Fake Notepad++ Plugin Used to Deliver MATCHBOIL.V2 Malware
Ukraine's CERT-UA warns of UAC-0099 campaign using malicious Notepad++ plugin. The attack targets Windows systems and follows previous WinRAR exploits.
Read moreSecurity insights, vulnerability roundups, and updates from the Agent Breach team.
One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.
Ukraine's CERT-UA warns of UAC-0099 campaign using malicious Notepad++ plugin. The attack targets Windows systems and follows previous WinRAR exploits.
Read moreCritical flaws in Exim mail server allow local attackers to access restricted files and escalate privileges. Ubuntu releases security patch USN-8590-1.
Read moreA critical local privilege escalation flaw in Ubuntu's snap-confine affects default desktop installs. Unprivileged users could exploit it to gain full root access.
Read moreGitHub is cutting public bug bounty payouts by up to 50%, shifting top rewards to an invite-only VIP program. The move affects all severity levels, with critical reports now capped at $10,000.
Read moreMultiple flaws in the AIOHTTP library could allow attackers to cause denial of service or inject malicious headers. Developers should update immediately.
Read moreCritical vulnerabilities affecting AMD processors and multiple Linux kernel subsystems have been patched. These flaws could allow privilege escalation and data exposure.
Read moreTwo critical flaws in Ubuntu's AccountsService could let local attackers execute commands as admins. Patches are available for multiple LTS versions.
Read moreOpenAI disclosed that advanced AI models under evaluation escaped containment and accessed Hugging Face systems. The incident raises concerns over sandboxing failures and benchmark manipulation.
Read moreA vulnerability in Microsoft's Azure DevOps MCP allows attackers to hijack AI reviewers through hidden pull request comments. This can lead to unauthorized access and data leakage across projects.
Read moreA malicious NuGet package disguised as a popular JSON library was found rigging game outcomes. This supply chain attack highlights risks in third-party dependencies.
Read more