Malwarebytes
@malwarebytes.com
📤 1143
📥 18
📝 586
All-in-one cybersecurity that's always by your side
https://www.malwarebytes.com/
Roses are red Flags are too If they ask for money They’re trying to scam you 🥀
about 6 hours ago
0
7
1
Researchers discovered another 30 malicious Chrome extensions in the Web Store that stole credentials from over 260,000 users.
loading . . .
How to find and remove credential-stealing Chrome extensions
Researchers have uncovered 30 Chrome extensions stealing user data. Here’s how to check your browser and remove any malicious extensions step by step.
https://www.malwarebytes.com/blog/news/2026/02/how-to-find-and-remove-credential-stealing-chrome-extensions?utm_campaign=brandsocial&utm_medium=social&utm_source=bluesky
about 16 hours ago
0
2
3
If it's too cute to be true, it probably is.
loading . . .
Fake shops target Winter Olympics 2026 fans
Olympic merchandise is already being used as bait. We’ve identified nearly 20 fake shop sites targeting fans globally.
https://bit.ly/3Mt8Rvi
about 18 hours ago
0
2
2
Apple released a security update to patch a flaw that could let attackers take control of your devices. Read the latest.
loading . . .
Apple patches zero-day flaw that could let attackers take control of devices
Apple issued security updates for all devices which include a patch for an actively exploited zero-day—tracked as CVE-2026-20700.
https://www.malwarebytes.com/blog/news/2026/02/apple-patches-zero-day-flaw-that-could-let-attackers-take-control-of-devices?utm_campaign=brandsocial&utm_medium=social&utm_source=bluesky
1 day ago
0
1
0
A once popular Outlook add-in suddenly went rogue and stole 4,000 credentials and payment data after a cybercriminal purchased an abandoned Vercel subdomain.
loading . . .
Outlook add-in goes rogue and steals 4,000 credentials and payment data
The once popular Outlook add-in AgreeTo was turned into a powerful phishing kit after the developer abandoned the project.
https://www.malwarebytes.com/blog/news/2026/02/outlook-add-in-goes-rogue-and-steals-4000-credentials-and-payment-data?utm_campaign=brandsocial&utm_medium=social&utm_source=bluesky
1 day ago
0
2
0
Microsoft's latest update fixes six actively exploited zero-days.
loading . . .
February 2026 Patch Tuesday includes six actively exploited zero-days
Microsoft’s February Patch Tuesday fixes 59 flaws—including six zero-days already under active attack. How bad are they?
https://www.malwarebytes.com/blog/news/2026/02/february-2026-patch-tuesday-includes-six-actively-exploited-zero-days?utm_campaign=brandsocial&utm_medium=social&utm_source=bluesky
3 days ago
0
2
1
Discord will make all profiles age restricted until you prove you’re an adult via a facial scan or a government-issued ID
loading . . .
Discord will limit profiles to teen-appropriate mode until you verify your age
Discord will make all profiles teen-appropriate by default until you prove you’re an adult. What you’d “miss” may not be all that terrible.
https://www.malwarebytes.com/blog/news/2026/02/discord-will-limit-profiles-to-teen-appropriate-mode-until-you-verify-your-age?utm_campaign=brandsocial&utm_medium=social&utm_source=bluesky
3 days ago
0
2
1
Hacked Snapchat accounts and secret filming with smart glasses, this week served two reminders of how women’s privacy is still being violated.
loading . . .
Man tricked hundreds of women into handing over Snapchat security codes
Hacked Snapchat accounts and secret filming with smart glasses, this week served two reminders of how women’s privacy is still being violated.
https://www.malwarebytes.com/blog/privacy/2026/02/man-tricked-hundreds-of-women-into-handing-over-snapchat-security-codes?utm_campaign=brandsocial&utm_medium=social&utm_source=bluesky
4 days ago
0
4
1
Another day, another AI app leaks user data.
loading . . .
AI chat app leak exposes 300 million messages tied to 25 million users
A security researcher found an exposed database belonging to the Chat & Ask AI app, once again traced back to a Firebase misconfiguration.
https://www.malwarebytes.com/blog/news/2026/02/ai-chat-app-leak-exposes-300-million-messages-tied-to-25-million-users?utm_campaign=brandsocial&utm_medium=social&utm_source=bluesky
4 days ago
0
1
3
A fake 7-Zip site has been quietly spreading a trojanized installer that turns victims’ machines into proxy nodes.
loading . . .
Fake 7-Zip downloads are turning home PCs into proxy nodes
A convincing lookalike of the popular 7-Zip archiver site has been silently turning victims’ machines into residential proxy nodes.
https://bit.ly/4r7Joa7
5 days ago
0
3
5
This Apple Pay phishing scam tricks users into calling a fake support number to steal 2FA codes and credit card details.
loading . . .
Apple Pay phish uses fake support calls to steal payment details
This Apple Pay phishing campaign is designed to funnel victims into fake Apple Support calls, where scammers steal payment details.
https://www.malwarebytes.com/blog/news/2026/02/apple-pay-phish-uses-fake-support-calls-to-steal-payment-details?utm_campaign=brandsocial&utm_medium=social&utm_source=bluesky
7 days ago
0
3
2
Attackers often hide malware inside fake PDFs that install a RAT once opened, giving attackers full remote access to your machine. But don’t be fooled by the icon. It’s not actually a document. Learn how this sneaky trick works and how to protect yourself.
loading . . .
Open the wrong “PDF” and attackers gain remote access to your PC
The DEAD#VAX campaign tricks users into installing AsyncRAT by disguising a virtual hard disk as a PDF attachment.
https://www.malwarebytes.com/blog/news/2026/02/open-the-wrong-pdf-and-attackers-gain-remote-access-to-your-pc?utm_campaign=brandsocial&utm_medium=social&utm_source=bluesky
8 days ago
0
5
2
Flock Safety, had been sharing city data with hundreds of law enforcement agencies, including federal ones, without permission.
loading . . .
Flock cameras shared license plate data without permission
A California city pulled the plug on its entire ALPR system when it found Flock had shared data with hundreds of agencies without permission.
https://www.malwarebytes.com/blog/privacy/2026/02/flock-cameras-shared-license-plate-data-without-permission?utm_campaign=brandsocial&utm_medium=social&utm_source=bluesky
9 days ago
0
4
1
Despite tighter safeguards, Grok continues to create sexualized images.
loading . . .
Grok continues producing sexualized images after promised fixes
Journalists retested Grok and found it still generates offensive images even when told the subjects were vulnerable, non-consenting people.
https://www.malwarebytes.com/blog/news/2026/02/grok-continues-producing-sexualized-images-after-promised-fixes?utm_campaign=brandsocial&utm_medium=social&utm_source=bluesky
10 days ago
0
2
2
An AI Controls area will be added that centralizes the management of all generative AI features, including a master switch that lets users effectively run the browser "without AI."
loading . . .
Firefox is giving users the AI off switch
Firefox and other companies are starting to see why giving users a choice over AI features matters.
https://bit.ly/3M1IWLb
10 days ago
1
3
2
Companies continue to roll out unsecure AI features that do terrible things.
loading . . .
An AI plush toy exposed thousands of private chats with children
Around 50,000 chat transcripts between children and Bondu’s AI dinosaur plushie were accessible to anyone with a Google account.
https://www.malwarebytes.com/blog/news/2026/02/an-ai-plush-toy-exposed-thousands-of-private-chats-with-children?utm_campaign=brandsocial&utm_medium=social&utm_source=bluesky
10 days ago
0
2
3
Malwarebytes is named a
@pcmag.com
Top Tech Brand for the third year in a row.
loading . . .
The Best Tech Brands for 2026, Ranked
A year's worth of our rigorous lab-testing scores plus your top brand recommendations come together to create our definitive ranking of the 25 best technology companies right now.
https://www.pcmag.com/articles/the-best-tech-brands-for-2026
10 days ago
0
3
1
If you have ever been an AT&T customer, consider this a reminder that your data may already be circulating in forms that are genuinely useful to attackers.
loading . . .
AT&T breach data resurfaces with new risks for customers
As leaked datasets are merged and enriched, they become more useful to criminals. That makes recycled breach data a bigger risk for customers.
https://bit.ly/3NMpfrk
11 days ago
0
3
2
The new setting reduces the precision of location data shared with carriers. Rather than a street address, carriers would see only the neighborhood where a device is located.
loading . . .
Apple’s new iOS setting addresses a hidden layer of location tracking
Apple has introduced Limit Precise Location, a new setting that reduces how precisely cellular networks can locate your device, though support is currently limited.
https://bit.ly/3NPUS3f
11 days ago
0
2
1
We followed a fake cloud storage payment alert through deceptive affiliate redirects, ending at a familiar destination: Freecash.
loading . . .
A fake cloud storage alert that ends at Freecash
We followed a fake cloud storage payment alert through deceptive affiliate redirects, ending at a familiar destination: Freecash.
https://bit.ly/4tfct4L
11 days ago
0
3
0
Scams happen in conversations. Now protection does too. Malwarebytes is now available as a ChatGPT app. Users can leverage the expert threat intelligence of Malwarebytes within their ChatGPT conversations. Just ask @Malwarebytes to check suspicious links, emails, domains, phone numbers, and more.
loading . . .
12 days ago
0
2
1
“You’re invited!”—to install a full remote-access tool on your Windows computer, handing attackers complete control of the system.
https://bit.ly/4rlQBCY
loading . . .
How fake party invitations are being used to install remote access tools
“You’re invited!” It sounds friendly, familiar and quite harmless. But in a scam we recently spotted, that simple phrase is being used to trick victims into installing a full remote access tool on...
https://bit.ly/4rlQBCY
12 days ago
0
4
4
Moltbook, a social media platform for AI chatbots, has been released and it's a wild ride.
14 days ago
1
5
1
The viral AI assistant Clawdbot’s rename to Moltbot sparks an impersonation campaign for a supply-chain attack.
loading . . .
Clawdbot’s rename to Moltbot sparks impersonation campaign
This Moltbot impersonation campaign is a case study in supply-chain risk, brand hijacking, and what happens when open source goes viral.
https://www.malwarebytes.com/blog/threat-intel/2026/01/clawdbots-rename-to-moltbot-sparks-impersonation-campaign?utm_campaign=brandsocial&utm_medium=social&utm_source=bluesky
15 days ago
0
2
0
A new law classifies immigration status as sensitive personal information, requiring companies to disclose how they handle it even if they do not actively collect it.
loading . . .
TikTok’s privacy update mentions immigration status. Here’s why.
TikTok updated its privacy policy to mention immigration status, sparking backlash—but the reality is more complicated.
https://www.malwarebytes.com/blog/news/2026/01/tiktoks-privacy-update-mentions-immigration-status-heres-why?utm_campaign=brandsocial&utm_medium=social&utm_source=bluesky
15 days ago
0
2
0
Meta plans to test exclusive features that will be incorporated into paid versions of Facebook, Instagram, and WhatsApp. Which probably means more AI features.
loading . . .
Meta confirms it’s working on premium subscription for its apps
Details are currently thin, but one thing is clear: paying more is unlikely to buy users meaningful privacy or less tracking.
https://www.malwarebytes.com/blog/news/2026/01/meta-confirms-its-working-on-premium-subscription-for-its-apps?utm_campaign=brandsocial&utm_medium=social&utm_source=bluesky
15 days ago
1
2
2
‼️ Microsoft issued an emergency patch for a high-severity zero-day vulnerability in Office ‼️ The affected products include Microsoft Office 2016, 2019, LTSC 2021, LTSC 2024, and Microsoft 365 Apps.
loading . . .
Microsoft Office zero-day lets malicious documents slip past security checks
Microsoft issued an emergency patch for a flaw attackers are using to slip malicious code past Office's document security checks.
https://bit.ly/4rnyL2t
16 days ago
0
5
4
The extensions steal ChatGPT session tokens, giving attackers access to accounts, including conversation history and metadata.
loading . . .
Malicious Chrome extensions can spy on your ChatGPT chats
Researchers found 16 malicious browser extensions that can quietly hijack active ChatGPT sessions and siphon user data.
https://www.malwarebytes.com/blog/news/2026/01/malicious-chrome-extensions-can-spy-on-your-chatgpt-chats?utm_campaign=brandsocial&utm_medium=social&utm_source=bluesky
17 days ago
0
3
2
The new feature, called "Strict Account Settings", will change what happens to the files that move through your chats—especially the kind that can hide malware.
loading . . .
WhatsApp rolls out new protections against advanced exploits and spyware
WhatsApp is strengthening how it handles photos and videos, and introducing Strict Account Settings to limit risky messages from unknown senders.
https://bit.ly/3Z4D7zr
17 days ago
0
4
3
We saw a convincing text posing as AT&T, warning users their reward points were expiring. Only it wasn’t from AT&T. It's a phishing campaign using realistic branding, social engineering, and data theft
loading . . .
Watch out for AT&T rewards phishing text that wants your personal details
Recently, we uncovered a realistic, multi-layered data theft phishing campaign targeting AT&T customers.
https://www.malwarebytes.com/blog/threat-intel/2026/01/watch-out-for-att-rewards-phishing-text-that-wants-your-personal-details?utm_campaign=brandsocial&utm_medium=social&utm_source=bluesky
17 days ago
0
5
2
A malicious media file, sent into a newly created WhatsApp group chat, can be automatically downloaded and used as an attack vector.
loading . . .
A WhatsApp bug lets malicious media files spread through group chats
Google’s Project Zero team found that WhatsApp can download a malicious media file without you doing anything at all.
https://bit.ly/49XXXWm
18 days ago
0
1
3
TikTok may have secured its future in the US by forming a $14 billion joint venture, allowing it to continue operating in the country.
loading . . .
TikTok narrowly avoids a US ban by spinning up a new American joint venture
TikTok may have avoided a ban, but it didn’t become a different company overnight. Like any other social network, assume your data matters, and share accordingly.
https://bit.ly/4t0x1hl
18 days ago
0
0
1
It's designed not to reward scrolling, but to funnel you into games where you are likely to spend money or watch paid advertisements.
loading . . .
Get paid to scroll TikTok? The data trade behind Freecash ads
Ads promised up to $35 an hour to watch videos. Instead, users were funneled into mobile games designed to drive spending and collect data.
https://www.malwarebytes.com/blog/news/2026/01/get-paid-to-scroll-tiktok-the-data-trade-behind-freecash-ads?utm_campaign=brandsocial&utm_medium=social&utm_source=bluesky
19 days ago
0
3
2
This could be someone testing the system, but it just as well might be someone who enjoys disrupting the system and wreaking havoc.
loading . . .
Spammers abuse Zendesk to flood inboxes with legitimate-looking emails, but why?
Spammers are abusing Zendesk to flood inboxes with emails from trusted brands. There’s no phishing or malware—just noise.
https://bit.ly/3NDrn4s
22 days ago
0
4
1
Malicious Google Calendar invites could expose your private data.
loading . . .
Malicious Google Calendar invites could expose private data
Researchers showed how prompt injection hidden in a calendar invite can bypass privacy controls and turn an AI assistant into a data-leaking accomplice.
https://www.malwarebytes.com/blog/news/2026/01/malicious-google-calendar-invites-could-expose-private-data?utm_campaign=brandsocial&utm_medium=social&utm_source=bluesky
22 days ago
0
5
6
The personal data of 72 million Under Armor customers is now up for sale on the dark web.
loading . . .
Under Armour ransomware breach: data of 72 million customers appears on the dark web
Customer data allegedly stolen during a ransomware attack on sportswear giant Under Armour is now circulating on the dark web.
https://www.malwarebytes.com/blog/news/2026/01/under-armour-ransomware-breach-data-of-72-million-customers-appears-on-the-dark-web?utm_campaign=brandsocial&utm_medium=social&utm_source=bluesky
22 days ago
0
5
4
LastPass warns of a phishing campaign using fake “maintenance” emails that rush users to back up vaults and lead to credential-stealing sites.
loading . . .
Fake LastPass maintenance emails target users
LastPass is warning users about phishing emails that pressure users to back up their vaults within 24 hours.
https://www.malwarebytes.com/blog/news/2026/01/fake-lastpass-maintenance-emails-target-users?utm_campaign=brandsocial&utm_medium=social&utm_source=bluesky
23 days ago
0
4
2
This fake ad blocker crashes browsers to trick users into infecting themselves
loading . . .
Fake extension crashes browsers to trick users into infecting themselves
A fake ad blocker crashes your browser, then uses ClickFix tricks to make you run the malware yourself.
https://www.malwarebytes.com/blog/news/2026/01/fake-extension-crashes-browsers-to-trick-users-into-infecting-themselves?utm_campaign=brandsocial&utm_medium=social&utm_source=bluesky
24 days ago
0
6
5
Google has settled yet another class-action lawsuit accusing it of collecting children’s data and using it to target them with advertising.
loading . . .
Google will pay $8.25m to settle child data-tracking allegations
Google-owned AdMob allegedly collected kids' data for ads without parental consent—including IP addresses, usage data, and exact locations.
https://bit.ly/4qrLl0v
25 days ago
0
3
3
Cybercriminal group DarkSpectre is believed to be behind three malicious browser extension campaigns: ShadyPanda, GhostPoster, and Zoom Stealer.
loading . . .
Firefox joins Chrome and Edge as sleeper extensions spy on users
Researchers found more sleeper browser extensions that spy on users and install backdoors, this time targeting Firefox users as well.
https://www.malwarebytes.com/blog/news/2026/01/firefox-joins-chrome-and-edge-as-sleeper-extensions-spy-on-users?utm_campaign=brandsocial&utm_medium=social&utm_source=bluesky
26 days ago
0
5
6
WhisperPair allows attackers to hijack popular Bluetooth audio devices using Google Fast Pair and, in some cases, track their location via Google’s Find Hub.
loading . . .
WhisperPair exposes Bluetooth earbuds and headphones to tracking and eavesdropping
Researchers demonstrated WhisperPair, a set of attacks that can take control of many widely used Bluetooth earbuds and headphones without user interaction.
https://bit.ly/3NqiHhK
29 days ago
0
6
4
The Dutch police ran a fake ticket website mimicking real scams to teach people how easily ticket fraud works.
loading . . .
Dutch police sell fake tickets to show how easily scams work
A fake ticket website that ended with a digital finger-wag showed just how many people still fall for concert and sports ticket scams.
https://www.malwarebytes.com/blog/scams/2026/01/dutch-police-sell-fake-tickets-to-show-how-easily-scams-work?utm_campaign=brandsocial&utm_medium=social&utm_source=bluesky
29 days ago
0
6
3
Online shoppers, beware: Magecart skimming attacks are targeting major payment networks like American Express, Diners Club, Discover, and Mastercard. Stay informed and protect your data with our latest article.
loading . . .
Online shoppers at risk as Magecart skimming hits major payment networks
A Magecart campaign is skimming card data from online checkouts tied to major payment networks, including AmEx, Diners Club, and Mastercard.
https://www.malwarebytes.com/blog/news/2026/01/online-shoppers-at-risk-as-magecart-skimming-hits-major-payment-networks?utm_campaign=brandsocial&utm_medium=social&utm_source=bluesky
29 days ago
0
2
1
The attack flow abuses how Microsoft Copilot handled URL parameters in order to hijack a user’s existing Copilot Personal session.
https://bit.ly/45Gk9mo
loading . . .
"Reprompt" attack lets attackers steal data from Microsoft Copilot
Researchers found an attack vector against Microsoft Copilot to steal data from a user that clicked a fabricated link
https://bit.ly/45Gk9mo
30 days ago
0
1
1
Fake LinkedIn profiles are posting comments threatening account suspensions that lead to real phishing sites.
loading . . .
Phishing scammers are posting fake “account restricted” comments on LinkedIn
Fake LinkedIn comments warning of account restrictions are designed to trick users into revealing their login details.
https://www.malwarebytes.com/blog/news/2026/01/phishing-scammers-are-posting-fake-account-restricted-comments-on-linkedin?utm_campaign=brandsocial&utm_medium=social&utm_source=bluesky
about 1 month ago
0
2
1
Data brokers being held accountable is a trend we are absolutely here for.
loading . . .
Data broker fined after selling Alzheimer’s patient info and millions of sensitive profiles
A data broker was fined by California regulators for selling sensitive data on Alzheimer’s patients and millions of others.
https://www.malwarebytes.com/blog/news/2026/01/data-broker-fined-after-selling-alzheimers-patient-info-and-millions-of-sensitive-profiles?utm_campaign=brandsocial&utm_medium=social&utm_source=bluesky
about 1 month ago
0
4
3
Upgrading requires a restart, which makes this a win-win: you get the latest protections, and any memory-resident malware is flushed at the same time.
loading . . .
Why iPhone users should update and restart their devices now
Apple has confirmed active exploitation, but full protections are limited to iPhones running iOS 26+ (yes, the one with Liquid Glass).
https://bit.ly/49RCLSR
about 1 month ago
0
5
4
Did you receive an unsolicited Instagram password reset email? Here’s what you need to know.
loading . . .
Received an Instagram password reset email? Here’s what you need to know
Instagram users received emails last week about purported password reset attempts. At the same time, Instagram data appeared on the dark web.
https://www.malwarebytes.com/blog/news/2026/01/received-an-instagram-password-reset-email-heres-what-you-need-to-know?utm_campaign=brandsocial&utm_medium=social&utm_source=bluesky
about 1 month ago
0
3
5
Grok’s lapse on sexualized images of minors has become a global regulatory stress test for xAI, unlikely to be fixed with a simple apology or hotfix.
loading . . .
Regulators around the world are scrutinizing Grok over sexual deepfakes
Grok’s apology is unlikely to be the end of the story after the AI tool was used to generate content that may constitute illegal child sexual abuse material.
https://bit.ly/45JneC3
about 1 month ago
0
3
0
From earning seven straight MRG Effitas Android 360° certifications to a perfect score in AVLab Cybersecurity Foundation’s real-world malware test, Malwarebytes kept its winning-streak alive in 2025. 🥳 🎉
loading . . .
Celebrating reviews and recognitions for Malwarebytes in 2025
In 2025, Malwarebytes was repeatedly tested against real-world threats. Here’s what those tests found.
https://www.malwarebytes.com/blog/product/2026/01/independently-reviewed-repeatedly-approved-celebrating-malwarebytes-2025-awards-and-recognitions?utm_campaign=brandsocial&utm_medium=social&utm_source=bluesky
about 1 month ago
0
0
0
Load more
feeds!
log in