A note…

While the WUWT website itself is fine, both Charles and Anthony are evaluating threat messages and Malware scans right now for our personal workstations. There is no threat to any of you visiting the site.

But, while we ensure our workstations are threat free, new postings will likely be delayed and/or lighter than usual.

Thank you for your attention to this matter!

The climate data they don't want you to find — free, to your inbox.
Join readers who get 5–8 new articles daily — no algorithms, no shadow bans.
5 12 votes
Article Rating
29 Comments
July 26, 2026 9:19 am

First they came for their workstations, and we commenters did nothing….well, …..thinking……

July 26, 2026 9:22 am

Thanks for the heads up.

July 26, 2026 9:39 am

Are you running an email gateway? Well over half of all compromises begin with an email (which may contain only a small part of the eventual attack). The email gateway ensures that the vast majority of attacks never even get to you. Provided you buy a good one of course. ProofPoint is my go to. The other question I would ask is, are you running an Enterprise class endpoint protection? Crowdstrike or SentinelOne are my go to’s though they will be pricy for a small number of desktops. Not knowing what your attack surface looks like, I’d consider an entry level ProofPoint deployment combined with perhaps Field Effect which basically gets you a comprehensive security suite founded by ex Five Eyes that has every feature practical for a small organization other than an email Gateway.

There are other combos I can think of, but if you are threat hunting after the fact using run of the mill anti-malware scans, you are taking a very big risk. A sophisticated attack can bury itself deep enough to evade detection. Modern threat hunting requires professional threat hunters with a full suite of threat hunting tools, which is part of what you get with Field Effect.

DM me if you want to get into the weeds on this thing. I’m recently retired but last decade has been 100% security in high value targets.

~davidmhoffer

Reply to  davidmhoffer
July 26, 2026 9:51 am

How come I never hear of anyone being busted for creating and distributing malware? Think of the immense cost to all of us. It should be seen as a major crime deserving major punishment.

Reply to  Joseph Zorzin
July 26, 2026 10:32 am

Agreed except the bad guys are almost always in foreign jurisdictions. Russia, China, North Korea are the big ones, good luck litigating them there. Some of these are big enough to rival nation state levels of security (Fancy Bear in Russia for example) and they leave their home countries alone of course. North Korea gets a considerable amount of its foreign currency revenue from security attacks.

Reply to  Joseph Zorzin
July 26, 2026 10:55 am

It is created by the same companies that sell anti-malware and anti-spyware and anti-virus software.

Reply to  TEWS_Pilot
July 26, 2026 12:24 pm

No, it is not.

Scarecrow Repair
Reply to  TEWS_Pilot
July 26, 2026 1:21 pm

Citation needed to be even one tenth believable.

Reply to  TEWS_Pilot
July 26, 2026 1:48 pm

SALE……. Big discount on tin hats. !

Reply to  TEWS_Pilot
July 26, 2026 2:14 pm

That may happen sometimes but it’s not the norm.
Who would keep using an anti- thing that didn’t work?
(OK. Maybe if you depend on something like Google’s (Generically meaning the sources own “protections”.), OK.
Rely on third party “free stuff”? You’ve got a point.
(Maybe I just hoist myself on my own petard? I’ve trusted Norton as a third party protection. But it’s not “free”, so maybe I’m off my own petard?)

July 26, 2026 9:48 am

I believe in capital punishment for those who create and distribute malware- and I ain’t kidding!

Reply to  Joseph Zorzin
July 26, 2026 10:56 am

Chi-Coms and NORKS and other enemies of civilization are using it as a weapon as well as an intel-gathering system.

Reply to  Joseph Zorzin
July 26, 2026 1:44 pm

I still hope you are. What a sad little life you would have if not.

Jeff Alberts
Reply to  MyUsernameReloaded
July 26, 2026 5:40 pm

Kind of like yours.

July 26, 2026 11:57 am

You might consider making a Htaccess file to block bad bots or AI bots.

Admin
July 26, 2026 12:10 pm

For all you people giving advice, no thanks. We’re dealing with it and it doesn’t look like it came from either a malicious website or an email.

Reply to  Charles Rotter
July 26, 2026 12:28 pm

The only person who offered any advice at all was me. My apologies for trying to help.

Reply to  davidmhoffer
July 26, 2026 12:31 pm

OK I missed Sunsettommy’s comment so two of us.

Reply to  davidmhoffer
July 26, 2026 2:50 pm

It’s fine. I understand and appreciate the desire to help. It’s just a distraction when you’ve already diagnosed are in in the midst of reinstalling operating systems.

Reply to  Charles Rotter
July 26, 2026 9:57 pm

Its been a few hours so I assume you are done with that 🙂

My comment about endpoint protection stands. Enterprise class endpoint protection has a rollback feature. So once the attack is understood, you can roll back to a few seconds before it began and you’re good to go. Data preserved, no need to reinstall the OS or the apps. But its expensive and you want the managed version of it because even large IT shops struggle with administration of these kinds of products.

Its very rare but there there are attacks that will survive formatting drives and installing from scratch. Enterprise endpoint protection nails those dead too. Usually.

Field Effect is almost enterprise grade and a lot cheaper than S1 or Crowd. They have several competitors in that price range.

dmh

Reply to  Charles Rotter
July 26, 2026 2:49 pm

Your comment sounds like you are are outright dismissing any of those who offerd to help.
I don’t think you meant it to sound like that.
I personally have a lot of things/people to pray for at the moment. You guys at WUWT fixing this is one of those things.
(Not the top of my list, but you’re on it.)

PS I’m going to stop trying to get on WUWT till tomorrow to give you less traffic to deal with as you fix this. Maybe others should do the same?

Reply to  Charles Rotter
July 26, 2026 5:51 pm

That is fine, but I have seen bots be smart enough to evade blocks by “tunneling” through them.

Rational Keith
July 26, 2026 4:49 pm

Reply to Joseph Zorzin:

Governments and large software/service companies like Microsoft have traced some offenders, reversed some attacks, and nailed some perps in court. It takes much effort which is costly in people time.

Today Iranian interests are probably probing US entities, Russia may be intensifying effort against anyone who helps Ukraine (as Canada does).

(Years ago Israel and the US damaged uranium enrichment centrifuges with malware aimed at their control systems, path of intrusion may have been employee bring a USB memory stick from home computer – large proportion of which have pirated software.)

Otherwise, my impression is that naive employees are often the path of intrusion, responding to fake invoices, phone calls claiming to be someone else including police or tax authority (in one case the employee’s big boss who s/he had never met so did not know his voice) ……

Canada and US have had some success finding and prosecuting scum who claim to be a grandchild in urgent need of bail money, sometimes distorting voice or faking it with software or saying has bad cold so sounds different.

Rational Keith
Reply to  Rational Keith
July 26, 2026 5:02 pm

I understand that some tracers have managed to turn the infection back into the sources own computers. Sweet irony!

Many companies do not have proper security.
Target stores gave a company access to collect statistics on energy consumption of its facilities but did not restrict that access – should have firewalls, then Target employees ignored warnings from their own system.
Dumbest was a large Midwest US industrial company who did not close the testing port of a new computer system – installer is supposed to change that access from open one that is shipped.
The book ‘The Cuckoo’s Egg’ is a good read, chronicles how a person found an intrusion that began via an old user account, end target was a military organization.

Ransomware has been a problem recently.

Reply to  Rational Keith
July 26, 2026 10:10 pm

I took on an airport that shall remain nameless, all the IoT devices on the runway were wide open to the internet. Oops.

I used to present at various conferences. One of my favorite stories is about a large computer sports gaming company whose main campus is in Burnaby BC. I don’t want to embarrass them so I’ll just say their initials are EA (pause for laughter). An employee was online in a coffee shop and an attacker stole a cookie and sold it for $5 on the dark web. The buyer used the cookie to get into EA’s Slack conference, used the Slack conference to reach out to support, told support that they were at a party last night and lost their phone and it was urgent that they get into one of the main systems to do some urgent maintenance. Support suspended 2FA and gave him a temporary username and password. The attacker exfiltrated all of EA’s proprietary code.

The only part of that whole attack chain that was really technical was stealing the cookie. The biggest of attacks start with human error.

Reply to  Rational Keith
July 26, 2026 10:27 pm

Re Target – I’ve done so many after the fact reviews that I sometimes get them mixed up but I believe that Target allowed a supposed power company employee to install a device in their main communications room. Just walked up to reception in overalls, toolbelt, box under his arm. So he installed the device behind their firewalls.

But it got worse. They actually detected it in Bangalore on Dec 2nd, but Minneapolis didn’t action the escalation to them until the 15th so cards were being stolen for two weeks. 40 million of them.

I was at a lunch with a customer, trying to get him to buy some security package, when his phone rang. He looked at it, said Royal Bank? That’s odd. Sent it to voicemail. Seconds later his phone rings again and its Bank of Montreal. Send to voicemail and seconds later TD Bank is calling. I said you better pick that up. 150,000 credit cards had already been exfiltrated and the banks picked it up before any of his security tools (and yes, that resulted in a sale, lol).

Reply to  Rational Keith
July 26, 2026 10:31 pm

path of intrusion may have been employee bring a USB memory stick from home computer

Actually there were multiple paths of intrusion. Some of the code was installed on network host bus adapters (HBAs) brand new right out of the box.

Bryan A
July 26, 2026 5:44 pm

This is very likely a testament to the fact that shining a light on malfeasance draws attention from malcontents, a light their shadowed realms can’t endure. And the Light from WUWT is powered by reliable energy 24/7/375 not unreliable part time renewables. They must feel like they’re losing the battle to resort to such tactics.

Sparta Nova 4
July 27, 2026 9:50 am

I receive annual security training, part of my job.
Here are a few key points.

  1. There is no such thing as absolute security shy of powering down the computer, disconnecting it, and never using it.
  2. The purpose of security is primarily to identify when penetration occurred and what was targeted so mitigation can be pursued.
  3. As fast as implementing new security protocols/software, the attackers are even faster. Point being, one can never get ahead. See point 1.