1. Notepad++ Compromise: State-Sponsored Supply Chain Attack
From June to December 2025, a suspected Chinese state-sponsored actor compromised the popular text editor Notepad++ by infiltrating its hosting provider. Attackers hijacked update traffic and delivered malicious installers by exploiting weak update verification.
Why this matters
- Many developers use Notepad++ inside corporate networks.
- Supply chain attacks bypass perimeter defenses.
- Malicious trojans could have been silently deployed for months.
Nevtec Recommendation
- Immediately update to v8.8.9 or later
- Enforce certificate-based update validation across dev tools
- Review developer endpoints for anomalous Notepad++ update traffic
2. New Windows Malware Uses Pulsar RAT for Live Chats with Victims
A new malware strain combining Pulsar RAT and Stealerv37 injects itself into explorer.exe entirely in-memory to evade antivirus.
The most disturbing feature: attackers can open a live chat window on the victim’s PC while stealing data.
Capabilities
- Webcam & microphone access
- Crypto wallet hijacking
- Credential theft (browsers, VPNs, gaming apps)
- Exfiltration via Discord & Telegram
- Persistence watchdog
- AV/Task Manager evasion
Nevtec Recommendation
- Enable PowerShell Constrained Language Mode
- Deploy EDR with memory scanning
- Hunt for Donut loader patterns and anomalous explorer.exe injection
- Block Discord/Telegram exfiltration channels when possible
3. Critical 1‑Click RCE – OpenClaw (formerly Moltbot) CVE‑2026‑25253
A devastating 1‑click remote code execution flaw allows attackers to hijack OpenClaw AI agents, bypass localhost protections, and execute arbitrary commands on the host machine.
What’s exploited
- Unsanitized gatewayUrl parameters
- Auth token leakage via WebSocket handshake
- Missing Cross-Site WebSocket Origin validation
Nevtec Recommendation
- Upgrade immediately beyond v2026.1.24-1
- Rotate all auth tokens
- Restrict agent system permissions
- Review your AI agent architecture for unnecessary OS privileges
Strategy & Defensive Tactics
4. Google Disrupts the World’s Largest Residential Proxy Network (IPIDEA)
Google disrupted IPIDEA’s massive residential proxy service used by over 550 threat groups weekly.
Nevtec Recommendation
- Block IPIDEA-associated domains
- Monitor traffic for proxy-like patterns
- Audit bandwidth-monetizing mobile apps in corporate BYOD programs
5. Your Phone’s GPS Can Be Queried by Carriers Without Consent
Carriers can silently request precise GPS from any modern phone using low-level baseband protocols (RRLP/LPP); bypassing OS controls, permissions, and VPNs.
Nevtec Recommendation
- For sensitive staff: issue devices with iPhone 16e + C1 modem
- Educate execs that “location permissions” ≠ true privacy
- Review mobile threat defense posture
6. macOS Hardening Series (New)
Security expert Gabriel Biondo releases a pragmatic, layered macOS hardening framework covering DNS filtering, browser compartments, MFA, passkeys, and more.
Nevtec Recommendation
- Apply layered hardening rather than individual point fixes
- Prioritize DNS control + credential security
Strengthen Your Security Posture Today
Book a Free 30-Minute Threat Exposure Assessment with Nevtec
We’ll review your environment for:
✓ Malware/memory attack exposure
✓ AI agent security risks
✓ Shadow IT & SaaS sprawl
✓ Mobile/GPS privacy weaknesses
✓ OT/ICS monitoring gaps