Browser-assembled malware, GitLab RCE exploit public, PTC manufacturing under attack
ID: d9ad2e8c-a2a9-5236-b8b6-91839fe3baea
STIX ID: report--d9ad2e8c-a2a9-5236-b8b6-91839fe3baea
Feed Name: defend.network
**TL;DR:** A high-priority intelligence briefing reports multiple active threats: a SourTrade malvertising campaign that fragments payloads and assembles malware in-browser on Windows, a public GitLab RCE PoC affecting self-managed instances, Cl0p-linked actors chaining PTC Windchill/FlexPLM flaws for unauthenticated RCE and data extortion, a Vatican prayer app API exposing ~700K users' PII, and other notable vulnerabilities and supply-chain mitigations—recommendations include immediate patching, network segmentation, auditing internet-exposed systems, and deploying detections for in-memory/runtime abuse.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
