A critical RCE vulnerability in Apache Tomcat (CVE-2025-24813) is actively exploited, enabling attackers to take control via simple PUT requests. Discovered on March 10, 2025, it affects multiple Tomcat versions and evades detection by traditional security tools. Apache advises upgrading to patched versions. Experts warn of evolving tactics, emphasizing the need for proactive security measures.

DocSwap Malware as Security Document Viewer Attacking Android Users Worldwide
The “DocSwap” malware campaign targets Android users by masquerading as a legitimate document viewer. Utilizing social engineering, it infects devices through phishing, exfiltrates sensitive data,