FeedMalwareChocoPoc malware delivered via trojanized exploits on GitHub...
MalwareBleeping Computer
10.0CRITICAL

ChocoPoc malware delivered via trojanized exploits on GitHub

📅 1 July 2026 at 20:08 UTC📰 Bleeping ComputerView original source ↗
ChocoPoc malware delivered via trojanized exploits on GitHub

Multiple weaponized proof-of-concept (PoC) exploits on GitHub delivered a Python-based remote access trojan (RAT) called ChocoPoC that can execute commands and steal sensitive data. [...]

🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview

ChocoPoC malware was delivered via trojanized exploits on GitHub, targeting vulnerability and penetration testers or low-skilled hackers, with a Python-based remote access trojan (RAT) that can execute commands and steal sensitive data.

⚙️Technical Details
Affected Systems
Fortinet FortiWebFacebook ReactMongoDB ServerPalo Alto Networks PAN-OSIvanti Standalone Sentry
Attack Vectors
NETWORK
💥Impact Assessment
Severity: CRITICAL
Who Is at Risk
Vulnerability and penetration testers or low-skilled hackers
🛡️Recommended Actions
1Never blindly trust GitHub repositories and only execute unverified code in isolated environments.
2Regularly update software and systems with the latest security patches.
3Monitor system logs for suspicious activity and implement intrusion detection and prevention systems.
📦Affected Products
Fortinet FortiwebFacebook ReactVercel Next.JsMongodb MongodbPaloaltonetworks Pan-OsPaloaltonetworks Prisma AccessSiemens Ruggedcom Ape1808Siemens Ruggedcom Ape1808 FirmwareIvanti Standalone SentryFortinet FortiWeb
🔐NVD Verified DataVERIFIED
CVE-2025-64446CVSS 9.8CRITICAL
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-23
Affected Products (CPE)
Fortinet Fortiweb
CVE-2025-14847CVSS 7.5HIGH
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weaknesses
CWE-130
Affected Products (CPE)
Mongodb Mongodb
CVE-2026-0257CVSS 9.1CRITICAL
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Weaknesses
CWE-565
Affected Products (CPE)
Paloaltonetworks Pan-OsPaloaltonetworks Prisma AccessSiemens Ruggedcom Ape1808Siemens Ruggedcom Ape1808 Firmware
CVE-2026-10520CVSS 10CRITICAL
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Weaknesses
CWE-78
Affected Products (CPE)
Ivanti Standalone Sentry

Read the full article

This is a curated summary. The complete article is available at Bleeping Computer.

Read on Bleeping Computer
← Back to feed