Over 1,000 WordPress websites have been compromised by four different backdoors delivered through malicious JavaScript code. The backdoors allow for the installation of a fraudulent plugin, the injection of harmful code, remote access, command execution, and additional payload retrieval. Security firm c/side urged WordPress admins to enhance security measures. Other reports revealed similar attacks on websites that redirect to Chinese gambling sites and Magento websites.

IXON VPN Vulnerabilities Let Attackers Gain Access to Windows & Linux Systems
A security assessment by Shelltrail revealed three critical vulnerabilities in the IXON VPN client, allowing privilege escalation on Windows and Linux. Identified as CVE-2025-ZZZ-01, CVE-2025-ZZZ-02,