Cybersecurity experts have identified a new campaign by the threat actor Sapphire Werewolf, targeting energy sector companies with an advanced version of the Amethyst stealer malware. Utilizing sophisticated evasion techniques, it exploits phishing emails and employs a multi-stage infection process to steal credentials. Enhanced virtual machine detection enhances its security against analysis, complicating effective countermeasures.

IXON VPN Vulnerabilities Let Attackers Gain Access to Windows & Linux Systems
A security assessment by Shelltrail revealed three critical vulnerabilities in the IXON VPN client, allowing privilege escalation on Windows and Linux. Identified as CVE-2025-ZZZ-01, CVE-2025-ZZZ-02,