

F5 BIG-IP APM Malware Hides a Web Shell in Memory: Inside the PoisonedRefresh Campaign

A new wave of attacks against F5 BIG-IP Access Policy Manager (APM) appliances is forcing security teams to rethink what “clean” actually means on a production edge device. Researchers disclosed this month that a newly identified malware strain, dubbed PoisonedRefresh, injects a fully functional PHP web shell directly into a running process’s memory rather than writing it to disk. A traditional file-integrity scan, antivirus sweep, or malware signature check comes back completely clean, because there is nothing on disk to find. The web shell only exists in RAM, activated the moment Apache loads one of the appliance’s own legitimate PHP scripts.

Read More

web security

InvisibleJS: The Steganography Threat Hiding in Plain Sight

In the ever-evolving landscape of cybersecurity threats, attackers continuously develop innovative methods to conceal malicious code from detection systems and security analysts. The latest addition to this arsenal is InvisibleJS, an open-source obfuscation tool that leverages zero-width Unicode characters to hide executable JavaScript code in files that appear completely empty. This sophisticated steganography technique represents a concerning evolution in code obfuscation methods, with significant implications for web application security, malware distribution, and threat detection.

Read More
Log4j Vulnerability

Critical Apache Log4j Vulnerability Exposes Applications to Man-in-the-Middle Attacks

The Apache Logging Services team has recently disclosed a critical security vulnerability in Apache Log4j Core that puts enterprise applications at significant risk of data interception. This latest security flaw, tracked as CVE-2025-68161, affects the widely-used logging framework and creates opportunities for sophisticated man-in-the-middle attacks targeting sensitive log data. For organizations relying on Log4j for application logging, understanding this vulnerability and implementing proper security measures is paramount.

Read More
React Security

Critical Alert: Multiple Hacker Groups Exploit React2Shell Vulnerability – What Website Owners Must Know

The cybersecurity landscape has been shaken by a critical vulnerability that’s being actively exploited by multiple threat actor groups worldwide. Google’s Threat Intelligence Group has issued urgent warnings about React2Shell (CVE-2025-55182), a maximum-severity security flaw affecting React Server Components and Next.js frameworks. With a CVSS score of 10.0, this vulnerability represents one of the most dangerous threats to modern web applications in recent years.

Read More
web security

MITRE Top 25 Most Dangerous Software Weaknesses 2025: Complete Analysis and Protection Guide

MITRE has released its 2025 Common Weakness Enumeration (CWE) Top 25 Most Dangerous Software Weaknesses list, revealing the root causes behind 39,080 Common Vulnerability and Exposure (CVE) records this year. These prevalent flaws enable attackers to seize system control, steal sensitive data, or cripple applications. Organizations must prioritize remediation of these weaknesses to protect their digital assets and maintain security posture in an increasingly hostile threat landscape.

Read More