The “Ballista” botnet campaign is exploiting a high-level security flaw to infect unpatched TP-Link routers. Detected by Cato CTRL researchers in January 2025, it has affected over 6,000 devices in countries including Brazil, the UK, and Turkey, with its main targets being the US, Australia, China, and Mexico, where it targets manufacturing, healthcare, and tech organizations. Once installed, Ballista can run remote commands, launch DoS attacks, and scour through sensitive files.

IXON VPN Vulnerabilities Let Attackers Gain Access to Windows & Linux Systems
A security assessment by Shelltrail revealed three critical vulnerabilities in the IXON VPN client, allowing privilege escalation on Windows and Linux. Identified as CVE-2025-ZZZ-01, CVE-2025-ZZZ-02,