Security researchers at Sucuri have discovered a malware campaign targeting WordPress sites via hidden malware in the mu-plugins directory. This attack facilitates remote code execution, leading to server compromise and data theft. Threat actors exploited the /wp-content/mu-plugins/ directory by planting an index.php file with obfuscated PHP code for persistent control over infected sites.

IXON VPN Vulnerabilities Let Attackers Gain Access to Windows & Linux Systems
A security assessment by Shelltrail revealed three critical vulnerabilities in the IXON VPN client, allowing privilege escalation on Windows and Linux. Identified as CVE-2025-ZZZ-01, CVE-2025-ZZZ-02,