Microsoft has detected a new strain of the XCSSET macOS malware variant, which has improved obfuscation techniques, persistence, and infection mechanisms. The infostealer malware targets users via infected Xcode projects and now uses randomized approaches for payload generation as well as two new persistence techniques. Microsoft is currently only seeing limited attacks but is urging users to verify any Xcode projects downloaded from repositories and only install apps from trusted sources.

400+ SAP NetWeaver Devices Vulnerable to 0-Day Attacks that Exploited in the Wild
Shadow Servers have identified 454 vulnerable SAP NetWeaver systems affected by a critical zero-day flaw, CVE-2025-31324, allowing unauthenticated file uploads and potential system compromise. Discovered