Russian state-sponsored group Sandworm has been launching malware attacks on Ukrainian Windows users, involving bogus updates and Microsoft Key Management Service activators. As part of the campaign, a fake KMS activation tool with BACKORDER malware loader facilitated DarkCrystal RAT delivery. The malware steals saved credentials, browser histories, keystrokes, and system details. These attacks are a threat to Ukraine’s national security, critical infrastructure, and private sector, warns EclecticIQ.

IXON VPN Vulnerabilities Let Attackers Gain Access to Windows & Linux Systems
A security assessment by Shelltrail revealed three critical vulnerabilities in the IXON VPN client, allowing privilege escalation on Windows and Linux. Identified as CVE-2025-ZZZ-01, CVE-2025-ZZZ-02,