Futures
Access hundreds of perpetual contracts
CFD
Gold
One platform for global traditional assets
Options
Hot
Trade European-style vanilla options
Unified Account
Maximize your capital efficiency
Demo Trading
Introduction to Futures Trading
Learn the basics of futures trading
Futures Events
Join events to earn rewards
Demo Trading
Use virtual funds to practice risk-free trading
CFD
U.S. stock CFD derivatives
US Stocks
Access real US stocks and ETFs
HK Stocks
Trade quality Hong Kong-listed stocks
Stock Futures
High leverage, 24/7 trading
Tokenized Stocks
Backed by real stock assets
IPO Access
Unlock full access to global stock IPOs
GUSD
Mint GUSD for Treasury RWA yields
Stocks Activities
Trade Popular Stocks and Unlock Generous Airdrops
Launch
CandyDrop
Collect candies to earn airdrops
Launchpool
Quick staking, earn potential new tokens
HODLer Airdrop
Hold GT and get massive airdrops for free
IPO Access
Unlock full access to global stock IPOs
Alpha Points
Trade on-chain assets and earn airdrops
Futures Points
Earn futures points and claim airdrop rewards
Promotions
AI
Gate AI
Your all-in-one conversational AI partner
Gate AI Bot
Use Gate AI directly in your social App
GateClaw
Gate Blue Lobster, ready to go
Gate for AI Agent
AI infrastructure, Gate MCP, Skills, and CLI
Gate Skills Hub
10K+ Skills
From office tasks to trading, the all-in-one skill hub makes AI even more useful.
GateRouter
Smartly choose from 40+ AI models, with 0% extra fees
Record fine for Coupang, users of Claude Code hacked, and other cybersecurity events - ForkLog
We have gathered the most important cybersecurity news of the week.
Microsoft disabled dozens of repositories on GitHub after an attack on Claude Code users
Microsoft temporarily closed access to dozens of its open source repositories on GitHub after malicious software was embedded in the code. The hacking campaign Miasma was reported by analysts from Cloudsmith and OpenSourceMalware.
At least 70 projects were affected, many related to the Azure platform. These include repositories with tools used by developers in AI coding applications, including Claude Code, Gemini CLI, and VS Code.
According to experts, the malicious code was aimed at stealing passwords and other sensitive credentials. It activated when users opened compromised tools.
Cloudsmith recommended taking protective measures:
Microsoft spokesperson Ben Hope stated in a TechCrunch comment that the company temporarily removed some repositories to check for potentially malicious content. Some of them have already been restored.
Hacktivists attacked Ukrainian users using a vulnerability in WinRAR
Hacktivist groups SHADOW-EARTH-066 (UAC-0226) and Gamaredon attacked Ukrainian government agencies through a vulnerability in the WinRAR archiver. This was reported by Trend Micro and Sekoia researchers.
A directory traversal flaw allows attackers to silently save malicious files outside the target folder during archive extraction—directly into the startup folder.
Experts note that the deep integration of an unpatched version of WinRAR into organizations' daily operations in Ukraine makes it an ideal entry point for hacking campaigns.
OpenClaw failed phishing tests
Varonis researchers tested OpenClaw as an AI agent for email handling and concluded that the system is vulnerable to techniques typically used against humans.
In the experiment, they simulated four phishing attacks and tested the agent's behavior in two configurations. For testing, OpenClaw was connected to Gmail, browser tools, Google Workspace API, and a set of synthetic internal data.
The framework was tested on Google Gemini 3.1 Pro and OpenAI GPT-5.4 in standard and "strict" modes with separate instructions for identity verification and anti-phishing procedures.
Dissatisfied researcher continued the "war" with Microsoft after patching previous vulnerabilities
Cybersecurity researcher pseudonym Nightmare Eclipse uncovered a new 0-day vulnerability in Microsoft Defender called RoguePlanet.
The exploit allows attackers to escalate privileges to SYSTEM level and execute arbitrary code even on fully patched Windows 10 and Windows 11 machines.
The incident is a continuation of a public conflict between the hacker and the IT giant. In April, Nightmare Eclipse promised to publish zero-day vulnerabilities after each patch released by Microsoft engineers. The June update patched several of his previous findings (GreenPlasma, MiniPlasma, and YellowKey), prompting the immediate release of RoguePlanet.
Cybersecurity firm ThreatLocker told BleepingComputer that they successfully reproduced the attack during their own testing. They confirmed that the exploit works on fully updated Windows 11 systems with the KB5094126 patch installed.
Korean tech giant fined $400 million for data breach
South Korea’s Personal Information Protection Commission (PIPC) imposed a record fine of 624.6 billion won (about $409 million) on tech giant Coupang following a large-scale data leak.
According to the regulator, insufficient security measures—including poor management of authentication keys and access controls—led to the exposure of personal data of approximately 37.55 million people. Coupang Fulfillment Service, a subsidiary, was separately fined 248 million won for illegal collection, use, and processing of customer personal and sensitive data.
PIPC also pointed out violations of data destruction and breach notification requirements, interference with an independent data protection officer, and obstruction of investigations.
The leak occurred in June 2025 but was only discovered in November. A month later, Coupang reported the compromise of 33.7 million accounts. Authorities say the main suspect is a 43-year-old Chinese national who worked in the company's IT division from 2022 to 2024.
Also on ForkLog:
What to read this weekend?
ForkLog explored how the Strategy business model works, why critics call it a pyramid scheme, and why supporters see it as an example of effective risk management.