Malwarebytes's Avatar

Malwarebytes

@malwarebytes.com

All-in-one cybersecurity that's always by your side https://www.malwarebytes.com/

1,520
Followers
18
Following
622
Posts
08.11.2024
Joined
Posts Following

Latest posts by Malwarebytes @malwarebytes.com

Preview
Fake CleanMyMac site installs SHub Stealer and backdoors crypto wallets We uncovered a fake CleanMyMac site delivering SHub Stealer, a macOS infostealer that steals credentials and silently backdoors crypto wallets.

We uncovered an impersonation campaign of the popular Mac utility CleanMyMac that is tricking users into installing a malicious infostealer.

07.03.2026 00:48 πŸ‘ 7 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Preview
Beware of fake OpenClaw installers, even if Bing points you to GitHub Bing search results pointed victims to GitHub repositories claiming to host OpenClaw installers, but in reality they installed malware.

Attackers are abusing OpenClaw’s popularity by seeding fake β€œinstallers” on GitHub to deliver infostealers and malware instead of the droids...er...AI assistant you were looking for.

06.03.2026 15:57 πŸ‘ 9 πŸ” 2 πŸ’¬ 0 πŸ“Œ 0
Preview
Scammers Have Found An Unexpected New Way Into Your iPhone Luckily, there's a relatively easy fix.

iPhone Calendar scams are on the rise. Learn how to spot them and remove them from your device with our tips featured in Huffington Post.

06.03.2026 00:29 πŸ‘ 11 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Preview
Supreme Court to decide whether geofence warrants are constitutional Google has urged the justices to strike down the controversial warrants, which can sweep up location data from hundreds of phones near a crime scene.

Google weighs in on a US Supreme Court case, arguing that geofence warrants are unconstitutional.
https://www.malwarebytes.com/blog/news/2026/03/supreme-court-to-decide-whether-geofence-warrants-are-constitutional?utm_campaign=brandsocial&utm_medium=social&utm_source=bluesky

05.03.2026 21:52 πŸ‘ 4 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Scam detector | Real-time free scam detection for iOS and Android Received a suspicious text? Use our Scam Guard to see if it's a scam. AI-powered scam detector is part of Malwarebytes Mobile security.

Scams suck. We created our free scam detector to help older users and those who just need a little extra help learning to identify scams.
www.malwarebytes.com/solutions/sc...

04.03.2026 23:42 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Does the UK really want to ban VPNs? And can it be done? Reports of a "Great British Firewall" are exaggerated. And even if they wanted to, here's why it would be virtually impossible.

The idea of a β€œGreat British Firewall” makes for a catchy headline, but it would be riddled with holes and cause huge problems.

04.03.2026 16:09 πŸ‘ 12 πŸ” 3 πŸ’¬ 0 πŸ“Œ 0
Preview
High-severity Qualcomm bug hits Android devices in targeted attacks Google has patched 129 Android vulnerabilities, including an actively exploited flaw in a widely used Qualcomm component.

‼️ Android users: update now ‼️

Google has fixed 129 vulnerabilities in Android, including a Qualcomm display flaw that is known to be actively exploited.

04.03.2026 13:46 πŸ‘ 10 πŸ” 8 πŸ’¬ 0 πŸ“Œ 0
Preview
Chrome flaw let extensions hijack Gemini’s camera, mic, and file access Researchers found a now-patched vulnerability in "Live in Chrome" that allowed a Chrome extension to inherit Gemini’s permissions.

A flaw in Google Chrome let extensions hijack Gemini’s camera, mic, and file access.

03.03.2026 22:59 πŸ‘ 16 πŸ” 6 πŸ’¬ 0 πŸ“Œ 0
Preview
Samsung TVs stop spying on viewers in Texas. Here's how to disable ACR anywhere As Samsung settles a lawsuit over how its smart TVs collect and monetize viewing data using ACR, here's how the rest of us can limit the data we're sharing.

If you’d prefer to limit or disable ACR-style monitoring of your watching behavior, here’s where to look.

03.03.2026 13:39 πŸ‘ 11 πŸ” 9 πŸ’¬ 0 πŸ“Œ 0
Preview
A fake FileZilla site hosts a malicious download A tampered copy of FileZilla quietly contacts attacker-controlled servers using encrypted DNS traffic that can slip past traditional monitoring.

When someone downloads the tampered version of FileZilla, Windows loads the malicious library first, allowing the malware to run within a normal FileZilla session.

02.03.2026 15:41 πŸ‘ 10 πŸ” 4 πŸ’¬ 0 πŸ“Œ 0
Post image

Adulthood is just getting letters from a company that you've never heard of, telling you they leaked your data that you didn't know they had, and including a multi-step to-do list for you to protect the data that they did not.

01.03.2026 15:12 πŸ‘ 41 πŸ” 18 πŸ’¬ 0 πŸ“Œ 0
Preview
Public Google API keys can be used to expose Gemini AI data Researchers found that Google API keys long treated as harmless can now unlock access to Gemini.

Google API keys, long treated as harmless, can now be used by cybercriminals as Gemini AI credentials.

27.02.2026 19:59 πŸ‘ 10 πŸ” 4 πŸ’¬ 0 πŸ“Œ 0
Preview
Inside a fake Google security check that becomes a browser RAT Disguised as a security check, this fake Google alert uses browser permissions to harvest contacts, location data, and more.

A website styled to resemble a Google Account security page is distributing what may be one of the most fully featured browser-based surveillance toolkits we have observed in the wild.

27.02.2026 16:40 πŸ‘ 12 πŸ” 5 πŸ’¬ 0 πŸ“Œ 0
Preview
Fake Zoom and Google Meet scams install Teramind: A technical deep dive Attackers don’t always need custom malware. Sometimes they just need a trusted brand and a legitimate tool.

This article provides a technical deep dive into the recent fake Zoom and Google Meet scams that we reported on two days ago.

27.02.2026 14:34 πŸ‘ 12 πŸ” 8 πŸ’¬ 0 πŸ“Œ 0
Preview
How to understand and avoid Advanced Persistent Threats APT stands for Advanced Persistent Threat. But what does that actually mean, and how does it translate into the kind of threat you’re facing?

Learn how Advanced Persistent Threats target individuals and organizations, and why knowing the warning signs can help you stay safe online.

27.02.2026 13:47 πŸ‘ 4 πŸ” 2 πŸ’¬ 0 πŸ“Œ 0
Preview
Instagram flagged explicit messages to minors in 2018. Image-blurring arrived six years later Unsealed court records reveal Instagram executives discussed explicit messages to teens years before a blur feature was introduced.

Meta took six years to blur explicit images on Instagram, even though internal emails show executives were aware in 2018 that minors were receiving them.

26.02.2026 18:24 πŸ‘ 9 πŸ” 3 πŸ’¬ 0 πŸ“Œ 0
Preview
The Conduent breach; from 10 million to 25 million (and counting) A third-party breach at Conduent now affects 25 million Americansβ€”many never knew their data flowed through its systems.

A massive healthcare data breach exposed sensitive information including medical information, addresses, dates of birth, and social security numbers of 25 million Americans (and growing).

26.02.2026 15:38 πŸ‘ 9 πŸ” 5 πŸ’¬ 1 πŸ“Œ 0
Preview
Developer creates app to detect nearby smart glasses A developer created an Android app that looks for nearby smart glasses. It's not perfect, but it can help people in certian circumstances.

Is it possible to spot smart glasses before they spot you?

26.02.2026 04:39 πŸ‘ 15 πŸ” 8 πŸ’¬ 0 πŸ“Œ 3
Preview
Roblox gives predators "powerful tools" to target children, says LA County Los Angeles County sued the online gaming platform Roblox for its alleged failure to protect children from danger.

Los Angeles County is filing a lawsuit against Roblox, claiming Roblox is misleading parents into thinking the platform is safe while leaving children exposed to predators and sexually explicit content.

24.02.2026 20:23 πŸ‘ 18 πŸ” 4 πŸ’¬ 0 πŸ“Œ 1
Preview
Fake Zoom meeting "update" silently installs surveillance software A fake Zoom meeting page looks real, triggers a bogus β€œupdate,” and silently installs surveillance software.

A fake Zoom meeting site mimics a video call, then uses an β€œUpdate Available” countdown to automatically download a malicious installer onto Windows machinesβ€”no permission required.

24.02.2026 17:10 πŸ‘ 13 πŸ” 7 πŸ’¬ 0 πŸ“Œ 0
Preview
Refund scam impersonates Avast to harvest credit card details A convincing fake Avast site displays a €499.99 charge and promises a refund. Instead, it harvests your name, address, and full credit card details.

A fraudulent website mimicking Avast is deceiving French-speaking users into providing their credit card details under the guise of processing a non-existent refund.

24.02.2026 11:34 πŸ‘ 12 πŸ” 4 πŸ’¬ 0 πŸ“Œ 1
conversation between Meta's Head of AI Safety and Alignment and their OpenClaw bot

conversation between Meta's Head of AI Safety and Alignment and their OpenClaw bot

>be Head of AI Safety and Alignment at Meta
>set up OpenClaw
>grant it full access to your personal inbox
>it starts mass-deleting emails
>β€œDon’t do that.”
>wipes out the remaining old emails too
>β€œI told you not to do that.”
>β€œDo you remember me saying that?”
>β€œYes. I remember. And I ignored it.”

23.02.2026 23:20 πŸ‘ 11 πŸ” 4 πŸ’¬ 0 πŸ“Œ 1
Preview
OpenClaw: What is it and can you use it safely? OpenClaw is a hot topic at the moment. But what is it and how can you use the 24/7 AI assistant in a safe way?

Giving OpenClaw root access to your device? What could possibly go wrong.

23.02.2026 22:11 πŸ‘ 12 πŸ” 3 πŸ’¬ 1 πŸ“Œ 0
Preview
Password managers keep your passwords safe, unless… Researchers investigated the zero-knowledge claims of password managers and they found some possible attack scenarios

Many issues are now patched, but be cautious and enable multi-factor authentication so a stolen password alone isn’t enough.

23.02.2026 14:58 πŸ‘ 10 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Preview
Age verification vendor Persona left frontend exposed, researchers say Behind a basic age check, researchers say Persona’s system runs extensive identity, watchlist, and adverse-media screening.

Researchers discovered a publicly exposed frontend on a government-authorized server, containing 2,456 accessible files from the age verification vendor used by Discord.

20.02.2026 16:00 πŸ‘ 2844 πŸ” 1669 πŸ’¬ 42 πŸ“Œ 343
Preview
Facebook ads spread fake Windows 11 downloads that steal passwords and crypto wallets Attackers are weaponizing Facebook ads to distribute password-stealing malware masked as a Windows download.

Attackers are running paid Facebook ads that look like official Microsoft promotions, then directing users to near-perfect clones of the Windows 11 download page.

20.02.2026 14:11 πŸ‘ 7 πŸ” 5 πŸ’¬ 0 πŸ“Œ 0
Preview
AI-generated passwords are a security risk AI-generated passwords are "highly predictable" and aren’t truly random, making them easier for cybercriminals to crack.

Using AI to generate passwords is a bad idea. It may produce passwords that criminals can exploit using dictionary attacks, where they test a list of likely passwords with automated tools.

19.02.2026 19:24 πŸ‘ 7 πŸ” 2 πŸ’¬ 0 πŸ“Œ 0
Preview
Intimate products producer Tenga spilled customer data US customers of sex toy manufacturer Tenga may have had some data leaked due to a phishing attack on a Tenga employee

Tenga confirmed reports published by several outlets that the company notified customers of a data breach.

19.02.2026 14:10 πŸ‘ 3 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Meta patents AI that could keep you posting from beyond the grave Hopefully Meta really will file this in the "just because we can do it doesn't mean we should" drawer.

Weekend at Zuckerberg's?

19.02.2026 11:44 πŸ‘ 3 πŸ” 1 πŸ’¬ 1 πŸ“Œ 0
Preview
Betterment data breach might be worse than we thought This breach now appears far more serious. The leaked data includes rich personal and financial details that phishers could use.

Stolen data from a breach at Betterment is now being shared online by threat actors.
https://www.malwarebytes.com/blog/news/2026/02/betterment-data-breach-might-be-worse-than-we-thought?utm_campaign=brandsocial&utm_medium=social&utm_source=bluesky

19.02.2026 09:51 πŸ‘ 4 πŸ” 3 πŸ’¬ 0 πŸ“Œ 0