Adobe shipped an emergency patch for a critical prototype pollution flaw in Acrobat Reader that has been exploited in the wild for months. The bug can lead to arbitrary code execution in the current user’s context—opening a crafted PDF is enough—so updating is urgent for both consumers and enterprises. Security teams should accelerate patch rollouts and consider tightening PDF handling policies and disabling JavaScript where feasible.
Source: Help Net Security
CPUID site hijack briefly served STX RAT via CPU‑Z and HWMonitor downloads
Attackers compromised CPUID’s website for ~6 hours (Apr 9–10), causing some visitors to receive malicious links that installed the newly observed STX RAT. CPUID says signed originals weren’t altered, but the website intermittently redirected to trojanized installers. Anyone who downloaded during the window should assume compromise, reimage if needed, rotate credentials, and hunt for STX RAT IOCs.
Source: SecurityWeek
OpenAI rotates macOS certs after Axios supply chain compromise; users must update apps
OpenAI determined that a macOS code-signing certificate may have been exposed after a developer tool automatically fetched a malicious Axios library, in an incident linked to North Korean threat activity. The company is revoking and rotating certs “out of an abundance of caution,” urging users to update Mac apps ahead of certificate blocking next month. The incident underscores how small dependency shifts can cascade into trust failures in build and signing pipelines.
Source: SecurityWeek
Rockstar breach tied to third‑party SaaS tokens; “pay or leak” extortion follows
ShinyHunters claims it accessed Rockstar Games data by abusing authentication tokens extracted via Anodot, a cloud cost analytics SaaS, to reach Rockstar’s Snowflake environment—without exploiting Snowflake itself. The case spotlights the growing risk from SaaS integrations and token reuse across cloud services: one weak link can open a much larger data estate.
Source: Help Net Security
CISA warns on exploited Windows and Acrobat bugs; patching urged across fleets
US authorities flagged actively exploited vulnerabilities impacting Microsoft Windows and Adobe Acrobat that enable privilege escalation and remote code execution. Organizations should prioritize these updates in line with KEV timelines and validate compensating controls, especially on high-value endpoints and VDI pools where PDF handling and local privilege paths are common.
Source: SecurityWeek
ShowDoc RCE (CVE-2025-0520) under active exploitation
A critical unrestricted file upload flaw in ShowDoc (CVSS 9.4) is being mass‑exploited, enabling unauthenticated remote code execution on unpatched servers. Teams should update immediately, restrict external access where possible, and scan for webshells and rogue processes in ShowDoc directories.
Source: The Hacker News
Critical wolfSSL flaw could let attackers forge signatures across routers, IoT, and apps
A newly reported vulnerability in the widely used wolfSSL cryptographic library could allow signature forgery, enabling spoofed identities and man‑in‑the‑middle scenarios across billions of devices and applications. Vendors and developers embedding wolfSSL should fast‑track patches, regenerate affected keys/certificates where advised, and monitor for abnormal certificate chains and trust anchors.
Source: CyberNews
You May Also Be Interested In...