Security researchers and vendors disclosed numerous critical vulnerabilities including zero-day flaws in SonicWall SMA1000 devices, infrastructure flaws tracked in an InfraTrust report, and large-scale malware campaigns using GitHub repositories and DDoS botnets. The Dysphoria botnet has infected approximately 200,000 devices worldwide.
The Chaos ransomware gang is using msaRAT, a Rust-based backdoor, to hide command-and-control communication by routing it through Chrome or Edge browsers to evade detection. Cisco Talos found the malware on a compromised Windows machine before the gang deployed ransomware encryption.