A critical vulnerability (CVE-2025-26849) in Docusnap allows attackers to decrypt sensitive system data due to a static encryption key used for inventory files. This flaw grants domain users read access to files, facilitating data extraction. Despite attempts to patch the issue, researchers found hardcoded keys still present in newer versions. Users should audit permissions and apply necessary patches.

Hackers Deliver XWorm via Malicious Registry Files in a New Stegocampaign Attack
A new variant of Stegocampaign has emerged, utilizing a Windows registry file to include a malicious script in Autorun. By exploiting user actions through phishing