Follow the latest coverage, related explainers and connected technology stories.
A malicious campaign exploited custom versions of ChatGPT to direct users to fake pages asking them to run PowerShell commands, leading to the deployment of a remote-access Trojan. Huntress observed at least 40 connections to the malicious page, confirming two infections linked to a custom GPT.
The domain third-party.com, used for years as a default address in programming documentation and code examples, has begun displaying a fake Cloudflare page that pressures Windows users into executing malicious PowerShell commands. There are no confirmed reports that the attack succeeded, but the domain’s prevalence in public repositories and projects makes it a potential danger for code copied verbatim.
Microsoft is investigating reports that update KB5124008 causes some Windows 11 devices to lose their secure communication channel with Active Directory, preventing sign-in with valid credentials. The company has not yet confirmed the root cause or published an official fix.