Amnesty International found a zero-day exploit sold by digital intelligence firm Cellebrite used to hack a Serbian student critic of the government. The human rights body had accused Serbia in December of using spyware routinely for wider state control and against civil societies, which led Cellebrite suspending sales to Serbian clients. Amnesty discovered the new case involving a lock screen attack chain for fully patched Android devices, calling it continued evidence of Serbia’s surveillance campaign.

IXON VPN Vulnerabilities Let Attackers Gain Access to Windows & Linux Systems
A security assessment by Shelltrail revealed three critical vulnerabilities in the IXON VPN client, allowing privilege escalation on Windows and Linux. Identified as CVE-2025-ZZZ-01, CVE-2025-ZZZ-02,