CVE-2026-20841
Domains:
vercel[.]app
Hashes:
f44c2169250f86c8b42ec74616eacb08310ccc81ca9612eb68d23dc8715d7370
Get tomorrow's brief in your inbox
Collected: 2026-02-11 11:12 PM EST Generated by: Claude Code (Opus 4.6)
Notepad++ Supply Chain Compromise by Lotus Blossom (State-Sponsored)
Between June and December 2025, the state-sponsored threat group Lotus Blossom compromised the official Notepad++ hosting infrastructure, hijacking the update server to deliver malicious NSIS installers to targeted users. Two infection chains were observed: DLL sideloading via a legitimate Bitdefender component (BluetoothService.exe loading log.dll) to deploy the Chrysalis backdoor, and a Lua script injection variant delivering Cobalt Strike Beacon. Targets span government, telecom, energy, financial, manufacturing, cloud hosting, and software development sectors across Southeast Asia, South America, the U.S., and Europe.
Notepad Markdown RCE - CVE-2026-20841 (CVSS 8.8)
Microsoft's Markdown rendering feature in Notepad contains a remote code execution vulnerability. An attacker can embed a malicious link in a Markdown file; when a user opens the file in Notepad and clicks the link, it launches unverified protocols that load and execute files with the user's permissions. Patched in the February 2026 Patch Tuesday update. No known exploitation in the wild.
.md files..md attachment could compromise a workstation.Microsoft Outlook Add-in (AgreeTo) Hijacked - 4,000+ Credentials Stolen
An abandoned Outlook add-in called AgreeTo, listed on Microsoft's official Office Add-in Store since December 2022, was hijacked by a threat actor who claimed its orphaned Vercel-hosted URL (outlook-one.vercel[.]app). The attacker deployed a fake Microsoft sign-in page that harvested over 4,000 Microsoft account credentials, credit card numbers, and banking security answers. Data was exfiltrated via Telegram bot API. The add-in retained ReadWriteItem permissions, giving it access to read and modify user emails. Microsoft has now removed the add-in. This is the first malware found on the official Microsoft Marketplace and the first malicious Outlook add-in detected in the wild.
Chipmaker Patch Tuesday: 80+ Vulnerabilities from Intel and AMD
Intel and AMD published over two dozen advisories covering more than 80 vulnerabilities across their product lines as part of their February 2026 coordinated disclosures.
Microsoft Secure Boot Certificate Refresh - June 2026
The current Windows Secure Boot certificates, in service for over 15 years, will expire. Microsoft plans to roll out new certificates in June 2026.
LummaStealer Resurges via CastleLoader and ClickFix Campaigns (Reported by 3 Sources)
LummaStealer (LummaC2) has scaled significantly between December 2025 and January 2026 after partially recovering from the May 2025 law enforcement takedown of 2,300 domains. The current delivery mechanism uses CastleLoader, a heavily obfuscated AutoIT/Python-based loader that executes LummaStealer entirely in memory. Distribution relies on the ClickFix technique: fake CAPTCHA pages trick users into running a malicious PowerShell command already placed in their clipboard. CastleLoader performs sandbox detection, adjusts persistence paths based on detected security products, and uses a deliberate failed DNS lookup as a C2 artifact. A separate campaign uses RenEngine, a modified Ren'Py game launcher, to deliver HijackLoader and ultimately ACR Stealer or LummaStealer via pirated game downloads.
dbghelp.dll.Payroll Redirect Attacks via Help Desk Social Engineering
Binary Defense documented a campaign where attackers compromise shared mailbox credentials, use them to identify employees, then call the help desk impersonating a locked-out physician to get password and MFA resets. After gaining access, the attacker authenticates via the organization's own VDI (bypassing security detections as a trusted internal user), registers new MFA devices, and redirects payroll direct deposits in Workday. Microsoft separately documented a variant using adversary-in-the-middle phishing to steal MFA codes and compromise Workday profiles at universities.
JokerOTP MFA Bypass Tool - Third Arrest
Dutch police arrested a 21-year-old suspected of selling access to JokerOTP, a phishing-as-a-service platform that intercepts one-time passwords via automated phone calls. The service caused $10M+ in losses across 28,000 attacks in 13 countries over two years, targeting PayPal, Venmo, Coinbase, Amazon, and Apple accounts. Three suspects have now been arrested. Dozens of Dutch buyers have been identified and will be prosecuted.
WSL Being Used as a Malware Attack Vector
SANS ISC documented a malware sample (OtterCookie socketScript module 3, SHA256: f44c2169250f86c8b42ec74616eacb08310ccc81ca9612eb68d23dc8715d7370) that actively checks for Windows Subsystem for Linux and uses it as an attack surface. The JavaScript-based Cryxos trojan/infostealer detects WSL via WSL_DISTRO_NAME env variable and /proc/version, then accesses the Windows filesystem through /mnt/ to steal browser data. WSL functions similarly to a LOLBIN: it's a Microsoft-shipped feature that allows execution of Linux binaries, and attackers can drop tools into the WSL rootfs via \\wsl$ and execute them from Windows.
dism /online /disable-feature /featurename:Microsoft-Windows-Subsystem-Linux. Monitor for wsl.exe execution in environments where it's not expected. Add \\wsl$ path monitoring to EDR rules.Windows 11 26H1 Released (Snapdragon X2 Only), .NET 3.5 Removed
Windows 11 26H1 is available exclusively for new Qualcomm Snapdragon X2 hardware. Microsoft explicitly states versions 24H2 and 25H2 remain the recommended enterprise releases. .NET Framework 3.5 has been removed as a Windows Feature on Demand in 26H1; it must now be installed via standalone installer. .NET 3.5 end of support is January 9, 2029.
SSH Worm Compromises Systems in 4 Seconds
SANS ISC captured a complete SSH worm attack from brute-force to full botnet enrollment in under 4 seconds. The worm targets default Raspberry Pi credentials (pi/raspberry variants), uploads a 4.7KB bash script, establishes persistence, kills competing malware, joins IRC C2 channels with cryptographically signed command verification, and begins lateral movement using Zmap and sshpass to scan 100,000 random IPs for SSH. The attack originated from an already-compromised Raspberry Pi (SSH client string: SSH-2.0-OpenSSH_8.4p1 Raspbian-5+b1).
Kimwolf IoT Botnet Disrupts I2P Anonymity Network
The Kimwolf botnet, which has infected millions of IoT devices since late 2025, attempted to join 700,000 infected devices as nodes on the I2P anonymity network to create a takedown-resistant C2 infrastructure. This Sybil attack overwhelmed I2P's 15,000-20,000 legitimate nodes, causing widespread service disruption. The botnet operators are also experimenting with Tor as backup C2.
287 Chrome Extensions Exfiltrating Browsing History (37M Installs)
A security researcher identified 287 Chrome extensions with a combined 37.4 million installations that exfiltrate browsing history to data brokers including Similarweb, Semrush, Alibaba Group, and ByteDance. The extensions present as harmless tools while requesting access to browsing history. An automated testing pipeline confirmed data leakage to 30+ collection entities.
history or webNavigation permissions unless justified. Use Chrome Enterprise's ExtensionSettings policy.SSHStalker Botnet Targets Linux via IRC C2
A new botnet called SSHStalker uses IRC for command and control and targets Linux systems via legacy kernel exploits. The toolset includes log cleaners (utmp/wtmp/lastlog tampering) and rootkit-class artifacts.
Microsoft Warns of AI Recommendation Poisoning
Microsoft's Defender team documented "AI Recommendation Poisoning," where businesses embed hidden prompts in "Summarize with AI" buttons and links on websites to manipulate AI model outputs. They identified 50+ unique malicious prompts from 31 companies across 14 industries. This extends to "AI Memory Poisoning," where injected instructions persist across future AI responses.
Supply chain attacks through trusted distribution channels dominate today's brief: Notepad++ update infrastructure hijacked by state actors, an Outlook add-in weaponized via abandoned domain takeover on the official Microsoft Marketplace, and 287 Chrome extensions harvesting data at scale. All three exploit the gap between initial platform approval and ongoing content monitoring. Infostealers (LummaStealer, CastleLoader, OtterCookie, ACR Stealer) continue to rebuild and diversify delivery methods after law enforcement disruptions, with ClickFix social engineering proving especially effective at getting users to infect their own machines. The payroll redirect and JokerOTP cases reinforce that identity verification processes, not just technical controls, remain the weakest link.
Carolina Clear Tech, LLC - carolinacleartech.com