HBO Max’s verified Reddit account hijacked to spread malware | Malware
Researchers at Hudson Rock found that cybercriminals hijacked HBO Max’s verified Reddit account and used it to run 108 malicious ads over roughly 48 hours. The ads used HBO Max’s…
Read moreA week in security (September 7 – September 13) | Malware
Here’s what we’ve covered in the last seven days on Malwarebytes Labs: Crypto customers targeted by scammers after email marketing provider breach Android malware creates a hidden copy of your…
Read moreNew DDRop Attack Breaks Intel TDX and AMD SEV-SNP Confidential Computing | Cybersecurity
Researchers have disclosed a new hardware attack, called DDRop, that breaks the memory protection in Intel and AMD confidential computing by silently dropping writes to a server’s memory, so the…
Read moreGoogle’s new search redirects make links harder to check before you click | Malware
Google is changing how some links in its search results work. Instead of linking directly to the destination, Google has started routing some search result links through opaque google.com/goto?url=… redirects….
Read more3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials | Cybersecurity
Swati KhandelwalSep 14, 2026Network Security / Cyber Attack An attacker was operating inside the network of 3BB, one of Thailand’s largest broadband providers, and maintained remote control of internal machines…
Read moreAI Changed the Exposure Problem. Validation Needs to Change With It. | Cybersecurity
There’s a lot of noise around AI and cybersecurity right now. What’s actually important is far simpler, if often lost in the hubbub. Vulnerability discovery is getting faster and happening…
Read moreRevolut gave customer IDs and financial data to a government impostor | Malware
Revolut has acknowledged that it disclosed sensitive customer records to an unauthorized party. The company had accepted fraudulent information requests sent from an email address on a legitimate government agency…
Read moreMalicious Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users | Cybersecurity
Ravie LakshmananSep 14, 2026Malware / Browser Security A malicious cross-store Twitch browser extension has leaked OAuth tokens associated with nearly 31,000 users to proxy servers operated by a Russian commercial…
Read moreAttackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data | Cybersecurity
Microsoft has disclosed details of two campaigns in which threat actors are abusing third-party email delivery infrastructure to blast financial fraud scam messages and using passkey-themed social engineering to breach…
Read moreCISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV | Cybersecurity
Ravie LakshmananSep 12, 2026Vulnerability / Enterprise Security The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five security flaws impacting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its…
Read moreOpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers | Cybersecurity
The “major malicious attack” that targeted RubyGems in May 2026 was the work of a swarm of OpenAI agents, according to a new report published by researchers Spencer Kitts, Thomas…
Read moreCrypto customers targeted by scammers after email marketing provider breach | Malware
An attacker breached an email marketing platform and launched targeted attacks against the newsletter subscribers of some of its customers, especially those working in cryptocurrency and adjacent fields. The incident…
Read moreGitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure | Cybersecurity
Ravie LakshmananSep 11, 2026Vulnerability / Web Security GitLab has released patches to address multiple flaws, including a maximum-severity security vulnerability that has witnessed in-the-wild probes within hours of public disclosure….
Read moreAndroid malware creates a hidden copy of your banking app | Malware
Researchers at Group-IB found that the Android banking Trojan Gigabud can create a separate work profile on an infected phone and run a cloned banking app inside it. The attacker…
Read moreYour Critical Vulnerabilities Might Not Be Your Biggest Risk | Cybersecurity
Security teams have become exceptionally talented at finding vulnerabilities. Now, it’s time to turn our attention to optimizing the process for determining which of those vulnerabilities actually create a path…
Read moreAttackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors | Cybersecurity
Attackers have chained two flaws in JFrog Artifactory, the repository that software build pipelines pull from, to take administrator control of self-hosted servers and plant backdoors, cloud security company Wiz…
Read moreUpdate Chrome now to protect against an actively exploited vulnerability | Malware
Chrome is rolling out an update for its desktop browser. The update includes 230 security fixes, one of which is known to be actively exploited. The stable channel has been updated to…
Read moreWill AI kill us all within the next decade? | Malware
The Wall Street Journal reports that concerns are rising inside AI labs that competition is pushing tech companies to race toward self-improving models that could spiral out of human control….
Read moreThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Stories | Cybersecurity
Ravie LakshmananSep 10, 2026Hacking News / Cybersecurity News A lot of this week’s security news has the same awkward answer to one question: “Why was that allowed to work?” An…
Read moreBlueMoon exploit kit turns Chrome and Windows flaws into attacks | Malware
BlueMoon, a shared Chrome and Windows exploit kit, shows why “patch later” is becoming a dangerous gamble. Security updates are easy to put off. The browser still opens, Windows still…
Read moreCheck Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE | Cybersecurity
Check Point has patched two critical vulnerabilities in the way its firewall and management products handle VPN certificates. The company says both could allow an unauthenticated remote attacker to run…
Read moreCopyright scammers get Instagram accounts suspended and demand payment | Malware
Scammers are abusing Meta’s copyright-reporting system to suspend people’s Instagram accounts and then hold them for ransom, according to the BBC. Criminals file fake copyright complaints with Instagram, claiming that…
Read moreNearly 1 in 10 Exposed LiteLLM Gateways Accepted the Example “sk-1234” Admin Key | Cybersecurity
Nearly one in ten of the internet-facing LiteLLM servers that Wiz Research scanned in February accepted sk-1234, the example admin key in LiteLLM’s own setup guide. LiteLLM is an open-source…
Read moreThe push to stop algorithms controlling social media feeds has begun | Malware
Remember when social media was filled only with posts from your friends, rather than what an algorithm decided you wanted to see? So does the Australian government, and it wants…
Read moreU.S. Disrupts Xinbi Guarantee Scam Marketplace, Freezes $52.8 Million in Crypto | Cybersecurity
The U.S. Department of Justice (DoJ) on Wednesday announced coordinated actions aimed at an illicit online marketplace called Xinbi Guarantee that offered scam services, including seizing Telegram channels used to…
Read moreMore than 100,000 fake stores are out to steal your card details | Malware
Researchers at German cybersecurity company Nebty have identified “DoppelCart,” a cluster of almost 119,000 domains linked to copied online stores. The researchers describe it as the largest publicly documented fake-shop…
Read moreInfostealer Logs Expose Replayable AI Tokens That Can Bypass MFA | Cybersecurity
Cybercriminals are hijacking artificial intelligence (AI) user accounts via information stealer logs to create “stolen keys” that grant illicit access to tools from model providers like Google, Anthropic, and others….
Read moreWebinar: Learn How to Answer “Are We Exposed?” Faster After a New CVE | Cybersecurity
The Hacker NewsSep 09, 2026Security Operations / Artificial Intelligenc A major vulnerability is disclosed. The alert lands immediately. Then comes the harder question: Are we actually exposed? For many security…
Read moreMicrosoft fixes record 964 flaws, including 2 exploited zero-days | Malware
Microsoft’s September 2026 Patch Tuesday addresses 964 CVEs, including 104 rated Critical and 860 rated Important, making it the company’s largest Patch Tuesday release on record. Microsoft lists 974 CVEs…
Read moreMicrosoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days | Cybersecurity
Microsoft on Tuesday broke Patch Tuesday records by addressing an earth-shattering 974 vulnerabilities spanning its software portfolio, including two flaws that it said have been actively exploited in the wild….
Read more