The Ballista botnet has compromised over 6000 TP-Link Archer AX-21 routers through a high-severity remote code execution flaw, according to The Hacker News. The botnet, thought to be operated by an Italy-based threat actor, has been targeting manufacturing, technology, and healthcare organizations primarily in the US, Mexico, China, and Australia, deploying malware to facilitate various attacks.

IXON VPN Vulnerabilities Let Attackers Gain Access to Windows & Linux Systems
A security assessment by Shelltrail revealed three critical vulnerabilities in the IXON VPN client, allowing privilege escalation on Windows and Linux. Identified as CVE-2025-ZZZ-01, CVE-2025-ZZZ-02,