resources

CIL Security Advisory

Your trusted resource for the latest security updates, threat intelligence, and proactive solutions.

Backdoor.ClickFix – The Fake Verification Trap

Backdoor.ClickFix – The Fake Verification Trap

Hackers are increasingly exploiting human trust through a clever social engineering technique known as "ClickFix" (or "Pastejacking"). They trick Microsoft…

AUGUST 31ST, 2026

Defence Against Living-off-the-Cloud (LotC) & Trusted Infrastructure Abuse

Defence Against Living-off-the-Cloud (LotC) & Trusted Infrastructure Abuse

Threat actors are abandoning easily blocked, newly registered domains in favour of hosting their Command and Control (C2) servers and…

AUGUST 24TH, 2026

Active Exploitation Alert: SharePoint Authentication Bypass

Active Exploitation Alert: SharePoint Authentication Bypass

A critical authentication bypass vulnerability in Microsoft SharePoint Server is now under active exploitation following the public release of technical…

AUGUST 19TH, 2026

AI-Powered Vulnerability Management: Exploits Faster Than Patches

AI-Powered Vulnerability Management: Exploits Faster Than Patches

Artificial intelligence is fundamentally changing how organisations identify, prioritise, and remediate vulnerabilities. Anthropic’s Project Glasswing has shown that advanced AI…

AUGUST 17TH, 2026

When Unsanctioned Intelligence Opens the Backdoor

When Unsanctioned Intelligence Opens the Backdoor

What starts as an effort to boost productivity rapidly transforms into an active hazard, exposing corporate IP and creating unauthorised…

AUGUST 12TH, 2026

The Virtualisation Frontline (Hypervisor Hijacking)

The Virtualisation Frontline (Hypervisor Hijacking)

By targeting hypervisors like VMware ESXi or Microsoft Hyper-V, threat actors execute "Hypervisor Hijacking" to encrypt or exfiltrate dozens of…

AUGUST 10TH, 2026

When the Trusted Partner Becomes the Trojan Horse

When the Trusted Partner Becomes the Trojan Horse

Supply Chain Identity Theft leverages the pre-established trust and integration privileges granted to third-party vendors to establish a silent beachhead…

AUGUST 5TH, 2026

regreSSHion (CVE-2024-6387) – When the Secure Shell Breaks Open

regreSSHion (CVE-2024-6387) – When the Secure Shell Breaks Open

OpenSSH enables secure remote server management, but a critical vulnerability known as “regreSSHion” (CVE-2024-6387) has resurfaced. This timing flaw allows…

JULY 1ST, 2026

Indirect Prompt Injection Attack (XPIA) – When Your AI Assistant is Tricked

Indirect Prompt Injection Attack (XPIA) – When Your AI Assistant is Tricked

Organisations now use the Model Context Protocol (MCP) to connect AI models directly to external data, databases, and apps. While…

JUNE 29TH, 2026

Disclaimer: This publication is provided for informational purposes only and does not constitute professional advice or an endorsement of any specific products, services, or strategies. Readers are advised to use their discretion and seek professional advice before making any business or technology-related decisions based on the information provided.

Never miss a CIL Security Advisory

Stay informed with the latest security updates and insights from CIL.

Contact Us

Message Sent!

Thank you for reaching out. We have received your message and will get back to you shortly.

Check your email for a confirmation from us.

Start a project

Project Request Submitted!

Thank you for your interest. Our team will review your project details and reach out to you soon.

Check your email for a confirmation from us.