Proofpoint has said that a recent phishing message used a “business-to-business sales lure” to exploit the relationship between a sender and targets. The message contained false URLs seeming to belong to INDIC Electronics, but actually linked to a bogus “indicelectronics.net” archive, including an Excel spreadsheet and two PDFs. These turned out to be a LNK file and two polyglots, which ultimately led to the Sosano backdoor hidden in the zip file.

400+ SAP NetWeaver Devices Vulnerable to 0-Day Attacks that Exploited in the Wild
Shadow Servers have identified 454 vulnerable SAP NetWeaver systems affected by a critical zero-day flaw, CVE-2025-31324, allowing unauthenticated file uploads and potential system compromise. Discovered