Add your product or open-source project on TechLogHub
Listing is free. Sponsored featured placements are paid and priced in USD — open the pricing dialog to see plan details.
Loading...
Explore software products worth tracking, open-source projects worth studying, and blog coverage that helps builders spot useful tools and ideas sooner.
Listing is free. Sponsored featured placements are paid and priced in USD — open the pricing dialog to see plan details.
Analysis, product insight, and practical reads for builders

Microsoft confirms a new issue where security warnings for Remote Desktop (.rdp) files display incorrectly after the April 2026 updates, affecting Windows 11, Windows 10, and Windows Server. The problem is especially prevalent on systems with multiple monitors using different display scaling, causing unreadable text and misaligned buttons in the warning dialogs. The April 2026 safeguards introduce a one-time educational prompt, followed by a pre-connection security dialog that shows publisher status, remote address, and local resource redirections (all disabled by default). Unsigned RDP files trigger a "Caution: Unknown remote connection" warning. The article notes that threat actors have abused RDP files in phishing campaigns, including past use by the APT29 group.

Microsoft has resolved a global Outlook.com outage that affected users worldwide and now requires iPhone users to re-authenticate their accounts in the iOS Mail app to regain access. The company cited a recently introduced change as the cause but did not disclose specifics or the scope, with service returning to normal around 7 PM UTC on April 27, 2026. The report notes related past outages—such as March’s Exchange Online issues and Copilot sign-in problems—and ongoing Microsoft 365 reliability efforts.

Robinhood’s account-creation process was abused to inject HTML into onboarding emails, allowing phishers to embed a convincing “Unrecognized Device” message and direct users to a phishing site. Attackers used known customer email lists from prior breaches and Gmail dot aliasing to send emails from a legitimate noreply@robinhood.com address with SPF/DKIM, prompting users to review activity. Robinhood says the incident did not involve a system or account breach and has removed the Device: field from onboarding emails; recipients are advised to delete the message and avoid clicking links.

GlassWorm malware returns to OpenVSX with 73 “sleeper” extensions that look benign until they update, delivering a malicious payload. Six extensions are active so far; the rest appear dormant or suspicious. The extensions clone legitimate listings and function as loaders, fetching the payload from GitHub, loading platform-specific modules, or using obfuscated JavaScript at runtime. This wave signals a shift from embedding malware to delivering it on update. Researchers note the campaign previously targeted wallets and credentials and mid-March 2026 saw hundreds of repos affected; a full list of the 73 extensions has been published, and developers are urged to rotate secrets and clean their environments.
Subscribe to our newsletter for updates.