TL;DR
AMD will invest up to $5B in Anthropic and deploy 2GW of MI450 GPUs. Claude will accelerate ROCm development. First GW ships H1 2027. Anthropic already uses MI355X GPUs.
The Steam Machine is already one of Valve’s most expensive gaming devices. However, it may not stay at its current price for long.
According to a Valve engineer, the ongoing DRAM shortage is continuing to drive up component costs. This raises the possibility that the handheld could become even more expensive in the months ahead.
Speaking to Bloomberg’s Jason Schreier, Valve engineer Yazan Aldehayyat said the company expected some supply chain challenges around memory, storage and chips. However, he said the current DRAM crisis has turned out to be far more severe than anticipated.
While he stopped short of confirming another price increase, Aldehayyat suggested that the worst may not be over. He explained that retail prices typically lag three to six months behind wholesale component costs. This means the most recent increases in DRAM pricing have yet to be reflected on store shelves.
That could have implications for the Steam Machine, which already starts at £879 / $1,049 for the version with 512GB of storage and no controller. Buyers looking for the 2TB model with a bundled gamepad currently have to pay £1,208 / $1,428.
The comments also suggest Valve is continuing to monitor the supply situation closely rather than ruling out future pricing changes. Aldehayyat noted that it’s still unclear whether memory prices will eventually stabilise or continue climbing. As a result, it is difficult to predict where hardware costs will settle over the longer term.
The Steam Machine has already weathered one major price adjustment. According to the report, Valve had originally intended to launch the device at a lower price. However, rising component costs forced the company to increase pricing ahead of release. The increase was compared to previous price changes affecting the Steam Deck.
Despite its premium positioning, demand doesn’t appear to have slowed. The Steam Machine is reportedly sold out, suggesting buyers have continued to snap up the hardware even at its current asking price.
For now, Valve hasn’t announced any official pricing changes, and Aldehayyat’s comments don’t confirm that one is imminent. However, if memory costs continue to rise and supply pressures persist, today’s retail prices may not be the final word on what the Steam Machine will ultimately cost.
Recent coverage of Flock Safety, the fast‑growing US surveillance technology company, reveals how opposition to automated license plate readers is playing out at the local level.
In South Carolina, officials have been sparring over whether to install 25 new cameras, a dispute that reflects broader questions about cost, oversight, and how much surveillance communities are willing to accept. The city of Los Angeles recently broke its contract with Flock Safety, though Flock’s CEO argues that the suspension should be temporary while the police department revises its rules.
These cancellations are in large part driven by public concern around a system designed to enable mass surveillance, which is susceptible to serious abuses, including biased policing and privacy violations.
To track such surveillance, journalists and researchers are increasingly turning to a free tool called the Atlas of Surveillance, a collaboration between the renowned digital privacy group Electronic Frontier Foundation and the University of Nevada, Reno. The site has become a go‑to source for mapping police technology — which also includes drones, facial-recognition cameras and body cameras — with a searchable database that’s often more dependable than alternatives.
With the Atlas of Surveillance tool, you enter a city, county, state, law enforcement agency or vendor in the US and select which technology you’re interested in tracking. You’ll get a list of details based on your search, including links to public records or news articles.
“We frequently run into situations where local councilpeople don’t even know that a certain tool is in use,” said Beryl Lipton, Electronic Frontier Foundation senior investigative researcher. “Learning about a technology we have logged in the Atlas of Surveillance is meant to help people have conversations [about] whether that tool is appropriate for local use, start asking questions, and advocate for standards around how their police can or can’t use this equipment.”
While other tools for tracking Flock cameras and similar surveillance systems exist, I prefer the EFF’s approach, which uses reliable crowdsourced data from specific volunteers, including University of Nevada students and staff, as well as experienced researchers. These volunteers use a variety of information, including government documents, press releases, news stories and confirmed social media posts, to create lists of exactly which surveillance technologies local police or sheriff departments are using, as well as when they were adopted.
Deflock, another popular crowdsourced app for reporting Flock camera locations, has an open-source design that leaves it vulnerable to false reports from people who only think they’re seeing a surveillance device. Self-reports are also becoming less reliable as surveillance cameras are being hidden in speed signs and cacti.

I tried the Atlas tool with several location searches, including Albany, Georgia, where five police officers were fired and arrested in July on charges of misusing the city’s Flock system. Sure enough, I could see exactly when Albany began its Flock program, among other details about the technology it uses.
“While we may know that a police department has a tool, we may not know that they don’t have a governing policy or what is in the policy they have, like how long the data is retained,” Lipton told me.
Lipton recommends that users pair the Atlas tool with the EFF’s Street-Level Surveillance hub, which offers deeper documentation, including details on third‑party vendors that collaborate with law enforcement.
The Atlas database isn’t perfect, and the volunteers can do only so much. In my own searches, I found that my home city offered accurate listings for traffic cameras, but didn’t mention the period when it adopted Flock automated license plate readers last year, before removing them after public complaint. I’ve seen similar patterns in other cities with comparable histories, suggesting the database may emphasize active programs or exclude portions of older records.
Resources like the Atlas of Surveillance give residents a clearer view of the technologies their police departments use, information that can otherwise be difficult to obtain. As I’ve covered before, some cities will carefully omit the name “Flock” when announcing new surveillance or monitoring programs, even if they are using the brand’s drones or ALPR cameras.
If you’d like to volunteer for the Atlas of Surveillance, you can select the Collaborate option to submit a datapoint for consideration.

Jean Paoli has spent his career making documents readable by machines — first as a co-creator of XML, then helping build the file formats behind Microsoft Office. Now his Kirkland, Wash.-based startup, Docugami, is open-sourcing the technology at the heart of its business, betting it can become a standard way to turn documents into data that people and AI agents can trust.
The company is releasing its technology, called DGML (short for Document Graph Markup Language), under Apache 2.0, a widely used open-source license, so other developers and companies can adopt it.
The idea is to turn it into a shared standard that no single company owns, much as XML became a common foundation across the tech industry.
The move reflects a shift in where the value is created in AI. Docugami until now has made its money selling software that turns unstructured documents into usable data. It’s betting now that there’s more value in proving that data is trustworthy instead.
How it works: Docugami is teaming up with Inveniam, a Detroit company whose software helps big investors keep tabs on the mountains of paperwork behind real estate and other hard-to-value assets. Inveniam will record a kind of digital fingerprint of each piece of DGML data on NVNM Chain, its blockchain built with Mantra, a crypto firm that Inveniam is acquiring.
That means, for example, that a single fact buried in a 200-page lease — such as the rental rate, a renewal option, or a default clause — can be verified on its own, without exposing the whole document. An investor, auditor, or AI agent can trace it to the page it came from.
To work with documents, AI systems usually convert them into a simpler format first. DGML enters a growing field of contenders in that regard, competing with the popular Markdown format and DocLang, a new open standard for AI-ready documents backed by IBM, Nvidia and Red Hat.
The business model: This is a big move for a company of Docugami’s size, taking the 30-person startup in a new direction. Paoli is handing the industry the technology his team spent years building, and pinning the company’s future on a larger idea.
The plan is to make money not from the format itself but from the value of the trusted data. Once a company converts its leases or loans into DGML and anchors the key numbers on the blockchain, investors, lenders and auditors can pay to draw on that verified data.
Docugami will share in the revenue through its partnership with Inveniam. The company also stands to collect a small fee each time a piece of data is recorded on the chain.
The company is giving away the DGML format and a working version of the software, but not everything. Paoli said the company is keeping some of its own technology private, including AI models it has fine-tuned to read documents, and could sell those or other tools to enterprises.
“The business model of everybody is changing. And if you know any company where it’s not true, you need to tell me, because I haven’t met them yet,” Paoli said in an interview.
Docugami has raised about $13 million to date, including a $10 million seed round in 2020 that drew the first investment in Grammarly’s history.
The partnership: Paoli met Patrick O’Meara, Inveniam’s CEO, a few months ago, through a former Microsoft colleague who had become one of O’Meara’s advisers. They quickly realized they had been working toward the same idea from different directions.
Inveniam, founded in 2017, helps big investors keep track of assets that are hard to value, like office towers, private loans and infrastructure. It monitors the documents behind those assets and flags changes as they happen, and its clients include some of the world’s largest sovereign wealth funds, according to O’Meara.
What it lacked was a consistent way to break those documents into verifiable pieces. That is what Docugami provides.
“We’re not putting the data itself on-chain, just a fingerprint of the document. Change one bit, one byte, one pixel, and the hash won’t match,” O’Meara said.
The blockchain comes from Mantra, a crypto company run by John Patrick Mullin. Inveniam invested $20 million in Mantra last year and has since agreed to acquire it outright. Mantra’s OM token collapsed in April 2025, erasing several billion dollars in value.
Paoli said the project uses the underlying blockchain, not the token.
“Crypto as an industry has gone through a lot of changes in the last 18 to 24 months, and it’s growing up in a lot of ways. This is a real use case with fundamental value, not just pure speculation,” Mantra’s Mullin said in an interview.
The result is a division of labor: Docugami turns documents into data, Inveniam verifies it and brings the customers, and Mantra provides the chain where the proof is recorded.
The DGML specification, sample documents and reference code are at dgml.io and on GitHub.
Editor’s note: This story was updated after publication to correct the name of a competing document format, DocLang, and to note that Inveniam’s blockchain is called NVNM Chain.
Scientists have been trying to figure out how kids pick up language so fast for decades, and a new study out of the Okinawa Institute of Science and Technology (OIST) might have cracked part of the puzzle: curiosity.
Researchers built a virtual robot with a brain-inspired neural network and set it loose in a simulated 3D world full of shapes, colors, and simple commands like “push left magenta dumbbell.”
Some robots were rewarded only for completing tasks correctly. Others got an extra reward for curiosity, essentially getting a little internal high whenever they encountered something that challenged their existing understanding of the world.
The curious robots didn’t just edge out their indifferent counterparts; they blew past them. According to the study, published in Science Advances, curious robots reached a genuine understanding of language in about half the time.

Study author Theodore Tinker compared it to trying white chocolate for the first time even though you already love dark chocolate. You take the risk anyway, and you walk away knowing more about chocolate in general.
Things got even more interesting halfway through training. The curious robots started knocking things over and experimenting with actions nobody asked for, basically playing. Nobody programmed that behavior in. It just showed up on its own.
The robots also mimicked a well-known quirk in how children learn language. Kids often get certain verb forms right at first, then start applying grammar rules too broadly and make mistakes on verbs they’d previously used correctly, before eventually sorting out the exceptions and correcting themselves. The robots followed the same U-shaped dip in performance.

It’s also a nice contrast to how today’s chatbots learn. Large language models like ChatGPT train on massive datasets and spit out the statistically likely next word. This robot’s brain works more like ours, prioritizing accuracy while trying to keep its beliefs intact, only updating them when something surprises it enough to be worth the trouble.
None of this means robots understand language the way we do. But it does suggest that curiosity paired with a wide variety of experiences might be a big part of how toddlers crack the language code with so little to go on.
AMD will invest up to $5B in Anthropic and deploy 2GW of MI450 GPUs. Claude will accelerate ROCm development. First GW ships H1 2027. Anthropic already uses MI355X GPUs.
AMD and Anthropic announced a strategic partnership on Tuesday that commits AMD to invest up to $5 billion in Anthropic and deploy up to 2 gigawatts of AMD Instinct MI450 Series GPUs in Helios rackscale solutions to run Claude. Deployment of the first gigawatt begins in the first half of 2027. Anthropic is already using AMD’s MI355X GPUs and will now scale to MI455X accelerators paired with EPYC “Venice” CPUs and Pensando networking.
The engineering collaboration may matter more than the hardware. AMD and Anthropic will use Claude to optimise workloads for AMD Instinct GPUs and accelerate ROCm software development. AMD will also adopt Claude broadly across its engineering and product development teams. ROCm is AMD’s answer to Nvidia’s CUDA, and its software gap has been the primary reason AI developers default to Nvidia hardware even when AMD’s specs are competitive. If Claude can materially improve ROCm’s developer experience, AMD addresses the problem that has held it back for years, using its customer’s AI to fix its own software.
Anthropic’s compute strategy is now genuinely multi-vendor. Anthropic signed its biggest compute deal with Google and Broadcom, and has separate arrangements with Amazon (Trainium chips, 5GW), CoreWeave (Nvidia GPUs), and SpaceX (Colossus data centres). Adding 2GW of AMD Helios gives Anthropic what Tom Brown, its chief compute officer, called the ability to “map the right workloads to the right hardware.” Diversifying away from any single chip vendor reduces dependency risk at a time when compute is the binding constraint on frontier model development.
For AMD, the $5 billion equity investment mirrors Nvidia’s playbook. Nvidia invested $2 billion in Nebius and has taken stakes in multiple AI infrastructure companies to lock in hardware demand. AMD is doing the same: investing in a customer to guarantee that its chips, not Nvidia’s, run a meaningful share of the world’s most capable AI models. Lisa Su called it “a major platform for the next generation of AI infrastructure.” Whether Helios can compete with Nvidia’s NVL72 at production scale is the question the first gigawatt will answer.
Travis Kalanick is back, and Uber is helping to fund him. The founder Uber forced out in 2017 has raised $1.7 billion for Atoms, an industrial-AI and robotics company he has built in near-total stealth for years.
Andreessen Horowitz led the round. Its co-founder Ben Horowitz is joining the board. And among the investors sits Uber, the company Kalanick started in 2009 and left under a cloud.
That exit still shadows the story. Uber pushed Kalanick out as chief executive in 2017 after complaints of sexual harassment, discrimination and a toxic workplace. Nine years on, his old company is writing him a cheque. Kalanick, never one for understatement, calls the round “unfinished business”.
The equity comes with serious debt. Alongside a16z, Bain Capital, Fifth Wall and others, Atoms lined up credit facilities from JPMorgan, Goldman Sachs, Bank of America, Wells Fargo and Barclays. The company did not disclose a valuation. That is the kind of firepower needed to build heavy machines, not apps.
Kalanick’s pitch is a single idea he has chased for 16 years: turning the physical world into something software can run. In his framing, manufacturing is the processor, real estate is the storage, and transport is the network. Uber digitised transport for the masses.
CloudKitchens, his ghost-kitchen venture, did the same for food. Atoms is meant to do it for whole industrial sectors. He calls the result an “atoms-based computer.”
The target is the unglamorous heart of the economy: mining, construction, heavy transport and food. His term for the toolkit is Industrial AI, a mix of software, sensors, robotics and models aimed at automating entire sectors. He calls the wider shift the “Age of Atoms.”
Here Kalanick parts ways with much of the field. While rivals pour billions into general-purpose humanoid robots, Atoms builds specialised machines for specific jobs. Horowitz argues that purpose-built hardware copes with brutal industrial environments far better than a humanoid could. It is a pointed bet against the hottest trend in physical AI.
Atoms is split into three parts, according to reports. Atoms Food folds in CloudKitchens and its cooking and delivery software. Atoms Mining puts autonomous machines to work at extraction sites, built on Atoms’ acquisition of Pronto, a startup run by former Uber and Google engineer Anthony Levandowski.
Atoms Transport is what Kalanick calls a “wheelbase for robots.”
Levandowski’s presence adds intrigue. He sat at the centre of a self-driving trade-secrets case involving Google and Uber, and later received a presidential pardon. Kalanick has also flirted with buying the US arm of China’s Pony AI, with Uber’s help, though those talks ended earlier this year.
The mood around the deal is euphoric. One a16z partner called it the largest cheque the firm has ever written. Another investor predicted Atoms would be worth a trillion dollars within a decade. Horowitz put it more simply: “Travis is back.”
Some scepticism is warranted. Atoms has revealed a grand vision and a very large bank balance, but little in the way of deployed industrial robots at scale. The valuation is a mystery, the claims are sweeping, and Kalanick’s Uber record is not easily forgotten. Yet the bet is coherent.
He turned the movement of people into a software business once. Now, with $1.7 billion and his old adversary alongside him, he wants to do the same to the machines that grow, dig and haul the physical world.
Mobileye founder and CEO Amnon Shashua plans to step down from the top leadership post after nearly three decades, just as the company pushes into robotaxis and humanoid robots.
Shashua will remain CEO until Mobileye hires a replacement, according to a regulatory filing Thursday.
Mobileye got its start making computer vision chips based on Shashua’s academic research at Hebrew University in Israel, and grew into a major supplier of the chips that power automotive safety and driver-assistance features. It had the largest IPO in Israel’s history, was acquired in 2017 by Intel for $15.3 billion, then spun back out as a publicly traded company in 2022, though Intel remains its largest shareholder.
Under Shashua, Mobileye also moved beyond selling chips to automakers and began building its own systems that handle autonomous driving, which it now supplies to Volkswagen and its MOIA subsidiary.
In January, the company acquired Shashua’s humanoid robotics startup Mentee Robotics for $900 million, which Shashua called part of “Mobileye 3.0,” the next phase of the business focused on robotics and automotive AI.
Mobileye also said in June it would expand beyond its supplier status to launch its own robotaxi service in a U.S. city in 2027.

Microsoft is putting $60 million behind the U.S. Department of Energy’s Genesis Mission, a push to use artificial intelligence to speed up scientific research across the government’s 17 national labs.
The company’s investment is split into two pieces: $40 million in Azure cloud computing and AI credits over three years, and $20 million for engineering and deployment help to get DOE researchers actually using the tools, Microsoft said in a blog post Wednesday.
Microsoft is also launching a new internal group called SPARK — Scientific Partnership Advancing Research & Knowledge — to serve as the single point of contact between the company and DOE on Genesis Mission work. It’s meant to combine Microsoft’s program management, engineering, security and research teams into one coordinated effort, instead of leaving individual labs to navigate Microsoft on their own.
President Trump created the Genesis Mission through an executive order in November 2025, directing DOE to build a unified computing and data platform — since named the American Science and Security Platform — that connects the national labs’ supercomputers, AI tools and scientific datasets.
The order likened the effort’s urgency and ambition to the Manhattan Project, and the White House said it’s expanded into a whole-of-government initiative involving more than 15 federal agencies, backed by more than $5 billion in commitments.
Microsoft named four initial projects taking shape under the partnership, including work with Pacific Northwest National Laboratory in Richland, Wash., to speed up the discovery of new energy storage materials — cutting analysis that used to take years down to weeks — and autonomous lab work with Lawrence Livermore National Laboratory aimed at detecting biological threats earlier.
“We move faster together,” Chris Barry, president of Microsoft’s U.S. Public Sector business, wrote in the blog post announcing the commitment, framing the investment as both a “national security imperative” and economic opportunity for the U.S.
Microsoft isn’t the only Seattle-area cloud giant courting the Genesis Mission. Amazon Web Services was recognized by DOE as a Genesis Mission supporter in December, highlighting its work with Idaho National Laboratory on AI tools for nuclear reactor design, and the company launched its own Genesis Accelerator Initiative in February, offering up to $50 million in cloud credits for DOE-related research over three years.
Google also announced Wednesday that it was committing $40 million of AI tokens and cloud credits for researchers in support of the Genesis Mission.
More Google AI Pro and Ultra users will now have access to Spark.
Google is making Gemini Spark, the agentic AI assistant it announced at this year’s I/O developer conference, available to more people. Unfortunately, they still don’t include free users. In the US, Spark is rolling out to everyone paying $20 a month for Google AI Pro. It’s also rolling out globally to Google AI Ultra users, who are paying between $100 to $200 a month for their subscription…unless they’re in the European Economic Area, Switzerland, the UK and Nigeria. Those who can now access Spark with this expansion may want to check if it also comes with local language support.
Spark is powered by Gemini 3.5 and is deeply integrated into Google’s Workspace apps. Users can assign tasks to it by going to the Spark page, either via the sidebar on a computer or by tapping on the option under menu on mobile. From there, they can type in the tasks they want Spark to do. They can tell Spark, for instance, to check their emails and calendar schedules every morning and then let them know what to prioritize. Spark can also automatically create draft responses for when emails from a particular person hit the user’s inbox, or summarize lengthy email threads. Users can use Spark to create detailed reports in Google Docs from meeting notes and emails, as well. As these are only a few possible tasks for Spark, users can check out Google’s support pages for more information.
Tails helps you to use the Internet anonymously and circumvent censorship almost anywhere you go and on any computer but leaving no trace unless you ask it to explicitly.
Tails is a complete OS designed to be used from a DVD, USB stick, or SD card independently of the computer’s original operating system. Start on your Tails USB stick instead of starting on Windows, macOS, or Linux. Tails leaves no trace on the computer when shut down.
Tails helps you to:
Tails includes a selection of applications to work on sensitive documents and communicate securely. It comes with several built-in applications pre-configured with security in mind: web browser, instant messaging client, email client, office suite, image and sound editor, etc.
If you are interested in giving Tails a try on your current computer without running any risk, please check out our Guide: Running Linux From a USB Drive As a Virtual Machine or Bootable Disk.
Tails is a portable Linux distribution based on Debian that combines the Tor network, the GNOME desktop and several other tools to offer a secure and anonymous computer experience.
Tails is very safe as long as you do not run it on an infected machine. Tails is designed to run from a USB stick on any computer as a completely independent OS. However, if the host computer is infected with malware such as a keylogger your privacy would be at risk.
Tails is set up out of the box to run from your computer’s memory and never stores information locally unless you configure it to. This means that every time you shut down Tails, the memory is wiped clean, deleting all traces of your work and every new session starts as a blank slate.
Yes, you can use Tails to circumvent internet censorship and browse the web anonymously. All the applications that come with Tails (email, browser, messaging client, office suite) use the Tor network to connect to the internet, so all your activity can be hidden.
Online anonymity and censorship circumvention with Tor
Tails relies on the Tor anonymity network to protect your privacy online:
Tor is free software and an open network that helps you defend against a form of network surveillance that threatens personal freedom and privacy, confidential business activities and relationships, and state security known as traffic analysis.
Tor protects you by bouncing your communications around a distributed network of relays run by volunteers all around the world: it prevents somebody watching your Internet connection from learning what sites you visit, and it prevents the sites you visit from learning your physical location.
Using Tor you can:
Detection of problems with Wi-Fi hardware
Problems with Wi-Fi are unfortunately quite common in Tails and Linux in general.
To help troubleshoot hardware compatibility issues with Wi-Fi interfaces, the Tor Connection assistant now reports when no Wi-Fi hardware is detected.
New shutdown procedure
Tails now uses the standard shutdown procedure from GNOME.
The standard shutdown procedure is a bit slower, but better prevents data loss.
For example, the Power Off confirmation dialog informs you if an application needs to be closed or an open document needs to be saved before shutting down.
Even without confirming or saving the open documents, Tails will shut down after 60 seconds.
You can still use the faster emergency shutdown as before.
Celluloid video player
We replaced GNOME Videos with Celluloid, a more modern and reliable video player.
For added security, Celluloid cannot access the network. You can either:
Celluloid doesn’t work on some computer from 2011 or earlier.
Changes and updates
For more details, read our changelog
Tails 7.6 changelog
GNOME Secrets
Tor Browser 7.4.2 Changelog
Changes and updates
Fixed problems
Tails 7.4.1
Included software
Fixed problems
Tails 7.4 Changelog
Tails 7.1 Changelog
Changes and updates
Fixed problems
Tails 7.0 Changelog
Tails 7.0 is dedicated to the memory of Lunar (1982 – 2024). Lunar was a traveling companion for Tails, a Tor volunteer, Free Software hacker, and community organizer.
Lunar has always been by our side throughout Tails’ history. From the first baby steps of the project that eventually became Tails, to the merge with Tor, he’s provided sensible technical suggestions, out-of-the-box product design ideas, outreach support, and caring organizational advice.
Outside of Tor, Lunar worked on highly successful Free Software projects such as the Debian project, the Linux distribution on which Tails is based, and the Reproducible Builds project, which helps us verify the integrity of Tails releases.
Lunar will be deeply missed, both in our community and in the many other communities he participated in.
Faster startup
Tails 7.0 starts 10 – 15 seconds faster on most computers.
We achieve this by changing the compression algorithm of the Tails USB and ISO images from xz to zstd. As a consequence, the image is 10% bigger than it would be with the previous algorithm.
While testing this change, we noticed that Tails on USB sticks of poor quality can also start 20 seconds slower than on quality USB sticks.
If you are in a place where counterfeit electronics are common, we recommend that you buy your USB stick from an international supermarket chain, which should have a more reliable supply chain.
Included software
Changes in GNOME
Removals
Hardware support
Previous release notes
Changes and updates
Fixed problems
Ukraine’s CERT has uncovered attacks distributing an archive containing the legitimate Notepad++ application and a malicious utility called LunchPoke disguised as a plugin to establish persistence.
The campaign has been attributed to a threat cluster tracked as UAC-0099, which primarily targets organizations in Ukraine and has previously been linked to providing initial access for attacks carried out by APT44, also known as Sandworm.
The attackers do not exploit any vulnerability or a supply-chain compromise impacting the popular software.
CERT-UA observed that UAC-0099 changed their modus operandi recently and now delivers a ZIP archive with a VBS script disguised as a PDF document. When launched, the PDF retrieves another compressed file named Evernote.zip.
The second archive contains a complete copy of the legitimate editor Notepad++ version 8.8.3, a malicious plugin (NppExport.dll), a password-protected archive (updater.rar), and the legitimate WinRAR executable.
.jpg)
The VBS script installs the package into a randomly named directory, launches Notepad++, and then loads the malicious NppExport.dll via the application’s normal plugin-loading mechanism.
CERT-UA explains that this DLL is LunchPoke, a tool that creates a scheduled task on Windows and extracts the contents of the RAR file, including RemoteLibUpdater.exe and InitTest.dll.
The executable in the RAR file is BurnyBear, a loader for the DLL file that is the MatchBoil V2 malware loader.

BurnyBear also features a fallback mechanism in case launching RemoteLibUpdater.exe fails, triggering a resource exhaustion attack targeting the host’s RAM and CPU.
The latter creates another scheduled task, updates its configuration and command-and-control (C2) address, and then uses WinRAR to extract downloaded programs.
CERT-UA does not mention the final payloads delivered in the observed attacks, the purpose of the campaign, or the targeted organizations.
The researchers mention CVE-2025-56383, a DLL hijacking flaw in Notepad++ v8.8.3, the exact version used in these attacks, but note that the Notepad++ team has disputed this issue, claiming that plugin loading is standard functionality.
CERT-UA advises system administrators to update Notepad++ to version 8.9.7, 7-Zip to version 26.02, and WinRAR to version 7.23, to prevent hackers from exploiting known flaws in existing products and enabling stealthy attacks.
Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
Weekend Open Thread – Corporette.com
The House | The City of London can help the new chancellor deliver growth in every postcode
Ripple Payments Joins MiCA With 14 Firms, Does It Mean Anything For XRP?
Two July Windows Left: The CLARITY Act’s Senate Fight and What Failure Means
Democrats look to World Cup watch parties to register thousands of voters
Ripple wins EU-wide access as ESMA adds it to MiCA register
Grayscale Files For Worldcoin ETF, WLD Registers Sharp Rise
Sail Virtually Aboard The “Itanic” With IA-64 Emulator
Unregistered fitter used Gas Safe logo on business flyers
Turtle Beach Command Series KB7 review: a nifty screen-equipped gaming keyboard
Registration is now open for March for Men with Kev 2026
Big Money Is Entering XRP
New Jersey voter registration controversy explained: How 6,600 noncitizens got on the rolls, and what happens next
Kaspersky exposes OkoBot’s 20-module crypto wallet attack
Airlines warn Sunshine Protection Act could disrupt flight scheduling
Johnny Depp’s R-Rated Gothic Cult Classic Gets New Release Ahead of Sydney Sweeney Remake
Durham County Council to send out electoral registration emails
MiCA Licensing Faces Delays as ESMA Adds 14 CASPs to Register
Ethics, other provisions in crypto Clarity Act to be further discussed
Chip Stocks Enter Bear Market After Moonshot Ai Unveils Kimi K3 Model
You must be logged in to post a comment Login