Microsoft is calling attention to an ongoing malvertising campaign that makes use of Node.js to deliver malicious payloads capable of information theft and data exfiltration.
The activity, first detected in October 2024, uses lures related to cryptocurrency trading to trick users into installing a rogue installer from fraudulent websites that masquerade as legitimate software like Binance or TradingView.
Ethereum price started a downside correction below the $4,650 zone. ETH is showing some bearish signs and might decline toward the $4,180 support zone.
Path traversal and XXE injection flaws allowing unauthenticated remote code execution have been patched in Xerox FreeFlow Core. www.osintinvestigate.com
OSINT Investigate’s analysis of dark web forums uncovers a thriving marketplace where top hackers sell access to corporate networks, turning cybercrime into a streamlined business.www.osintinvestigate.com
Hackers targeted Connex, one of the largest credit unions in Connecticut, and likely stole files containing personal information.www.osintinvestigate.com
WinRAR has patched CVE-2025-8088, a zero-day exploited by Russia’s RomCom in attacks on financial, defense, manufacturing and logistics companies.www.osintinvestigate.com