Researchers from Splunk uncovered a malware campaign targeting over 4,000 ISPs in the U.S. and China, originating from Eastern Europe. Using credential brute force attacks, the malware establishes access to mine cryptocurrency and steal information. Key components include a self-extracting file and a clipboard monitor that hijacks cryptocurrency transactions. Security teams are urged to strengthen password protocols and monitor for unusual WINRM activity.

400+ SAP NetWeaver Devices Vulnerable to 0-Day Attacks that Exploited in the Wild
Shadow Servers have identified 454 vulnerable SAP NetWeaver systems affected by a critical zero-day flaw, CVE-2025-31324, allowing unauthenticated file uploads and potential system compromise. Discovered