Malwarebytes
@malwarebytes.com
📤 921
📥 18
📝 346
The official account for Malwarebytes. Protection you can trust.
https://www.malwarebytes.com/
The FBI is warning that cybercriminals are creating fake versions of its Internet Crime Complaint Center (IC3) website to trick people into sharing personal information.
loading . . .
Scammers are impersonating the FBI to steal your personal data
Been invited to report a scam to the FBI? Beware of fake versions of the IC3 website—they lead straight back to the scammers.
https://bit.ly/4ni3pc5
about 10 hours ago
0
3
1
Zelle transfers are instant and difficult to reverse, making them a common method for scammers to steal money from victims. Learn how to stay safe in our latest article. 👇
loading . . .
Beware of Zelle transfer scams
Zelle scams are back, or perhaps they never went away. Here's what to look out for.
https://www.malwarebytes.com/blog/news/2025/09/beware-of-zelle-transfer-scams?utm_campaign=brandsocial&utm_medium=social&utm_source=bluesky
1 day ago
0
2
1
Most of the openly accessible AI chat agents have been barred from solving CAPTCHAs by their developers. But now researchers say they’ve found a way to get ChatGPT to solve image-based CAPTCHAs.
loading . . .
ChatGPT solves CAPTCHAs if you tell it they're fake
Researchers have convinced ChatGPT to solve CAPTCHAs, even though it's against its policy.
https://bit.ly/3Kjmn3b
1 day ago
0
3
2
Them: "Security is expensive." Us:
4 days ago
1
2
1
ShadowLeak was an issue in OpenAI’s Deep Research project that attackers could exploit by simply sending an email to the target.
loading . . .
ChatGPT Deep Research zero-click vulnerability fixed by OpenAI
OpenAI has fixed a vulnerability in ChatGPT Deep Research after researchers found a prompt injection method to exfiltrate PII.
https://www.malwarebytes.com/blog/news/2025/09/chatgpt-deep-research-zero-click-vulnerability-fixed-by-openai?utm_campaign=brandsocial&utm_medium=social&utm_source=bluesky
4 days ago
0
0
1
This raccoon is not out for your trash; it's after your data. The disrupted phishing campaign stole logins, cookies, and other sensitive information. Criminals use these to break into accounts, steal money, extort victims, or launch bigger cyberattacks.
loading . . .
Disrupted phishing service was after Microsoft 365 credentials
Microsoft and Cloudflare have delivered a major blow to the fastest growing Phishing-as-a-Service operation called RaccoonO365.
https://bit.ly/3VoIB6q
5 days ago
1
3
1
‼️ Update your Chrome browser ‼️ Google has released an update for its Chrome browser to patch four security vulnerabilities.
loading . . .
Update your Chrome today: Google patches 4 vulnerabilities including one zero-day
Google has issued a Chrome update to fix four high priority flaws including one zero-day, zero-click vulnerability.
https://bit.ly/4nwfhXu
5 days ago
0
1
1
You know you can download Malwarebytes on your Android or iPhone, right?🤔
6 days ago
1
3
1
Researchers have discovered a large fraud campaign on the Google Play Store. 224 malicious apps were downloaded over 38 million times and generated up to 2.3 billion ad requests per day.
loading . . .
224 malicious apps removed from the Google Play Store after ad fraud campaign discovered
Researchers have discovered a large ad fraud campaign on Google Play Store.
https://bit.ly/4grczQV
6 days ago
0
1
2
Apple released iOS 18.7 and iOS 26, fixing dozens of vulnerabilities that could give attackers access to your sensitive data.
loading . . .
Update your Apple devices to fix dozens of vulnerabilities
Apple has released security updates for all platforms to fix dozens of vulnerabilities which could give cybercriminals access to sensitive data.
https://www.malwarebytes.com/blog/news/2025/09/update-your-apple-devices-to-fix-dozens-of-vulnerabilities?utm_campaign=brandsocial&utm_medium=social&utm_source=bluesky
6 days ago
0
0
1
The US airline industry has been providing the government access to passenger records, and it has now been revealed that the number of records is much higher than previously thought.
loading . . .
Airline data broker selling 5 billion passenger records to US government
At least five billion airline passenger records are being sold to government agencies via a searchable database—far more than was initially believed.
https://bit.ly/468y4Ct
6 days ago
0
0
0
🎣 Some AI chatbots are willing to create phishing messages that can be used to scam people.
loading . . .
Grok, ChatGPT, other AIs happy to help phish senior citizens
Big name AI chatbots are happy to create phishing emails and malicious code to target senior citizens.
https://bit.ly/47MlVo6
7 days ago
0
1
2
“Children are hacking into their schools’ computer systems – and it may set them up for a life of cyber crime.”
loading . . .
"A dare, a challenge, a bit of fun:" Children are hacking their own schools' systems, says study
Research shows that students are responsible for over half of school incidents, often without realizing the possible consequences.
https://bit.ly/469UhAc
7 days ago
0
3
0
🚫 Don’t fall for fake remote job offers. Scammers are taking advantage of job seekers with bogus remote jobs. Learn how to spot employment scams and get tips on how to stay safe in our latest article.
loading . . .
Watch out for the "We are hiring" remote online evaluator message scam
Several of our staff have reported receiving a job offer as an online evaluator. A job that pays very well for a few hours of work.
https://www.malwarebytes.com/blog/news/2025/09/watch-out-for-the-we-are-hiring-remote-online-evaluator-message-scam?utm_campaign=brandsocial&utm_medium=social&utm_source=bluesky
7 days ago
0
2
2
Discover how a "like" on the Fitbit app spiraled into years of financial hardship. Read the true story of how one woman lost her life savings to a scammer with our tips on how to keep your loved ones safe online.
loading . . .
From Fitbit to financial despair: How one woman lost her life savings and more to a scammer
We often don't find out the real details of a scam, and how one ‘like' can turn into a nightmare that controls someone's life for many years. This is that story.
https://www.malwarebytes.com/blog/scams/2025/09/from-fitbit-to-financial-despair-how-one-woman-lost-her-life-savings-and-more-to-a-scammer?utm_campaign=brandsocial&utm_medium=social&utm_source=bluesky
8 days ago
0
3
1
Browsers like Chrome, Edge, and Firefox have been our traditional gateway to the internet. But a new generation of AI-powered browsers or “agentic browsers” have the internet asking: "Are AI browsers safe?"
loading . . .
AI browsers or agentic browsers: a look at the future of web surfing
Agentic and AI browsers are here: What are they? Which ones are there? How can they help me? Are they safe to use?
https://www.malwarebytes.com/blog/ai/2025/09/ai-browsers-or-agentic-browsers-a-look-at-the-future-of-web-surfing?utm_campaign=brandsocial&utm_medium=social&utm_source=bluesky
8 days ago
1
2
2
AI chatbot apps are leaking user data for several reasons, but mostly because security is an afterthought.
loading . . .
When AI chatbots leak and how it happens
Several AI chatbot apps are leaking user data for several reasons, but mostly because security is an afterthought.
https://www.malwarebytes.com/blog/news/2025/09/when-ai-chatbots-leak-and-how-it-happens?utm_campaign=brandsocial&utm_medium=social&utm_source=bluesky
11 days ago
0
2
4
The New York Blood Center’s (NYBC) suffered a ransomware attack in January, when an unauthorized party gained access to user data.
loading . . .
Ransomware attack at blood center: Org tells users their data's been stolen
NYBC has started sending out data breach notifications to those affected by a recent ransomware attack.
https://www.malwarebytes.com/blog/news/2025/09/ransomware-attack-at-blood-center-org-tells-users-their-datas-been-stolen?utm_campaign=brandsocial&utm_medium=social&utm_source=bluesky
12 days ago
0
3
3
Scammers are sending out texts that claim to be from the Bureau of Motor Vehicles (BMV), saying that you have outstanding traffic tickets.
loading . . .
Fake Bureau of Motor Vehicles texts are after your personal and banking details
Many state departments are warning about scam text messages targeting motorists. Here's how you can recognize them.
https://www.malwarebytes.com/blog/news/2025/09/fake-bureau-motor-vehicles-texts-are-after-your-personal-and-banking-details?utm_campaign=brandsocial&utm_medium=social&utm_source=bluesky
12 days ago
1
2
2
Japanese octogenarian promised the stars but left with a black hole in her wallet after “astronaut-in-distress" romance scam.
loading . . .
'Astronaut-in-distress' romance scammer steals money from elderly woman
A Japanese octogenarian lost thousands of dollars after being scammed by someone who described himself as an astronaut in need of help.
https://www.malwarebytes.com/blog/news/2025/09/astronaut-in-distress-romance-scammer-steals-money-from-elderly-woman?utm_campaign=brandsocial&utm_medium=social&utm_source=bluesky
12 days ago
0
1
1
Weight loss scams aren't always a too good to be true social media post. They are also being sent via text message. Read our latest research on phishing domains hosting GLP-1 scams.
loading . . .
Pre-approved GLP-1 prescription scam could be bad for your health
This scammy text pretends to come from a doctor and says a weight-loss medication prescription has been approved.
https://www.malwarebytes.com/blog/news/2025/09/pre-approved-glp-1-prescription-scam-could-be-bad-for-your-health?utm_campaign=brandsocial&utm_medium=social&utm_source=bluesky
13 days ago
0
3
1
Plex warns users to reset their passwords after attackers access customer data.
loading . . .
Plex users: Reset your password!
Media streaming platform Plex is recommending all users to chnage their password after noticing a security incident
https://www.malwarebytes.com/blog/news/2025/09/plex-users-reset-your-password?utm_campaign=brandsocial&utm_medium=social&utm_source=bluesky
13 days ago
0
1
1
Google ordered to pay $425M for misleading users about their online privacy.
loading . . .
Google misled users about their privacy and now owes them $425m, says court
A court has ordered Google to pay $425m in a class action lawsuit after it was found to have misled users about their online privacy.
https://www.malwarebytes.com/blog/news/2025/09/google-misled-users-about-their-privacy-and-now-owes-them-425m-says-court?utm_campaign=brandsocial&utm_medium=social&utm_source=bluesky
14 days ago
1
5
6
Popeyes, Tim Hortons, Burger King platforms have “catastrophic” vulnerabilities, say hackers.
loading . . .
Popeyes, Tim Hortons, Burger King platforms have "catastrophic" vulnerabilities, say hackers
Researchers found a host of vulnerabilities in the platforms run by RBI to service Burger King, Tim Horton's, and Popeyes.
https://www.malwarebytes.com/blog/news/2025/09/popeyes-tim-hortons-burger-king-platforms-have-catastrophic-vulnerabilities-say-hackers?utm_campaign=brandsocial&utm_medium=social&utm_source=bluesky
14 days ago
0
2
1
The lawsuit filed against Google alleges that the company misled users about the "Web & App Activity" setting, claiming that even after users disabled it, Google continued to collect app usage data, stating that it was anonymized.
loading . . .
Google misled users about their privacy and now owes them $425m, says court
A court has ordered Google to pay $425m in a class action lawsuit after it was found to have misled users about their online privacy.
https://mwb.link/41GCUEn
14 days ago
0
3
4
Phishers are targeting PayPal users again, this time through iCloud Calendar invitations.
loading . . .
iCloud Calendar infrastructure abused in PayPal phishing campaign
Phishers are abusing Apple and Microsoft infrastructure to send out call-back phishing emails with legitimate sender and return addresses.
https://mwb.link/3HNsqwj
15 days ago
0
4
3
Dangerous dashcam data dump deeply disturbs drivers.
loading . . .
Nexar dashcam video database hacked
Nexar, a company that sells dashcams--and the footage taken by those dashcams--was a privacy and security nightmare according to a hacker
https://www.malwarebytes.com/blog/news/2025/09/nexar-dashcam-video-database-hacked?utm_campaign=brandsocial&utm_medium=social&utm_source=bluesky
17 days ago
0
2
0
The popular online platform, which faced several lawsuits and criticism for not doing enough to protect kids, announced a plan to implement age estimation for all Roblox users.
loading . . .
Roblox introduces age checks to use communication features
Roblox announced plans to roll out age estimation for using the communication features on the platform to help fight sexual predators.
https://mwb.link/4gdWSwo
18 days ago
0
1
0
Several Android VPN apps for sale on the Google Play Store have security flaws that allow others to snoop on their traffic. They’re also deceiving users about their ownership.
loading . . .
Popular Android VPN apps found to have security flaws and China links
A recent report has revealed that many VPNs might allow others to sniff your data—and they're not being honest about who's behind them.
https://mwb.link/462695Q
18 days ago
0
2
2
TP-Link has issued a warning about a botnet that exploits two vulnerabilities to infect small office and home routers, which are then used to attack Microsoft 365 accounts.
loading . . .
TP-Link warns of botnet infecting routers and targeting Microsoft 365 accounts
The Quad7 botnet is adding End-of-Life TP-Link routers to its arsenal and using them to steal Microsoft 365 accounts.
https://mwb.link/4gaWDlJ
19 days ago
1
2
1
New feature alert! 🚨 Say hello to Malwarebytes Tools. 🛠️ Manage your startup apps, tweak your system, and protect your device with smarter firewall controls—all built-in to the Malwarebytes app and designed to keep your device running smoothly and securely. Available free for all Windows users.
loading . . .
19 days ago
1
7
3
‼️ Android users, update now ‼️ Google fixed 111 security issues in Android, including two serious flaws.
loading . . .
Update your Android! Google patches 111 vulnerabilities, 2 are critical
Google has issued updates to patch a whopping 111 Android vulnerabilities, including two actively exploited ones.
https://mwb.link/3JKf3gY
19 days ago
0
4
1
A highly sophisticated email scam is targeting PayPal users with the subject of “Set up your account profile," aiming to clean out your PayPal account.
https://mwb.link/4p4Rek3
loading . . .
PayPal users targeted in account profile scam
A highly sophisticated email scam is targeting PayPal users with the subject line of "Set up your account profile."
https://mwb.link/4p4Rek3
20 days ago
0
9
6
"These botnets use known vulnerabilities in internet-connected network equipment as hosts for their code and to infect other nearby devices." Malwarebytes's Researcher Pieter Arntz. Learn how cybercriminals are exploiting vulnerabilities in network devices to build powerful botnets in Metro.
loading . . .
'Gayfemboy' virus is raising a secret bot army without you even realising
Once infected, the malware leaves the message: 'Twink :3'
https://metro.co.uk/2025/09/02/gayfemboy-virus-raising-a-secret-bot-army-without-even-realising-24056225/
21 days ago
0
2
0
Even outside of tax season, scammers are out to get your information.
loading . . .
Tax refund scam targets Californians
Californians are receiving scammy text messages that tell them they're owed a tax refund. Don't click any links or reply!
https://mwb.link/46gUcKN
21 days ago
0
3
1
Some scammers are selling ETA documents at exaggerated prices, and others are after your personal and financial data.
loading . . .
Travelers to the UK targeted in ETA scams
Some scammers are selling ETA documents at exaggerated prices, and others are after your personal and financial data.
https://mwb.link/3I0oqII
22 days ago
0
0
1
Two-step verification, or two-factor authentication, is one of the best ways to protect your WhatsApp account from hackers. Here's how you set it up.
loading . . .
How to set up two-step verification on your WhatsApp account
This guide gives step-by-step instructions how how to enable two-step verification for WhatsApp on Android, iPhone and iPad.
https://mwb.link/45JSPEn
22 days ago
0
0
1
WhatsApp has patched a vulnerability that was used alongside an Apple vulnerability in zero-click attacks. WhatsApp advised the affected users to perform a full factory reset of their phone to make sure they are rid of the malware.
loading . . .
WhatsApp fixes vulnerability used in zero-click attacks
WhatsApp has patched a vulnerability that was used in conjunction with an Apple vulnerability in zero-click attacks.
https://mwb.link/3JEYnaC
22 days ago
0
2
1
Users are afraid that with AI integration and saving documents to the cloud, their work will be used to train artificial intelligence (AI) or that this is a Microsoft scheme to sell more cloud storage.
loading . . .
Microsoft wants to automatically save your Word docs to the cloud
Microsoft is rolling out a feature that defaults to saving your documents to the cloud. Consumers are divided.
https://mwb.link/4n5Z0se
26 days ago
0
4
2
Everyone hates robocalls. And tracking down the scammers and spammers responsible for these calls can be challenging. So the FCC is taking a new approach: disconnecting over a thousand voice operators from the network for not taking measures to stop robocalls on their networks.
loading . . .
"No place in our networks": FCC hangs up on thousands of voice operators in robocall war
Everyone hates robocalls. However, it's difficult to track down all the scammers and spammers that make them, so the Federal Communications...
https://mwb.link/3HKp794
26 days ago
0
2
0
TheTruthSpy stalkerware is designed to be installed secretly on a victim’s Android phone. It then monitors the phone’s activities and sends the gathered information back to central servers, which may be vulnerable to attacks.
loading . . .
More vulnerable stalkerware victims' data exposed in new TheTruthSpy flaw
TheTruthSpy is at it again. A security researcher has discovered a flaw in the Android-based stalkerware that allows anyone to compromise any record in the system.
https://mwb.link/4p0tJZu
27 days ago
0
0
0
Google has removed 77 malicious apps from the Google Play Store. Before they were removed, researchers discovered the apps had been installed over 19 million times.
loading . . .
77 malicious apps removed from Google Play Store
Researchers have found 77 malicious apps in the official Google Play Store ranging from adware to state of the art banking Trojans.
https://mwb.link/423S0DU
27 days ago
0
2
1
Prompt injection attacks could be coming to an AI browser near you. 🤖 Learn how “prompt injection” attacks work, how one team found a flaw in an agentic browser, and how to stay safe. 👇
loading . . .
AI browsers could leave users penniless: A prompt injection warning
Prompt injection attacks could be coming to an AI browser near you. Read on to understand what these attacks do and how to stay safe.
https://www.malwarebytes.com/blog/news/2025/08/ai-browsers-could-leave-users-penniless-a-prompt-injection-warning?utm_campaign=brandsocial&utm_medium=social&utm_source=bluesky
29 days ago
0
2
2
Learn how a recent clickjacking attack targeted password managers and what you can do to stay secure. Read more. 👇
loading . . .
Clickjack attack steals password managers' secrets
A clickjack attack was revealed this summer that can steal the credentials from password managers that are integrated into web browsers.
https://www.malwarebytes.com/blog/news/2025/08/clickjack-attack-steals-password-managers-secrets?utm_campaign=brandsocial&utm_medium=social&utm_source=bluesky
about 1 month ago
0
5
5
Grok, is it true?
loading . . .
Grok chats show up in Google searches
Grok AI chats that users wanted to share with individual people were in fact shared with the broader web and searchable by everyone.
https://www.malwarebytes.com/blog/news/2025/08/grok-chats-show-up-in-google-searches?utm_campaign=brandsocial&utm_medium=social&utm_source=bluesky
about 1 month ago
0
3
2
‼️ If you're an Apple user, update your devices now ‼️ Apple has released security updates for iPhones, iPads, and Macs to fix a zero-day vulnerability (a vulnerability that Apple was previously unaware of) that is reportedly being used in targeted attacks.
loading . . .
All Apple users should update after company patches zero-day vulnerability in all platforms
Apple has released security updates to patch a zero-day vulnerability tracked as CVE-2025-43300 for all platforms
https://mwb.link/4mvZh7O
about 1 month ago
0
4
3
Google has settled a lawsuit against YouTube for $30 million, but did not admit to collecting the data of minors for targeted advertising.
loading . . .
Google settles YouTube lawsuit over kids' privacy invasion and data collection
Google has settled a lawsuit against YouTube for $30 million but did not admit collecting data of minors for targeted advertising.
https://mwb.link/41ULT4L
about 1 month ago
0
1
0
"AI-powered stuffed animals" is not a phrase we had on our 2025 bingo card, yet here we are.
loading . . .
AI-powered stuffed animals: A good alternative for screen time?
Startups are ready to bring AI powered toys to the market as an alternative for screen time. But is that really progress?
https://www.malwarebytes.com/blog/news/2025/08/ai-powered-stuffed-animals-a-good-alternative-for-screen-time?utm_campaign=brandsocial&utm_medium=social&utm_source=bluesky
about 1 month ago
0
3
1
Scammers posing as Google support call victims to steal their login credentials under the pretense of account recovery, aiming to take over the victim's account.
loading . . .
How to spot the latest fake Gmail security alerts
Fake Gmail security alerts are tricking users into inadvertently handing over control of their accounts to scammers. Here's what to look for.
https://mwb.link/4oFPVrp
about 1 month ago
0
1
3
Instagram Map is a new feature—for Instagram, anyway—that users may have enabled without being fully aware of the consequences. The feature shares your current location with your friends.
loading . . .
Instagram Map: What is it and how do I control it?
Meta has introduced Instagram Map. How can you control what others can see about your location? An explainer.
https://mwb.link/4mlRg5a
about 1 month ago
0
2
0
Load more
feeds!
log in