Malware Bytes

More than 100,000 fake stores are out to steal your card details

Malware Bytes Security - Wed, 09/09/2026 - 11:02am

Researchers at German cybersecurity company Nebty have identified “DoppelCart,” a cluster of almost 119,000 domains linked to copied online stores.

The researchers describe it as the largest publicly documented fake-shop network by associated domain count. They found 118,787 .shop domains in the cluster, representing 2.72% of the .shop top-level domain (TLD) population they examined.

The operation copies legitimate retailers’ product catalogs, descriptions, branding, and images, sometimes even loading images directly from the real companies’ infrastructure.

As we have reported in the past, AI-powered website builders make it easy to clone major brands. However, Nebty’s findings are based on shared website and infrastructure characteristics, rather than evidence that every domain is operated by a single identified group.

BleepingComputer reports an important checkout-level detail: 96% of confirmed DoppelCart shops reportedly shared identical build files and used just 27 ecommerce backends.

The fake shops mimic more than 44,000 brands, with a median of two clones for each brand.

“However, some brands like SodaStream, Velasca, CurrentBody, Daniel Wellington, Dreame, Horze, MOVA, and SPARK PAWS received more attention, with over 30 shops each.”

Nebty observed advertised discounts of up to 65%, a tactic designed to encourage shoppers to act before closely checking the domain, company details, or payment process.

The fraudulent checkout pages collect cardholder data and transmit it to attacker-controlled servers over WebSockets in real time. That may include card numbers, expiry dates, CVVs (card verification values), billing information, and even one-time confirmation codes issued by banks.

Capturing an authentication code in real time can help criminals to complete a payment while the victim is still going through the checkout flow.

How shoppers can stay safe

A professional-looking store, the use of HTTPS, authentic product images, and a familiar logo do not prove that a website is legitimate. Before entering payment details, shoppers should take a few minutes to verify where they are buying from.

  • Check the web address carefully. If possible, reach the retailer through its official app, a saved bookmark, or a web address you already know, rather than sponsored search results or ads on social media.
  • Be wary of unusually large discounts. A low price does not prove that a store is fake, but it is a reason to check the site more carefully.
  • Search for the exact web address alongside terms such as “scam” or “reviews.” Check that the contact details, returns policy, and company information match the real retailer.
  • Pay by credit card or another service with buyer protection. Avoid cryptocurrency, bank transfers, gift cards, and other payments that are difficult to reverse.
  • Check every bank verification request carefully. Make sure the merchant and amount are correct, and never give a one-time code to a retailer or anyone who contacts you.
  • Use an up-to-date, real-time anti-malware solution with web protection.
  • If you’re unsure whether a store is genuine, use Malwarebytes Scam Guard to help you assess it.

If you’ve already paid, act quickly. Contact your card issuer, report the suspected fraud, ask about replacing or monitoring your card, and save screenshots, order confirmations, web addresses, and correspondence.

Stop threats before they can do any harm.

Malwarebytes Browser Guard blocks phishing pages and malicious sites automatically. Free, one click to install. Add it to your browser →

Categories: Malware Bytes

Microsoft fixes record 964 flaws, including 2 exploited zero-days

Malware Bytes Security - Wed, 09/09/2026 - 6:01am

Microsoft’s September 2026 Patch Tuesday addresses 964 CVEs, including 104 rated Critical and 860 rated Important, making it the company’s largest Patch Tuesday release on record.

Microsoft lists 974 CVEs in its full September security release. However, 10 of those affect cloud services or involve fixes that Microsoft applies itself, leaving 964 vulnerabilities that customers need to patch.

The release includes fixes for two actively exploited Windows zero-days. Both are local elevation-of-privilege vulnerabilities that could allow an attacker who already has access to a device to gain SYSTEM privileges. Neither provides remote access by itself, but SYSTEM-level access is valuable to malware operators after they gain an initial foothold through phishing, stolen credentials, or another method.

How to apply patches and check if you’re protected

These updates fix security problems and help keep your Windows PC protected. Here’s how to make sure you’re up to date:

  • Click the Start button, then open Settings.
  • Select Windows Update (usually at the bottom of the menu on the left).
  • Click Check for updates. Windows will search for the latest security updates. If you’ve enabled Get the latest updates as soon as they’re available under More options, you may be prompted to restart immediately to complete the update. Otherwise, continue to the next step.
Windows 11 up to date
  • If updates are available, they’ll start downloading automatically. When they’re ready, click Install or Restart now if prompted. Your computer may need a restart to finish the update.
  • After restarting, go back to Windows Update and check again. If it says You’re up to date, you’re all set.
Technical details

The unusually large batch also includes high-severity remote-code-execution vulnerabilities in Windows DNS Server and Remote Desktop Services, as well as fixes affecting Exchange Server, SharePoint, SQL Server, Office, and core Windows components.

Let’s take a closer look at the two zero-day vulnerabilities. Microsoft classifies a vulnerability as a zero-day if it was publicly disclosed or actively exploited before an official fix became available.

The first is a Windows Update Stack elevation-of-privilege (EoP) vulnerability with a CVSS score of 7.8 out of 10, tracked as CVE-2026-81963. The description says:

“Improper link resolution before file access (‘link following’) in Windows Update Stack allows an authorized attacker to elevate privileges locally.”

This means Windows can be persuaded to open or modify the wrong file because it follows a shortcut-like pointer without properly checking where that pointer leads. Microsoft says attackers exploited the bug before a patch was available.

The second zero-day, tracked as CVE-2026-85880, also has a CVSS score of 7.8 out of 10. Microsoft describes it as:

“heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.”

Microsoft says an attacker who can execute code in a low-privilege AppContainer could exploit the vulnerability locally to escape the sandbox and elevate their privileges on the affected system. No additional user interaction is required.

Windows ALPC is an internal messaging system in the Windows operating system that allows different programs on the same computer to communicate with each other quickly.

A buffer overflow occurs when an area of memory within a software application reaches its boundary and data spills into an adjacent memory region. The heap is a region of memory used for dynamic memory allocation.

These are not the kinds of bugs a typical victim triggers merely by opening a malicious document or visiting a website. But local privilege escalation is a critical part of many attack chains: After malware runs with limited rights, a SYSTEM-level exploit can help an intruder disable defenses, access protected data, establish persistence, or move through a network.

From reporting threats to removing them.

Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.

Categories: Malware Bytes

The push to stop algorithms controlling social media feeds has begun

Malware Bytes Security - Wed, 09/09/2026 - 4:28am

Remember when social media was filled only with posts from your friends, rather than what an algorithm decided you wanted to see? So does the Australian government, and it wants that internet back.

Yesterday, the government released draft legislation outlining a Digital Duty of Care. The proposal includes a measure that Prime Minister Anthony Albanese labeled “My Feed, My Way.” It would allow Australians over 16 to switch off the algorithmic feed that social media platforms deliver automatically to users, instead allowing them to see content from friends and creators they choose to follow.

This legislation, which is expected to reach Parliament before Christmas, would force platforms to send notifications to both new and existing users asking them to choose between the two types of feed. Platforms would then have to respect that choice unless the user changed it.

The feed controls are grabbing the headlines, but the Digital Duty of Care also includes protections for users under 18. Digital services, including social media, online games, apps, and AI chatbots, would have to protect under-18s from harmful content and design features that could negatively affect their behavior or self-esteem.

That includes content that promotes eating disorders, misogyny, crime, life-threatening stunts, pornography, or serious mental health distress.

The proposed law is the latest move from a country known for its aggressive stance on social media safety. Australia banned under-16s from using a wide range of social media platforms, although it hasn’t gone that well.

Three months after the December 2025 ban, 81% of Aussie kids were still using at least one restricted social media platform, down from 86% when the ban was introduced. Before the ban took effect, about 60% used social media at least once a day. Three months later, that figure was 58%.

Bans sound good on paper but they’re hard to enforce.

The new proposal takes a different approach by placing more responsibility on social media companies. The government promises penalties of up to $109.2 million Australian dollars (US$78.6 million) for companies that fail to comply with the Digital Duty of Care.

The Australian eSafety Commissioner would also gain the power to issue removal notices for nudify apps and websites, and streamline its existing child cyberbullying and adult cyber abuse schemes so it can deal with harmful material more quickly.

The move comes less than two weeks after Meta agreed to let teens choose a non-personalized feed as part of a multi-billion dollar settlement with US states.

Why is an opt-out from automatically curated feeds important? Companies that automatically curate your content with their own algorithms tend to show you more of what you’ve been seeing.

That can be great if you’re building a chicken coop and want as much advice as possible on nest box placement. But it can also narrow the range of content you see, making it harder to develop a well-rounded view of a subject.

Perhaps sensing a change in the political wind, social media companies have already begun offering friends-only feeds. Facebook reintroduced this capability in its Friends tab in the US and Canada in March 2025. It called this one of its “OG” Facebook experiences.

TikTok also now has a Friends tab alongside its regular For You feed, while Instagram has offered chronological Following and Favorites feeds since 2022. YouTube has its Subscriptions feed, while Snapchat created separate feeds for friends and other content creators back in 2017.

The problem is that these feeds aren’t the default. Recommended content remains the easiest option to consume.

If you use social media and want more control over what you see, look for its Friends, Following, Favorites, or Subscriptions feed. You might end up with more humblebragging, vaguebooking, or faux-wisdom memes, but at least you’ll know why you’re seeing them. And you can always get some new friends.

Scammers don’t need to hack you. They just need you to click once. 

Malwarebytes Identity Theft Protection catches suspicious activity before it becomes a problem.

Categories: Malware Bytes

Grindr settles HIV status data-sharing lawsuit for $35 million

Malware Bytes Security - Tue, 09/08/2026 - 8:51am

Grindr has reportedly agreed to pay £26 million (around $35 million) to settle a UK privacy lawsuit alleging that it shared sensitive user data, including some users’ HIV status, with advertisers.

The claim was brought by London law firm Austen Hays on behalf of roughly 12,000 UK Grindr users. It alleges that the dating app breached privacy and data-protection laws during a period ending in early 2020.

The claimants allege that Grindr shared personal and highly sensitive information with advertising companies without consent. According to Austen Hays, the shared data may have included ethnicity, HIV status, the date of a user’s last HIV test, and whether they used pre-exposure prophylaxis (PrEP).

At the time of the alleged data sharing practices, Grindr was owned and controlled by the Chinese gaming company Beijing Kunlun Tech. Grindr was sold to US owners in 2020.

According to a US regulatory filing, Grindr will make two payments of £13 million: one by December 31, 2026, and the second by March 31, 2027.

In its SEC filing, Grindr said that the settlement is not an admission of liability and, while it disputes the allegations, it:

recognizes and acknowledges the distress and loss of trust expressed by some of its UK users regarding that pre-2020 period.

The UK settlement follows a separate enforcement case in Norway. The country’s Data Protection Authority found that Grindr had shared users’ personal data with advertising partners for behavioral advertising without a valid legal basis.

These cases illustrate a crucial privacy point: information does not need to be explicitly labeled as medical information or information about sexual orientation to expose intimate details about someone. Advertising identifiers, IP addresses, locations, device information, and confirmation that a person uses a particular app can be combined to identify them or draw sensitive conclusions about their life.

Many free apps rely on advertising SDKs, analytics providers, and other third parties to make money. These integrations can receive identifiers and event data that help target or measure advertising, but they can also create extensive trails of user behavior.

How to protect your privacy on dating apps

Grindr says it has overhauled its privacy program since 2020 and remains committed to user control and responsible data practices. Even so, dating apps can hold unusually personal information about their users.

To limit what you reveal:

  • Review the app’s privacy settings and turn off optional personalized advertising where available.
  • Limit your profile to details you’re comfortable sharing with potential matches.
  • Avoid linking a dating profile to public social-media accounts unless you want identities to be easily connected.
  • Revoke location permissions when you’re not actively using the app, or choose “while using the app” rather than continuous access where your operating system offers it.
  • Keep the app, your operating system, and your security software updated.
  • Watch for romance scams and extortion attempts, particularly requests to move the conversation off the app, send money, share intimate photos, or reveal identifying information.

If you’re unsure whether a message may be part of a scam, you can check it with Malwarebytes Scam Guard, which can help you assess the conversation and decide what to do next.

Scammers don’t need to hack you. They just need you to click once. 

Malwarebytes Identity Theft Protection catches suspicious activity before it becomes a problem.

Categories: Malware Bytes

MikroTik router flaws allow takeover without a password

Malware Bytes Security - Tue, 09/08/2026 - 5:49am

CERT Polska warns that attackers are actively exploiting a chain of critical MikroTik RouterOS flaws to seize control of routers exposed to the internet.

Although the warning comes from Poland’s national cybersecurity response team, MikroTik routers are sold worldwide, including in the US. The vulnerabilities can affect users anywhere if their router is running a vulnerable version of RouterOS and its SSH remote-management service is accessible from the internet.

Attackers are exploiting two vulnerabilities, collectively dubbed “MikroTrick,” to take full control of vulnerable devices, CERT Polska says.

A compromised router is especially serious because it sits at the edge of your network. An intruder may be able to change DNS settings, redirect or capture traffic, create remote-access tunnels, alter firewall rules, or use the device as a foothold to attack other devices on the network.

Two of the six disclosed vulnerabilities form the chain of compromise known as MikroTrick. The first, tracked as CVE-2026-67276, is an SSH authentication-bypass flaw in the handling of RSA public keys. The second, CVE-2026-86060, is a privilege-escalation flaw involving a specially crafted username in the SSH login process.

Put simply, the first flaw lets attackers get in without a password, and the second lets them make themselves an administrator.

SSH (short for Secure Shell) is a network protocol that establishes encrypted connections between computers for secure remote access.

CERT Polska issued the warning because the patched RouterOS packages are already public, and their comparative analysis has allowed the community to reconstruct some of the flaws they fix. 

How to stay safe

MikroTik router owners should install the latest RouterOS security update as soon as possible. Use the router’s update mechanism or obtain the supported package directly from MikroTik. The update option should be available under Check for updates.

You should also remove public access to the router’s management services. Make sure that SSH is not accessible from untrusted networks. If remote administration is necessary, limit access to known IP addresses.

Remote management should be the exception, not the default. MikroTrick demonstrates that a strong password alone cannot protect a device from an authentication-bypass vulnerability.

MikroTik has added a detection mechanism that scans the configuration at startup for selected signs of unauthorized changes. If it finds any, RouterOS disables the recognized suspicious entries and sets the device’s Flagged status to Yes. Administrators can check this with /system/device-mode/print.

RouterOS restricts several potentially abusable functions while the device is flagged, but MikroTik stresses that the router’s full configuration still needs to be audited before the flag is cleared.

From reporting threats to removing them.

Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.

Categories: Malware Bytes

Pages