Nepal’s Flood Renews Warning Push, Plus 5 Tech Stories
A catastrophic flood in the Himalayas is renewing Nepal’s push for better cross-border warning data. Today’s Brief also covers stolen Claude sessions, browser extensions that turned malicious after people trusted them, a critical WooCommerce privilege-escalation flaw, Microsoft Defender’s very convincing false alarm, and NASA sending a new telescope toward deep space.
Nepal is pushing for better cross-border flood warnings after catastrophe
Nepal is asking for more frequent cross-border glacier and river data after last week’s catastrophic Himalayan flood killed more than 900 people and left thousands missing across Nepal and Tibet. The instinctive version of this story is that somebody failed to send an alert. The evidence is more complicated than that — and, frankly, more useful.
Nepali officials told Reuters that they had asked China in May for broader access to information on glacier movement, water levels and other hazards. China says it has shared information in a timely way and, twelve days before the disaster, warned Nepal about heavy rain and the possibility of landslides and flash floods. Experts quoted by Reuters are also explicit that limited data-sharing was not a significant cause of this particular disaster. A glacier broke apart in a remote, difficult-to-monitor area, and detecting that kind of failure before it happens is extraordinarily hard.
But look at what happened once the flood started. Surveillance footage showed the torrent hitting a Tibetan border crossing around 8:32 a.m. Nepal time. A border monitoring station stopped transmitting minutes later. Downstream stations also went silent, apparently because the flood destroyed them, and Nepal’s public mobile alert went out at 9:13. At least four monitoring stations were lost.
That doesn’t prove a better system would have prevented these deaths. It does show why Nepal wants one.
Nepal now plans to seek data from China as often as every 10 minutes, similar to an arrangement it already has with India. That’s the technology story here. Early warning isn’t just a sensor, a satellite or a weather model. The measurement has to exist, cross a border, reach the right agency, survive a disaster that may destroy the instruments themselves, and turn into a warning quickly enough for somebody downstream to act on it.
There is no magic dashboard that makes a glacier predictable. But when the hazard is moving downhill faster than the bureaucracy, shaving minutes out of that chain matters.
Technology is rarely just about the technology
Some of the most important technology stories aren’t product launches at all. They’re about health, privacy, education, law, accessibility, work, and what happens when technology reaches ordinary people. Browse more Raymond Tec News for the stories worth understanding without the hype.
Infostealers are stealing Claude sessions, not breaking Claude
Anthropic is warning some Claude users about a very different kind of stolen access: infostealer malware on their own computers copied active Claude login sessions, and attackers then used those sessions to consume account usage.
This is not evidence that Anthropic’s servers were breached, and it isn’t a Claude-specific piece of malware. Infostealers are general-purpose thieves. They grab passwords, browser cookies, login tokens and other credentials stored on a computer. According to emails Anthropic sent to affected users and reported by BleepingComputer, the company has seen Vidar, LummaC2, StealC, RedLine and Acreed on Windows, plus Atomic Stealer on a smaller number of Macs.
The important part is the session cookie. Two-factor authentication protects the process of logging in. A stolen session is, in effect, a copy of the proof that you already logged in. An attacker replaying a valid session may not need your password or a new 2FA code.
Anthropic is signing affected users out, removing saved payment methods and refunding charges it identifies as unauthorized. If you get one of these notices — or your Claude usage mysteriously refills and drains while you’re not using it — don’t just change the Claude password on the same machine and call it done. Treat the computer itself as potentially compromised. Revoke sessions, clean or rebuild the endpoint as appropriate, and change important credentials from a device you trust. Otherwise you can create a shiny new session for the same malware to steal again.
A trusted browser extension can become malware later
Browser extensions have a trust problem that is a lot harder to solve than “only install extensions with good reviews.”
Socket researchers found 19 Chrome and Edge extensions delivering a modular malware framework. Fourteen were apparently created by the threat actor. Five are more interesting: they began as legitimate extensions, built users and trust, were acquired by the attacker, and later received malicious updates.
The largest example, Enable Right Click & Copy — Smart Unlock + OCR, had about 70,000 Chrome users when malicious functionality appeared; a related Edge listing had around 10,000. Socket is careful to say that 80,000 is potential exposure, not 80,000 confirmed infected people.
The malware could maintain a WebSocket connection to command-and-control servers, strip Content Security Policy headers from pages, inject new JavaScript modules, steal wallet secrets and credentials, harvest browsing history and display fake browser-update instructions designed to trick people into running commands themselves. Chrome’s normal automatic extension updates are what make the ownership-change angle so ugly: yesterday’s harmless tool can become today’s malware without the user deciding to install anything new.
The five acquired extensions Socket identified are Enable Right Click & Copy — Smart Unlock + OCR, RapidLens, QuickLens, Password Protect PDF, and the Edge extension Allow Copy — Select & Enable Right Click. Socket’s report lists the other 14 and their extension IDs.
If any of these are installed, remove them and read Socket’s indicator list. If you used a malicious version while logged into important services, especially financial or crypto accounts, assume the extension may have seen considerably more than your browsing history. And as a general rule, periodically delete extensions you no longer need. “It was trustworthy when I installed it” is no longer enough.
Technical discovery & auditing
The public page doesn’t tell you much about the machinery behind it. Raymond Tec audits inherited and long-running projects to uncover the plugins, integrations, data, dependencies, and old decisions that determine what the next change will really involve.
A WooCommerce registration plugin can hand an attacker the administrator role
A newly disclosed WordPress flaw gives WooCommerce store owners a much simpler job: update one plugin.
CVE-2026-15369 affects Addify’s Custom User Registration Fields for WooCommerce through version 2.2.3 and carries a CVSS score of 9.8. The plugin can optionally let customers select a WordPress user role during registration. Wordfence found that, when that User Role Selection setting is enabled, an unauthenticated attacker can manipulate the WooCommerce Store API checkout request and supply a role the site owner never intended to offer — including administrator.
That’s the distinction worth keeping: this is not every WooCommerce store, and it isn’t even every installation of this plugin. The vulnerable configuration requires User Role Selection. But on a site that matches those conditions, “customer creates an administrator account at checkout” is about as subtle as a brick through the window.
Wordfence says version 2.2.4 fixes the problem, and the WooCommerce Marketplace now lists 2.2.4 as the current release. If you use this extension, update it and check your recent WordPress users for administrator accounts you don’t recognize.
WordPress security & maintenance
Keeping WordPress current is only part of keeping it healthy. Raymond Tec handles updates, backups, security monitoring, compatibility problems, access cleanup, and maintenance — plus the assorted weirdness that accumulates on a site over time.
Microsoft Defender’s “antivirus is off” warning may be wrong
Microsoft has also confirmed a much broader problem that is considerably less dangerous: current Defender updates can produce false notifications saying “Microsoft Defender Antivirus is turned off” even while Defender remains active and functioning normally.
Microsoft says the alert can occur on supported Windows client and server versions and may keep appearing even when notifications are disabled. A fix is planned in a future Defender update.
The useful advice here is not “ignore antivirus warnings.” Verify them. Open Windows Security or your normal management console and confirm Defender is actually active. If the protection status is healthy and the only problem is this specific notification, Microsoft says you’re looking at a known false alert. If the protection status also says Defender is off, that’s a different problem and deserves investigation.
NASA’s Roman telescope is on its way to survey the universe
And, because this week has supplied plenty of reasons to be suspicious of computers, NASA ended Sunday with one very good reason to be excited about one.
The Nancy Grace Roman Space Telescope launched from Kennedy Space Center at 7:26 a.m. EDT Sunday aboard a SpaceX Falcon Heavy and is now headed toward the Sun-Earth L2 point about a million miles away. Its 300-megapixel infrared Wide Field Instrument is designed to survey the universe roughly a thousand times faster than Hubble, studying dark matter, dark energy and planets beyond our solar system.
Roman is expected to send back about 1.4 terabytes of data every day, enough that machine learning, AI and citizen scientists will help astronomers sort through what it finds. NASA expects the first images in early 2027.
No patch to install. No account to reset. Just a new machine on its way to look at an absurd amount of the universe. That’s a pretty good place to end Monday.
Still in a reading mood? The Raymond Tec News archive covers security, AI, small-business technology, policy, and the places technology collides with ordinary life — without requiring a computer-science degree to get through it.
Sources / Further Reading
- Reuters: Nepal renews push for Chinese data and early warnings
- Reuters: Rescue effort continues after Himalayan flood
- ICIMOD: Rasuwa flood assessment and monitoring challenges
- BleepingComputer: Infostealers hijack Claude sessions
- Socket: 19 Chrome and Edge extensions deliver malicious payloads
- Wordfence: CVE-2026-15369
- WooCommerce Marketplace: Custom User Registration Fields
- Microsoft: Defender false notification known issue
- NASA: Nancy Grace Roman Space Telescope launches
