Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks
2026-07-24T07:24:13Z•35733163c14f08c42cb5e371125936b5d7fb8cd5f598f75b9c9034d901bce27e
ChaosJadeProxKratosNotepad++TriBackUAC-0099active-exploitationbrowser-exploitationcloud-infrastructureemail-theftespionagegit-compromiselinuxmacOSmalwaremsaRATopen-source-malwarephishingprivilege-escalationransomwareremote-code-executionsupply-chaintwo-factor-bypasswindowszero-day
What happened
The feed aggregates multiple high-impact security incidents and active exploitation campaigns: a Russia‑aligned cluster UAC-0099 is distributing MATCHBOIL.V2 via a fake Notepad++ plugin; a Russian state‑aligned group exploited a Zimbra zero‑day to steal mail and 2FA codes; active exploitation observed for Microsoft SharePoint RCE (CVE-2026-50522) and Check Point SmartConsole auth‑bypass (CVE-2026-16232). Several other serious flaws and attacks were reported, including a local root XFS bug (RefluXFS CVE-2026-64600), Ubuntu snap‑confine LPE (CVE-2026-8933), Adobe Acrobat extension chain (CVE-202
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 35733163c14f08c42cb5e371125936b5d7fb8cd5f598f75b9c9034d901bce27e
- Enrichment time
- 2026-07-24T07:24:13Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.