Fake listings can turn trusted platforms into scam springboards | Malware

Recently, we found a listing on BuzzFeed from someone pretending to be Malwarebytes Support. It reminded us why we need to be cautious about content on platforms where anyone can…

Read more

Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE | Cybersecurity

Credit: Hacktron Vercel has released security patches for two critical-severity vulnerabilities in the Next.js web framework, both of which allow unauthenticated remote code execution, one exploitable via specially crafted AVIF…

Read more

Flock wants privacy to meet surveillance halfway | Malware

Flock Safety CEO Garrett Langley says the United States needs a “compromise” between privacy and public safety. It’s a neat phrase, except I don’t like to see “compromise” and “privacy”…

Read more

Learn How to Build Security Operations Ready for AI-Powered Attacks | Cybersecurity

The Hacker NewsAug 27, 2026Artificial Intelligence / Webinar Security teams have spent years trying to detect threats faster. AI is changing the harder part: how much time defenders have left…

Read more

AliExpress caught using silent audio to fingerprint visitors’ browsers | Malware

AliExpress, the online marketplace owned by Alibaba Group, has come under scrutiny after researchers and browser maker Brave reported finding silent Web Audio processing on the site that could help…

Read more

CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs | Cybersecurity

Ravie LakshmananAug 27, 2026Vulnerability / Web Security The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added six flaws to its Known Exploited Vulnerabilities (KEV) catalog, including a high-severity…

Read more

Popular school apps may be sharing student data with advertisers | Malware

A two-year investigation into educational technology (EdTech) apps used by Utah schools found that many were collecting and sharing student data in ways that appeared inconsistent with their privacy commitments….

Read more

FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations | Cybersecurity

The U.S. Department of Justice (DoJ) on Wednesday announced the disruption of two hacking platforms named QScan and QTRouter operated by Chinese threat actors to target critical infrastructure and other…

Read more

Update Chrome before you browse again | Malware

Chrome is rolling out an update for its desktop browser. The update includes 327 security fixes, ten of which address critical vulnerabilities. The stable channel has been updated to 152.0.7977.64/.65 for Windows and…

Read more

NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions | Cybersecurity

Cybersecurity researchers have disclosed details of a new adversary-in-the-middle (AitM) phishing toolkit called NovaCookies that’s used as a proxy to redirect Microsoft 365 sign-ins, while capturing authenticated sessions in the…

Read more

Beware of fake Indeed interview apps used to install spyware | Malware

From several independent reports, we’ve seen evidence of scammers using fake Android “interview” apps to target job seekers on the Indeed platform. Indeed is one of the world’s largest employment…

Read more

Unpatched Kaltura mwEmbed Flaws Could Let Remote Attackers Read Files and Run Code | Cybersecurity

The CERT Coordination Center (CERT/CC) has disclosed two unpatched vulnerabilities in Kaltura’s HTML5 video player library that allow a remote, unauthenticated attacker to read arbitrary files from a server and…

Read more

WARNING: Critical Microsoft SharePoint Exploit Chain Discovered | Windows

Attackers are actively probing internet-exposed Microsoft SharePoint servers for a newly documented vulnerability chain capable of bypassing authentication and delivering remote code execution, intensifying pressure on organisations that have not…

Read more

Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload | Cybersecurity

Ravie LakshmananAug 26, 2026Vulnerability / Cryptojacking The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday warned of active exploitation efforts targeting a recently patched critical security flaw impacting Gitea….

Read more

TikTok phishing: How to spot fake login and verification pages | Malware

Phishing pages don’t need to be sophisticated. They just need to look convincing enough to make you trust them. TikTok phishing often starts with an email or message designed to…

Read more

U.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure Breaches | Cybersecurity

The U.S. Department of the Treasury has announced fresh sanctions on Iranian cyber actors as part of what it called an “unprecedented, whole-of-government, economic campaign” against the nation and its…

Read more

GTA 6 leak hunt could expose data belonging to thousands of Discord users | Malware

Someone leaked footage of the upcoming game Grand Theft Auto (GTA) 6 this month, and the game’s publisher badly wants to know who. It’s after a range of data about…

Read more

A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw | Cybersecurity

Oasis Security has disclosed a weakness in NVIDIA NemoClaw that could let an attacker-controlled webpage take unauthenticated control of the local Ollama instance serving an AI agent and plant hidden…

Read more

Grok fooled into stealing user chat, location data, and more | Malware

A new type of prompt injection attack shows why giving AI assistants access to browsers, code tools, and private data deserves extra caution. AI researchers describe “Cryptographic Context Injection”—an attack…

Read more

Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access | Cybersecurity

Ravie LakshmananAug 25, 2026Vulnerability / Web Security Bad actors are attempting to exploit two severe unauthenticated authentication bypasses in the Xecurify miniOrange SAML 2.0 Single Sign On plugin that make…

Read more

What happens to your data when you die? (Lock and Code S07E17) | Malware

This week on the Lock and Code podcast… You will die. Your data will not. The afterlife of our information is a recent phenomenon, and some of the companies with…

Read more

Shipping More AI Code Than You Can Secure? Watch How to Control Remediation Debt | Cybersecurity

The Hacker NewsAug 24, 2026AI Security / Webinar If your developers are using AI coding tools, you are probably already seeing the upside: faster development, more code, and less time…

Read more

Fake Microsoft security scans trick victims into uninstalling their antivirus | Malware

A wave of websites is offering to check whether your antivirus is working. They call themselves SysScan, carry Microsoft branding, and all reach the same conclusion: Your computer has serious…

Read more

Weedhack Malware Spreads via Fake Minecraft Clients and SEO Poisoning | Cybersecurity

Ravie LakshmananAug 24, 2026Malware / SEO Poisoning Cybersecurity researchers have found that several websites are still actively distributing a malware family known as Weedhack to gamers by masquerading as Minecraft…

Read more

Fake GTA 6 Extended Look and demo sites deliver an infostealer | Malware

GTA 6 footage really has leaked online, and Rockstar has an official Extended Look coming to Netflix on August 27. But cybercriminals are exploiting the hype with fake Rockstar sites…

Read more

WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords | Cybersecurity

Cybersecurity researchers have flagged two new malware families called WordlistLoader and SynkLoader that’s used to deliver next-stage payloads and likely sell access to ransomware groups. According to findings from Gen…

Read more

A week in security (August 17 – August 23) | Malware

Last week on Malwarebytes Labs: Zombie Card: An expired Visa credit card can be used for purchases Medical records, SSNs, and bank details exposed in CareCloud data breach ChatGPT for…

Read more

UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit | Cybersecurity

Cybersecurity researchers have disclosed details of a Chinese-speaking cybercrime group dubbed UAT-10147 that’s targeting Windows and Linux web servers globally across the education, media, technology, and gaming sectors. The vast…

Read more

TikTok Agrees to $400 Million Settlement in U.S. Child Privacy Lawsuit | Cybersecurity

Ravie LakshmananAug 22, 2026Privacy / Regulation The U.S. Department of Justice (DoJ) announced on Friday that ByteDance-owned TikTok will pay $400 million to settle a 2024 lawsuit accusing the company…

Read more

A week in security (August 10 – August 16) | Malware

Last week on Malwarebytes Labs: Apple now uses iPhone alerts for targets of mercenary spyware WhatsApp is testing a new warning for scam messages New Android malware lets criminals use…

Read more
Update cookies preferences