‼️🚨 The official JDownloader website was breached, attackers swapped the Windows and Linux installers with malware for over a day before anyone noticed.
JDownloader is a popular download manager with millions of users on Windows, macOS, and Linux.
Timeline:
▪️ May 5, 23:55 UTC: attacker tests the method on a dummy page.
▪️ May 6, 00:01 UTC: real attack goes live. Alternative download links for Windows and Linux are replaced with malicious installers.
▪️ May 7: a Reddit user notices Windows SmartScreen flagging the installer with a strange publisher ("Zipline LLC", "The Water Team", "Peace Team") instead of "AppWork GmbH".
▪️ Hours later, the JDownloader dev team confirms the breach and takes the site offline.
How they got in: an unpatched vulnerability let attackers modify the website's access control list (ACL), give themselves edit rights, and swap the download links. No further details on the bug have been shared.
What's compromised:
▪️ Windows installer (alternative download links).
▪️ Linux shell installer (alternative download links).
What's safe:
▪️ macOS installers (still validly signed).
▪️ The core JDownloader.jar file.
▪️ Flatpak, Winget, and Snap packages (separate infra, sha256 checksums unchanged).
▪️ In-app auto-updates (separate servers, end-to-end signed).
If you downloaded JDownloader from the website between May 6 and May 7, treat your machine as compromised.
This is the third trusted-software website breach in recent weeks, after Daemon Tools and CPU-Z / HWMonitor.
No Cost EMI” in India is peak marketing comedy.
Bank charges interest. Seller calls it a “discount”. Customer feels smart. Everyone claps like it’s free money. 😂
Translation: “You are paying interest… but we renamed it so you won’t notice.”
🚨 HANTA “VIRUS” PANIC CAMPAIGN ALREADY LOOKS PRE-PLANNED 🚨
So let’s get this straight…
In 2024, Moderna quietly partners with Korea University on an mRNA-based Hantavirus vaccine…
AND buried in the research network tied to these “global health” initiatives is none other than Peter Hotez and longtime global pandemic players connected to the RIGHT Fund and neglected-disease programs.
Now suddenly the media starts whispering about “Hantavirus threats” again? 👀
Same script.
Same players.
Same fear cycle.
1️⃣ Identify a “future threat”
2️⃣ Build the vaccine platform first
3️⃣ Flood the media with panic headlines
4️⃣ Roll out emergency measures
5️⃣ Cash in on public fear
And remember… Hantavirus has existed for DECADES.
But NOW the mRNA machine is suddenly interested? 🤔
People are waking up to the pattern:
Problem → Panic → Pharmaceutical Product.
The real question is…
How long have they been preparing this narrative BEFORE the public ever heard a word about it? 🔥
❗️🚨 Microsoft Edge keeps every saved password in process memory as cleartext from the moment it launches. Microsoft's responsed when reported: "by design."
All of them. Including credentials for sites you won't open this session.
Researcher @L1v1ng0ffTh3L4N tested every major Chromium browser. Edge is the only one that behaves this way.
Chrome decrypts credentials on demand, and App-Bound Encryption locks the keys to an authenticated Chrome process so other processes can't reuse them.
In Chrome, plaintext surfaces only during autofill or when a password is viewed, making memory scraping far less useful.
What makes this extra weird is that Edge still demands re-authentication before revealing those passwords in its Password Manager UI, while the same browser process already holds every one of them in plaintext.
In shared environments, this turns into a credential harvest. On a terminal server, an attacker with admin rights can read the memory of every logged-on user process. In the published PoC video, a compromised admin account lifts stored credentials from two other logged-on (and even disconnected) users with Edge running.
Microsoft's official response when notified: "by design."
The finding was disclosed April 29 at BigBiteOfTech by PaloAltoNtwks Norway, alongside a small educational tool that lets anyone verify the cleartext storage for themselves.
So, as it turns out for poor people, Financial Inclusion is not the only issue…
Financial Exclusion, that is, the possibility of proving that I am unalive, and should be excluded from the system… and my money be given to next of my kins, is the next big problem 🙏
🛡️ Microsoft Confirms Windows 11 Updates May Force Users to Enter BitLocker Recovery Key
Source: https://t.co/rZDSYgtEw5
Microsoft has officially acknowledged a known issue affecting Windows 11 users following the release of its April 2026 Patch Tuesday cumulative updates.
Devices running certain BitLocker Group Policy configurations may unexpectedly prompt users to enter their BitLocker recovery key after installing updates KB5083769 or KB5082052.
The known issue was added to both update documentation pages on April 14, 2026, with Microsoft warning that "devices with an unrecommended BitLocker Group Policy configuration might be required to enter their BitLocker recovery key" post-installation.
#cybersecuritynews #Windows11 #bitlocker
IPv8 proposal draft.
It’s 64 bits (IPv6 is 128, IPv4 is 32).
“IPv4 is a proper subset of IPv8. An IPv8 address with r.r.r.r = 0.0.0.0 is an IPv4 address, processed by standard IPv4 rules. No existing device, application, or network requires modification to participate in an IPv8 network”
Also interesting that “Every manageable element in an IPv8 network is authorised via OAuth2 JWT tokens served from a local cache.”