• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

CPUID site was hijacked for ~6hrs compromised HWMonitor and CPU-Z downloads came from the website.

atarione

2[H]4U
Joined
Mar 17, 2011
Messages
2,499
https://www.theregister.com/2026/04/10/cpuid_site_hijacked/

Visitors to the CPUID website were briefly exposed to malware this week after attackers hijacked part of its backend, turning trusted download links into a delivery mechanism for something far less welcome.


The issue hit tools like HWMonitor and CPU-Z, with users on Reddit and elsewhere starting to notice something wasn't right when installers tripped antivirus alerts or showed up under odd names. One example that did the rounds had the HWMonitor 1.63 update pointing to a file called "HWiNFO_Monitor_Setup.exe," which is not what anyone went there to download, and a pretty clear sign that something upstream had been tampered with.

CPUID has since confirmed the breach, pinning it on a compromised backend component rather than tampering with its software builds.

"Investigations are still ongoing, but it appears that a secondary feature (basically a side API) was compromised for approximately six hours between April 9 and April 10, causing the main website to randomly display malicious links (our signed original files were not compromised)," one of the site's owners said in a post on X. "The breach was found and has since been fixed."


The files themselves appear to have been left alone and remain properly signed, so it doesn't seem like anyone got into the build process. Instead, the problem sat in front of that, in how downloads were being served. For anyone who hit the site during that stretch, though, that distinction offers little comfort. If the link you clicked had been swapped out, you were pulling whatever it pointed to, whether you realized it or not.

great... just great.
 
With AI it's only going to get worse, much worse.

Maybe it's time for a federal-level root CA, and all software digitally signed with features in Windows (and Linux) that check the software for a valid signature.
I'm good il Rather get hacked by a guy in China then to have that dystopic level of control on what I can install
 
The federal CA would probably be compromised in a couple years when AI takes over and starts using humans as living memory banks anyway.
 
I'm good il Rather get hacked by a guy in China then to have that dystopic level of control on what I can install
Or maybe we have to go back to software distribution via floppy disk, CD, or thumb drive.:(
 
Back
Top