Microsoft has stopped a global malvertising campaign impacting around a million devices. GitHub repositories, crucial to the attack, were eliminated. The attack likely originated from illicit streaming websites. Hackers injected malevolent ads into video streams on illegal streaming sites, redirecting viewers to GitHub repositories under hacker control. Microsoft’s Threat Intelligence team also found that payloads were hosted on Dropbox and Discord. The attack methodology included setting a dropper for later payloads and using PowerShell to extract information.

IXON VPN Vulnerabilities Let Attackers Gain Access to Windows & Linux Systems
A security assessment by Shelltrail revealed three critical vulnerabilities in the IXON VPN client, allowing privilege escalation on Windows and Linux. Identified as CVE-2025-ZZZ-01, CVE-2025-ZZZ-02,