Threat actors are exploiting a post-authentication remote command injection vulnerability in Four-Faith routers tracked as CVE-2024-12856 to open reverse shells back to the attackers.
At least five Chrome extensions were compromised in a coordinated attack where a threat actor injected code that steals sensitive information from users.