A critical remote code execution vulnerability (CVE-2025–27364) in MITRE Caldera affects all versions prior to commit 35bc06e, allowing unauthenticated attackers to exploit dynamic compilation processes. Discovered by researcher Dawid Kulikowski, the flaw enables command execution via linker flag manipulation. Users are advised to update to v5.1.0, isolate servers, and audit instances for exploitation signs.

IXON VPN Vulnerabilities Let Attackers Gain Access to Windows & Linux Systems
A security assessment by Shelltrail revealed three critical vulnerabilities in the IXON VPN client, allowing privilege escalation on Windows and Linux. Identified as CVE-2025-ZZZ-01, CVE-2025-ZZZ-02,