SquareX’s research reveals a new class of malicious browser extensions that can impersonate legitimate ones, tricking users into entering sensitive information. These polymorphic extensions exploit existing browser features and mimic popular tools, such as password managers and crypto wallets. SquareX warns that current security measures are inadequate and advocates for advanced browser-native solutions to combat these threats.

IXON VPN Vulnerabilities Let Attackers Gain Access to Windows & Linux Systems
A security assessment by Shelltrail revealed three critical vulnerabilities in the IXON VPN client, allowing privilege escalation on Windows and Linux. Identified as CVE-2025-ZZZ-01, CVE-2025-ZZZ-02,