Klingon Elsa Performs ‘Let It Go’ In Her Native Language

Captain’s log, Stardate 43957.2: Klingon Elsa performed ‘Let It Go’ in her native language in the Ten Forward lounge tonight. I think I’m in love. End log. Data, bring me some tea! Earl Grey, iced. This is a video of Princess Jackie from Seattle-based party character provider The Painted Palace dressed as a Klingon Elsa performing a full length cover of ‘Let It Go’ in Klingon at Emerald City Comic Con. The performance was so moving it won the talent show. And I think we can all hear why — it blows the original out of the water. If the original was a cereal box kazoo, this was a Stradivarius. FULL DISCLOSURE: I did have to watch the video on mute, but I could tell by the way her mouth was moving and the scowling that this sounded like angels.

@emeraldcitycomicco � Our fans are so talented! #frozen #startrek #cosplaytiktok #cosplay #eccc ♬ original sound – ECCC

Moltbook, the AI social network, exposed human credentials due to vibe-coded security flaw

Moltbook bills itself as a social network for AI agents. That’s a wacky enough concept in the first place, but the site apparently exposed the credentials for thousands of its human users. The flaw was discovered by cybersecurity firm Wiz, and its team assisted Moltbook with addressing the vulnerability.

The issue appears to be the result of the entire Reddit-style forum being vibe-coded; Moltbook’s human founder posted a few days ago on X that he “didn’t write one line of code” for the platform and instead directed an AI assistant to create the whole setup. 

According to the blog post from Wiz analyzing the issue, Moltbook had a vulnerability that allowed for “1.5 million API authentication tokens, 35,000 email addresses and private messages between agents” to be fully read and accessed. Wiz also found that the vulnerability could let unauthenticated human users edit live Moltbook posts. In other words, there is no way to verify whether a Moltbook post was authored by an AI agent or a human user posing as one. “The revolutionary AI social network was largely humans operating fleets of bots,” the company’s analysis concluded. 

So ends another cautionary tale reminding us that just because AI can do a task doesn’t mean it’ll do it correctly.

This article originally appeared on Engadget at https://www.engadget.com/ai/moltbook-the-ai-social-network-exposed-human-credentials-due-to-vibe-coded-security-flaw-230324567.html?src=rss

Looking back at Catacomb 3D, the game that led to Wolfenstein 3D

If you know anything about the history of id Software, you know how 1992’s Wolfenstein 3D helped establish the company’s leadership in the burgeoning first-person shooter genre, leading directly to subsequent hits like Doom and Quake. But only the serious id Software nerds remember Catacomb 3D, id’s first-person adventure game that directly preceded and inspired work on Wolfenstein 3D.

Now, nearly 35 years after Catacomb 3D‘s initial release, id co-founder John Romero brought the company’s founding members together for an informative retrospective video on the creation of the oft-forgotten game. But the pioneering game—which included mouse support, color-coded keys, and shooting walls to find secrets—almost ended up being a gimmicky dead end for the company.

id Software’s founders look back at an oft-forgotten piece of gaming history

Texture maps and “undo” animation

Catacomb 3D was a follow-up to id’s earlier Catacomb, which was a simplified clone of the popular arcade hit Gauntlet. As such, the 3D game still has some of that “quarter eater” mentality that was not very fashionable in PC gaming at the time, as John Carmack remembered.

Read full article

Comments

Feds Skipping Infosec Industry’s Biggest Conference This Year

An anonymous reader shares a report: The US Cybersecurity and Infrastructure Security Agency won’t attend the annual RSA Conference in March, an agency spokesperson confirmed to The Register. Sessions involving speakers from the FBI and National Security Agency (NSA) have also disappeared from the agenda.

“Since the beginning of this administration, CISA has made significant progress in returning to our statutory, core mission and focusing on President Trump’s policies for maximum security for all Americans,” CISA spokesperson Marci McCarthy told us. “CISA has reviewed and determined that we will not participate in the RSA Conference since we regularly review all stakeholder engagements, to ensure maximum impact and good stewardship of taxpayer dollars.”

McCarthy declined to comment on whether the decision had anything to do with former CISA director Jen Easterly being named chief executive of RSAC last week. Easterly, who was appointed to lead America’s top cyber-defense agency under the Biden administration, joined her predecessor and CISA’s first-ever director Chris Krebs in President Trump’s line of fire back in July.


Read more of this story at Slashdot.

Streaming service Crunchyroll raises prices weeks after killing its free tier

Crunchyroll is one of the most popular streaming platforms for anime viewers. Over the past six years, the service has raised prices for fans, and today, it announced that it’s increasing monthly subscription prices by up to 20 percent.

Sony bought Crunchyroll from AT&T in 2020. At the time, Crunchyroll had 3 million paid subscribers and an additional 197 million users with free accounts, which let people watch a limited number of titles with commercials. At the time, Crunchyroll monthly subscription tiers cost $8, $10, or $15.

After its acquisition by Sony, like many large technology companies that buy a smaller, beloved product, the company made controversial changes. The Tokyo-based company folded rival Funimation into Crunchyroll; Sony shut down Funimation, which it bought in 2017, in April 2024.

Read full article

Comments

Elon Musk’s SpaceX has acquired his AI company, xAI

Elon Musk’s SpaceX has acquired Musk’s xAI, the companies announced. The merger will “form the most ambitious, vertically-integrated innovation engine on (and off) Earth, with AI, rockets, space-based internet, direct-to-mobile device communications and the world’s foremost real-time information and free speech platform,” Musk wrote in an update.

The AI company that right now is best known for its CSAM-generating chatbot might seem like a strange fit for a rocket company. But SpaceX is key to Musk’s latest scheme to build AI data centers in space. In his update, Musk wrote that “global electricity demand for AI simply cannot be met with terrestrial solutions” and that moving the resource-intensive operations to space is “the only logical solution.” SpaceX just days ago filed an application with the FCC to create an “orbital data center” by launching a million new satellites.

Musk also claimed that, eventually, space-based data centers will enable other advancements in space travel. “The capabilities we unlock by making space-based data centers a reality will fund and enable self-growing bases on the Moon, an entire civilization on Mars and ultimately expansion to the Universe.” Notably, it’s not the first time Musk has made lofty claims about Mars. He predicted in 2017 that SpaceX would send crewed missions to Mars by 2024.

This also isn’t the first time Musk has acquired one of his own companies. He merged xAI and X last year, which means SpaceX now owns the social network Musk bought in 2022. And he recently announced that Tesla was investing $2 billion into xAI. SpaceX is planning to go public later this year in an initial public offering (IPO) that could value the company at more than $1 trillion, according to Bloomberg, which notes that SpaceX has also “discussed a possible merger with Tesla.”

This article originally appeared on Engadget at https://www.engadget.com/ai/elon-musks-spacex-has-acquired-his-ai-company-xai-221617040.html?src=rss

Ubisoft fires employee who publicly criticized its RTO plan

Ubisoft continues to raise eyebrows around how it is treating employees as it attempts a business overhaul. David Michaud-Cromp, a level design team lead at Ubisoft Montreal, said last week that he was suspended for three days without pay after voicing opposition to the company’s return to office mandate. Today, Michaud-Cromp posted on LinkedIn that he has been fired. “I was terminated by Ubisoft, effective immediately,” he wrote. “This was not my decision.”

A spokesperson for Ubisoft gave Kotaku the following statement regarding Michaud-Cromp’s dismissal: “Sharing feedback or opinions respectfully does not lead to a dismissal. We have a clear Code of Conduct that outlines our shared expectations for working together safely and respectfully, which employees review and sign each year. When that is breached, our established procedures apply, including an escalation of measures depending on the nature, severity, and repetition of the breach.” We’ve reached out to the company for additional confirmation and comment. 

This is the latest in a sequence of bad press Ubisoft has faced regarding its workforce. Shortly after many employees at Ubisoft Halifax unionized, the parent company shut down the studio. In announcing the closure, Ubisoft said the move was part of a broader cost-cutting endeavor across its operations; it shut down a support studio and cut more jobs later in January, with even more layoffs proposed. Most recently, unions representing other Ubisoft workers called for a three-day strike in response to the “penny-pinching and worsening our working conditions” they alleged of the company’s management.

All these issues could all be coincidental timing. But if so, they’re coincidences that don’t reflect favorably on Ubisoft.

This article originally appeared on Engadget at https://www.engadget.com/gaming/ubisoft-fires-employee-who-publicly-criticized-its-rto-plan-220913747.html?src=rss

Firefox Will Soon Let You Disable All Current (and Future) AI Features

Since ChatGPT kicked off the generative AI revolution in 2022, it seems like every company under the sun has tried to stuff AI features into their products in one way or another. Sometimes, these features can be useful; often, they’re not, only serving as proof these companies are “keeping up with the times.” Can you even say you’re a tech company if you aren’t all-in on AI in 2026?

There’s nothing wrong with companies offering AI features to users, so long as they also offer easy ways to disable them. Some customers don’t want AI in their day-to-day products, but, anecdotally, I know many do not. Give us an off switch though, and it’s all good. The issue is when these features are not only offered, they’re made mandatory. Unfortunately, that’s the road many companies seem to be taking.

Perhaps that’s where some of the frustration originated last year, when Mozilla’s new CEO Anthony Enzor-Demeo first announced that Firefox would “evolve into a modern AI browser” in the near future. An open letter, written by a Redditor critical of Enzor-Demeo’s statement, received over 5,000 upvotes on the Firefox subreddit from users concerned that AI features would negatively impact the browser. Interestingly, Enzor-Demeo responded to the thread himself, and assured users that the company would offer “a clear way” to disable AI features, including a dedicated kill switch to keep them all turned off. It seems he was as good as his word.

Firefox’s AI features are easy to opt out of

On Monday, Mozilla announced that new AI controls are coming to Firefox, starting with Firefox 148. This version, which drops Feb. 24, sports a brand-new AI controls section in the settings panel on the desktop browser. (You’ll find it in the between “Sync” and “AI controls.”) From here, you’ll be able to block all current and future AI features, and cherry pick which features you want to use—if any.

What AI features Firefox offers

Firefox 148 launches with these five AI features, which you can choose to enable to disable:

  • Translations: Translates web pages into your target language.

  • Alt text in PDFs: Adds accessibility descriptions to images attached to PDFs.

  • AI-enhanced tab grouping: Suggests related tabs and group names for series of tabs.

  • Link previews: Shows key points before opening a link.

  • AI chatbot in the sidebar: Firefox is getting its own AI chatbot, though users can choose from existing chatbots like Claude, ChatGPT, Copilot, Gemini, and Le Chat Mistral.

If you want absolutely nothing to do with AI when browsing the web with Firefox, you can use the “Block AI enhancements” toggle. Once activated, not only will these features not appear, but Firefox will block any pop-ups or alerts pushing you to try existing or future AI features.

Any Firefox users who aren’t keen on AI features will want to check out this new controls menu starting Feb. 24—though there are certainly more egregious AI features out there. Translations can be convenient, as can link previews. But I know I’d never want a chatbot in the sidebar of my browser. If I used Firefox as my main browser, I would definitely disable at least that feature, if not all of them.

SpaceX acquires xAI, plans to launch a massive satellite constellation to power it

SpaceX has formally acquired another one of Elon Musk’s companies, xAi, the space company announced on Monday afternoon.

“SpaceX has acquired xAI to form the most ambitious, vertically-integrated innovation engine on (and off) Earth, with AI, rockets, space-based internet, direct-to-mobile device communications and the world’s foremost real-time information and free speech platform,” the company said. “This marks not just the next chapter, but the next book in SpaceX and xAI’s mission: scaling to make a sentient sun to understand the Universe and extend the light of consciousness to the stars!”

The merging of what is arguably Musk’s most successful company, SpaceX, with the more speculative xAI venture is a risk. Founded in 2023, xAI’s main products are the generative AI chatbot, Grok, and the social media site X, formerly known as Twitter. The company aims to compete with OpenAI and other artificial intelligence firms. However, Grok has been controversial, including the sexualization of women and children through AI-generated images, as has Musk’s management of Twitter.

Read full article

Comments

SpaceX acquires xAI, plans 1 million satellite constellation to power it

SpaceX has formally acquired another of Elon Musk’s companies, xAi, the space company announced on Monday afternoon.

“SpaceX has acquired xAI to form the most ambitious, vertically-integrated innovation engine on (and off) Earth, with AI, rockets, space-based internet, direct-to-mobile device communications and the world’s foremost real-time information and free speech platform,” the company said. “This marks not just the next chapter, but the next book in SpaceX and xAI’s mission: scaling to make a sentient sun to understand the Universe and extend the light of consciousness to the stars!”

The merging of what is arguably Musk’s most successful company, SpaceX, with the more speculative xAI venture is a risk. But Musk strongly believes that artificial intelligence is central to humanity’s future and wants to be among those leading in its development.

Read full article

Comments

Russian drones use Starlink, but Ukraine has plan to block their Internet access

Ukraine and SpaceX say they recently collaborated to stop strikes by Russian drones using Starlink and will soon block all unregistered use of Starlink terminals in an attempt to stop Russia’s military from using the satellite broadband network over Ukraine territory.

Ukrainians will soon be required to register their Starlink terminals to get on a whitelist. After that, “only verified and registered terminals will be allowed to operate in the country. All others will be disconnected,” the Ukraine Ministry of Defense said in a press release today.

Ukraine Minister of Defense Mykhailo Fedorov “emphasized that the only technical solution to counter this threat is to introduce a ‘whitelist’ and authorize all terminals,” according to the ministry. “This is a necessary step by the Government to save Ukrainian lives and protect critical energy infrastructure,” Fedorov said.

Read full article

Comments

Intel’s Xeon 600 Brings Granite Rapids Muscle To High-End Desktops

Intel’s Xeon 600 Brings Granite Rapids Muscle To High-End Desktops
Some folks act as if Intel and AMD have killed off the “high-end desktop” or HEDT market, but that’s never really been the case. Instead, what happened is that mainstream desktops went from a maximum of four cores to 16  – 24 cores basically overnight, propelling HEDT systems out of reach for most enthusiasts. If you want a processor with

1994 Sega Saturn Pulls Off Real-Time Ray Tracing In Stunning Homebrew Demo

1994 Sega Saturn Pulls Off Real-Time Ray Tracing In Stunning Homebrew Demo
The Saturn was Sega’s fifth generation fully-3D console, launched in 1994 to compete with the PlayStation 1 and Nintendo 64—and all these years later, homebrew developer XL2 has managed to create a functioning ray tracing demo on the hardware. The first video of the demo is a single room without any static lighting sources and all ray tracing

Notepad++ Confirms Hackers Hijacked Update Infrastructure To Push Malware

Notepad++ Confirms Hackers Hijacked Update Infrastructure To Push Malware
Notepad++ reported that its built-in auto-update feature had been hijacked by Chinese state-sponsored hackers from June to September of 2025, and the credentials gathered by the bas actors enabled further exploits until December 2nd, 2025. In an effort to thwart similar issues moving forward, Notepad++ has moved to a hosting provider “with

Everything We Know About Apple’s Rumored Folding iPhone (and iPad)

Now that Apple has finally brought OLED to the iPad in the form of the most recent iPad Pro, its next goal seems to be foldables. The big news on the horizon is the foldable iPhone, which The Information first reported on way back in 2024, saying the company hopes to have a foldable iPhone on the market in 2026. But according to Bloomberg’s Mark Gurman, the iPhone maker is also working towards releasing a foldable iPad, originally rumored to be coming by 2028. Since those reports, others have come forward with supposed design leaks and potential release dates, and now we’ve got a pretty good idea of what Apple’s first foldable devices might look like.

The foldable iPhone’s design, release window, and price

Way back when the iPhone Fold (or whatever Apple will call it) was first being discussed, the Wall Street Journal said it’ll have a bigger screen than the iPhone 16 Pro Max. Since then, others had speculated that it might look like two iPhone Airs side-by-side. But now, we’ve got a much better idea about the specifics, including a price.

In a new post on Chinese social media site Weibo today, leaker Instant Digital laid out several key details about the iPhone Fold’s design. Previously, Instant Digital had leaked details about the iPhone 17, which all turned out to be correct. It’s unclear what these leaks’ sources are, but as far as rumors go, Instant Digital has a decent track record.

Via a machine translation, the post says that the iPhone Fold will feature an “elegant internal stacking structure” and will be thin enough to “shock the industry.” More concretely, the post also said that all buttons are being moved to the right side of the phone, as that’s where the phone’s motherboard will be. That means the volume buttons would be on the top-right of the device, while the camera and power buttons will be on the right side of the device. If that sounds cramped to you, it’s worth noting that Samsung’s Galaxy Fold Z 7 also only has buttons on the right side of the device.

Speaking of Samsung’s Galaxy phones, people who dislike the iPhone’s large Dynamic Island should also be happy, as the leaks say the selfie camera is changing to a small pinhole design more akin to what you’d find on Android.

As for how the phone will actually function, internal specs are still a bit up in the air, although yet another leaker named Fixed Focus Digital (no relation) alleged that the iPhone Fold will have a 5,500 mAh battery, which matches a previous rumor from last fall. That’s a bit larger than any iPhone so far, and if the rumor pans out, shows that Apple will use the phone’s extra internal space well.

All of this is, of course, in service of a bigger screen, which we can also nail down a bit now. The most recent leaks, coming from South Korean publication The Elec, say that the iPhone Fold’s outer display will be 5.38 inches and the inner display will be 7.58 inches. That makes the internal screen just a little over half-inch larger than the 6.9-inch iPhone 17 Pro Max display, although maybe the enhanced portability of folding part of that screen away will help supplement it a bit. For comparison, the Samsung Galaxy Z Fold 7’s screen is 8 inches.

In its report, The Elec also expressed concern that Apple might miss its 2026 release target. Analyst Ming-Chi Kuo split the difference, saying that the device is likely to be announced in 2026, but that “smooth shipments” may not come until 2027.

Regardless, when the phone does come, it’s expect to cost between $2,100 and $2,500, going by another leak from Instant Digital.

All of this helps us have a much better idea about what to expect, but there’s still plenty of time for changes to be made. For instance, a 2026 release would see the phone come out during an ongoing RAM crisis that could raise prices, although Kuo recently said that, at least for the iPhone 18 series, Apple plans to eat any extra costs rather than pass them on to the consumer.

An iPhone flip?

Even if it gets delayed to next year, the iPhone Fold’s release seems imminent. Much less certain is a potential successor, a clamshell iPhone Flip.

In his Power On newsletter, Bloomberg’s Mark Gurman said that Apple Labs is also now considering a smaller foldable device akin to the Samsung Galaxy Z Flip or Motorola Razr lines, which are essentially standard, candy bar-shaped phones that can fold once vertically to store away like makeup compacts.

“The product is far from guaranteed to reach the market,” writes the reporter, citing unnamed sources inside Apple. But Gurman says “Apple is betting that its first foldable iPhone will be successful enough to generate real demand” and that “customers will want additional shapes and sizes.”

This is our first time hearing that Apple is interested in additional foldable phones beyond one that opens horizontally like a book. On that note, Gurman also speculated that Apple might also make a larger foldable phone in the future, with a screen closer in size to Samsung’s Galaxy Z Fold 7. Although, unlike with the flip phone, this appears to simply be a prediction.

The foldable iPad faces a delay

Finally, speaking of larger foldable devices, Gurman has some bad news for iPad fans. While the reporter had previously covered a folding iPad with a rumored 18.8-inch display, following up on predictions from market research firm Omdia, it now seems to be behind schedule.

Earlier, Gurman had said the new iPad would be like “two iPad Pros side-by-side” and wouldn’t feature an external screen. While the expected design hasn’t changed, it seems Apple’s now run into some manufacturing issues. Now, instead of being projected for 2028, the foldable iPad seems more likely to come out in 2029.

Gurman says that’s because of “engineering challenges” with the device’s weight and display technology, so at least skeptics can breathe a sigh of relief that it isn’t due to supply chain issues. As such, pricing is likely to remain unaffected. Granted, the expected price is still likely to be on the high end—Gurman says you’ll likely have to pay around $3,000 for the device.

France might seek restrictions on VPN use in campaign to keep minors off social media

France may take additional steps to prevent minors from accessing social media platforms. As its government advances a proposed ban on social media use for anyone under age 15, some leaders are already looking to add further restrictions. During an appearance on public broadcast service Franceinfo, Minister Delegate for Artificial Intelligence and Digital Affairs Anne Le Hénanff said VPNs might be the next target. 

“If [this legislation] allows us to protect a very large majority of children, we will continue. And VPNs are the next topic on my list,” she said.

A virtual private network would potentially allow French citizens younger than 15 to circumnavigate the social media ban. We’ve already seen VPN’s experience a popularity spike in the UK last year after similar laws were passed over age-gating content. However, a VPN also offers benefits for online privacy, and introducing age verification requirements where your personal data must be submitted negates a large part of these services’ appeal. 

The French social media ban is still a work in progress. France’s National Assembly voted in favor of the restrictions last week with a result of 116-23, moving it ahead for discussion in the country’s Senate. While a single comment doesn’t mean that France will in fact ban VPNs for any demographic, it does point to the direction some of the country’s leaders want to take. Critics responded to Le Hénanff’s statements with worry that these attempts at protective measures were veering into an authoritarian direction. 

The actions in France echo several other legislative pushes around the world aimed at reducing children and teens’ access to social media and other potentially sensitive content online. The US had seen 25 state-level laws for age verification introduced in the past two years, which has created a new set of concerns around users’ privacy and personal data, particularly when there has been no attempt to standardize how that information will be collected or protected. When data breaches at large corporations are already all too common, it’s hard to trust that the individual sites and services that suddenly need to build an age verification process won’t be an easy target for hacks.

This article originally appeared on Engadget at https://www.engadget.com/cybersecurity/france-might-seek-restrictions-on-vpn-use-in-campaign-to-keep-minors-off-social-media-205308716.html?src=rss

Court orders restart of all US offshore wind construction

The Trump administration is no fan of renewable energy, but it reserves special ire for wind power. Trump himself has repeatedly made false statements about the cost of wind power, its use around the world, and its environmental impacts. That animosity was paired with an executive order that blocked all permitting for offshore wind and some land-based projects, an order that has since been thrown out by a court that ruled it arbitrary and capricious.

Not content to block all future developments, the administration has also gone after the five offshore wind projects currently under construction. After temporarily blocking two of them for reasons that were never fully elaborated, the Department of the Interior settled on a single justification for blocking turbine installation: a classified national security risk.

The response to that late-December announcement has been uniform: The companies building each of the projects sued the administration. As of Monday, every single one of them has achieved the same result: a temporary injunction that allows them to continue construction. This, despite the fact that the suits were filed in three different courts and heard by four different judges.

Read full article

Comments

Firefox will soon offer a way to block all of its generative AI features

Like practically every other tech company under the sun, Mozilla has been jamming generative AI features into its products. The organization has now acknowledged that not everyone wants things like plagiarism machines chatbots in the Firefox sidebar, so it’s giving you the option to turn off all of that. 

On February 24 (or earlier in Firefox Nightly builds), Mozilla will roll out Firefox 148, which will include an AI controls section in the desktop browser settings. From here, you’ll be able to block current and future generative AI features, or only enable select tools. 

At the jump, you’ll have the option to disable (or enable) chatbots in the sidebar, automated translations and alt text generation for PDFs. You’ll also be able to nix a tool called AI-enhanced tab grouping (which offers suggestions of related tabs and group names), as well as webpage previews that display “key points” before you actually click on a link. If you’d prefer to get rid of all of these — and for Firefox to not bother you with pop-ups and notifications about current and upcoming AI features — just make sure the “Block AI enhancements” toggle is on. 

Perhaps Mozilla has come to realize that, rather than having AI cruft soaking up resources and causing apps to bloat, what many people actually want is a fast, secure and streamlined web browser. At the very least, giving users a way to opt out of features they don’t want is a positive step. Now then, Google, about AI Overviews…

This article originally appeared on Engadget at https://www.engadget.com/ai/firefox-will-soon-offer-a-way-to-block-all-of-its-generative-ai-features-203132958.html?src=rss

Notepad++ users take note: It’s time to check if you’re hacked

Infrastructure delivering updates for Notepad++—a widely used text editor for Windows—was compromised for six months by suspected China-state hackers who used their control to deliver backdoored versions of the app to select targets, developers said Monday.

“I deeply apologize to all users affected by this hijacking,” the author of a post published to the official notepad-plus-plus.org site wrote Monday. The post said that the attack began last June with an “infrastructure-level compromise that allowed malicious actors to intercept and redirect update traffic destined for notepad-plus-plus.org.” The attackers, whom multiple investigators tied to the Chinese government, then selectively redirected certain targeted users to malicious update servers where they received backdoored updates. Notepad++ didn’t regain control of its infrastructure until December.

Hands-on keyboard hacking

Notepad++ said that officials with the unnamed provider hosting the update infrastructure consulted with incident responders and found that it remained compromised until September 2. Even then, the attackers maintained credentials to the internal services until December 2, a capability that allowed them to continue redirecting selected update traffic to malicious servers. The threat actor “specifically targeted Notepad++ domain with the goal of exploiting insufficient update verification controls that existed in older versions of Notepad++.” Event logs indicate that the hackers tried to re-exploit one of the weaknesses after it was fixed but that the attempt failed.

Read full article

Comments