China-linked Amaranth Dragon exploits WinRAR flaw in Southeast Asian espionage campaigns
Amaranth Dragon began exploiting CVE-2025-8088 on August 18, 2025, just days after a working exploit became public.
In brief: Russian hackers exploit a Microsoft Office flaw, Citrix NetScaler infrastructure targeted in a coordinated campaign, and more.
Amaranth Dragon began exploiting CVE-2025-8088 on August 18, 2025, just days after a working exploit became public.
Attackers modify legitimate NGINX configuration files by injecting malicious u201clocationu201d blocks.
A contractor improperly accessed customer information affecting approximately 30 users.
The activity, tracked between January 28 and February 2, indicates deliberate infrastructure mapping rather than opportunistic crawling.
With valid login details, threat actors can take over accounts, gain internal access or use the data for additional follow-on fraud.
Researchers estimate that approximately 3,500 exposed React Native Metro servers are currently accessible online.