Skip to content

Cyber Risk Assessment

FireCompass Raises $20 Million to Scale Offensive Security with Agentic AI

Funding accelerates FireCompass’s global expansion and innovation in its AI-powered 6-in-1 Offensive Security Platform FireCompass, the leader in AI-powered Automated Penetration Testing and Red Teaming, today announced it has raised over $20 million in strategic funding from EC-Council, the global authority in ethical hacking and creator of the Certified Ethical Hacker (CEH) program. The investment,… Read More »FireCompass Raises $20 Million to Scale Offensive Security with Agentic AI

Weekly Cybersecurity Intelligence Report Cyber Threats & Breaches 11 Aug – 18 Aug, 2025

The week of August 11-18, 2025, witnessed an unprecedented escalation in cybersecurity threats, marking one of the most destructive periods for data security in recent history. This period was dominated by a sophisticated Salesforce-targeting campaign orchestrated by ShinyHunters, compromising over 275 million patient records across healthcare organizations, and multiple high-profile breaches affecting financial and HR… Read More »Weekly Cybersecurity Intelligence Report Cyber Threats & Breaches 11 Aug – 18 Aug, 2025

Weekly Report: New Hacking Techniques and Critical CVEs 4 Aug – 11 Aug, 2025

The cybersecurity landscape during August 4-11, 2025, witnessed a surge in critical zero-day exploitations, sophisticated ransomware campaigns, and nation-state attacks targeting critical infrastructure. Four major zero-day vulnerabilities were actively exploited in the wild, with threat actors demonstrating unprecedented speed in weaponizing newly disclosed flaws. The week’s most significant incidents included active exploitation of Citrix NetScaler… Read More »Weekly Report: New Hacking Techniques and Critical CVEs 4 Aug – 11 Aug, 2025

Weekly Report: New Hacking Techniques and Critical CVEs 28 July – 4 Aug , 2025

From 28 July to 4 August 2025, threat actors leveraged novel AI-assisted malware, zero-day chains against on-prem SharePoint, critical command-injection in CI/CD pipelines, and advanced social-engineering playbooks. Fourteen CVEs reached Critical severity, including two actively exploited zero-days. Dark-web chatter intensified around Medusa and BlackSuit takedown fallout, with ransomware affiliates trading victim data and custom tooling… Read More »Weekly Report: New Hacking Techniques and Critical CVEs 28 July – 4 Aug , 2025

CVE-2025-43712: JHipster Platform Privilege Escalation Vulnerability Discovered by FireCompass Research, Added to NIST

Product Name: JHipster Platform Vulnerability: Privilege Escalation via Response Manipulation Vulnerable Versions: Up to 8.9.0 CVE: CVE-2025-43712 Discovered by: Hritik Godara, FireCompass Research Team Researchers from the FireCompass Security Team discovered a privilege escalation vulnerability in the JHipster Platform (up to v8.9.0). The issue was identified in how the application processes authentication responses—specifically, improper server-side validation of user roles… Read More »CVE-2025-43712: JHipster Platform Privilege Escalation Vulnerability Discovered by FireCompass Research, Added to NIST