Microsoft has detected a new variant of the modular malware XCSSET, which targets users by infecting Xcode projects. This is the first new variant of XCSSET observed since 2022. It features enhanced obfuscation methods, updated persistence mechanisms and new infection strategies. Microsoft warned users and organizations about the threat, despite only seeing it in limited attacks so far.

IXON VPN Vulnerabilities Let Attackers Gain Access to Windows & Linux Systems
A security assessment by Shelltrail revealed three critical vulnerabilities in the IXON VPN client, allowing privilege escalation on Windows and Linux. Identified as CVE-2025-ZZZ-01, CVE-2025-ZZZ-02,