September 28, 2025 at 04:13PM

■■■■□ Iranian State Sponsored Hackers Use SSL.com Certificates to Sign Malware. Security researchers say multiple threat groups, including Iran’s Charming Kitten APT offshoot Subtle Snail, are deploying malware with code-signing certificates from the Houston-based company. https://www.darkreading.com/vulnerabilities-threats/iranian-hackers-ssl-certificates-sign-malware

September 28, 2025 at 01:17PM

■■■■□ 🔥CVE-2025-59934: Critical Flaw in Formbricks Allows Unauthorized Password Resets via Forged JWT Tokens 🚀POC -https://github.com/formbricks/formbricks/security/advisories/GHSA-7229-q9pv-j6p4 Dorks: http://product.name=”Formbricks”

September 27, 2025 at 02:04AM

■■■□□ Widespread Infostealer Campaign Targeting macOS Users. Threat actors rely on malicious GitHub repositories to infect LastPass’s macOS users with the Atomic infostealer. https://www.securityweek.com/widespread-infostealer-campaign-targeting-macos-users/