A critical remote code execution vulnerability (CVE-2025-31324) in SAP NetWeaver Visual Composer is exploited by a Chinese group, Chaya_004, targeting manufacturing systems. Attackers upload web shells through a specific endpoint, gaining extensive access. Over 700 IPs related to the attacks were identified, utilizing Chinese cloud services. Immediate patching and restricted access are recommended for affected organizations.

20 Years old Proxy Botnet Network Dismantled That Exploits 1000 Unique Unpatched Devices Weekly
Lumen Technologies, in collaboration with the DOJ, FBI, and Dutch National Police, dismantled a long-running criminal proxy network that exploited IoT and end-of-life devices. This