resources
CIL Security Advisory
Your trusted resource for the latest security updates, threat intelligence, and proactive solutions.
Backdoor.ClickFix – The Fake Verification Trap
Hackers are increasingly exploiting human trust through a clever social engineering technique known as "ClickFix" (or "Pastejacking"). They trick Microsoft…
AUGUST 31ST, 2026
Defence Against Living-off-the-Cloud (LotC) & Trusted Infrastructure Abuse
Threat actors are abandoning easily blocked, newly registered domains in favour of hosting their Command and Control (C2) servers and…
AUGUST 24TH, 2026
Active Exploitation Alert: SharePoint Authentication Bypass
A critical authentication bypass vulnerability in Microsoft SharePoint Server is now under active exploitation following the public release of technical…
AUGUST 19TH, 2026
AI-Powered Vulnerability Management: Exploits Faster Than Patches
Artificial intelligence is fundamentally changing how organisations identify, prioritise, and remediate vulnerabilities. Anthropic’s Project Glasswing has shown that advanced AI…
AUGUST 17TH, 2026
When Unsanctioned Intelligence Opens the Backdoor
What starts as an effort to boost productivity rapidly transforms into an active hazard, exposing corporate IP and creating unauthorised…
AUGUST 12TH, 2026
The Virtualisation Frontline (Hypervisor Hijacking)
By targeting hypervisors like VMware ESXi or Microsoft Hyper-V, threat actors execute "Hypervisor Hijacking" to encrypt or exfiltrate dozens of…
AUGUST 10TH, 2026
When the Trusted Partner Becomes the Trojan Horse
Supply Chain Identity Theft leverages the pre-established trust and integration privileges granted to third-party vendors to establish a silent beachhead…
AUGUST 5TH, 2026
regreSSHion (CVE-2024-6387) – When the Secure Shell Breaks Open
OpenSSH enables secure remote server management, but a critical vulnerability known as “regreSSHion” (CVE-2024-6387) has resurfaced. This timing flaw allows…
JULY 1ST, 2026
Indirect Prompt Injection Attack (XPIA) – When Your AI Assistant is Tricked
Organisations now use the Model Context Protocol (MCP) to connect AI models directly to external data, databases, and apps. While…
JUNE 29TH, 2026
Disclaimer: This publication is provided for informational purposes only and does not constitute professional advice or an endorsement of any specific products, services, or strategies. Readers are advised to use their discretion and seek professional advice before making any business or technology-related decisions based on the information provided.
Never miss a CIL Security Advisory
Stay informed with the latest security updates and insights from CIL.