Fake Claude site installs malware that gives attackers access to your computer
We found a convincing fake site that installs a trojanized Claude app while quietly deploying PlugX malware.
Related Vulnerabilities
- CVE-2026-23782: An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. An API management endpoint allow HIGH
- CVE-2026-35620: OpenClaw before 2026.3.24 contains missing authorization vulnerabilities in the /send and /allowlist MEDIUM
- CVE-2026-3498: The BlockArt Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'clien MEDIUM
- CVE-2026-33618: Chamilo LMS is a learning management system. Prior to .0.0-RC.3, the PlatformConfigurationController HIGH
- CVE-2026-35621: OpenClaw before 2026.3.24 contains a privilege escalation vulnerability where the /allowlist command HIGH
Related Coverage
Threat Actors