Threat actors are exploiting OpenAI’s popular Sora video generation model to distribute harmful software. The hackers are using social engineering, disguising their malware as a legitimate file called “SoraAI.lnk”. Reported first in Vietnam in May 2025, it’s been detected in various countries. The malware attempts to steal sensitive info such as browser cookies, passwords, gaming platform data, and cryptocurrency wallet details. Collected data is sent via Telegram, while larger files are uploaded to GoFile.io.

Cisco IOS XR Vulnerability Exposes Systems to Root Command Execution by Attackers
Cisco has issued high-severity software updates to address two high-severity privilege escalation vulnerabilities in its IOS XR Software. Network administrators must take immediate action, as


