Over 18k devices worldwide have had sensitive data stolen due to intrusions involving a trojanized XWorm RAT builder. The attackers used the aliases “@shinyenigma” and “milleniumrat” to target amateur threat actors. The altered XWorm RAT builder enables data theft, registry alteration, and virtualization checks via Telegram bot tokens and API calls. The attack follows the usage of XWorm by Russian hackers in Ukraine-targeted attacks.

IXON VPN Vulnerabilities Let Attackers Gain Access to Windows & Linux Systems
A security assessment by Shelltrail revealed three critical vulnerabilities in the IXON VPN client, allowing privilege escalation on Windows and Linux. Identified as CVE-2025-ZZZ-01, CVE-2025-ZZZ-02,