View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

Counterfeit software installers compromise Windows users across

🚨 ACTIVE EXPLOITATION

  • Counterfeit software installers compromise Windows users across multiple sectors
    Cybercriminals are using counterfeit software installers to compromise Windows systems.
    • Targets include Chinese-speaking users and China-based operations across healthcare, manufacturing, gaming, technology, logistics, government, and education.
    • Look-alike download pages impersonate Razer, Microsoft Edge, Kaspersky, Calibre, and other software brands.
    • Malicious ZIP installers establish persistence, weaken security protections, and communicate with attacker-controlled infrastructure.
    • Observed infrastructure includes pc-razerzone[.]com[.]cn, gehie246[.]com/712down, yimxg25tiy[.]com/73inst, cc8ttkv35b[.]com/7qinst, and n7b8t85zsg[.]com/ins711.
    • The same-named archives are regenerated server-side with different hashes on each download.
      📄 Source: cyberproof.com · 📎 Coverage: microsoft.com · 👁 via Microsoft Security Blog

💥 BREACHES & INCIDENTS

  • FBI Probes Dark-Web Service Selling 153 Million Driver’s Licenses
    The FBI is investigating a dark-web service selling more than 153 million driver’s licenses.
    • People in the United States and Canada are affected, including government officials and identity-verification customers.
    • The Nexus service offers more than 153 million driver’s licenses, 10 million ID cards, and 3 million travel documents.
    • The records include license fronts, backs, basic scans, and infrared and ultraviolet images.
    • Nexus claims the data comes from an ongoing breach at a Louisiana-based identity-verification company.
    • The service allegedly exfiltrated and uploaded records for more than a year; the FBI’s New Orleans field office opened an inquiry.
      📎 Coverage: krebsonsecurity.com · 👁 via Krebs on Security, @briankrebs@infosec.exchange

🔓 CVEs & KEV

  • CVE-2026-84372 — predis — CVSS 9.8 — Predis PHP Client: Critical Command Injection via Pipeline Handling

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check