Adobe shipped emergency updates for Acrobat and Reader to fix CVE-2026-34621, a zero-day that allows arbitrary code execution and has been exploited in the wild for months. The flaw can be triggered via malicious PDFs on Windows and macOS. Prioritize patching via the Admin Console or auto-update, and consider hardening measures (e.g., disabling JavaScript in PDFs) until the update is broadly deployed.
Source: SecurityWeek
Popular CPUID downloads briefly hijacked to deliver STX RAT
Attackers compromised CPUID’s site and, for several hours, swapped download links for CPU-Z and HWMonitor with trojanized installers that deployed the STX remote access trojan. Impacted users risk full system compromise. If you downloaded recently, verify checksums, reimage or thoroughly clean affected hosts, rotate credentials, and re-download only from verified sources.
Source: Security Affairs
OpenAI revokes macOS app certificate after Axios npm supply-chain incident
OpenAI invalidated its macOS app signing certificate after a GitHub Actions workflow pulled a malicious Axios library on March 31. The company says no user data or internal systems were compromised, but is hardening its code-signing process. The incident underscores the risks of pulling unpinned dependencies in CI/CD; teams should inventory builds, pin/verify packages, and review SBOMs and pipeline egress controls.
Source: The Hacker News
Critical wolfSSL flaw enables signature forgery across routers, IoT, and apps
A critical vulnerability in the widely used wolfSSL cryptography library could allow attackers to forge digital signatures and impersonate trusted entities, putting routers, IoT devices, and applications at risk. Organizations should urgently update to patched wolfSSL versions, track embedded usage across firmware and SDKs, and follow vendor guidance on key/certificate rotation where applicable.
Source: CyberNews
Police seize VerifTools servers exposing 915,655 fake IDs; eight arrested
Dutch authorities arrested eight suspects and seized infrastructure behind VerifTools, uncovering a cache of 915,655 fraudulent identity documents used in large-scale identity fraud. The takedown highlights the industrialization of synthetic ID operations and the need for stronger document forensics, liveness checks, and cross-platform fraud intelligence sharing.
Source: Help Net Security
Fake Claude website pushes PlugX RAT via DLL sideloading
Threat actors are distributing a counterfeit installer that mimics Anthropic’s Claude, abusing DLL sideloading to deploy the PlugX remote access trojan and then cleaning up artifacts to evade detection. Defenders should block lookalike domains, enforce code-signature verification, and restrict unsigned or unexpected DLL loads; users should only download AI tools from official vendor domains.
Source: SecurityWeek
MITRE launches F3: a shared, behavior-based framework to fight fraud
MITRE released the Fight Fraud Framework (F3), built from real attack data to bridge long-standing gaps between fraud investigation and cybersecurity operations. With U.S. fraud losses hitting $16.6B in 2024, F3 provides a common language for describing techniques and coordinating detection and response across account takeover, social engineering, and monetization phases.
Source: Help Net Security
You May Also Be Interested In...
North Korea's APT37 Uses Facebook Social Engineering to Deliver RokRAT Malware
Hackers claim access to pump system protecting Venice’s iconic St. Mark’s Square from flooding
FBI Atlanta and Indonesian National Police Take Down W3LLSTORE Phishing Marketplace