yohanmanuja

former bug bounty hunter ,web pentester

Concept image showing Akira ransomware attacks spreading across global networks through VPN and firewall weaknesses.

How Akira Ransomware Turned VPN Weaknesses Into a $244M

Akira ransomware has evolved into one of the most disruptive ransomware-as-a-service operations, hitting more than 250 organizations and extorting over $244 million. This article walks through how Akira gains initial access, exploits VPN and firewall weaknesses, moves laterally, and applies double extortion — then outlines practical defenses security teams can deploy now.

Read More
AI inference vulnerabilities in Meta, Nvidia, Microsoft and vLLM exposed through ShadowMQ, alongside a Cursor IDE compromise via rogue MCP servers

Serious AI Bugs Expose Meta, Nvidia and Microsoft Inference

Researchers uncovered serious AI bugs across Meta, Nvidia, Microsoft and open-source inference frameworks after tracking a ShadowMQ deserialization pattern built on ZeroMQ and Python pickle. At the same time, new research shows how Cursor’s AI IDE can be hijacked via rogue MCP servers, turning developer workstations into high-value malware delivery platforms if teams ignore AI supply-chain security.

Read More