Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks
The Computer Emergency Response Team of Ukraine (CERT-UA) has warned of a new campaign involving a malicious program disguised as a Notepad++…
The Computer Emergency Response Team of Ukraine (CERT-UA) has warned of a new campaign involving a malicious program disguised as a Notepad++…
A suspected China-aligned threat activity cluster tracked as UNK_MassTraction by Proofpoint has been exploiting critical Roundcube webmail vulnerabilities to target physics and…
CVE-2024-42009 is a critical cross-site scripting (XSS) vulnerability in Roundcube webmail with a CVSS score of 9.3. Exploitation requires the victim to…
CVE-2025-49113 is a vulnerability in Roundcube's file upload handler that allows unsafe PHP deserialization, used by TA458 to deploy SpyPress backdoors.
UNK_MassTraction is a suspected China-aligned threat activity cluster first detected by Proofpoint in May 2026. It targets physics and engineering departments at…
IceCube is a JavaScript malware deployed by UNK_MassTraction after exploiting CVE-2024-42009 in Roundcube. It steals credentials, 2FA tokens, cookies, and browser information,…
SquareShell is a web shell deployed by UNK_MassTraction using a PHP gadget shell command after exploiting CVE-2025-49113 in Roundcube. It is accessible…
Roundcube was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs, malware,…