The Google Threat Intelligence Group has now confirmed widespread and ongoing attacks using no-password-required malware.
CVE-2025-66516 is a critical Apache Tika vulnerability can be exploited on all platforms in XXE injection attacks via crafted ...