A critical vulnerability (CVE-2025-3500) in Avast Free Antivirus could let attackers execute malicious code with kernel-level access. Discovered by Baris Akkaya and patched on April 24, 2025, it affects versions from 20.1.2397 to 2016.11.1.2262. Users are urged to update immediately for protection. Enabling automatic updates and using standard accounts can also mitigate risks.

New GitHub Actions Attack Chain Uses Fake CI Updates to Exfiltrate Secrets and Tokens
A new attack campaign is actively targeting open-source repositories on GitHub by carefully disguising malicious code as completely routine CI build configuration updates. The campaign,


