Cyber Threats & Vulnerabilities to Watch

Vulns Full

1. Notepad++ Compromise: State-Sponsored Supply Chain Attack

From June to December 2025, a suspected Chinese state-sponsored actor compromised the popular text editor Notepad++ by infiltrating its hosting provider. Attackers hijacked update traffic and delivered malicious installers by exploiting weak update verification.

Why this matters

  • Many developers use Notepad++ inside corporate networks.
  • Supply chain attacks bypass perimeter defenses.
  • Malicious trojans could have been silently deployed for months.

Nevtec Recommendation

  • Immediately update to v8.8.9 or later
  • Enforce certificate-based update validation across dev tools
  • Review developer endpoints for anomalous Notepad++ update traffic

2. New Windows Malware Uses Pulsar RAT for Live Chats with Victims

A new malware strain combining Pulsar RAT and Stealerv37 injects itself into explorer.exe entirely in-memory to evade antivirus.
The most disturbing feature: attackers can open a live chat window on the victim’s PC while stealing data.

Capabilities

  • Webcam & microphone access
  • Crypto wallet hijacking
  • Credential theft (browsers, VPNs, gaming apps)
  • Exfiltration via Discord & Telegram
  • Persistence watchdog
  • AV/Task Manager evasion

Nevtec Recommendation

  • Enable PowerShell Constrained Language Mode
  • Deploy EDR with memory scanning
  • Hunt for Donut loader patterns and anomalous explorer.exe injection
  • Block Discord/Telegram exfiltration channels when possible

3. Critical 1‑Click RCE – OpenClaw (formerly Moltbot) CVE‑2026‑25253

A devastating 1‑click remote code execution flaw allows attackers to hijack OpenClaw AI agents, bypass localhost protections, and execute arbitrary commands on the host machine.

What’s exploited

  • Unsanitized gatewayUrl parameters
  • Auth token leakage via WebSocket handshake
  • Missing Cross-Site WebSocket Origin validation

Nevtec Recommendation

  • Upgrade immediately beyond v2026.1.24-1
  • Rotate all auth tokens
  • Restrict agent system permissions
  • Review your AI agent architecture for unnecessary OS privileges

Strategy & Defensive Tactics

4. Google Disrupts the World’s Largest Residential Proxy Network (IPIDEA)

Google disrupted IPIDEA’s massive residential proxy service used by over 550 threat groups weekly.

Nevtec Recommendation

  • Block IPIDEA-associated domains
  • Monitor traffic for proxy-like patterns
  • Audit bandwidth-monetizing mobile apps in corporate BYOD programs

5. Your Phone’s GPS Can Be Queried by Carriers Without Consent

Carriers can silently request precise GPS from any modern phone using low-level baseband protocols (RRLP/LPP); bypassing OS controls, permissions, and VPNs.

Nevtec Recommendation

  • For sensitive staff: issue devices with iPhone 16e + C1 modem
  • Educate execs that “location permissions” ≠ true privacy
  • Review mobile threat defense posture

6. macOS Hardening Series (New)

Security expert Gabriel Biondo releases a pragmatic, layered macOS hardening framework covering DNS filtering, browser compartments, MFA, passkeys, and more.

Nevtec Recommendation

  • Apply layered hardening rather than individual point fixes
  • Prioritize DNS control + credential security

Strengthen Your Security Posture Today

Book a Free 30-Minute Threat Exposure Assessment with Nevtec

We’ll review your environment for:
Malware/memory attack exposure
AI agent security risks
Shadow IT & SaaS sprawl
Mobile/GPS privacy weaknesses
OT/ICS monitoring gaps

Schedule here.

Scroll to Top