Android malware Tanzeem, linked to the threat actor DoNot Team, believed to be Indian, extracted personal data via fake apps. Two such apps, Tanzeem and Tanzeem Update, requested unnecessary access permissions, and used the OneSignal platform to send phishing links embedded in notifications. The malware collected sensitive data including texts, contacts, call logs, location and account info to track victims. It’s suspected the malware targeted specific individuals.

IXON VPN Vulnerabilities Let Attackers Gain Access to Windows & Linux Systems
A security assessment by Shelltrail revealed three critical vulnerabilities in the IXON VPN client, allowing privilege escalation on Windows and Linux. Identified as CVE-2025-ZZZ-01, CVE-2025-ZZZ-02,