Malicious Sicoob.Sdk stole PFX certificates and client IDs via NuGet downloads, enabling API impersonation and payment abuse risks.
IT researchers have demonstrated a side-channel attack called "FROST" where browsers can spy on user behavior via SSD access times.