The maintainer of Notepad++ disclosed that state-sponsored attackers compromised its hosting provider and redirected software update traffic to malicious servers. The intruders appear to have maintained access for months and selectively targeted certain customers, with no vulnerability found in Notepad++ itself. The incident underscores how third-party infrastructure compromises can subvert trusted update channels.
Source: SecurityWeek
eScan antivirus update servers compromised to deliver multi-stage malware
Unknown attackers hijacked eScan’s legitimate update infrastructure to push a persistent downloader to enterprise and consumer systems. The campaign used malicious updates to initiate a multi-stage infection chain, highlighting the growing risk of supply-chain abuse within security products themselves. Organizations should review endpoint telemetry for anomalous update behavior and follow vendor guidance.
Source: The Hacker News
Open VSX Registry attack used a compromised dev account to spread ‘GlassWorm’ via extensions
On January 30, threat actors took over a legitimate developer’s Open VSX account and published malicious versions of four established extensions embedding the GlassWorm malware. Because the packages appeared trusted, downstream users were exposed via normal update flows. The incident reinforces the need for strict publisher verification, pinned versions, and extension allowlists in dev environments.
Source: The Hacker News
Over 1,400 exposed MongoDB databases ransacked by a single threat actor
Researchers found 3,100 unprotected MongoDB instances online; roughly half had already been compromised, most by one attacker. The wave of breaches shows how quickly misconfigured databases are discovered and abused at Internet scale. Immediate actions include removing public exposure, enforcing authentication, and enabling backups and audit logging.
Source: SecurityWeek
Microsoft moves to disable NTLM by default in upcoming Windows and Windows Server
The next major Windows and Windows Server releases will ship with the long-deprecated NTLM authentication protocol disabled by default. Enterprises relying on NTLM should inventory legacy dependencies, test Kerberos/Negotiate scenarios, and mitigate relay risks before the change arrives. The shift is a significant step toward hardening identity across Windows estates.
Source: SecurityWeek
NSA releases phased Zero Trust implementation guidance aligned to DoD maturity model
The NSA published Phase One and Phase Two Zero Trust Implementation Guidelines, mapping 36 activities to 30 capabilities to help organizations sequence real-world deployments. The documents aim to translate framework principles into actionable steps across identity, network, data, and application domains, closing gaps between policy and enterprise reality.
Source: Help Net Security
ShinyHunters reportedly breached Bumble, OkCupid, and others via phone-based social engineering
The ShinyHunters group allegedly gained access to major brands by calling employees and persuading them to grant or reset access to cloud systems. The incidents highlight the continued effectiveness of vishing against help desks and internal support workflows, and the importance of call-back verification, strong MFA, and strict change-control procedures.
Source: CyberNews
You May Also Be Interested In...
AI is flooding IAM systems with new identities
Open-source AI pentesting tools are getting uncomfortably good
How fake party invitations are being used to install remote access tools