Cybernews CPUID Website Breach Serves Malware via CPU-Z and HWMonitor Downloads
Article Content
- •CPUID's website was compromised for six hours, serving malware to users downloading CPU-Z and HWMonitor.
- •The malware, disguised as legitimate software, is designed to steal sensitive data and evade detection.
- •CPUID has fixed the breach and is now providing clean downloads, but users are urged to secure their systems.
The CPUID website was compromised for approximately six hours between April 9 and April 10, 2026, allowing attackers to hijack download links for popular utilities CPU-Z and HWMonitor. Users who attempted to download these tools received trojanized installers, specifically a file named 'HWiNFO_Monitor_Setup.exe,' which triggered antivirus alerts. The malware is designed to steal sensitive data, including browser credentials, and employs advanced evasion techniques to bypass detection. CPUID confirmed that the original software files were not compromised, but the attack exploited a secondary API feature. Security researchers noted that the malicious downloads were flagged by multiple antivirus engines. The breach has since been fixed, and CPUID is now serving clean versions of the software. Users are advised to check for any installations during the attack period and take necessary precautions.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (20)
Following this threat?
Track Cpuid in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…