Toggle light / dark theme

Get the latest international news and world events from around the world.

Log in for authorized contributors

ClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 Infrastructure

The cybersecurity company described the activity as part of a broader pattern of attacks that employ trusted services and large language model (LLM) shared chats to serve fake installation instructions, while bypassing browser warnings, URL inspection, and Safe Browsing heuristics.

In a report published last month, Microsoft said it observed a macOS ClickFix campaign propagating MacSync and Atomic Stealer using a cluster of no less than 250 look-alike domains.

“The campaign evolved from broadly serving ClickFix lures to using a server-side browser-fingerprinting gate that shows the lure primarily to visitors whose environment appears consistent with a genuine macOS browser,” it said. “This cloaking limits visibility for crawlers, sandboxes, and some automated analysis workflows.”

Microsoft: September updates break File History backup feature

Microsoft warned that the built-in File History backup feature in Windows may stop working on some systems after installing the September 2026 security updates.

File History (introduced in Windows 8 and replaced by Windows Backup, which backs up data to OneDrive) automatically saves copies that let users recover accidentally deleted or damaged files using an older version from hours, days, or weeks ago.

By default, File History backs up all folders under the user’s account profile (Documents, Music, Pictures, Videos, and Desktop) to an external hard drive, such as a USB flash drive, or a network storage location (NAS).

WordPress Click2Shell flaw lets hackers execute PHP on the server

Technical details and a proof-of-concept exploit have been published for a new WordPress cross-site request forgery (CSRF) vulnerability dubbed ‘Click2Shell’ that affects the platform’s Core component.

The security problem does not have an official identifier but was addressed last week with the release of WordPress version 7.1.1.

It is a pre-authenticated remote code execution chain that allows an attacker to install any theme in the official WordPress.org catalog and run an arbitrary PHP file.

Microsoft to retire Microsoft 365 Companion apps in December

Microsoft announced that it will retire the Calendar, People, and Files Microsoft 365 companion apps on December 16 and urged admins to remove them from managed devices in their organization.

This follows Microsoft’s October 2025 announcement that it will begin automatically installing them on all Windows 11 enterprise devices with the Microsoft 365 desktop client apps by the end of December 2025.

The Microsoft 365 companion apps integrate Copilot for contextual AI assistance and can help locate people within the organization, access Microsoft 365 and locally stored files, and manage one’s schedule using the Microsoft 365 calendar from the Windows 11 taskbar.

Microsoft fixes broken Excel copy and paste for all Office users

Microsoft has fixed a known issue that causes copy-and-paste failures for Excel users after installing the September 2026 security updates.

The bug was confirmed following a wave of customer reports on Reddit and the Microsoft Q&A forums that this month’s updates (including the KB5002914 security update) break copy-and-paste, autofill, and formula dragging in Excel.

“In Microsoft Excel 2024, 2021, 2019, and 2016, as well as Excel Online in Office Online Server, the paste operation might fail silently,” Microsoft explains in a support document updated on Friday.

Microsoft reminds admins to migrate Entra ID users to passkeys

Microsoft has reminded administrators to migrate Entra ID users to phishing-resistant methods, such as passkeys, to avoid sign-in disruptions after it retires SMS first-factor sign-in starting in February 2027.

Admins also have alternatives, including QR code authentication, FIDO2 security keys, and other Entra ID-supported authentication methods.

Before this date, organizations should ensure all users use a phishing-resistant method because they will no longer be able to use SMS or voice to complete multifactor authentication and sign in to their accounts.

Solar system built its first bodies from fire, not ice

Iron meteorites reveal the solar system’s earliest planetesimals were up to 92% heat-forged chondrules, not icy dust. [ https://www.labroots.com/trending/space/31088/solar-system-b…fire-ice-2](https://www.labroots.com/trending/space/31088/solar-system-b…fire-ice-2)


What processes are responsible for the first planets in our solar system forming? This is what a recent study published in Nature Astronomy hopes to address as a team of scientists from the United States and Germany investigated the complex geological processes that formed the first planetesimals, or young planets, in our early solar system. This study has the potential to help scientists better understand the formation and evolution of the solar system’s first planets and what this could mean for finding life beyond Earth.

For the study, the researchers conducted a series of geochemical analyses on iron meteorites to ascertain the geochemical composition of their original state billions of years ago, specifically the silicate (volcanic) rock called chondrules that comprise space rocks. This is because the rocks have melted and eroded so much over time, so the researchers have to examine radioactive isotopes to ascertain the composition of the parent body the meteorites broke away from.

The primary motivation behind the study was to fill a longstanding knowledge gap regarding how the first planets, also called planetesimals, formed and evolved. In the end, the researchers found that the first planetesimals were formed from hot impacts, as opposed to longstanding hypotheses that they formed from icy materials.

Chinese researchers plot path to 3-nm chips using older lithography tools

Chinese researchers have made early strides in pushing semiconductor processing nodes below 3-nm using older lithography technology, as more advanced extreme ultraviolet lithography (EUV) tools from ASML remain blocked under US sanctions.

The breakthrough marks the latest progress in China’s drive to chart an alternative path to advanced chipmaking amid US export restrictions. Under current export control rules, Dutch equipment giant ASML is barred from selling its state-of-the-art EUV machines – essential for producing chips below the 7-nm node – to Chinese clients.

In the latest development, state-backed Chinese Academy of Sciences (CAS) has established a preliminary gate-all-around (GAA) device development path using the less advanced deep ultraviolet (DUV) lithography, Taiwanese media Digitimes reported on Thursday, citing a speech by Ye Tianchun, a veteran from the academy’s Institute of Microelectronics (IMECAS).

/* */