[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fAf7T7QVjswVvC1N8Ek7205kLOQ7epniyHK86U_lxmsM":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":18,"created_at":19,"published_at":20,"article":21,"tags":25,"podcasts":38},"55a151bc-5d00-4420-b889-badd9b67c4f7","cpuid-website-compromise-delivers-trojanized-system-utilities","06fd68ea-f5df-46f0-b2f4-ba5a85783f8f","CPUID Website Compromise Delivers Trojanized System Utilities","Attackers compromised CPUID's backend API and replaced legitimate download links with malicious versions of popular system monitoring tools CPU-Z and HWMonitor. This supply chain attack demonstrates how compromising trusted software distributors can impact millions of users who expect safe downloads from official sources. The incident highlights critical weaknesses in API security and software distribution integrity controls. Organizations and individuals downloading software from compromised official sources unknowingly installed malware, creating widespread security exposure.","**Immediate actions:**\n- Verify integrity of recently downloaded CPUID utilities using official checksums or digital signatures\n- Scan systems that downloaded HWMonitor 1.63 between April 9-10, 2026 for malware\n- Temporarily suspend downloads from CPUID until security is confirmed\n\n**Supply chain security:**\n- Implement code signing verification for all downloaded software before installation\n- Establish trusted software repositories with integrity checking mechanisms\n- Create vendor security assessment procedures for critical software suppliers\n\n**API security measures:**\n- Deploy API security monitoring to detect unauthorized modifications to backend systems\n- Implement multi-factor authentication and least privilege access for API management interfaces\n- Enable real-time alerting for changes to download links or file repositories",[12,13,14,15,16,17],"CIS Control 2.1","CIS Control 16.7","NIST SP 800-161","NIST AC-3","NIST SI-7","ISO 27001 A.15.1.1","published","2026-04-10T17:08:44.686655+00:00","2026-04-10T17:08:44.347+00:00",{"id":7,"url":22,"slug":23,"title":24},"https:\u002F\u002Fx.com\u002FDarkWebInformer\u002Fstatus\u002F2042627058472243687","on-april-9-10-2026-attackers-compromised-a-backend-api-on-the-cpuid-website-and--a2623c","‼️ On April 9–10, 2026, attackers compromised a backend API on the CPUID website and replaced the...",[26,32],{"id":27,"name":28,"slug":29,"description":30,"color":31},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":33,"name":34,"slug":35,"description":36,"color":37},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[39],{"id":40,"date":41,"edition":42,"title":43,"audio_url":44},"993e8114-39e6-455e-9f63-e99184078da9","2026-04-11","morning","ThreatNoir Weekend Brief — April 11","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-04-11\u002Fthreatnoir-morning-brief-2026-04-11.mp3"]