Fake listings can turn trusted platforms into scam springboards | Malware
Recently, we found a listing on BuzzFeed from someone pretending to be Malwarebytes Support. It reminded us why we need to be cautious about content on platforms where anyone can…
Read moreNext.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE | Cybersecurity
Credit: Hacktron Vercel has released security patches for two critical-severity vulnerabilities in the Next.js web framework, both of which allow unauthenticated remote code execution, one exploitable via specially crafted AVIF…
Read moreFlock wants privacy to meet surveillance halfway | Malware
Flock Safety CEO Garrett Langley says the United States needs a “compromise” between privacy and public safety. It’s a neat phrase, except I don’t like to see “compromise” and “privacy”…
Read moreLearn How to Build Security Operations Ready for AI-Powered Attacks | Cybersecurity
The Hacker NewsAug 27, 2026Artificial Intelligence / Webinar Security teams have spent years trying to detect threats faster. AI is changing the harder part: how much time defenders have left…
Read moreAliExpress caught using silent audio to fingerprint visitors’ browsers | Malware
AliExpress, the online marketplace owned by Alibaba Group, has come under scrutiny after researchers and browser maker Brave reported finding silent Web Audio processing on the site that could help…
Read moreCISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs | Cybersecurity
Ravie LakshmananAug 27, 2026Vulnerability / Web Security The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added six flaws to its Known Exploited Vulnerabilities (KEV) catalog, including a high-severity…
Read morePopular school apps may be sharing student data with advertisers | Malware
A two-year investigation into educational technology (EdTech) apps used by Utah schools found that many were collecting and sharing student data in ways that appeared inconsistent with their privacy commitments….
Read moreFBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations | Cybersecurity
The U.S. Department of Justice (DoJ) on Wednesday announced the disruption of two hacking platforms named QScan and QTRouter operated by Chinese threat actors to target critical infrastructure and other…
Read moreUpdate Chrome before you browse again | Malware
Chrome is rolling out an update for its desktop browser. The update includes 327 security fixes, ten of which address critical vulnerabilities. The stable channel has been updated to 152.0.7977.64/.65 for Windows and…
Read moreNovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions | Cybersecurity
Cybersecurity researchers have disclosed details of a new adversary-in-the-middle (AitM) phishing toolkit called NovaCookies that’s used as a proxy to redirect Microsoft 365 sign-ins, while capturing authenticated sessions in the…
Read moreBeware of fake Indeed interview apps used to install spyware | Malware
From several independent reports, we’ve seen evidence of scammers using fake Android “interview” apps to target job seekers on the Indeed platform. Indeed is one of the world’s largest employment…
Read moreUnpatched Kaltura mwEmbed Flaws Could Let Remote Attackers Read Files and Run Code | Cybersecurity
The CERT Coordination Center (CERT/CC) has disclosed two unpatched vulnerabilities in Kaltura’s HTML5 video player library that allow a remote, unauthenticated attacker to read arbitrary files from a server and…
Read moreWARNING: Critical Microsoft SharePoint Exploit Chain Discovered | Windows
Attackers are actively probing internet-exposed Microsoft SharePoint servers for a newly documented vulnerability chain capable of bypassing authentication and delivering remote code execution, intensifying pressure on organisations that have not…
Read moreCritical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload | Cybersecurity
Ravie LakshmananAug 26, 2026Vulnerability / Cryptojacking The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday warned of active exploitation efforts targeting a recently patched critical security flaw impacting Gitea….
Read moreTikTok phishing: How to spot fake login and verification pages | Malware
Phishing pages don’t need to be sophisticated. They just need to look convincing enough to make you trust them. TikTok phishing often starts with an email or message designed to…
Read moreU.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure Breaches | Cybersecurity
The U.S. Department of the Treasury has announced fresh sanctions on Iranian cyber actors as part of what it called an “unprecedented, whole-of-government, economic campaign” against the nation and its…
Read moreGTA 6 leak hunt could expose data belonging to thousands of Discord users | Malware
Someone leaked footage of the upcoming game Grand Theft Auto (GTA) 6 this month, and the game’s publisher badly wants to know who. It’s after a range of data about…
Read moreA Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw | Cybersecurity
Oasis Security has disclosed a weakness in NVIDIA NemoClaw that could let an attacker-controlled webpage take unauthenticated control of the local Ollama instance serving an AI agent and plant hidden…
Read moreGrok fooled into stealing user chat, location data, and more | Malware
A new type of prompt injection attack shows why giving AI assistants access to browsers, code tools, and private data deserves extra caution. AI researchers describe “Cryptographic Context Injection”—an attack…
Read moreAttackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access | Cybersecurity
Ravie LakshmananAug 25, 2026Vulnerability / Web Security Bad actors are attempting to exploit two severe unauthenticated authentication bypasses in the Xecurify miniOrange SAML 2.0 Single Sign On plugin that make…
Read moreWhat happens to your data when you die? (Lock and Code S07E17) | Malware
This week on the Lock and Code podcast… You will die. Your data will not. The afterlife of our information is a recent phenomenon, and some of the companies with…
Read moreShipping More AI Code Than You Can Secure? Watch How to Control Remediation Debt | Cybersecurity
The Hacker NewsAug 24, 2026AI Security / Webinar If your developers are using AI coding tools, you are probably already seeing the upside: faster development, more code, and less time…
Read moreFake Microsoft security scans trick victims into uninstalling their antivirus | Malware
A wave of websites is offering to check whether your antivirus is working. They call themselves SysScan, carry Microsoft branding, and all reach the same conclusion: Your computer has serious…
Read moreWeedhack Malware Spreads via Fake Minecraft Clients and SEO Poisoning | Cybersecurity
Ravie LakshmananAug 24, 2026Malware / SEO Poisoning Cybersecurity researchers have found that several websites are still actively distributing a malware family known as Weedhack to gamers by masquerading as Minecraft…
Read moreFake GTA 6 Extended Look and demo sites deliver an infostealer | Malware
GTA 6 footage really has leaked online, and Rockstar has an official Extended Look coming to Netflix on August 27. But cybercriminals are exploiting the hype with fake Rockstar sites…
Read moreWordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords | Cybersecurity
Cybersecurity researchers have flagged two new malware families called WordlistLoader and SynkLoader that’s used to deliver next-stage payloads and likely sell access to ransomware groups. According to findings from Gen…
Read moreA week in security (August 17 – August 23) | Malware
Last week on Malwarebytes Labs: Zombie Card: An expired Visa credit card can be used for purchases Medical records, SSNs, and bank details exposed in CareCloud data breach ChatGPT for…
Read moreUAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit | Cybersecurity
Cybersecurity researchers have disclosed details of a Chinese-speaking cybercrime group dubbed UAT-10147 that’s targeting Windows and Linux web servers globally across the education, media, technology, and gaming sectors. The vast…
Read moreTikTok Agrees to $400 Million Settlement in U.S. Child Privacy Lawsuit | Cybersecurity
Ravie LakshmananAug 22, 2026Privacy / Regulation The U.S. Department of Justice (DoJ) announced on Friday that ByteDance-owned TikTok will pay $400 million to settle a 2024 lawsuit accusing the company…
Read moreA week in security (August 10 – August 16) | Malware
Last week on Malwarebytes Labs: Apple now uses iPhone alerts for targets of mercenary spyware WhatsApp is testing a new warning for scam messages New Android malware lets criminals use…
Read more