A curated dispatch from GajShield

The GajShield Gazette

Lead story

Hackers abuse Notepad++ plugins to stealthily install malware

The abuse of Notepad++ plugins to install malware highlights how attackers are increasingly hiding inside trusted software workflows instead of relying only on obvious malicious executables.Notepad++ is a widely used text and code editor, especially among developers, admin…

Also today
In brief

New Dolphin X malware uses AI to rank high-value targets

The Dolphin X malware campaign shows how attackers are beginning to use AI not only to write malware or phishing content, but also to prior…

Jul 24, 2026

Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers

The campaign weaponizing GitHub Actions runners highlights how CI/CD infrastructure can be abused as attack infrastructure when repositorie…

Jul 23, 2026

Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs

The RefluXFS Linux flaw highlights why local privilege-escalation vulnerabilities in the kernel remain a serious enterprise risk, even when…

Jul 23, 2026

Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access

The actively exploited Check Point SmartConsole vulnerability highlights the serious risk of compromise in security management platforms. S…

Jul 23, 2026

Ubuntu snap-confine Flaw Could Give Local Users Root on Default Desktop Installs

The Ubuntu snap-confine vulnerability highlights why local privilege-escalation flaws should never be treated as low priority simply becaus…

Jul 23, 2026

Adobe Chrome extension flaw let sites access private WhatsApp chats

The Adobe Acrobat Chrome extension flaw highlights a serious privacy risk created when browser extensions are given deep access to web page…

Jul 22, 2026

Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication

The active exploitation of the Windmill vulnerability highlights the serious risk created when automation platforms expose server-side file…

Jul 22, 2026

CISA orders urgent action on actively exploited Langflow RCE flaw

CISA’s order to urgently patch the actively exploited Langflow RCE flaw highlights a growing risk around AI workflow and agent-building pla…

Jul 22, 2026

Chick-fil-A discloses data breach after credential stuffing attacks

The Chick-fil-A data breach is another reminder that credential stuffing remains one of the most reliable ways attackers compromise custome…

Jul 22, 2026

Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents

The Microsoft Azure DevOps MCP flaw highlights a serious risk in AI-assisted software development: hidden instructions inside normal develo…

Jul 22, 2026

Trojanized Newtonsoft.Json Fork Hides Game-Rigging Code in a Working Library

The trojanized Newtonsoft.Json fork campaign highlights how attackers are abusing developer trust, fake coding tests, and open-source famil…

Jul 22, 2026