Reverse Engineering the Tapo C260 and Tapo Discovery Protocol v2
Earlier in 2025, I participated in the SPIRITCYBER IoT hardware hacking contest organised by the Cyber Security Agency of Singapore with YesWeHack. Among several devices,…
Earlier in 2025, I participated in the SPIRITCYBER IoT hardware hacking contest organised by the Cyber Security Agency of Singapore with YesWeHack. Among several devices,…
Hackers have launched a sophisticated phishing campaign exploiting Google Tasks notifications to target over 3,000 organizations worldwide, primarily in the manufacturing sector. The December 2025…
Phishing campaign abuses Google Cloud Application to impersonate legitimate Google emails Pierluigi Paganini January 02, 2026 Researchers uncovered a phishing campaign abusing Google Cloud Application…
A sophisticated phishing campaign is currently circulating within the Cardano community, posing significant risks to users seeking to download the newly announced Eternl Desktop application.…
Attack Surface Management (ASM) tools promise reduced risk. What they usually deliver is more information. Security teams deploy ASM, asset inventories grow, alerts start flowing,…
ServiceNow has forecast that more than 1.03 million jobs will be created in the UAE by 2030 as artificial intelligence (AI) and digital technologies become…
This week, The Cyber Express takes a closer look at the events shaping the global cybersecurity landscape as we transition from 2025 to 2026. Throughout…
A critical security advisory warned of severe vulnerabilities in WHILL electric wheelchairs that could allow attackers to hijack the devices via Bluetooth remotely. The alert…
Cybersecurity researchers have identified a new variant of the Shai Hulud malware that reveals important insights into how threat actors are evolving their attack strategies.…
In 2025, protest policing in major US cities increasingly took on the character of a spectacle: overwhelming deployments, theatrical staging, and aggressive crowd-control tactics that…
French postal and banking services faced fresh disruptions on Thursday, January 1, 2026, following a cyberattack that temporarily rendered the websites and mobile applications of La Poste and La Banque Postale largely inaccessible, according…
IBM warns of critical API Connect bug enabling remote access Pierluigi Paganini January 02, 2026 IBM disclosed a critical API Connect flaw (CVE-2025-13915, CVSS 9.8)…