Threat actors are leveraging bogus installers masquerading as popular software to trick users into installing malware as part of a global malvertising campaign dubbed TamperedChef.
The end goal of the attacks is to establish persistence and deliver JavaScript malware that facilitates remote access and control, per a new report from Acronis Threat Research Unit (TRU). The campaign, per the
A vulnerability, which was classified as problematic, has been found in danny-avila librechat up to 0.8.0-rc1. Affected by this issue is some unknown functionality of the component API Endpoint. Performing manipulation results in expected behavior violation.
This vulnerability is cataloged as CVE-2025-8850. It is possible to initiate the attack remotely. There is no exploit available.
It is advisable to upgrade the affected component.
A vulnerability was found in Cisco Identity Services Engine Software. It has been rated as problematic. This affects an unknown part of the component Web-based Management Interface. The manipulation leads to insufficient granularity of access control.
This vulnerability is traded as CVE-2025-20305. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is advised.
A vulnerability categorized as critical has been discovered in Cisco Identity Services Engine Software 3.4.0. This vulnerability affects unknown code of the component RADIUS. The manipulation results in incorrect comparison.
This vulnerability is known as CVE-2025-20343. It is possible to launch the attack remotely. No exploit is available.
It is advisable to upgrade the affected component.
A vulnerability identified as problematic has been detected in Cisco Identity Services Engine Software. This issue affects some unknown processing. This manipulation causes cross site scripting.
This vulnerability is handled as CVE-2025-20289. The attack can be initiated remotely. There is not any exploit available.
You should upgrade the affected component.
A vulnerability was found in Advantech DeviceOn and iEdge up to 2.0.2. It has been classified as critical. The affected element is an unknown function of the component Configuration File Handler. The manipulation leads to path traversal. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability is traded as CVE-2025-59171. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability was found in Advantech DeviceOn and iEdge up to 2.0.2. It has been declared as critical. The impacted element is an unknown function of the component Configuration File Handler. The manipulation results in path traversal. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability is known as CVE-2025-62630. It is possible to launch the attack remotely. No exploit is available.
A vulnerability described as critical has been identified in Advantech DeviceOn and iEdge up to 2.0.2. Impacted is an unknown function of the component Dashboard Label. Such manipulation leads to cross site scripting. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability is referenced as CVE-2025-64302. It is possible to launch the attack remotely. No exploit is available.
A vulnerability identified as problematic has been detected in IBM DB2 and DB2 Connect Server up to 11.1.4.7/11.5.9/12.1.3. The affected element is an unknown function. Performing manipulation results in uncontrolled memory allocation.
This vulnerability is reported as CVE-2025-2534. The attack is possible to be carried out remotely. No exploit exists.
You should upgrade the affected component.
A vulnerability labeled as critical has been found in IBM DB2 up to 10.5.11/11.1.4.7/11.5.9/12.1.3. The impacted element is an unknown function. Executing manipulation can lead to use of a key past its expiration date.
This vulnerability appears as CVE-2025-33012. The attack may be performed from remote. There is no available exploit.
The affected component should be upgraded.
A vulnerability marked as critical has been reported in IBM DB2 and DB2 Connect Server up to 10.5.11/11.1.4.7/11.5.9/12.1.3. This affects an unknown function. The manipulation leads to stack-based buffer overflow.
This vulnerability is traded as CVE-2024-47118. It is possible to initiate the attack remotely. There is no exploit available.
It is suggested to upgrade the affected component.
A vulnerability classified as problematic was found in IBM DB2 and DB2 Connect Server up to 11.5.9/12.1.3. Affected by this vulnerability is an unknown functionality. Such manipulation leads to allocation of resources.
This vulnerability is uniquely identified as CVE-2025-36136. Local access is required to approach this attack. No exploit exists.
Upgrading the affected component is advised.