Intrusions leveraging the critical React Native Community CLI NPM package vulnerability, tracked as CVE-2025-11953, have been launched to compromise Windows and Linux systems with malware since late December, reports SecurityWeek.
The newly added vulnerabilities include a high-severity deserialization flaw in SolarWinds Web Help Desk (CVE-2025-40551), enabling remote code execution.
Chinese-speaking cybercrime operation UAT-8099 has targeted unsecured Internet Information Services servers across Asia, particularly in Thailand and Vietnam, as part of an attack campaign that commenced late last year, reports Cyber Security News.