XE Hacker Group Exploits Veracode 0-Day to Deploy Malware and Steal Credit Card Data

A sophisticated cybercriminal group known as XE Group has been exploiting zero-day vulnerabilities in VeraCore software to deploy malware and steal sensitive data, including credit card information. The vulnerabilities, identified as CVE-2024-57968 (Upload Validation Vulnerability) and CVE-2025-25181 (SQL Injection), have been exploited since at least 2020, according to researchers from Intezer and Solis Security. Exploitation … Continue reading XE Hacker Group Exploits Veracode 0-Day to Deploy Malware and Steal Credit Card Data