MalwareBleeping Computer
10.0 — CRITICAL
ChocoPoc malware delivered via trojanized exploits on GitHub
Multiple weaponized proof-of-concept (PoC) exploits on GitHub delivered a Python-based remote access trojan (RAT) called ChocoPoC that can execute commands and steal sensitive data. [...]
🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview
ChocoPoC malware was delivered via trojanized exploits on GitHub, targeting vulnerability and penetration testers or low-skilled hackers, with a Python-based remote access trojan (RAT) that can execute commands and steal sensitive data.
⚙️Technical Details
Affected Systems
Fortinet FortiWebFacebook ReactMongoDB ServerPalo Alto Networks PAN-OSIvanti Standalone Sentry
Attack Vectors
NETWORK
💥Impact Assessment
Severity: CRITICAL
Who Is at Risk
Vulnerability and penetration testers or low-skilled hackers
🛡️Recommended Actions
1Never blindly trust GitHub repositories and only execute unverified code in isolated environments.
2Regularly update software and systems with the latest security patches.
3Monitor system logs for suspicious activity and implement intrusion detection and prevention systems.
📦Affected Products
Fortinet FortiwebFacebook ReactVercel Next.JsMongodb MongodbPaloaltonetworks Pan-OsPaloaltonetworks Prisma AccessSiemens Ruggedcom Ape1808Siemens Ruggedcom Ape1808 FirmwareIvanti Standalone SentryFortinet FortiWeb
🔐NVD Verified DataVERIFIED
CVE-2025-64446 ↗CVSS 9.8 — CRITICAL
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HWeaknesses
CWE-23
Affected Products (CPE)
Fortinet Fortiweb
CVE-2025-55182 ↗CVSS 10 — CRITICAL
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HWeaknesses
CWE-502
Affected Products (CPE)
Facebook ReactVercel Next.Js
CVE-2025-14847 ↗CVSS 7.5 — HIGH
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NWeaknesses
CWE-130
Affected Products (CPE)
Mongodb Mongodb
CVE-2026-0257 ↗CVSS 9.1 — CRITICAL
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NWeaknesses
CWE-565
Affected Products (CPE)
Paloaltonetworks Pan-OsPaloaltonetworks Prisma AccessSiemens Ruggedcom Ape1808Siemens Ruggedcom Ape1808 Firmware
CVE-2026-10520 ↗CVSS 10 — CRITICAL
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HWeaknesses
CWE-78
Affected Products (CPE)
Ivanti Standalone Sentry
Read the full article
This is a curated summary. The complete article is available at Bleeping Computer.
