A phishing email campaign targeting users in Poland and Germany has been delivering various payloads such as Agent Tesla, Snake Keylogger, and a previously unknown backdoor called TorNet via PureCrypter. The threat actor disconnects the victim machine from the network before dropping the payload and then reconnecting, helping them to evade detection by cloud antimalware solutions. The attacks usually start with phishing emails impersonating financial institutions and manufacturing and logistics companies.

400+ SAP NetWeaver Devices Vulnerable to 0-Day Attacks that Exploited in the Wild
Shadow Servers have identified 454 vulnerable SAP NetWeaver systems affected by a critical zero-day flaw, CVE-2025-31324, allowing unauthenticated file uploads and potential system compromise. Discovered