A cross-site scripting (XSS) vulnerability in the Krpano framework has been exploited to inject malicious scripts into over 350 websites, manipulating search results and spreading spam. Discovered by researcher Oleg Zaytsev, the flaw involved improper handling of the “xml” parameter. Krpano has since released an updated version to address this issue, urging users to update and secure their configurations.

Multi-Vector Malware Exploiting Outlook API, DNS & ICMP Tunneling for C2
The newly identified malware “Squidoor,” suspected to be created by a Chinese threat actor, is a sophisticated tool targeting sectors such as government, defence, telecommunications,