⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More
This week saw a surge in exploitation activity and new malware discoveries. A China-nexus APT is leveraging a newly patched VMware vulnerability to deploy a backdoor and ransomware (Babuk-derived). Simultaneously, a zero-day exploit targeting Windows is being used by North Korean hackers (Lazarus Group) to deliver a new backdoor and spyware campaign. Other notable events include a critical SQL injection vulnerability in GeoServer, a new macOS stealer (Amnesia Stealer) with remote browser control, and a growing trend of AI-assisted exploit generation. Several high-severity CVEs were also highlighted, emphasizing the shrinking gap between vulnerability disclosure and exploitation.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
