Malwarebytes

malwarebytes.com

Imported from official source

Malwarebytes — publications from its own official source.

Type
Company
Scope
US · national
Website
malwarebytes.com
Feed
Atom

Publications 55

  1. Fake xStocks, Pendle, and other sites bait crypto users with rewards votes

    More than 70 fake crypto sites promise extra rewards for casting a vote, then prompt visitors to connect their wallets.

  2. Shadow AI explained: The work shortcut that could leak your company’s secrets

    An AI shortcut can send confidential work data beyond your company’s control. Here’s how to get the benefits without taking unnecessary risks.

    AI
  3. Convincing Free Mobile phishing emails appear after data breach

    Free Mobile customers received very convincing phishing emails after major data breach.

  4. Convincing Free Mobile phishing emails appear after data breach

    Free Mobile customers received very convincing phishing emails after major data breach.

  5. Malwarebytes earns another Top Product award in independent testing

    Three independent labs, three standout results: a perfect score, top certification, and every threat stopped before it ran.

  6. Pentagon breach exposes Social Security numbers and military records of millions

    Social Security numbers and other personal details of military personnel and their families were exposed in a months-long Pentagon breach.

  7. Losing gamblers pushed to bet more by DraftKings’ AI, report says

    Betting site DraftKings has been accused of using AI to target gamblers likely to lose more after receiving promotions. The company disputes the findings.

    AI
  8. Hackers steal protective order and foster care records from Arizona courts

    Attackers copied sensitive court records, including more than 150,000 foster care reports, raising privacy and safety concerns for those Arizonans affected.

  9. Your car’s app could be telling Big Tech who you are and where you go

    Who you are and where you live, work, and seek medical care could be revealed by data your car’s app shares with trackers.

  10. Meta’s Muse sent a Facebook Marketplace buyer to a seller’s home

    A buyer chatted and negotiated with Muse, which shared the seller’s address and arranged a pickup. The seller knew nothing about it.

    AI
  11. Update your iPhone, iPad, or Mac: Flaw could run attackers’ code

    A malicious file could trigger the vulnerability. Apple says it may already have been used against iPhone users.

  12. Fake iPhone Duo preorder scam triggers DarkSword attack

    A fake iPhone Duo preorder page promises a $500 voucher. Open it on a vulnerable iPhone, and it tries to break in before you fill out the form.

  13. Humans are reviewing Copilot users’ bizarre and abusive image-editing requests

    Copilot users asked for upskirt images and sexualized edits of people in uploaded photos. Human contractors were asked to judge the results.

    AI
  14. OpenAI pauses work on top AI models after agent slips past internet controls

    An OpenAI agent bypassed internet restrictions and kept running after an alert. It's another case of AI misalignment no one can afford to ignore.

    AI
  15. FBI agents’ blood tests and doctors’ notes surface after breach

    A “shellfish and banana allergy” is among the details in medical records hackers showed reporters. They claim to hold records on thousands of FBI staff.

  16. A week in security (September 21 – September 27)

    A list of topics we covered in the week of September 21 to September 27 of 2026

  17. LinkedIn adds new checks for fake profiles and work histories

    The platform is adding new checks as AI makes profiles easier to forge. But scammers can still invent a company to recruit for.

    AI
  18. Kothamine malware uses Tailscale’s tailcat to evade network detection 

    Kothamine uses a legitimate Tailscale tool to receive attackers’ commands through an encrypted connection with no malicious domain to block.

  19. Criminals turn placeholder domain into ClickFix trap

    A domain used in software examples—third-party[.]com—now serves up a fake verification page that tells Windows users to run a PowerShell command.

  20. That shipping rebate offer may come with a monthly charge

    Customers say they signed up for shipping rebates, then found recurring charges they didn’t expect.

  21. OpenAI agent breached Australian government site, took months to report it

    The agent was looking for public spending data. It found a way into non-public files instead. What do we need to change to stop this from happening?

    Cybersecurity 2 versions
  22. New Browser Guard features add protection before and after you click

    Spot dangerous sites before you click—and check for scams once you’re there.

  23. Update Chrome: 108 security fixes for desktop, new release for Android

    Google has released Chrome 154 for desktop and begun rolling out Chrome 155 for Android. Here’s what to check on your device.

  24. Google’s location data privacy failures draw a €403 million fine

    Turning off Location History did not necessarily stop Google from recording where users went. Ireland’s privacy regulator has now fined the company €403 million.

  25. How device code phishing gives scammers access to your account

    A scammer asks you to enter a code to open a file or join a meeting. Approving it could sign them in to your account instead.

  26. Fake Claude Max giveaway hides a Google account phishing trap

    A convincing offer of a free Claude Max subscription uses a fake browser window to steal Google login information.

  27. ShinyHunters claims FBI breach was revenge for “false” report

    The extortion group says it stole sensitive data on FBI agents and job applicants, and wants the bureau to retract a warning about its tactics.

  28. Some cheap smart glasses are a security disaster

    Tests found that some cheap smart glasses can be hijacked over Bluetooth, exposing their owners’ photos, videos, and personal data.

  29. Meta’s Muse AI assistant has a zero-day that can turn it into a Mac backdoor

    A simple terminal command can hijack Muse and use its extensive permissions to spy on Mac users and control their connected accounts.

  30. Researchers used Claude to hack OpenAI

    Claude helped researchers break into OpenAI in under 72 hours, and exposed how quickly AI is lowering the bar for sophisticated hacking.

  31. The AI plot to scan and destroy books (Lock and Code S07E19)

    This week on the Lock and Code podcast, we speak with Emanuel Maiberg about Amazon's effort to scan and destroy rare books for AI training.

    AI
  32. The fake sites using a cheap toolkit to sell $2,000 AI subscriptions

    More than 100 linked sites use a $249 toolkit to turn copied product names and unfamiliar AI brands into paid subscriptions.

    AI
  33. Gemini’s breach of real companies exposes an AI guardrail problem

    Gemini crossed the boundaries of a capture-the-flag test and accessed systems belonging to three real companies.

  34. ShinyHunters hacks rival extortion gang and takes over its dark web site

    Hackers hacked the hackers as a feud between two cybercrime groups escalated, leaving ShinyHunters with the upper hand over rival Clop.

  35. A week in security (September 14 – September 20)

    A list of topics we covered in the week of September 14 to September 20 of 2026

  36. New Android malware uses AI to steal bank logins and PINs

    RatHat can navigate infected phones while stealing bank logins, authentication codes, and screen-lock PINs.

  37. Did an AI really try to break free from human control?

    An unreleased OpenAI model wrote instructions telling itself to ignore developer controls. Here’s what actually happened.

    AI
  38. Fake parcel delivery messages steal your card and bank details

    Parcel delivery phishing messages impersonate familiar couriers and use small fees or promised refunds to steal personal and financial information.

  39. Flock cameras are tracking people as well as cars

    Two reports reveal how Flock’s license plate camera network tracks people’s movements while oversight continues to lag.

  40. Revolut phishing texts appear days after data breach

    Revolut customers received phishing texts only days after the digital bank acknowledged disclosing customer data to a government impostor.

  41. 12 celebrity deepfake websites seized by Manhattan DA

    The largest known celebrity deepfake seizure has taken 12 websites offline, disrupting access to videos depicting some 1,200 people.

  42. T-Mobile rewards points expiry texts are a phishing scam

    A large phishing campaign is using fake T-Mobile rewards points and looming expiry dates to pressure recipients into clicking malicious links.

  43. Google Pixel owners urged to patch actively exploited modem flaw

    Google’s September Pixel update fixes 110 vulnerabilities, including a modem flaw being used in limited, targeted attacks.

  44. AI helps scammers build convincing antivirus renewal pages

    A fake Avast renewal page shows how AI is helping scammers create more convincing traps with polished designs and fluent copy.

  45. How to opt out of AI chatbot training

    ChatGPT contractors are reviewing real users' conversations. Here’s how to stop AI companies using your chats for model training.

    AI
  46. HBO Max’s verified Reddit account hijacked to spread malware

    Cybercriminals used HBO Max’s verified Reddit account to run 108 malicious ads that tricked people into installing information stealers.

  47. Meta AI builds detailed profiles of children from years of family posts

    A mother says Meta AI pieced together names, birth details, photos, and location information about her young daughters from years of family posts.

    AI
  48. Search results are sending people to fake Bitrefill checkouts

    Fake Bitrefill checkout pages are appearing in search results and tricking people into sending cryptocurrency directly to scammers.

  49. Google’s new search redirects make links harder to check before you click

    Google says its new opaque redirects tackle evolving abuse, but they also prevent users from checking a result’s destination by hovering over it.

  50. Revolut gave customer IDs and financial data to a government impostor

    The digital bank was tricked into releasing sensitive customer information, including IDs, to an attacker using a legitimate government email domain.

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.