U.S. computer software and services provider PTC has alerted that potential exploitation of a critical flaw in its product lifecycle management solutions FlexPLM and Windchill via trusted data deserialization could result in remote code execution, reports BleepingComputer.
Intrusions exploiting the high-severity stored cross-site scripting flaw in Zimbra Collaboration, tracked as CVE-2025-66376, have been launched against Ukraine by a Russian advanced persistent threat operation suspected to be APT28, also known as Fancy Bear, Sofacy Group, BlueDelta, and STRONTIUM, according to Security Affairs.