A high-severity vulnerability (CVE-2025-24043) in the SOS debugging extension allows remote code execution via improper cryptographic signature validation in .NET diagnostic packages. Attackers can exploit this flaw during debugging sessions, potentially compromising systems and executing arbitrary code. Microsoft has released patches, urging immediate updates for developers to mitigate cascading supply chain risks and secure development environments.

Phantom Goblin Leveraging Social Engineering Tactics To Deliver Stealer Malware
A sophisticated malware operation named ‘Phantom Goblin’, employing deceptive social engineering techniques, has been identified by Cyble Research and Intelligence Labs (CRIL). The malware uses