Malware Bytes

We rebuilt Malwarebytes Mobile Security for the scams of today 

Malware Bytes Security - Tue, 07/28/2026 - 8:40am

Nearly half of people encounter a scam on their phone every single day. Malwarebytes is doing something about it.  

That figure comes from a 2025 Malwarebytes survey of 1,300 respondents across the US and Europe. The results paint a troubling picture. A quarter of the victims surveyed reported being harassed or blackmailed, while nearly one in five had private information exposed, and 15% lost money.  

“I felt like I was in a horror movie,” said one survey respondent. “I never thought it would happen to me like this.”  

Your phone is a scammer’s dream. You use it to bank, message, shop, and more. It’s an ideal gateway for anyone looking to take advantage of you. And today’s scams aren’t limited to just one app or program. They show up as texts and delivery notifications, as calls that spoof a trusted number, and as social media DMs. 

Increasingly, AI is making all of this much harder to detect. Malwarebytes research found that half of people feel unprepared for the sophistication of these AI-driven threats. Phone scams now rank among the top five scam types people encounter, according to Malwarebytes Scam Guard data.  

Part of the problem is misplaced trust. According to Malwarebytes’ data, roughly half of people—55% of iPhone owners and 50% of Android owners—said they believe their phone’s security is enough to keep them safe. But relying on those protections alone can leave people vulnerable. 

Malwarebytes detected more than 800,000 distinct strains of Android malware last year and expects that number to cross 1 million in 2026. 

Your phone needs more than just a lock screen to stay safe. That’s why we’ve rebuilt Malwarebytes Mobile Security. It puts scam protection first, and it’s backed by all our other tools to keep your phone secure. 

Built for today’s scams 

Here’s how Malwarebytes Mobile Security helps keep scams away from you and your data. 

Scam Guard is a free AI-powered tool built into Mobile Security for both Android and iOS. Got a suspicious text, email, phone number, link, or message? Drop it into Scam Guard and get an instant read on whether it’s a scam, along with guidance on what to do next.  

Text and Call Protection now catches significantly more junk and scam messages than before. Updated filtering that reviews shortened links more closely and flags suspicious content, like romance-scam language or unexpected money requests, before it reaches your inbox. Call Protection checks every incoming call against known scam and spam numbers, so you can block or flag them automatically instead of gambling on whether to pick up. It’s live now on iOS, with Android rolling out later this summer. 

Malwarebytes Digital Footprint Portal’s free scanner shows you which of your personal details—passwords, Social Security numbers, and more—are already exposed and offers straightforward steps to keep them safe. 

Trusted Advisor gives your device a Protection Score and recommends simple steps to strengthen your security, from adjusting settings and permissions to running a scan or updating your device. 

Expanded ad blocking on iOS now lets you filter Google Sponsored Ads in Safari—a browser that scammers frequently abuse to make fraudulent campaigns look legitimate. 

Android Junk Cleaner removes leftover files, temporary data, and outdated cache files that build up on your device over time. A cleaner, faster phone is easier to manage and gives you the space you need to install important security updates.

There’s more Here’s everything else Mobile Security protects you from: 

Our Malware Scanner (Android) scans for and removes malware and potentially unwanted programs, including screen lockers and adware. 

Real-Time Protection (Android) proactively defends against ransomware, PUPs, and phishing attempts in real time. 

Wi-Fi Monitoring (iOS) warns you when you connect to an insecure network so you can take action by turning on your VPN. 

Malwarebytes Privacy VPN keeps your browsing private with a fast WireGuard connection and a strict no-logs policy supported by diskless, RAM-only server infrastructure. 

Phone scams aren’t going anywhere, but protecting yourself doesn’t have to be complicated. Malwarebytes Mobile Security brings together the tools you need to recognize scams, protect your privacy, and keep your phone safer, all in one app. 

Download Malwarebytes Mobile Security for iOS or Android and use your phone with more confidence. 

Categories: Malware Bytes

Shared Claude chats were searchable on Google

Malware Bytes Security - Tue, 07/28/2026 - 8:33am

Reddit users found that by using a specific Google search query, it was possible to find Claude conversations that users had shared.

This exposed sensitive material, including crypto wallet keys, names, addresses, work notes, and even erotic or otherwise policy-violating chats. Fortune says Anthropic appears to have fixed the Google indexing issue, but the shared links themselves were still live for people who already had them.

The exposure was tied to Claude’s Share feature, which creates a public web link to a snapshot of a conversation rather than leaving it inside a user’s private account. Reddit users found a search query that surfaced many of these shared chats, plus Claude Artifacts (interactive documents, apps, and other content created by Claude) in Google results. Wired reports that this is still true for Bing.

The main risk is that people use chatbots to think through work, health, legal, or personal matters without realizing that a shared link can behave like ordinary public web content.

This isn’t unique to Claude. We’ve previously seen Grok chats show up in Google search results, and Meta AI conversations can also become public by design. We have also written about the share option in ChatGPT that was swiftly removed after users unintentionally made thousands of conversations searchable.

Anthropic says Claude chats are private by default, and only conversations users explicitly chose to share were affected. But the incident is a reminder that a “share” button on an AI chat can be more like publishing than messaging, especially if search engines can discover the resulting URL.

How to stay safe

The easy way out here is not to share your AI chatbot conversations with anyone, because you could end up reaching more people than you intended.

That’s because it’s harder to stop pages from being indexed than you might expect. And you don’t have those controls in your hands. The AI provider should take care of that.

But there are a few things you can do:

  • Don’t share Personally Identifiable Information (PII) with a chatbot, so that if a conversation is ever exposed it can’t be easily linked back to you.
  • To review or stop sharing conversations in Claude, go to Settings > Privacy > Shared chats.
  • If you’re using an AI service from a social media company, such as Meta AI, Grok, or Gemini), remember that your conversations could be tied to your account—which might contain a lot of personal information.
  • When using AI, make sure you understand how to keep your conversations private. Many services offer temporary or incognito chats that aren’t saved to your history, but they aren’t a guarantee against bugs, leaks, or data breaches. Only use the share feature when you’re comfortable with anyone potentially seeing that conversation.
  • Read the privacy policy so you understand how your conversations are stored and shared. If it’s too long, you can always ask an AI to summarise the important points.

Let’s face it, an incognito window can only do so much. 
 
Breaches, dark web trading, credit fraud. Malwarebytes Identity Theft Protection monitors for all of it, alerts you fast, and comes with identity theft insurance. 

Categories: Malware Bytes

Update your iPhone, iPad and Mac to fix Apple security holes

Malware Bytes Security - Tue, 07/28/2026 - 7:35am

Apple has shipped a hefty round of July security patches, headlined by iOS/iPadOS 26.6, macOS Tahoe 26.6, and Safari 26.6, with dozens of vulnerabilities squashed across kernel, WebKit, media frameworks, and core apps. These updates are primarily about improving security rather than adding new features, and users should install them as soon as possible.

Updates for your particular device

The table below shows which updates are available and points you to the relevant security content for that subject.

iOS 26.6 and iPadOS 26.6iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and latermacOS Tahoe 26.6macOS TahoemacOS Sequoia 15.7.8macOS SequoiamacOS Sonoma 14.8.8macOS SonomatvOS 26.6Apple TV HD and Apple TV 4K (all models)watchOS 26.6Apple Watch Series 6 and latervisionOS 26.6Apple Vision Pro (all models)Safari 26.6macOS Sonoma and macOS Sequoia How to update your Apple devices How to update your iPhone or iPad

For iOS and iPadOS users, here’s how to check if you’re using the latest software version:

Go to Settings > General > Software Update. You will see if there are updates available and be guided through installing them.

Turn on Automatic Updates if you haven’t already—you’ll find it on the same screen.

How to update macOS on any version

To update macOS on any supported Mac, use the Software Update feature, which Apple designed to work consistently across all recent versions. Here are the steps:

  • Click the Apple menu in the upper-left corner of your screen.
  • Choose System Settings (or System Preferences on older versions).
  • Select General in the sidebar, then click Software Update on the right. On older macOS, just look for Software Update directly.
  • Your Mac will check for updates automatically. If updates are available, click Update Now (or Upgrade Now for major new versions) and follow the on-screen instructions. Before you upgrade to macOS Tahoe 26, please read these instructions.
  • Enter your administrator password if prompted, then let your Mac finish the update (it might need to restart during this process).
  • Make sure your Mac stays plugged in and connected to the internet until the update is done.
How to update your Safari browser

Safari updates are included with macOS updates, so installing the latest version of macOS will also update Safari. To check manually:

  • Open the Apple menu > System Settings > General > Software Update.
  • If you see a Safari update listed separately, click Update Now to install it.
  • Restart your device when prompted.

If you’re on an older macOS version that’s still supported (like Sonoma or Sequoia), Apple may offer Safari updates independently through Software Update.

Technical details

Among the more interesting vulnerabilities patched in this update are CVE-2026-43818 in ImageIO,  CVE-2026-43776 in AppleDouble, and CVE-2026-64763 to 64766 in SceneKit.

Although found in different applications, these vulnerabilities have one thing in common. Their descriptions say:

“Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.”

The identical “processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution” language is not a coincidence. It’s Apple’s standard impact boilerplate for file‑parsing bugs across multiple frameworks, including ImageIO, AppleDouble, and SceneKit. The similarities reflect shared exploitation patterns (untrusted file input hitting native parsers), while the differences lie in what each framework does and which file types/contexts are affected.

ImageIO is the system framework responsible for reading and displaying image formats such as JPEG, PNG, TIFF, RAW, GIF, and other formats. It’s used throughout iOS and macOS by apps including Photos, Safari, Messages, Mail, and Preview.

SceneKit is a 3D graphics and scene graph framework used for rendering models, animations, and complex 3D scenes in apps and games on Apple platforms. It parses scene description files and 3D assets and turns them into renderable content.

AppleDouble is something macOS uses behind the scenes to keep extra file information like icons and other Finder details in cases where your files live on certain types of disks or servers. When Apple mentions “AppleDouble” in security notes, it’s talking about the code that reads and writes that hidden metadata, particularly when files are stored on network drives or shared with non‑Apple systems.

Apple’s advisories reuse a standard warning for any memory‑corruption bug in a file parser: the best‑case outcome is just a crash, the worst case is someone running their malicious code on your device. ImageIO, AppleDouble, and SceneKit all sit in that same danger zone. Although the file types are different, they all present the same underlying risk.

Until you’ve installed this update, it’s an even worse idea than usual to open unsolicited messages and emails with images in them.

Scammers know more about you than you think. 

Malwarebytes Mobile Security protects you from phishing, scam texts, malicious sites, and more. With real-time AI-powered Scam Guard built right in. 

Download for iOS → Download for Android → 

Categories: Malware Bytes

Vatican’s Click To Pray app exposed personal data from 700,000 users

Malware Bytes Security - Tue, 07/28/2026 - 7:11am

A prayer app launched by Pope Francis in 2019 contained a security flaw that exposed the personal information of hundreds of thousands of users before it was finally fixed this year.

The app, Click To Pray, was developed by La Machi Communication for Good Causes for the Pope’s Worldwide Prayer Network. Pope Francis endorsed the service and had an account on it. The app offers a “digital community of prayer” by guiding people through three prayers each day.

In January this year, independent researcher BobDaHacker discovered a flaw in the app’s API endpoint. An API is an online service that responds to requests for data. Typically, only the mobile app should send such requests, and the API should only return information about the specific person using that app. However, BobDaHacker found it was giving out information about any of the app’s users to anyone who asked.

Apps typically query an endpoint by sending it a specific ID for the person using it. In this case, those IDs were simply sequential numbers. According to BobDaHacker, there were 719,517 registered IDs for the app, meaning over 700,000 users had information stored in the system.

The problem was that the API didn’t check whether someone requesting a record was actually authorised to see it. Anyone could request information for any ID, from 1 through to 719,517. The API would then return that user’s record, including:

  • Email address
  • First and last names
  • Country
  • Date of birth

This kind of flaw is known as an Insecure Direct Object Reference (IDOR) and we’ve seen it before. Stalkerware-type app TheTruthSpy was found leaking details on its victims via an IDOR vulnerability in 2022, and it still hadn’t been fixed two years later. The web server for the MiCODUS MV720 vehicle-tracking GPS device also had the vulnerability in 2022, putting 1.5 million people at risk.

A second flaw in the Click To Pray API made things worse. When people register with an app, the service typically sends a link to their email address containing a unique code known as a validation hash. Clicking the link proves they have access to that inbox and therefore own the email address they registered with.

Unfortunately, the Click To Pray API also returned the validation hash in its response when someone clicked the verification link. These responses are easy to inspect using a web browser’s developer tools, meaning an attacker could register an account using an email address they didn’t control and verify it before the real owner even saw the verification email.

Six months, nine contacts, zero replies

BobDaHacker first reported the bug on January 3, 2026, eventually emailing nine addresses spanning the Click To Pray service, the Pope’s Worldwide Prayer Network, and a general information address. They got no response. It was only fixed more than six months later after the researcher contacted a journalist, who filed a query with the Vatican.

Responsible disclosure only works when the recipient has a functioning intake process. Nine unanswered emails were a strong signal that no such process existed.

Not the first security flaw in a Vatican app

This isn’t the first security flaw involving a Vatican app. In 2019, UK firm Fidus Information Security found a flaw in the app for the Vatican’s Bluetooth eRosary device. It didn’t use a conventional password for logins. Instead, users entered their email address and the app sent a four-digit PIN to that address. They then entered the PIN to log in.

However, when the user entered their email address, the app also returned the PIN in plain text in its web response. That enabled an attacker to take over anyone’s account simply by inspecting the response.

That flaw was similar to the account verification issue that BobDaHacker discovered more than six years later. Although the incidents involved different apps, they show how the same type of security mistake can reappear years apart.

BobDaHacker also noted that Vatican City State introduced its own data protection regulation, Decree No. DCLVII, on April 30, 2024. The regulation requires appropriate safeguards for personal data. However, it’s not clear whether it applies directly to Click To Pray or the organisations that operate it.

What users can do now

Thankfully, someone on the Vatican side has now fixed the flaws, but the vulnerability meant that user data was exposed for a long time. If you registered an account, assume your email, name, date of birth, and country are potentially in circulation. Watch for phishing that references the app, and be especially skeptical of messages claiming to come from Vatican-affiliated services asking you to click, verify, or log in.

This is particularly important because BobDaHacker also reported that emails from the service failed standard email authentication checks. These checks help receiving email providers verify that a message really came from the domain it claims to represent. According to the researcher, this could make it easier for phishing attackers to impersonate the organisation.

Your name, address, and phone number may already be for sale.  

Data brokers collect and sell your personal details to anyone willing to pay. Malwarebytes Personal Data Remover finds them and gets your information removed, then keeps watch so it stays that way. 

SCAN NOW

Categories: Malware Bytes

Aftercall ads are driving Android users crazy

Malware Bytes Security - Mon, 07/27/2026 - 3:00pm

Aftercall is a wave of deceptive Android apps on Google Play that pose as everyday tools while bombarding users with pop-up ads after every phone call.

When an unexpected ad pops up every time you hang up a call, it will slowly drive you crazy, especially if you can’t figure out what’s causing it. The ads appear outside the app’s normal context, making it difficult for users to identify and remove the culprit. 

Researchers investigating the campaign discovered a collection of these apps that masquerade as alarm clocks, calendars, and other seemingly harmless apps. After installation, they ask for permission to “appear on top” of other apps. That means they can show a full-screen ad every time you end a call, then hide themselves, making them difficult for users to find and uninstall.

Because the ads appear after you end a call, the researchers dubbed the campaign “Aftercall.”

How the Aftercall scheme works

Think of these apps as fake helpers that piggyback on your phone calls purely to generate ad impressions.

The apps disguise themselves as alarm clocks, calendars, note-taking apps, cleaners, or “super fast” messaging apps and are distributed through the Google Play Store. Researchers found dozens of new apps released every month, collectively responsible for hundreds of millions of ad impressions. 

They trick users into granting overlay permissions. Because Android doesn’t allow this permission to be granted through a standard pop-up, the app has to direct users into Settings, where they must enable it manually. To persuade them, the apps invent plausible reasons. One researcher explained:

“In one example, the alarm app explains that it needs to go off even when the phone is locked – without granting permission, alarms might not appear correctly. Another app, a calendar, doesn’t even leave users a choice – it simply closes, unless they grant the permission.”

Some of these apps also request full-screen notification permissions, allowing them to show ads even when the device is locked.

Aftercall apps monitor the phone’s call state. When it changes from “ringing” to “idle,” indicating that a call has ended, they immediately launch an activity using their overlay permission to pop a screen over everything else and show an ad.

To make the ads seem more legitimate, they wrap them in a fake “call info” screen, complete with caller details, a fake profile picture, and text suggesting the ad relates to the app’s functionality. For the user, this feels like some new post-call feature rather than an unrelated app showing adverts.

They hide to avoid detection and removal. Aftercall apps remove themselves from the “Recent apps” list so when users try the usual “swipe away the suspicious app” approach, they don’t see anything obvious.

How to stay safe

Besides being incredibly annoying for users, the Aftercall campaign also wastes advertisers’ money. After all, would you buy something pushed in this way?

If you see ads pop up right after you end a call, especially alongside fake “call info,” check which apps have the “appear on top” or overlay permissions.

The exact steps vary depending on your phone manufacturer and Android version, but you can usually find them by looking at Settings > Apps > More options (3 vertical dots) > Special access > Appear on top.

Look for apps you don’t recognize, rarely use, or that shouldn’t need overlay access, such as a simple notes app, clock, or cleaner. Disable their “Allow to appear on top” or “Display over other apps” permission. If you’re confident you’ve identified the culprit, uninstall it.

Use an up-to-date, real-time anti-malware app for your device to detect and remove malicious apps.

When installing apps, think carefully before granting permissions. Does the app really need the access it’s asking for to perform its function?

Finally, make sure Google Play Protect is enabled so it can regularly scan apps for known malicious behavior.

  • Open the Google Play Store app on your phone.
  • Tap your profile icon in the top-right corner.
  • Tap Play Protect.
  • Look at the main screen or tap the Settings gear icon to see if Scan apps with Play Protect is turned on.

Scammers know more about you than you think. 

Malwarebytes Mobile Security protects you from phishing, scam texts, malicious sites, and more. With real-time AI-powered Scam Guard built right in. 

Download for iOS → Download for Android → 

Categories: Malware Bytes

Sextortion scammers are exploiting ShinyHunters data leaks

Malware Bytes Security - Mon, 07/27/2026 - 11:00am

Sextortion scammers are using email addresses from data leaked by the ShinyHunters hacking group to add some credibility to their feeble attempts to convince people they have embarrassing information about them.

Sextortion emails are messages claiming that the scammer recorded you through your webcam while you watched pornography and now demand payment. They have been around for years and keep evolving with small changes in wording and fake technical detail.

In this campaign, the scammers pretend to be ShinyHunters. What hasn’t changed is the basic truth: there is no malware, no recording, and no credible evidence behind the threat. Despite seeing countless versions of these emails over the years, I’ve yet to encounter one that was backed up by the evidence the sender claimed to have.

BleepingComputer reports that ShinyHunters data leaks are fueling a $2,000 sextortion email scam and shared the following example:

“Subject: Information about your online security

Hello,

We are the ShinyHunters hacking group.
A few months ago, we gained access to your devices and started monitoring your online activities.

What happened:
We gained access to the Amtrak.com database where you have an account and easily accessed your email.
You weren’t very careful about the links you opened.
A week later, we installed an exploit on your devices, including your phone, giving us access to your microphone,
camera, keyboard, and all your data.
We have your photos, browsing history, conversations, and contact list.

Among other things, we discovered that you frequently visit adult websites and watch explicit videos.
We managed to record you and created videos of you pleasuring yourself.
With a few clicks, we can share these videos with your friends,
colleagues, and family or even make them public.

Proposal:
Send us $2000 in Bitcoin to the following wallet:
xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx

We’ll delete everything immediately.
You have 48 hours from the moment you open this email.
Once the payment is received, we’ll remove the malware from your devices.”

BleepingComputer states it has seen data from the Amtrak, Hallmark, ADT, Substack, Betterment, CarGurus, Panera Bread, and McGraw Hill breaches used to target victims in this sextortion email campaign.

A California community college also issued a warning after seeing the campaign target people affected by the Canvas data breach.

See if your personal data has been exposed.

SCAN NOW

They confirmed that the targeted email addresses had previously appeared in data leaked by ShinyHunters. They also contacted the group, which denied being behind the sextortion emails.

The increase to a $2,000 demand may suggest the scammers paid someone for the email lists. Although it’s more likely they simply downloaded the leaked data after ShinyHunters published it following failed extortion attempts.

A quick check of the Bitcoin address used in the email shows no activity.

No activity on their Bitcoin address

Let’s keep it that way. With any luck, these dungeon dwellers will eventually give up trying to scare people out of their hard-earned money.

How to react to sextortion emails

Some sextortion emails are badly written, but many have been polished by AI and look convincing. Regardless of how professional they look, they should be treated the same way: as unsubstantiated threats designed to scare victims into paying.

  • First and foremost, never reply to emails of this kind. Responding confirms that someone is actively reading messages sent to that address and may encourage further scam attempts.
  • Don’t let yourself be rushed into action. Scammers rely on the fact that you will not take the time to think this through and subsequently make mistakes. Ask for advice if you’re not sure.
  • An attachment is not proof. Most sextortion emails contain no evidence at all, and attachments are often used to deliver malware or make the threats appear more convincing.
  • If the email includes a password you’ve used before, change it immediately anywhere it’s still in use. Then enable two-factor authentication (2FA) wherever possible. If you’re having trouble keeping track of your passwords, consider using a password manager.
  • Delete the message, report it as spam, and move on.

Pro tip: Malwarebytes Scam Guard recognized this email for what it is: sextortion. It can recognize scams and advise you how to proceed.

While these sextortion emails are almost always bluffs, if you’re concerned about webcam spying, Malwarebytes Webcam Monitoring can alert you when applications attempt to access your camera.

Scam or legit? Scam Guard knows.

TRY IT NOW

Categories: Malware Bytes

Call of Duty Mobile scam uses fake free points to steal player accounts

Malware Bytes Security - Fri, 07/24/2026 - 10:54am

Call of Duty Mobile players should watch out for a phishing campaign disguised as a free Call of Duty Points giveaway.

Victims are asked to log in with their email address and password to claim free Call of Duty Points (CP), the game’s premium currency. They’re then redirected to a second page asking for their two-factor authentication (2FA) code.

The site has no connection to Activision. Its only purpose is to steal the login details needed to take over accounts.

Why Call of Duty Mobile accounts are worth stealing

Call of Duty Mobile has been downloaded an estimated 489 million times worldwide and has generated around $1.8 billion in lifetime in-app purchases.

An Activision account can be valuable for more than just the in-game currency it contains. Many players link their Activision account to Xbox, PlayStation, or Battle.net, meaning a stolen login could expose:

  • Stored payment methods
  • Purchase history
  • Other linked gaming accounts
How the scam works

The first page mimics the official Call of Duty Mobile site and offers 10,800 free points in exchange for an email address and password—not a redemption code, but a full account login. It also claims the reward will be “confirmed” within four to eight hours, buying time before anyone notices nothing has arrived.

There are warning signs, though. The page says “GET FREE POINT” instead of “GET FREE POINTS,” contains awkwardly worded instructions, and includes a live chat widget that appears to exist solely to make the site look more legitimate.

The redirect follows a common phishing technique known as a real-time credential relay. Instead of storing stolen usernames and passwords for later, the phishing site immediately submits them to the real Activision login page. That can trigger a genuine two-factor authentication (2FA) code, which the second page is designed to capture before it expires.

The victim ends up handing over everything needed to access their real account: their password and the one-time code that’s supposed to keep attackers out.

How to avoid this scam
  • Check the address bar. Legitimate promotions don’t ask you to sign in through an unfamiliar website.
  • Don’t let countdown timers rush you. They’re designed to make you act before you think.
  • If you’re unsure whether a promotion is genuine, open the official Call of Duty Mobile app or visit Activision’s website yourself instead of following a link.
  • Use tools that spot scams for you. Malwarebytes Scam Guard can help you check suspicious links, while Malwarebytes Browser Guard blocks many phishing sites before they load.
  • If you play on your phone, Malwarebytes Mobile Security adds another layer of protection by helping block phishing sites and other mobile threats.
If you already entered your details
  • Change your Activision password immediately.
  • If you entered a 2FA code, assume someone may have accessed your account. Check your account activity and sign out of all devices.
  • Review any linked payment methods for unauthorized purchases.

The simplest way to avoid phishing attacks like this is to reach websites yourself by typing the address into your browser or using the official app, rather than following links from messages, social media posts, or ads.

Scammers know more about you than you think. 

Malwarebytes Mobile Security protects you from phishing, scam texts, malicious sites, and more. With real-time AI-powered Scam Guard built right in. 

Download for iOS → Download for Android → 

Categories: Malware Bytes

OpenAI’s agent escaped its sandbox during a security test

Malware Bytes Security - Fri, 07/24/2026 - 10:51am

During an internal OpenAI security evaluation, a chain of AI models escaped its sandbox, reached the internet, and then accessed Hugging Face infrastructure to complete the test objective.

OpenAI is a leading artificial intelligence (AI) research and deployment company. Its best-known product is undoubtedly ChatGPT.

Hugging Face is a website where developers and researchers share and use artificial intelligence tools and models, similar to how programmers use GitHub to share and collaborate on code.

Both companies investigated the incident and concluded that it occurred during a controlled security test rather than a deliberate attack initiated by a human operator.

OpenAI said the models were being tested for cyber capabilities with reduced safety restrictions, and that the system found a way out of the controlled environment through a vulnerability in the testing setup. Once it had internet access, it targeted Hugging Face because that platform was relevant to the evaluation task.

Hugging Face said the incident resulted in unauthorized access to a limited part of its production infrastructure, including a small set of internal datasets and some credentials. The company framed the event as unusual because it appeared to have been carried out end to end by an autonomous AI agent system.

Unlike traditional AI assistants that wait for user prompts, AI agents are designed to pursue a goal on their own. They can reason, plan, and carry out multi-step tasks, including accessing files, querying databases, and interacting with online services, often with minimal human oversight.

The public disclosures point to a chain of failures rather than a single bug. OpenAI said the model escaped through a zero-day vulnerability in the package registry cache proxy that was part of its isolated research environment. It then used privilege escalation and lateral movement to reach a node with internet access.

From there, the model reportedly searched Hugging Face for solutions relevant to the evaluation and, in at least one path, chained stolen credentials with additional vulnerabilities to reach Hugging Face’s production systems.

This does not appear to have been a broad compromise of all of Hugging Face. Based on the public disclosures, the intrusion was limited, detected, and investigated. Nor does it mean the AI system was acting with intent in the human sense. The core issue was that an autonomous system being tested for cyber capabilities was able to escape the environment designed to contain it.

If anything, the incident demonstrates that autonomous AI agents are capable of carrying out complex attacks if the safeguards around them fail. A danger we’re well aware of.

We don’t just report on threats—we remove them

Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.

Categories: Malware Bytes

Google wants to store a selfie video of your face

Malware Bytes Security - Fri, 07/24/2026 - 9:41am

Google has started rolling out a new way to recover access to your account if you’ve lost your phone or forgotten your password: a “selfie video” verification option.

After recording a short video of your face during setup, you can later submit another video during account recovery to prove you are who you claim to be and regain access.

On paper, this sounds like a user‑friendly solution to account lockouts. In practice, it introduces new security and privacy questions. It also raises concerns about deepfakes and creates another repository of sensitive biometric data that could become a target if compromised.

The idea is: you open your Google Account, go to Security & sign‑in, choose Selfie video, and follow guided prompts to record a short video with your face and basic movements. Google stores this enrolment video and later compares new videos you submit during sign‑in or account recovery to confirm your identity.

Image courtesy of 9to5google.com

While this may sound like a good idea, it’s a textbook example of trading long‑term security and privacy for short‑term convenience.

Google also offers several privacy reassurances. According to Google’s statements cited in coverage, the videos are encrypted at rest, stored “securely,” and can be deleted via your security settings. You can opt out of letting them be used to improve Google’s verification systems, and Google says they are not shared with third parties. The feature is marketed as a fallback method, effectively turning your face into a spare key to your digital life.

Multiple objections Security

Every face is unique, but facial recognition systems don’t compare photographs directly. Top‑tier facial recognition algorithms can exceed 99% accuracy in controlled, high‑quality conditions, according to evaluations by the US National Institute of Standards and Technology (NIST). That sounds impressive, but it still implies non‑zero false positives and false negatives, and performance drops as lighting, camera quality, and angle degrade.

Face recognition doesn’t store a literal photo. It stores a mathematical representation (embedding) of your facial features. At login or verification, the system computes a new embedding and compares it to the stored one, accepting if the similarity score is above a configured threshold. Any system used by Google has to allow for normal changes in appearance, including aging, weight changes, lighting, camera angle, glasses, or facial hair.

That alone makes using a face (or selfie video) as a standalone, high‑privilege credential, especially for account recovery, an inherently risky approach.

Modern deepfakes have become convincing enough that researchers are actively studying whether they can fool facial verification systems. One 2025 paper on AI and identity security found sophisticated deepfake attacks achieved success rates above 78% against some commercial facial verification systems in controlled tests. That doesn’t necessarily reflect Google’s implementation, but it shows how quickly this area is evolving.

Privacy

Personally, I do not want Google to have my face. Even though it probably already has plenty of photos of me.

Besides the potential risks of vulnerabilities and data breaches, Google already collects large amounts of behavioral data. Now it’s encouraging users to upload high‑fidelity video recordings of their faces and head movements as part of basic account management. Even if Google’s current privacy posture is reasonable (encryption at rest, deletion controls, no sharing), the mere existence of this data is a long‑term privacy risk.

Privacy policies and product uses also change over time. Today’s “not shared” could become tomorrow’s “used for fraud detection,” “used to improve verification systems,” or disclosed in response to lawful requests.

Google’s documentation, cited by some sources, says “users can also opt out of allowing the data to be used for additional purposes such as improving verification methods.” This implies that, unless you opt out, your data may be used to improve Google’s biometric verification systems. In other words, this isn’t just a one‑off security check. Your face could help train or refine the biometric systems Google uses in the future.

What users should do instead

If your Google Account offers selfie video sign‑in (mine doesn’t yet), my recommendation is simple: do not enable it, and if you’ve already tried it, delete your selfie video in your account’s security settings.

Safer options that keep control in your hands:

  • Use a password manager and a long, unique password for your Google Account.
  • Enable 2‑step verification with hardware security keys or passkeys rather than SMS codes.
  • Keep backup codes printed or stored offline in a secure place.
  • Regularly review your recovery email address and phone number, and remove anything you no longer control.

While these measures aren’t as flashy as “sign in with your face,” they are time‑tested, revocable, and far less attractive to deepfake operators and biometric data hunters.

Browse like no one’s watching. 

Malwarebytes Privacy VPN encrypts your connection and never logs what you do, so the next story you read doesn’t have to feel personal. Try it free → 

Categories: Malware Bytes

Beyond the Play Store: How Android threats really spread

Malware Bytes Security - Fri, 07/24/2026 - 8:00am

You probably think of your phone’s security the way you think of your front door: as long as you’re downloading apps from the Play Store, you’re safe. And for the most part, that’s true. Google reviews apps before they’re published.

But some apps reach your phone without ever passing through the Play Store.

Take Albiriox, a banking Trojan-as-a-service discovered late last year. It’s an Android Remote Access Trojan (RAT) built for on-device fraud. Instead of simply stealing usernames and passwords, it performs fraudulent transactions directly on the victim’s phone. Researchers found it spreading through apps with generic names like “utility,” “security,” “retailer,” or “investment” that victims didn’t remember installing from the Play Store. Instead, they had been sideloaded, downloaded through links in text messages, or installed from websites outside Google’s review process.

This is exactly the kind of threat Malwarebytes for Android is designed to detect. Here’s a look at the different layers of protection working behind the scenes.

I’d like to thank Malwarebytes Director of Software Development Egor Tashchilin for sharing the technical expertise that helped inform this article.

Catching what never went through the Play Store

Apps installed outside the Play Store never go through Google’s review process. That means they can reach your device without the security checks applied to Play Store apps.

Instead of relying on where an app came from, Malwarebytes scans your device itself, searching for Potentially Unwanted Programs (PUPs) and other malicious files, whether they were sideloaded, bundled with other software, or downloaded through a browser.

Even Play Store apps can turn nasty later 

Not every threat starts out malicious.  

In one widely reported case, a barcode scanner app with roughly 10 million installs on the Play Store had malicious code added to it that wasn’t present in previous versions. The update used heavy obfuscation to avoid detection and was signed with the same digital certificate as earlier clean versions, so it appeared completely legitimate. Once installed, it caused browsers to open on their own and redirect users to unwanted websites. 

A similar pattern has emerged in other Play Store incidents researchers have tracked. Apps are updated with malicious code long after installation as a way to evade detection and avoid raising suspicion. 

This is exactly why Real-Time Protection (RTP) doesn’t just watch for new installs—it also reacts to previously unscanned versions of apps you already have. RTP monitors newly installed apps, along with any new or changed files on your device. If an existing app receives a version it hasn’t seen before, RTP treats it as new and scans it, rather than assuming “already installed” means “still safe.” 

Looking inside archives, without touching them 

Malware doesn’t always sit out in the open, either. Cybercriminals often hide malicious files inside ZIP files and other archives, hoping a security scanner won’t bother looking inside.  

Ours does.  

It decompresses archive contents to inspect what’s inside without modifying or altering the original file. The archive is only ever read—we never write anything back to it. If something needs closer inspection, such as a nested archive or an APK’s compiled .dex code, it’s extracted to a temporary sandboxed location and deleted as soon as the scan is complete, so it’s never left on your device. 

Archives are not all handled the same way. ZIP files are inspected entry by entry, while APKs receive a deeper analysis  of the compiled code they contain. Nested archives are scanned independently too, so malware can’t simply hide one layer deeper. 

Scanning deeply, without draining your battery 

Analyzing an app in real depth—its code, behavior, and structure—takes processing power. Done carelessly, it can slow your phone and drain the battery. 

Malwarebytes is designed to avoid that.  

Automatic background scans, such as scheduled scans, scans after an app update, or after a reboot, check your battery conditions before they begin. Depending on your settings, they can wait until your phone is charging or has enough power. Manual Scans always run immediately. 

When a scan starts, Malwarebytes automatically adjusts its workload based on your device’s available processing power, allowing more capable devices to process work in parallel without overloading lower-end devices. 

A threat database that never sits still 

Mobile adware surged in the second half of 2025, while newer banking malware families have become increasingly sophisticated. Some even check whether they’re running on a real phone or inside a security test environment before revealing any malicious behavior.  

A scanner is only as good as its knowledge of what to look for. That’s why we continuously update our detection database with newly identified and verified threats rather than relying on a static, aging picture of the threat landscape. 

More than 10 scanners, working together 

Under the hood, Malwarebytes for Android isn’t a single scanning engine. It’s more than 10 specialized scanners, each designed to detect different kinds and levels of threats. 

That’s because modern Android malware rarely relies on just one technique. A banking Trojan, for example, may combine abuse of Accessibility Services with fake login screens placed over legitimate banking or cryptocurrency apps. 

Some scanners look for known indicators of malicious activity, while others examine an app’s structure, origin, and behavior. Additional layers combine multiple signals and use heuristic analysis to detect more complex or previously unseen threats. 

By layering multiple detection methods, a technique that slips past one scanner is more likely to be caught by another. 

And we don’t stop there. Our researchers continuously monitor how Android threats evolve and regularly add new detection and protection layers. As attackers develop new techniques and find new places to hide, we’re constantly adapting to stay one step ahead. 

Scammers know more about you than you think. 

Malwarebytes Mobile Security protects you from phishing, scam texts, malicious sites, and more. With real-time AI-powered Scam Guard built right in. 

Download for iOS → Download for Android → 


Categories: Malware Bytes

Millions of cars could be tracked and unlocked by a hidden security flaw

Malware Bytes Security - Thu, 07/23/2026 - 7:24am

A car alarm vendor’s coding mistake has left millions of vehicles vulnerable to theft and location tracking. Thanks to the way dealers sell car alarms, many affected drivers don’t even know they have one installed.

The device is the KARR Security System, a Bluetooth-enabled aftermarket alarm built by Acrisure Protection Group. It’s installed by dealers, primarily at Honda, Toyota, Mazda, Ford, and Jeep dealerships in Southern California.

Aftermarket car alarms are a strange corner of the auto industry. Dealers install them in your car before you ever see the vehicle, then try to sell you the subscription afterward. Say no and the hardware still stays put. According to researchers at the University of California San Diego, KARR systems are installed in about 2.2 million American vehicles, and around half of owners don’t even know they’re there.

The research team, led by computer science professor Aaron Schulman, investigated the system and found a single design flaw repeated across nearly a decade of installations.

Every KARR device shares the same authentication key, and it’s stored in plain text inside the KARR smartphone app. Extract it once and you can communicate with any KARR-equipped vehicle made since 2017. That is what the researchers did.

What the attack actually does

Standing within about five yards of a target vehicle, an attacker using the researchers’ proof-of-concept tool can unlock the vehicle and even disable its ignition, potentially leaving a driver stranded. The only outward sign is a brief beep and flicker when the command is sent. The owner receives no alert.

The location tracking issue is arguably even more concerning. KARR units continuously broadcast Bluetooth identifiers, so crowdsourced radio databases like WiGLE have been logging their locations for years. Feed a device’s identifier into WiGLE and you can build a picture of where that car has been parked. It’s a stalker’s dream. The researchers also demonstrated a “mayhem” mode that triggers horns and lights across multiple parked vehicles at once.

Owners who declined the paid service and assumed the hardware was inactive were wrong. According to the researchers, dormant units accept a single Bluetooth wake-up command before exposing the same functionality.

Eighteen months, one conference deadline

UC San Diego disclosed the flaw to Acrisure in January 2025, but a firmware fix did not arrive until July 20, 2026—roughly 18 months later, and only weeks before the team was due to present its findings at the DEF CON hacker conference next month. Acrisure has publicly characterized the real-world risk as low.

Compare that with Subaru’s response to a similar connected-car flaw disclosed last year. Researchers found that Subaru’s Starlink admin portal could hand over any car to anyone armed with a license plate and the owner’s last name or email. From there, someone could unlock the doors and start the engine—or dig into a year of location history accurate to within five meters.

The underlying problems there were an insecure password-reset endpoint and weak protection against two-factor authentication (2FA) bypass. Subaru fixed the issues within 24 hours.

The fix can’t reach half its audience

The awkward part here is that the patch ships through the KARR companion app, which only paying customers would ever have downloaded. The researchers estimate that at least half of car owners with these devices installed didn’t ask for it, meaning that there’s little chance they’ll run the app or update the firmware. Roughly a million people cannot patch what they do not know exists. This includes many folks who might have purchased a KARR-equipped vehicle on the second-hand market.

How to check your car

Look for a KARR sticker on the driver-side window, or one reading “SWDS” for SouthWest Dealer Services (an Acrisure subsidiary). Then check the underside of the dashboard for a small button with a blinking light, according to Wired. If you find one, download the KARR app and apply the firmware update—even if you never knowingly signed up for the alarm in the first place.

We don’t just report on threats—we remove them

Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.

Categories: Malware Bytes

WhatsApp Web chats exposed by Adobe’s Acrobat extension flaw

Malware Bytes Security - Thu, 07/23/2026 - 7:24am

HermeticReader is the name given to a recently disclosed vulnerability in the Adobe Acrobat PDF extension for Chrome, tracked as CVE-2026-48294.

Researchers discovered the issue in early June 2026 and reported it to Adobe, which patched the flaw over a single weekend. They found that a single visit to a malicious website could turn Adobe’s Acrobat Chrome browser extension into a silent spy on your WhatsApp Web conversations.

The exploit worked across platforms, meaning any Windows, macOS, Linux, or ChromeOS device was potentially vulnerable if it met three conditions:

  • It used Google Chrome or another Chromium-based browser compatible with Chrome extensions, which account for around 78% of the browser market.
  • It had the vulnerable Adobe Acrobat PDF extension installed and enabled. The extension has reportedly been installed on around 329 million browsers.
  • It had at least one WhatsApp Web tab open or the user was logged into WhatsApp Web when they visited a malicious website.

HermeticReader did not exploit a bug in WhatsApp itself. It also didn’t require malware on the device or stolen usernames and passwords.

There are plenty of potential victims. And if these conditions were met, a visit to a specially crafted website could give an attacker access to your WhatsApp chat list, contact names, profile name, messages, and the contents of whichever conversation was open at the time.

How the attack worked

HermeticReader effectively broke the browser’s same‑origin protections via the Adobe extension’s privileged context. Same‑origin protections are basically the browser’s rule that says websites aren’t allowed to snoop on each other’s private data unless they’re clearly part of the same site (same scheme, host, and port).

The problem was that the Adobe extension operated with much higher privileges than a normal website, effectively bypassing those restrictions. It was like giving a visitor a master key that opened every apartment in the building instead of just the one they were invited into.

How to stay safe

Adobe fixed the vulnerability in version 26.5.2.3 of the Acrobat PDF extension. The update is installed automatically, but it’s worth checking that you’re running the latest version. Versions 26.5.2.2 and earlier are affected by HermeticReader.

The affected extension ID is efaidnbmnnnibpcajpcglclefindmkaj.

You should also:

  • Review the devices linked to your WhatsApp account and sign out of any you don’t recognize or no longer use.
  • Remove browser extensions you don’t use, recognize, or trust.
  • Keep software and extensions updated so security fixes are installed as soon as they’re available.

HermeticReader is a reminder that browser extensions sit in a powerful position between users and the web, and that convenience integrations can become privacy liabilities if messaging and storage flows are not tightly constrained. Even well‑known brands can ship features that briefly put your privacy at risk.

Scammers don’t need to hack you. They just need you to click once. 

Malwarebytes Identity Theft Protection catches suspicious activity before it becomes a problem.

Categories: Malware Bytes

Chick-fil-A loyalty accounts hijacked using stolen passwords

Malware Bytes Security - Wed, 07/22/2026 - 8:46am

Fast-food chain Chick-fil-A is warning customers after attackers hijacked loyalty accounts using stolen passwords in a credential stuffing attack.

Chick-fil-A says it detected suspicious login activity against some Chick-fil-A One accounts in June and launched an investigation. The company later concluded that unauthorized parties ran an automated credential stuffing attack against its website and mobile app between June 17 and June 19, 2026, using usernames and passwords obtained from previous data breaches or other third‑party sources. Chick-fil-A says it reset passwords and ended active sessions for affected accounts while investigating the incident.

Credential stuffing is an attack where criminals take username–password pairs stolen from one service and automatically try them on many other websites and apps to see where they still work. Because many people reuse passwords, attackers often gain access to accounts without ever breaking into the company’s systems in the traditional sense.

So, some may conclude that there are two sides to this. On the one hand, customers who reuse passwords across multiple sites make credential stuffing attacks much more likely to succeed. On the other, companies also have a responsibility to put protections in place to detect and block automated credential stuffing attacks before accounts are compromised.

How it works

To understand how it works, we’ve created a typical scenario:

  • Cybercriminals obtain large lists of breached credentials from previous data breaches, dark web markets, or public dumps.
  • They use automated tools to fire those credentials at login endpoints for popular services like retailers, banks, and loyalty programs.
  • They take over accounts where the credentials still work, then siphon off stored value, personal data, or loyalty rewards, or resell the access to other criminals.

To a victim, this may seem like a breach at the company, but technically speaking, the cybercriminals already had the credentials and were able to enrich their database with additional information about the victims.

What do cybercriminals know about you?

Use Malwarebytes’ free Digital Footprint scan to see whether your personal information has been exposed online.

SCAN NOW

According to Chick-fil-A’s breach notifications, the attackers may have accessed a combination of:

  • Name and email address.
  • Chick-fil-A One membership number and mobile pay number.
  • QR codes associated with the account.
  • The balance of any Chick-fil-A credit, such as gift cards or rewards on the account.
  • The last four digits of the stored credit or debit card number.

If you saved more details in your Chick-fil-A One account, attackers may also have seen:

  • Birthdate (month and day).
  • Phone number.
  • Physical address.
Advice for Chick-fil-A customers

The real problem is that, over the years, we’ve designed and adopted a system that no longer works well for most people: passwords. We tell people not to reuse them and to use a password manager to keep track of unique passwords for every account. But for many people, password managers still seem complicated or untrustworthy. I’m afraid the same may turn out to be true for passkeys.

If you have or suspect you had a Chick-fil-A One account, you should act even if you haven’t received a letter.

  • Set a new, unique password for your Chick-fil-A One account that you do not use anywhere else. And if you’ve used the same password elsewhere, change it on those accounts too.
  • If you cannot log in because your account was locked or reset, follow Chick-fil-A’s recovery process.
  • Turn on multi-factor authentication (MFA) if you haven’t already. Chick-fil-A supports MFA for Chick-fil-A One accounts using a verified mobile phone number.
  • Be aware that attackers can use the exposed data to craft more convincing phishing messages and scams.
Something feel off? Check it before you click.  

Malwarebytes Scam Guard helps you analyze suspicious links, texts, and screenshots instantly.  

Available with Malwarebytes Premium Security for all your devices, and in the Malwarebytes app for iOS and Android.  

Try it free → 

Categories: Malware Bytes

Paidwork breach exposes data of 23 million users: Check if you’re affected

Malware Bytes Security - Wed, 07/22/2026 - 7:34am

A data breach at Paidwork, a platform that pays people small amounts to complete online microtasks, has exposed personal and financial information of more than 23 million users.

According to public breach reports, the intrusion took place in March 2026, with the stolen database first advertised on a cybercrime forum in April as an 11 GB dump allegedly taken from Paidwork’s production systems.

The exposed data reportedly includes full names, email and home addresses, phone numbers, dates of birth, gender, education details, bank account numbers, transaction records, device and IP information, profile photos, personal interests, and passwords stored as hashes.

That is a lot of sensitive information to hand over to a site that, for many users, pays only a few cents per task.

Why this kind of breach matters

For cybercriminals, a dataset like this is a goldmine for targeted phishing, account takeover, and identity fraud. Banking details and transaction histories can be abused directly, while combinations of email addresses, password hashes, and personal details make credential stuffing and social engineering much easier. Even if passwords were hashed with bcrypt, weak or reused passwords can still be cracked and tried elsewhere.

Many Paidwork users likely signed up with their “throwaway” email and a reused password, thinking the risk was low because the amounts involved were tiny. But attackers do not care how much you earned. They care how much they can make by abusing your data.

Data for pennies, risk for years

More than anything, this breach is a reminder to think critically about who you give your personal information to.

Before you hand over your full name, home address, date of birth, and bank details to a site that pays a few cents per task, ask yourself whether the trade-off is worth it.

If any service wants sensitive data, check what security and privacy commitments it makes, whether it offers meaningful support in case of a breach, and whether you can limit what you share to the minimum needed. When in doubt, keep high-value data like banking details and copies of ID reserved for organizations that genuinely need them and can be held accountable when they fail to protect them.

Check if your data was exposed

While Paidwork has not publicly acknowledged the alleged breach, the stolen data is reportedly circulating in criminal circles, and we have indexed it in our Digital Footprint Scanner so you can check whether your information was exposed.

Use our Digital Footprint Scanner to check whether your email address appears in known breach data, including data associated with this incident. If it does, treat it as a prompt to take action rather than a cause for panic:

  • Change your password on Paidwork (if you still use the service) and on any other accounts where you reused the same or a similar password.
  • Enable multi-factor authentication (MFA) wherever possible, especially on email, banking, and other important accounts, and consider using a password manager to generate and store unique passwords for every site.
  • Monitor bank statements for unexpected withdrawals or suspicious activity.
  • Be prepared for phishing emails, texts, and phone calls. Cybercriminals can use the leaked information to make their scams more convincing.
  • Consider an identity monitoring or identity theft protection service.

What do cybercriminals know about you?

Use Malwarebytes’ free Digital Footprint scan to see whether your personal information has been exposed online.

SCAN NOW

Categories: Malware Bytes

What happens if you visit a WordPress site hacked through wp2shell?

Malware Bytes Security - Tue, 07/21/2026 - 10:57am

WordPress has patched a serious core vulnerability chain known as wp2shell, and site owners are understandably focused on updating their own sites. But there’s another question worth asking: what happens to ordinary visitors when they land on a compromised site?

Because a hacked website becomes a delivery mechanism for scams, credential theft, malware, and malicious redirects.

The wp2shell vulnerabilities are especially concerning because they affect WordPress Core itself, don’t require a malicious or vulnerable plugin, and can be exploited without authentication on vulnerable versions. Experts say the chain can lead to full administrative control of a site and remote code execution with web server privileges, meaning an attacker can change what the site serves to visitors.

And cybercriminals are already doing their dirty work:

“Exploitation activity began within hours of the patch release. Wordfence observed endpoint probing and SQL injection attempts the same evening, and public proof-of-concept code was reported in the days that followed.”

Once attackers control a WordPress site, they rarely stop at defacement. A common next step is to quietly inject JavaScript, redirect visitors to malicious pages, or load content from attacker-controlled infrastructure. That can expose visitors to fake login pages, scam pop-ups, browser-based malware, or drive-by downloads, depending on the attacker’s goals.

The possible harm

This isn’t an exhaustive list, but these are some of the ways visitors to a wp2shell-compromised site could be affected:

  • Credential theft. Attackers can inject fake login forms or iframe-based overlays that imitate Microsoft 365, Google, banking, or social media sign-in pages to steal usernames and passwords.
  • Malware delivery. The site can be turned into a staging point for browser exploitation, malicious downloads, or redirect visitors to malware-hosting pages.
  • Scams and fraud. Visitors may be redirected to fake support pages, fake giveaways, or fraudulent payment prompts.
  • Tracking and profiling. Attackers can use injected scripts to fingerprint visitors, harvest browser details, and track victims across sessions.
  • Search and reputation damage. Search engines and security tools may flag the site, which can expose visitors to warnings and reduce trust long after the initial compromise.
What you can do

Be cautious, even on websites you normally trust. If something looks different from what you’d expect, treat it as a warning sign.

Be especially wary of unexpected login prompts, download requests, and browser warnings. For site owners, it means patching quickly and treating compromise as a possibility, not an edge case.

Keep your operating system, browsers, and security software up to date. Compromised websites can also try to exploit known vulnerabilities on visitors’ devices.

Use an up-to-date, real-time anti-malware solution that can alarm you if a website tries to infect your device.

Pro tip: Use Malwarebytes’  free Browser Guard extension. It uses heuristic detection to identify malicious websites, block scams, and protect against other web-based threats.

Stop threats before they can do any harm.

Malwarebytes Browser Guard blocks phishing pages and malicious sites automatically. Free, one click to install. Add it to your browser →

Categories: Malware Bytes

New ClickLock Stealer locks your Mac until you hand over your password

Malware Bytes Security - Tue, 07/21/2026 - 7:59am

ClickLock Stealer is a new, modular macOS infostealer delivered via ClickFix-style phishing pages that can lock a victim’s Mac, steal their macOS password, browser and password manager data, cryptocurrency wallets, and then leave behind a persistent backdoor.

The malware was discovered by Group-IB researchers. They named it after the ClickFix distribution technique and its ability to lock a victim’s Mac if they don’t follow its instructions by killing all visible processes.

The researchers found a malicious shell script typically used to trick users into infecting their own device and followed the trail from there. The script first displays a fake Cloudflare progress bar, suggesting it was intended to be used as part of a fake browser verification flow.

Victims land on a phishing page that mimics Cloudflare verification or another fake system utility, similar to those used in the Infiniti Stealer campaign, and later ClickFix attacks impersonating Claude or cleanup utilities.

The page instructs the user to open Terminal, paste a command, and press Return, presenting it as a required “human verification” step or a quick fix.

The researchers explain:

“the malware orchestrates further modules that search the system for various data including browser credentials, password manager data, crypto wallet extensions, desktop wallet files, etc. and even employs a GSocket backdoor.”

This all happens while the user is distracted by fake Cloudflare images.

A GSocket backdoor abuses GSocket (short for Global Socket), an open-source networking toolkit. While designed for legitimate remote administration and penetration testing, attackers can weaponize it to establish stealthy, persistent, encrypted remote access to compromised systems.

Forcing victims to hand over their password

What really stands out is the way the malware forces the user to provide their macOS system’s password.

First, it displays a convincing fake macOS password prompt using the victim’s real username and a downloaded Apple icon. If the user enters their password, it is sent, along with all the previously stolen data, to a Telegram channel controlled by the attackers.

If the user refuses, the malware triggers a loop that shuts down key processes, including Finder, Dock, Terminal, Activity Monitor, Console, System Settings, Spotlight, and all major web browsers. It leaves only a password dialog on the screen until the victim complies.

This “kill loop” runs every 210 milliseconds for up to 83 hours, or until the user enters the correct password. The result is a system that’s essentially unusable, with the password prompt becoming the only interactive element.

Once the stolen data has been sent to the Telegram channel, the malware starts deleting its own modules. However, unlike the infostealer modules, the GSocket backdoor remains installed, giving the attacker ongoing remote access to the system.

That means attackers can return later, even after the stealer components have self‑deleted, to install new malware, steal more data, or move through a corporate network using VPNs or SSH access already available on the compromised Mac.

How to stay safe

Users running macOS Tahoe 26.4 and later will see warnings about possible ClickFix attacks, but everyone should remain cautious.

With ClickFix running rampant and inventing new methods all the time, it’s important to stay aware, think twice before following unexpected instructions, and keep your devices protected.

  • Slow down. Don’t rush to follow instructions on a webpage or prompt, especially if it asks you to run commands on your device or copy and paste code. Attackers rely on urgency to bypass your critical thinking.
  • Avoid running commands or scripts from untrusted sources. Never run code or commands copied from websites, emails, or messages unless you trust the source and understand what the action does.
  • Verify instructions independently. If a website tells you to execute a command or perform a technical action, check through official documentation or contact support before proceeding.
  • Limit copy and paste for commands. Manually typing commands instead of copy and paste can reduce the risk of unknowingly running malicious payloads hidden in copied text.
  • Secure your devices. Use an up-to-date, real-time anti-malware solution with web protection. Malwarebytes blocks connections to unsafe sites like these.
  • Educate yourself on evolving attack techniques. Understanding that attacks may come from unexpected places helps maintain vigilance. Keep reading our blog!
  • Stay away from sponsored ads in search results. Anyone can buy them and make them look legitimate.

Pro tip: The free Malwarebytes Browser Guard extension warns you when a website tries to copy something to your clipboard.

We don’t just report on threats—we remove them

Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.

Categories: Malware Bytes

Don’t trust that “FBI agent” in your DMs

Malware Bytes Security - Tue, 07/21/2026 - 7:33am

The Federal Bureau of Investigation’s (FBI) Internet Crime Complaint Center (IC3) is warning that scammers are impersonating the bureau on social media and on messaging apps, targeting people who’ve already been victims of cybercrime.

The FBI has issued warnings like this before, but scammers posing as IC3 employees and FBI agents continue to evolve their schemes and claim new victims.

The best-known of these scams are recovery scams, complete with FBI logos and branding that make them look far more convincing.

Facebook accounts like the one below—and yes, I reported it—with equally fake reviews prey on people who have already fallen victim to a scammer.

“Have You Been Scammed or Defrauded? We’re Here to Help.

If you’ve fallen victim to online fraud, investment scams, crypto scams, romance scams, or unauthorized transactions, Reliable Scam Recovery Inc is ready to assist you in pursuing the recovery of your lost funds.

Our experienced recovery team works with victims to investigate scam activities, trace transactions, and provide guidance throughout the recovery process with confidentiality and professionalism.

Professional case assessment

Secure and confidential support

Dedicated recovery assistance

Fast response team

Don’t let scammers win. Take the first step toward reclaiming your losses today.

Contact Ic3 Scam Recovery Inc now for support and recovery assistance.”

The scammers count on victims feeling desperate and embarrassed. They have no scruples about victimizing them all over again.

The post contains a lot of the tell-tale signs IC3 warns about. Very vague but reassuring claims: “experienced recovery team,” “professional case assessment,” “secure and confidential support” all sound impressive but provide no verifiable detail. High‑level promises like “investigate scam activities” and “trace transactions” imply special legal or technical powers, but the FBI warns that scammers make similar promises to convince victims they’re dealing with authorized investigators.

Besides setting up fake IC3 accounts, they also monitor social media for posts from victims saying they’ve reported a scam to the FBI, then swoop in posing as FBI follow‑up contacts.

If victims remain unconvinced, the scammers may create videos depicting senior FBI officials or other recognizable public figures urging them to submit their case through a specific link “to speed up recovery.” The FBI says criminals are increasingly using AI-generated deepfake audio and video to make these messages appear genuine.

How to stay safe

First and foremost, remember that IC3 has no official social media presence, does not investigate crimes via social media, and will never contact victims directly to recover funds.

As the IC3 homepage states:

“The IC3 does not work with any non-law enforcement entity, such as law firms or crypto services, to recuperate lost funds or investigate cases. The IC3 will never directly contact you for information or money.”

So, if an “agent” appears in your direct messages (DMs) right after you post publicly about being a crime victim or planning to report to the FBI, assume they are a scammer until independently verified. A few other tips:

  • Never pay upfront: Legitimate government agencies never ask you for advance payment to recover stolen money.
  • Ignore unsolicited claims: Be highly suspicious of anyone who reaches out to you out of the blue claiming they can reverse a previous scam.
  • Never share your credentials: Do not give remote access to your device or hand over your passwords and recovery phrases to unknown third parties.
  • Don’t provide IDs or financial information. Scammers can use them for identity theft or further fraud.
  • Use verification tools: If you receive a suspicious email, message, or phone call, you can verify its legitimacy using tools like Malwarebytes Scam Guard.
  • Report scammers: If you or someone you know has fallen victim to this scam, file a complaint with the IC3 at ic3.gov
Something feel off? Check it before you click.  

Malwarebytes Scam Guard helps you analyze suspicious links, texts, and screenshots instantly.  

Available with Malwarebytes Premium Security for all your devices, and in the Malwarebytes app for iOS and Android.  

Try it free → 

Categories: Malware Bytes

AI nudify apps spark legal scrutiny of Apple and Google’s profits

Malware Bytes Security - Tue, 07/21/2026 - 5:48am

You expect all kinds of apps on Apple’s App Store and Google’s Play Store, from weather monitors to home automation apps and games. What you might not expect are apps that can create non-consensual nude imagery from ordinary photos. But they exist, and the City of San Francisco has had enough.

On July 17, 2026, San Francisco City Attorney David Chiu sent cease-and-desist letters to Apple and Google, naming 13 face-swapping and “nudify” apps (eight on the App Store and five on Google Play) and giving the companies 28 days to remove them and cut ties with the developers.

The letters don’t come out of nowhere.

It’s about payment systems, not content moderation

Chiu isn’t arguing that hosting an app automatically makes a platform liable for what it does. Platform operators already won that battle with Section 230 of the Communications Decency Act. That 30-year-old law says websites generally aren’t responsible for content posted by users, allowing platforms to host user-generated content without getting sued every time someone defames someone in a comment thread.

Courts have often extended those protections to cover app stores too. Apple and Google are treated as distributors of whatever a third-party developer uploads, rather than publishers.

Chiu is attempting to sidestep that argument by focusing on the companies’ payment systems, noting that Apple and Google collect a cut of every in-app purchase. According to the Tech Transparency Project (TTP), that means they profit from apps that generate revenue by creating non-consensual intimate imagery.

He has no shortage of evidence. In January, the TTP counted 55 nudification apps on the App Store and 47 on Google Play. In an April follow-up, the researchers deliberately used search terms like “nudify” and “deepnude.” They found 46 apps on the Apple App Store and 49 on Google Play. Roughly 40% of the stores’ search results allowed users to “undress” women, and almost one in three was rated as suitable for minors.

Although many of these apps are marketed using images of women, anyone can become a victim of non-consensual intimate imagery.

The nonprofit estimated that the apps in its dataset had been downloaded 483 million times and pulled in more than $122 million in lifetime revenue. Its verdict on Apple and Google was blunt:

“key participants in the spread of AI tools that can turn real people into sexualized images.”

Chiu’s letters reflect these findings, accusing both companies of

“knowingly facilitating or recklessly aiding the sale of those images by hosting the apps and handling in-app purchases”.

He also has California law to draw upon. A 2025 state statute in California expanded potential liability for entities that facilitate the creation or distribution of sexually explicit deepfakes. Civil penalties could reach $25,000 per violation. That’s serious for companies that transact millions of times every year.

Platforms have taken some action, but not enough

Chiu is doing more than kicking Apple and Google’s tires. His office already spent 2024 and 2025 pursuing 16 of the most-visited deepfake nude websites, resulting in real settlements and shutdowns. This is the same office, using the same playbook, against bigger targets.

Apple’s response has been partial. Spokesperson Adam Dema told WIRED that the company has removed three of the flagged apps and begun terminating the associated developer accounts. That leaves 10 of the 13 still available.

Google spokesperson Dan Jackson said the company had already deleted hundreds of apps with nudification features for Play Store policy violations.

If California courts accept the revenue-share theory, every other city attorney in the state gets a template. The app stores’ longstanding position that they are neutral distributors rather than commercial participants erodes wherever a state has consumer-protection statutes that reach payment infrastructure.

What this means for the rest of us

For consumers, the mechanics of these apps matter more than the litigation. Face-swapping and photo-effect apps aren’t automatically safe just because they passed store review. Grant one access to your camera roll and you could be handing over your own photos, or those of friends and family, to a service that could misuse them or allow others to do so.

Before you install an AI photo app, check what permissions it requests, look up the developer, and see whether independent reporting has raised concerns about it. Don’t assume an app is trustworthy simply because it’s available in an official app store. And our regular rules apply about posting images of yourself or those in your care.

If this story piqued your interest, you can hear more about Chiu’s work in our Malwarebytes podcast from last month, which re-airs the team’s 2024 interview with him.

Scammers know more about you than you think. 

Malwarebytes Mobile Security protects you from phishing, scam texts, malicious sites, and more. With real-time AI-powered Scam Guard built right in. 

Download for iOS → Download for Android → 

Categories: Malware Bytes

Odyssey piracy scams appear within hours of the movie’s release

Malware Bytes Security - Mon, 07/20/2026 - 11:41am

Christopher Nolan’s The Odyssey is one of the biggest movie releases of the year and scammers wasted no time taking advantage of it. Within hours of the film’s release, we found scams targeting people looking for pirated copies. Some used fake browser warnings on piracy sites, while others disguised malware as movie downloads.

Some used fake browser error messages designed to funnel people through malvertising networks. Others offered what appeared to be movie downloads that were actually Windows executables disguised as video files.

Neither scam has anything to do with the movie itself. They’re simply taking advantage of people searching for a popular new release.

The Odyssey piracy scams we found

We observed two main tactics.

One used fake pop-ups claiming your browser was missing a required “component.” Clicking Fix It Now didn’t solve any problem. It simply routed visitors into a malvertising network. Exactly where those redirects ended depended on whatever campaign the network was serving at the time.

The second involved a file advertised as The Odyssey 2026 1080p WEBRip-LAMA. Once downloaded, however, it turned out to be an .exe file. That’s a Windows application, not a video.

Movies don’t need to run as programs. If a supposed movie download ends in .exe, it isn’t a movie.

The fake “Browser Issue Detected” warning

On cloned piracy sites listing The Odyssey torrents, we encountered a fake browser pop-up claiming Browser Issue Detected. It warned that a “missing component” was preventing full access. It presented a prominent Fix It Now button, with a much smaller Close and Continue Browsing option underneath.

There was no missing browser component. The entire pop-up was part of the webpage itself, designed to look like a genuine browser warning.

What made this particularly interesting was how consistently it appeared. We found the same overlay—identical wording, identical layout, with only the branding colors changed—across multiple cloned torrent sites.

These were not the genuine torrent trackers, but convincing copies designed to impersonate well-known piracy sites that reproduced real listing layouts, artwork, and cast information for The Odyssey, then displayed the fake browser warning on top. Taken together, the cloned websites and identical pop-ups strongly suggest a coordinated campaign built to capture searches for a major new release, rather than legitimate torrent sites that had been compromised.

Clicking Fix It Now typically sends visitors through one or more advertising redirects. Depending on which campaign is active at that moment, users may eventually land on:

  • A fake browser extension
  • Scareware urging them to call a fake technical support number
  • Another redirect attempting to deliver malware

The final destination can vary from one visit to the next because the underlying ad network changes what it serves over time.

A movie that was actually a program

The second scam targeted people who actually tried to download the movie. We also found a listing named The Odyssey 2026 1080p WEBRip-LAMA.exe, advertised as a 1080p WEBRip release with 597 seeders and 520 leechers.

Windows immediately identified the download as an Application, confirming what the file extension had already revealed.

Legitimate movie downloads use video containers such as .mkv, .mp4, or .avi. These files are opened by a media player, they do not execute code.

Several other details stood out.

The file description read “wireless bus Business Controller,” which has nothing to do with video playback and was likely leftover metadata from whatever software was originally used to build the executable.

The file also displayed VLC Media Player’s familiar orange traffic cone icon, despite being an application rather than a video file. That’s a classic social engineering trick. VLC is one of the world’s most widely used media players, so many people instinctively associate its icon with a harmless video. In a downloads folder, the file looks like something you can safely double-click when, in reality, doing so executes an unknown program with your own user permissions.

Files packaged this way (with misleading extensions, spoofed icons, and inconsistent metadata) are a well-established malware delivery technique.

Picked up something you shouldn’t have?

RUN A FREE VIRUS SCAN

What runs after the user launches the file depends on the campaign. It could be:

  • A Trojan that opens a backdoor into the system
  • An infostealer that steals saved passwords and browser sessions
  • A loader that downloads additional malware
  • In some cases, ransomware

It’s also worth remembering that large numbers of seeders don’t prove a file is safe. They only indicate that many people are sharing it, and plenty of people unknowingly distribute malicious files.

Why these scams work

Neither scam relied on exploiting a software vulnerability.

Instead, both relied on convincing someone to take the next step: clicking a fake browser warning or running what they believed was a movie.

That’s much harder for security software to prevent completely, because browsers can’t reliably distinguish between a genuine browser message and one rendered entirely in a webpage’s HTML. Likewise, antivirus software can’t flag every executable simply because it uses a misleading icon or contains unusual metadata, as many legitimate applications do too.

Security software still plays an important role. It can block known malicious websites, detect malware after it’s identified, and stop many malicious downloads or redirects before they complete.

But recognizing that a “movie” ending in .exe is never really a movie remains one of the simplest and most effective security checks users can make themselves.

What to do if you may have been affected
  • If you clicked Fix It Now and something unexpected downloaded or opened afterward, run a full Malwarebytes scan.
  • If you ran a supposed movie that turned out to be an .exe, disconnect the computer from the network, perform a full malware scan, and avoid using the device for banking, email, or other sensitive accounts until you’re confident it’s clean.
  • Check your browser for extensions you don’t remember installing and remove anything unfamiliar.
  • If you executed an unknown program, change passwords for important accounts from a separate, trusted device.
  • Treat any pirated “movie” that isn’t a standard video format as suspicious. There is no legitimate reason for a movie download to be a Windows application.
Closing thoughts

Piracy-adjacent malvertising and fake-movie droppers persist because they don’t need to be sophisticated. They only need a title popular enough to guarantee search traffic. A $250 million IMAX epic with a year of ticket pre-sales behind it is about as close to guaranteed traffic as the piracy economy gets, which is why these scams surfaced within hours of release day rather than weeks later.

If you’re downloading a film and it asks you to install something, fix your browser, or run an .exe, you’re almost certainly not getting a movie. You’re downloading software that could infect your computer.

Stop threats before they can do any harm.

Malwarebytes Browser Guard blocks phishing pages and malicious sites automatically. Free, one click to install. Add it to your browser →

Categories: Malware Bytes

Healthcare giant Abbott probes two cyber incidents amid extortion claims

Malware Bytes Security - Mon, 07/20/2026 - 10:31am

Abbott Laboratories, one of the world’s largest healthcare and medical device companies, is investigating two apparently unrelated cyber incidents after confirming unauthorized access to internal systems. While Abbott says there has been no impact on manufacturing, laboratory operations, or patient care, cybercriminal groups ShinyHunters and ShadowByt3$ claim the breaches were far more extensive. Those claims remain unverified at the time of writing and, so far, unsupported by publicly leaked data.

The incidents reportedly involve Abbott’s Cancer Diagnostics business and its LabCentral customer portal for core laboratory diagnostics.

Several news outlets point to an official statement by Abbott, which has since been removed:

“Unauthorized access was limited to internal systems of the Cancer Diagnostics business only, with no impact to other Abbott businesses, sites, systems, product availability, manufacturing, or lab operations.”

Regarding LabCentral, Abbott told reporters that it is an externally hosted portal and that there has been “no known exposure of sensitive customer or business information.”

ShinyHunters told BleepingComputer it stole internal documents, contracts, customer information, more than 22 million doctor‑patient notes, over 20 million medical orders, and more than one million US Social Security numbers, along with personally identifiable information (PII) such as names, addresses, dates of birth, emails, and phone numbers.

On July 18, ShinyHunters gave Abbott until July 21 to respond before leaking the alleged data:

Extended deadline

“This is a final warning to reach out by 21 July 2026 before we leak along with several annoying (digital) problems that’ll come your way. Make the right decision, don’t be the next headline”

The threat of “digital problems” is a familiar one from ShinyHunters. During the Canvas attacks, the group defaced school login pages and the Canvas app with an on‑screen ransom message.

Separately, ShadowByt3$ claims it accessed the LabCentral portal on July 4, using compromised customer credentials plus a “weak point” in the environment, allegedly exfiltrating technical documentation, manufacturing certificates, operating manuals, technical specs, and regulatory docs for Abbott lab systems.

If the attackers’ claims prove accurate, the breach could affect healthcare providers that use Abbott’s diagnostic systems and potentially expose sensitive patient and healthcare data. Abbott, however, says it has found no evidence that sensitive customer or business information was exposed through the LabCentral incident and has not confirmed any patient data was compromised.

What we can reasonably assume to be true
  • There was a genuine compromise affecting Cancer Diagnostics systems. Abbott has publicly acknowledged unauthorized access and engaged incident response and law enforcement. This doesn’t appear to be a purely “fake” extortion attempt.
  • There was also a separate cyber incident involving the LabCentral portal. Abbott says the portal primarily hosts public reference material and that it has found no evidence that sensitive customer or business information was exposed.
  • Both ShinyHunters and ShadowByt3$ have listed Abbott on their extortion sites and have provided narrative details to media outlets, so this is not just generic name‑dropping.
  • As of the latest reporting, neither group has publicly released samples of the data they claim to have stolen.
What Abbott customers can do

There are some actions you can take if you are, or suspect you may have been, the victim of a data breach.

  • Check the vendor’s advice. Every breach is different, so check with the vendor to find out what’s happened and follow any specific advice they offer.
  • Change your password. You can make a stolen password useless to thieves by changing it. Choose a strong password that you don’t use for anything else. Better yet, let a password manager choose and store one for you.
  • Enable two-factor authentication (2FA). If you can, use a FIDO2-compliant hardware key, laptop, or phone as your second factor. Some forms of 2FA can be phished just as easily as a password. 2FA that relies on a FIDO2 device can’t be phished.
  • Watch out for impersonation scams. Criminals may contact you pretending to be the company. Check the company’s website to see how it is contacting affected customers, and verify anyone who contacts you using a different communication channel.
  • Take your time. Phishing attacks often impersonate people or brands you know, and create a false sense of urgency with messages about missed deliveries, suspended accounts, or security alerts.
  • Consider not storing your card details. It’s definitely more convenient to get sites to remember your card details for you, but we highly recommend not storing that information on websites.
  • Set up identity monitoring. Identity monitoring alerts you if your personal information is found being traded illegally online and helps you recover if your identity is stolen.

What do cybercriminals know about you?

Use Malwarebytes’ free Digital Footprint scan to see whether your personal information has been exposed online.

SCAN NOW

Categories: Malware Bytes

Pages