Malware Bytes
Apple fixes another image-processing flaw that could allow code execution
Apple has released security updates for more than two dozen security vulnerabilities across iPhone, iPad, and macOS Tahoe,including yet another image parsing vulnerability that could compromise your device.
This update delivers security fixes that were first made available in the iOS 27 and iPadOS 27 betas.
Updates for your particular deviceThe table below shows which updates are available and points you to the relevant security content for each one.
Name and information linkAvailable foriOS 26.6.1 and iPadOS 26.6.1iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and lateriOS 18.7.10 and iPadOS 18.7.10iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generationmacOS Tahoe 26.6.2macOS TahoevisionOS 26.6.1Details coming soon How to update your Apple devices How to update your iPhone or iPadFor iOS and iPadOS users, here’s how to check if you’re using the latest software version:
Go to Settings > General > Software Update. You will see if there are updates available and be guided through installing them.
Turn on Automatic Updates if you haven’t already—you’ll find it on the same screen.
Update is ready How to update macOS on any versionTo update macOS on any supported Mac, use the Software Update feature, which Apple designed to work consistently across all recent versions. Here are the steps:
- Click the Apple menu in the upper-left corner of your screen.
- Choose System Settings (or System Preferences on older versions).
- Select General in the sidebar, then click Software Update on the right. On older macOS, just look for Software Update directly.
- Your Mac will check for updates automatically. If updates are available, click Update Now (or Upgrade Now for major new versions) and follow the on-screen instructions. Before you upgrade to macOS Tahoe 26, please read these instructions.
- Enter your administrator password if prompted, then let your Mac finish the update (it might need to restart during this process).
- Make sure your Mac stays plugged in and connected to the internet until the update is done.
Of the 27 vulnerabilities, CVE-2026-65346 is the one that stands out. It is an ImageIO integer-overflow bug in which merely processing a malicious image may result in arbitrary code execution, a substantially stronger stated impact than the many “crash-only” findings in this release.
ImageIO is Apple’s framework that handles image parsing. An integer overflow means the vulnerability lets a malicious hacker trick the program into performing an integer operation where the result exceeds the allocated memory space. This can lead to attackers running malicious programs or gaining elevated privileges. In this case, it allows the attacker to run code on the target’s device.
There is no indication in Apple’s advisory that CVE-2026-65346 or any other listed vulnerability was exploited in the wild, but cybercriminals will often try to reverse engineer the patch to come up with an exploit, or the researchers who found it will post a proof-of-concept once everyone has had a chance to apply the update. At that point, these vulnerabilities can be used against you.
Scammers know more about you than you think.
Malwarebytes Mobile Security protects you from phishing, scam texts, malicious sites, and more. With real-time AI-powered Scam Guard built right in.
Be careful what you put in “anyone with the link” Google Docs
The next time you type something sensitive into a Google Doc—or any other online tool with a sharing feature—be careful about the permissions you grant.
Speaking with The Register, the founder of QR generation service Pageloot said that he learned that the hard way. Siim Kostabi recalled how a contractor working for the company accidentally exposed login details for its staging environment—credentials that were never meant to leave an internal testing setup.
The hapless developer had access to a staging environment (used to test new software code before it goes live). They stored the login details in a Google Doc and then set it to “anyone with the link can view.”
It turns out Google Search can index Google Docs with that setting if the link becomes discoverable on the public web. “Anyone with the link” files aren’t automatically indexed, so we don’t know exactly how Google discovered this particular document. What we do know is that it did: The credentials file ended up in Google Search.
A Pageloot developer typed the company’s domain into Google while debugging, and Google’s autocomplete feature surfaced a staging hostname followed by what looked like a credential string. Sure enough, the document was accessible online. Google Search was surfacing information from a document that had been shared too widely.
To its credit, Pageloot moved quickly. It cut the contractor’s access and changed every affected credential. It also banned password storage in Google Docs, Slack, Notion, and any other shared workspace.
The problem is that none of those fixes existed before autocomplete surfaced the password. If nobody had spotted it, the credentials could have remained exposed.
People share private data in online tools all the timeIf there was ever an example of why you should use a password manager, this is it. Instead, the contractor typed their login details into a Google Doc, presumably to keep them handy.
Pageloot isn’t alone in dealing with this problem. Ateam, a Japanese Android game developer, left a Google Drive instance set to “Anyone on the internet with the link can view” from March 2017 until November 2023. That single misconfiguration exposed 1,369 files and personal data for 935,779 people. Ateam said it had seen no evidence anything was taken, though seven years of open access is hardly reassuring.
Scale AI, the data-labeling company central to Meta’s AI ambitions, also left 85 Google Docs with training material for Meta, Google, and xAI editable to anyone with a link. Contractors called the setup “incredibly janky”. Scale later disabled users’ ability to share managed documents publicly.
This is a trend. Three years ago, AI security company Metomic scanned approximately 6.5 million Google Drive files and found that 40.2% contained sensitive information. Just over a third were shared externally, while 0.5% were fully public.
That 0.5% might not sound like a lot, but across 6.5 million files, it still represents thousands of publicly accessible files.
This isn’t just a Google problem, though. People accidentally share sensitive information through other tools too, like the Trello project management system. Making a Trello board public makes it viewable to everyone, which was unfortunate for government users when they exposed passwords and security plans that way in 2018.
The problem is that as tools become increasingly collaborative, people can’t keep up. They make mistakes. Verizon’s 2025 Data Breach Investigations Report attributes around 60% of breaches to human factors including misconfiguration and misuse of valid credentials.
What the checkbox costPageloot encountered another access-control failure involving a customer. A disgruntled former employee whose access had never been revoked used it to redirect the customer’s QR codes to a competitor’s site. It was the same root cause: nobody was watching who had access to what.
Kostabi learned his lesson, which is to keep an eye on who has access to what.
Consumers can take a few simple precautions too. Don’t store passwords or other highly sensitive information in ordinary shared documents. Use a password manager for passwords, and before hitting Share in any online service, check exactly who will be able to access what you’re sharing.
“One of the best cybersecurity suites on the planet.”According to CNET. Read their review →
Heights Finance data breach: What customers need to know
Heights Finance Holdings’ online data breach notification says an unauthorized party accessed a third-party cloud platform containing customer data, potentially exposing highly sensitive personal, banking, and identity information.
Heights Finance is a consumer lender that offers personal installment loans. Reportedly, the company filed a report with Texas regulators mentioning 734,828 affected people, though that figure should not automatically be read as a confirmed nationwide total, since Heights Finance operates dozens of personal loan companies across Alabama, Tennessee, Georgia, Texas, and South Carolina.
The company is associated with the former CURO Management business and related brands. The breach notice covers not only some Heights Finance customers, but potentially people connected to certain current or former CURO-related brands.
On May 7, Heights Finance discovered that an unauthorized party had gained access to a cloud-based platform run by a third party and used to store certain customer information. The company says its investigation found that the intruder may have viewed or copied information in that environment.
Heights says affected people may include:
- People who received a loan through Heights Finance.
- People who inquired about or applied for a loan product, including through a third party.
- Some customers of former parent company CURO Management and its present or former related brands.
What makes the incident especially concerning is the nature of the potentially exposed records, which can include the combination of information criminals need to impersonate someone, target their bank accounts, or create highly convincing phishing attempts.
Breaches happen every day. Don’t be the last to know.Potentially exposed data includes:
- Contact information: Name, home address, phone number, and email address.
- Financial information: Account details, bank name, bank account number, routing number, and related financial information.
- Government identifiers: Social Security number (SSN), tax identification number, driver’s license number, or state ID number.
- Other personal data: Date of birth and personal circumstances voluntarily disclosed during customer service interactions.
The combination of a Social Security number, date of birth, address, and bank account details can create a much more serious risk than a breach exposing only email addresses. It can support identity fraud, financial fraud, account takeover attempts, and tailored social engineering scams.
The personal circumstances customers may have shared with support staff could also make scams more persuasive or potentially more harmful, particularly for people who discussed financial distress, repayment problems, or other sensitive subjects.
What affected customers should doPeople who receive a letter from Heights Finance should follow the company’s instructions and enroll in the offered protection service. Exact instructions can be found on Heights Finance’s website.
Since people who were not actual customers could also be affected, there may be some uncertainty about whether someone’s information was included in the data breach. If you believe you fall into one of the listed groups but do not receive a notice, use contact details published by Heights Finance for inquiries. Do not use a number provided in an unexpected email, text, phone call, or even sponsored search result to ask whether your information was involved.
More general advice on what to do is available in our article Involved in a data breach? Here’s what you need to know.
What do cybercriminals know about you?
Use Malwarebytes’ free Digital Footprint scan to see whether your personal information has been exposed online.
ShieldBreak bypasses Microsoft’s patch for earlier Defender flaw
Microsoft Defender’s latest patch bypass shows a familiar problem.
A newly disclosed Microsoft Defender flaw called ShieldBreak shows that fixing one attack path doesn’t always close every route to the same result.
Microsoft has assigned ShieldBreak the identifier CVE-2026-69414 and confirmed it is an elevation of privilege (EoP) vulnerability in the Microsoft Malware Protection Engine. Microsoft says it is still working on a security update.
If that sounds somehow familiar, you’re probably thinking of RoguePlanet, another vulnerability in Defender that Microsoft acknowledged on June 16 and patched on July 8.
A short timelineAt the time, the published exploit for RoguePlanet was described as depending on a race condition, meaning it was not guaranteed to work the same way on every machine. That was one reason the vulnerability was concerning but still somewhat limited from a practical point of view.
Microsoft’s July fix should have closed the door on that problem. But security fixes do not always eliminate a weakness at the root of the problem. Sometimes they block one known attack path, while a researcher later finds a different route to reach the same end result.
That appears to be what happened here. ShieldBreak has been described as a patch bypass because it reportedly sidesteps the earlier RoguePlanet fix, although it uses a different exploitation method rather than simply repeating the original attack.
In August, the same researcher disclosed ShieldBreak, and Microsoft responded by publishing a new advisory for CVE-2026-69414.
The advisory says the issue has been publicly disclosed, proof-of-concept (PoC) exploit code exists, exploitation is considered more likely, and no official fix is available yet. Microsoft says it is working on one.
How to stay safeUntil Microsoft releases a fix, the most important protection is preventing untrusted code from running on your computer in the first place. ShieldBreak is a local privilege escalation issue, so an attacker first needs some level of access to the machine.
Based on the best public reporting available right now, ShieldBreak appears to require Microsoft Defender to be enabled in order to work. Public testing indicates that the exploit does not succeed when Defender is off or when another product is registered as the active antivirus provider.
So, narrowly speaking, disabling Defender appears to stop this specific ShieldBreak chain from working. However, that is not a good safety recommendation for most people. Turning off your antivirus removes an important layer of protection and could leave your computer exposed to other attacks.
For home users, all that means:
- Install Microsoft’s security updates as soon as they become available.
- Be very careful with downloads, email attachments, cracked software, and “fix” tools from random websites.
- Keep backups of important files somewhere not directly connected to the PC.
- Use an up-to-date, real-time anti-malware solution to alert you about and remove threats from your computer.
According to CNET. Read their review →
Fake TikTok rewards promise cash you’ll never get
TikTok-branded “rewards” pages are promising users cash for checking in every day, completing small tasks, and earning points. Those points supposedly convert into real money, and the balances look enormous. A countdown timer usually warns that your balance is about to expire. But when you try to withdraw it, there’s always something else you need to do first.
If you just want the short versionTikTok does have a legitimate Creator Rewards Program, but it doesn’t work like the sites we’re talking about here. Creator Rewards is for eligible creators in certain countries who meet specific requirements. They earn rewards for eligible original videos, not for checking in every day or completing tasks on a separate rewards website.
If you find a TikTok-branded site offering large cash rewards for check-ins, referrals, or simple tasks, don’t assume it’s legitimate just because TikTok has its own rewards program.
You can end up chasing a payout that was never coming, handing over personal or banking details, or installing an unwanted app.
How these pages typically workMost versions of this scam are built to look like a mobile shopping or loyalty app. There’s a TikTok logo, a “welcome back” greeting, a daily check-in tracker, and tabs for tasks, referrals, and your profile. At first glance, it can easily look like an official rewards program connected to TikTok.
When you tap through to the “redeem” screen, the numbers can show a cash balance in the thousands, converted from a huge pile of points, along with a countdown warning that your balance is about to expire. The minimum withdrawal is usually low enough to make cashing out look easy.
It isn’t.
Sites like this tend to introduce one more requirement every time you get close to actually withdrawing the cash. Refer more friends, watch more videos, complete a sponsored offer through an affiliate network, or download a separate app to “verify” your identity.
The app download may be the real goal, particularly if the operator gets paid for generating installs. The app could also be adware or other unwanted software.
Big numbers don’t mean real moneyNothing on these pages reflects a real ledger. A balance on the screen doesn’t mean there’s money waiting for you.
On a fake rewards site, the points, cash balance, and countdown can simply be numbers generated by the site itself, with no connection to TikTok’s actual systems.
The operator simply invents a sum that feels too good to walk away from.
So who is making money?These sites tend to make money the same way most ad-funnel scams do: through affiliate and CPA (cost-per-action) programs.
CPA means the site operator can get paid when you do something, such as clicking an ad, signing up for a service, or installing an app. So even if you never receive the promised reward, your clicks, sign-ups, and downloads can still make money for someone else.
Why it’s easy to get pulled inA daily check-in streak creates a small sense of investment. Walking away means giving up your streak and the money you think you’ve already earned.
Then there’s the big balance sitting on the screen and a countdown telling you it’ll disappear if you don’t act soon. Together, they give you plenty of reasons to keep going and very little time to question whether any of it is real.
What to do if you find one- Don’t enter banking details, card numbers, or ID information unless you’ve confirmed you’re using an official TikTok service.
- If you were prompted to download an app outside TikTok itself, don’t install it. If you already have, uninstall it and run a security scan on your device.
- Don’t refer friends or family to keep a streak going or unlock a withdrawal. You’d just be pulling them into the same funnel.
- Check rewards in TikTok itself. TikTok’s Creator Rewards Program is for eligible creators and is managed through TikTok. If a separate website claims you can earn TikTok cash rewards through check-ins or simple tasks, don’t assume it’s part of the same program.
Reward-mill scams like this aren’t unique to TikTok. The same check-in-and-cash-out formula appears with other brand names too. The name may change, but the trick is much the same: Keep you clicking with the promise that your money is just one more task away.
Something feel off? Check it before you click.Malwarebytes Scam Guard helps you analyze suspicious links, texts, and screenshots instantly.
Available with Malwarebytes Premium Security for all your devices, and in the Malwarebytes app for iOS and Android.
Update your Mac: Screen Sharing vulnerability exploited in the wild
The Dutch National Cyber Security Centre (NCSC) issued a warning after being notified of several incidents where a vulnerability in Apple’s Screen Sharing feature was exploited to install Monero cryptominers.
The vulnerability, tracked as CVE-2026-65400, was patched by Apple on August 6. It is an authentication-bypass flaw in macOS Screen Sharing that can let an attacker on the network connect without valid credentials.
macOS’s built-in Screen Sharing service is a remote-control feature commonly associated with port 5900. Successful exploitation can allow a remote attacker on a reachable network to authenticate to the service without legitimate credentials.
Apple said the bug was fixed through “improved state management,” which suggests an authentication-flow or session-state validation failure rather than a cryptographic break.
The patch was issued for macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9. Practical exposure requires Screen Sharing to be enabled, so the highest-risk systems are those where port 5900 is internet-accessible, typically through a router port-forward, public IP assignment, or hosting-provider setup. Hosts reachable only from an internal network are still potentially exposed, but attackers would have to gain a position on that network.
An attacker could view and control the Mac remotely because that is the function Screen Sharing provides. NCSC says active cases involved attackers gaining root access and installing cryptomining software, specifically for Monero mining.
The criminals likely chose Monero mining because it does not depend on heavily specialized, application-specific integrated circuits (ASICs), but can be done with any CPU or GPU.
Cryptomining isn’t necessarily the worst an attacker could do. With a root-level compromise an attacker could enable persistence, data theft, credential and key harvesting, deployment of additional malware, and lateral movement.
How to stay safe Install the updateThe best way to protect your Mac is to install the update.
To update macOS on any supported Mac, use the Software Update feature, which Apple designed to work consistently across all recent versions. Here are the steps:
- Click the Apple menu in the upper-left corner of your screen.
- Choose System Settings (or System Preferences on older versions).
- Select General in the sidebar, then click Software Update on the right. On older macOS, just look for Software Update directly.
- Your Mac will check for updates automatically. If updates are available, click Update Now (or Upgrade Now for major new versions) and follow the on-screen instructions. Before you upgrade to macOS Tahoe 26, please read these instructions.
- Enter your administrator password if prompted, then let your Mac finish the update (it might need to restart during this process).
- Make sure your Mac stays plugged in and connected to the internet until the update is done.
If you can’t update immediately, check whether Screen Sharing is enabled and turn it off if you don’t use it.
- Click the Apple menu in the top-left corner of the screen.
- Select System Settings.
- In the left sidebar, click General.
- Click Sharing on the right; you may need to scroll down.
- Find Screen Sharing:
- If the switch is off/grey, it is disabled.
- If the switch is on/colored, click it to switch it off.
Also check Remote Management on that same Sharing page. It provides another remote-control route and should be off unless the owner knowingly uses it for work or IT support.
Macs need protection too
Malwarebytes Premium Security for Mac stops threats and protects your Mac and personal files from hackers and cybercriminals.
Why Facebook’s war on ad blockers could help scammers
Reports that uBlock Origin is stepping back from the never-ending effort to filter Facebook ads are a reminder that ad blocking is no longer only an argument about inconvenience, publishers, and lost advertising revenue.
It is also an issue of security.
For years, ad blockers have occupied an uncomfortable place in the web economy. Publishers and platforms rely on advertising to fund their services, while users install blockers to escape intrusive banners, autoplay videos, tracking scripts, and feeds that increasingly feel designed around monetization rather than the people using them.
That debate is usually framed as a contest between a platform’s right to make money and a user’s desire for a cleaner browsing experience. But it leaves out an important detail: Ads are not always merely ads.
Malwarebytes General Manager Mark Beare stated:
“While it’s easy to look at ad blockers solely as a way of hurting monetization for these businesses, the other thing that ad blockers are doing is blocking malicious and scam ads.”
Sometimes ads are scams. At other times, they lead to malicious sites. And often, they impersonate trusted brands, promise fictional government payments, promote fake investment opportunities, or send victims into private messaging channels where the fraud continues.
In those cases, an ad blocker is not simply removing something annoying. It’s removing a route into a scam.
The advantage lies with the platformsThe reported decision by uBlock Origin’s team to stop continually chasing changes to Facebook ads highlights a structural advantage held by large platforms.
An ad blocker generally works by identifying requests, scripts, page elements, and patterns associated with advertising or tracking. A platform that controls the entire delivery stack can alter those patterns: It can change element names, move content into new components, serve ads through first-party infrastructure, or make sponsored content look more like ordinary posts.
This creates a familiar cat and mouse game. Filter-list maintainers identify a new method, the platform changes its implementation, users receive an update, and then the cycle starts all over. Again and again.
It’s the difference in resources that matters. A major platform can deploy changes on an enormous scale and has dedicated teams working on its products, advertising systems, and infrastructure. Open-source filter maintainers and independent blocking tools do not have the same staffing, telemetry, or ability to anticipate upcoming changes in how ads are delivered or how the platform will modify its systems.
That does not mean platforms should be expected to design their products around every third-party extension. Nor does it mean every attempt to detect or resist blocking is malicious. Advertising funds a great deal of the online content and services people use every day.
Not every blocked ad is harmlessA platform’s ability to make ads harder to distinguish from ordinary content should come with a corresponding responsibility: Make sure the ads being delivered deserve the trust implied by that integration.
Internal Meta documents reviewed by Reuters showed that the company projected about 10% of its 2024 revenue, or $16 billion, would come from ads for scams and banned goods. Meta said the estimate was “rough and overly-inclusive,” and that the true figure was lower.
That is a clear mismatch with Meta’s advertising rules, which explicitly prohibit deceptive and misleading ads, including schemes intended to scam people. Meta said its ad-review system examines ads before they go live and can re-review them later, but Meta also acknowledges that an ad may begin delivering before it has been reviewed against every policy.
That time gap is important. Scam campaigns are built to exploit speed and scale. Fraudsters can test new creatives, swap landing pages, impersonate a brand or public figure, and adapt when enforcement catches up. Meta disputed Reuters’ characterization of its anti-fraud efforts.
This is not an argument that every ad on Facebook, Instagram, or another large platform is dangerous. Most are not. The problem is that users cannot reliably tell, at a glance, which ad is a legitimate offer and which one is an attempt to steal money, credentials, or personal data.
Better moderation of ads is better for everyoneRather than treating every blocker as a threat to revenue, a more productive response to ad blocking is to make the advertising experience safer, less invasive, and more accountable.
That starts with focusing less on defeating filters and more on preventing harmful ads from being approved or reaching users in the first place.
Some practical priorities include:
- Verify advertisers more consistently, especially in high-risk categories such as financial services, cryptocurrency, health products, job offers, and government-benefit claims.
- Review not only the visible creative, but also the destination page, redirects, tracking behavior, and later changes to the advertiser’s site.
- Detect and act on coordinated impersonation campaigns quickly, rather than treating each fraudulent ad account as an isolated incident.
- Make it easy for users to report ads and give them useful feedback when action has been taken.
- Tackle ads before they can direct people into private messages, where scammers can continue the conversation outside public scrutiny.
- Treat repeat offenders, cloned campaigns, and accounts linked to known fraud infrastructure as a network problem, which is much more effective than moderating them one ad at a time.
- Give users meaningful controls over ad personalization, tracking, and the volume of ads they see.
Meta has policies against scams in place, continues to remove ads that violate those policies, and has announced additional anti-scam measures. Those are necessary steps. The question is whether they are sufficient for an environment where criminals are motivated, well-funded, and able to adapt rapidly.
No ad-review system will catch everything. Criminals will continue to use deception, compromised advertising accounts, and fast-changing infrastructure to get around automated checks.
That is why layered protection matters here as well.
Users should be able to choose tools that reduce tracking, block intrusive advertising, and stop access to known malicious sites. They should also be able to use browser protections, security software, and healthy skepticism when an ad promises easy money, a surprise refund, a miracle product, or a deal that seems too good to be true.
If ad blockers and the platforms that rely on advertising can find ways to work together, allowing security tools to intercept the malicious content their moderation systems miss, we can make the internet safer for everyone.
Stop threats before they can do any harm.
Malwarebytes Browser Guard blocks phishing pages and malicious sites automatically. Free, one click to install. Add it to your browser →
A week in security (August 10 – August 16)
Last week on Malwarebytes Labs:
- Apple now uses iPhone alerts for targets of mercenary spyware
- WhatsApp is testing a new warning for scam messages
- New Android malware lets criminals use your bank card in real time
- Parents take on Meta, TikTok, Google, and Snap in 3,000 youth safety lawsuits
- “Zoomsday” flaws could let one Zoom participant attack another
- Patch Tuesday: Update now to fix 421 flaws, including three zero-days
- Fake CCleaner installs GhostDesk Chrome spyware
- Valve warns Steam hardware buyers: Expect fake delivery scams
- Social media platforms crack down on drone factory recruiting game
- Sexual predators targeting online accounts for intimate images, FBI warns
- Love/hate relationship: The AI affair. Young people love AI, but it’s breaking their trust
- Watch out for fake TikTok Shops trying to steal your money
- Fake popular sites offer a free app, instead take over PCs
- How to fake a data trail (and maybe lower prices) (Lock and Code S07E16)
- New turnkey kit makes it easy for anyone to become a scammer
- Edge is dropping older extensions, affecting popular privacy tools
Stay safe!
From reporting threats to removing them.
Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.
Apple now uses iPhone alerts for targets of mercenary spyware
Apple has expanded its threat-notification system for targets of mercenary spyware.
Apple now shows a warning directly on an iPhone’s Lock Screen and in Settings when it believes the device owner has been targeted by mercenary spyware. The new on-device alert is meant to make a high-risk warning harder to overlook and complements notifications by email and through the user’s Apple Account page.
In the explanation, Apple states:
“Apple threat notifications are high-confidence alerts that a user has been individually targeted by a mercenary spyware attack, and should be taken very seriously.”
“Apple Threat Notification
Apple detected a mercenary spyware attack targeted at your iPhone. There are actions you can take now to help protect your data and device.”
Apple says its threat notifications are intended for people individually targeted by mercenary spyware attacks, which are highly sophisticated campaigns usually associated with commercial surveillance vendors and their government customers. Apple says it has notified targets in over 150 countries since the launch of the program in 2021, while the latest round of notifications reached people in 110 countries.
Mercenary spyware campaigns are usually not aimed at the average iPhone owner—at least at first. The initial targets are often people selected for who they are, what they know, or the work they do. But it would be a mistake to view this as someone else’s problem.
Attack techniques developed for narrowly targeted operations have a habit of spreading. Exploits can be reused, sold onward, reverse engineered, copied by other surveillance vendors, or adapted by criminal groups. A vulnerability initially valuable because it compromises a small number of carefully chosen devices may become much more dangerous once public disclosure, patch analysis, or exploit sharing makes them available for more widespread campaigns.
How to stay safeApple advises users to:
- Update your devices to the latest software, which includes the latest security fixes.
- Protect your devices with a passcode, Touch ID, or Face ID.
- Use two-factor authentication and a strong password for your Apple Account.
- Turn on Stolen Device Protection.
- Install apps from the App Store.
- Use strong and unique passwords, and passkeys where available.
- Don’t open links or attachments from unknown senders.
We’d like to add:
- Potential targets of mercenary spyware should consider applying Apple’s Lockdown Mode.
- Check if an Apple Threat Notification is real. Scammers will undoubtedly try and mimic them. You can verify a notification by signing in to your Apple account. A genuine Threat Notification will always be clearly listed there.
- If you receive an Apple Threat Notification, Apple recommends seeking expert help, such as the Digital Security Helpline from Access Now.
Scammers know more about you than you think.
Malwarebytes Mobile Security protects you from phishing, scam texts, malicious sites, and more. With real-time AI-powered Scam Guard built right in.
WhatsApp is testing a new warning for scam messages
Meta announced it’s rolling out a new feature for WhatsApp users in the fight against scammers.
Scam Alert is an optional beta feature that uses an on-device machine-learning model to flag likely scam messages from people who are not in a user’s contacts.
The Scam Alert feature arrives as scammers increasingly use WhatsApp for impersonation, fake jobs, fake sales, investment fraud, romance baiting, malicious links, and payment requests. These campaigns often begin on another platform before moving victims into a private chat, where criminals can apply pressure and build trust.
Once enabled, Scam Alert downloads a machine-learning model to the device and examines incoming messages from non-contacts for patterns associated with scams. WhatsApp says the model uses linguistic signals and conversational structure learned from scam conversations previously reported by users.
It is a meaningful new defensive layer, but it will not block anything. Instead, it alerts the user to stop and think carefully before engaging with the sender.
There’s another important limitation: some of the most effective WhatsApp scams arrive from a compromised contact, such as the recent “vote for my friend” account-takeover campaign. Because the message appears to come from someone the victim already knows, an unknown-sender warning may never appear.
Scam Alert is another step in Meta’s anti-scam campaign across WhatsApp, Facebook, and Messenger to fight sophisticated fraud tactics.
Don’t recognize that number? We’ll check it.If the model identifies what might be a scam, WhatsApp displays a warning banner in the chat. The sender does not see the warning, so the feature should not tip off a scammer that their approach has been detected.
Users can then:
- Block the sender, preventing further messages.
- Report the chat to WhatsApp.
- Continue the conversation if they believe it is legitimate.
- Mark the chat as trusted, which removes the warning and prevents Scam Alert from flagging that conversation again.
WhatsApp’s Scam Alert is a promising example of using on-device AI to add friction to scams without requiring a provider to read private conversations. Its optional nature, local classification, transparency commitments, and lack of automatic reporting are notable design choices for an encrypted messaging service.
The feature is currently in a limited beta rollout and is being tested with researchers in Meta’s bug bounty community before a wider release.
How to stay safeTo protect your WhatsApp account from takeover:
- Enable two-step verification for WhatsApp.
- Don’t click unexpected links, particularly if the message asks you to verify, connect, or link your WhatsApp account.
- Never follow instructions to link devices or scan QR codes unless you initiated the action yourself.
- Regularly review your linked devices in WhatsApp (Settings > Linked devices) and log out of any you don’t recognize.
To stay out of the hands of scammers:
- Be wary when a Facebook or Instagram exchange tries to migrate to WhatsApp. That handoff to a private channel is a classic scammer move, taking the conversation away from public scrutiny and platform enforcement.
- Research the account that contacted you. What other activity is there on the account? Do they have an established profile?
- Pay with a card or service that offers chargeback protection. Never pay by bank transfer, cryptocurrency, gift card, or Friends and Family payment methods when buying from someone you don’t know.
- Remember that seeing an ad on a major platform isn’t an endorsement. Scammers routinely place ads alongside legitimate businesses.
If you’re unsure whether a flagged chat is a scam attempt, you can always ask Malwarebytes Scam Guard for a second opinion. It’s free, available for mobile, desktop, and integrated into major AI chatbots like ChatGPT and Claude.
Something feel off? Check it before you click.Malwarebytes Scam Guard helps you analyze suspicious links, texts, and screenshots instantly.
Available with Malwarebytes Premium Security for all your devices, and in the Malwarebytes app for iOS and Android.
New Android malware lets criminals use your bank card in real time
Researchers at Group-IB have discovered a new NFC relay malware family, purpose-built to capture live card data via NFC and forward it in real time to attackers. They dubbed it “WindRelay.”
NFC (Near Field Communication) is wireless technology that allows devices such as smartphones, payment cards, and payment terminals to communicate when they’re very close together. So, instead of stealing your physical bank card, the attackers capture NFC activity on an infected mobile phone and relay it in real time to a criminal-controlled device held against a contactless payment terminal, or an ATM that supports contactless cash withdrawals.
The researchers describe a 13-minute call impersonating a bank, in which a victim was persuaded to install an Android app labelled with the bank’s name. That app was a remote access Trojan (RAT) called SpyNote. SpyNote gave the attacker remote control of the phone and enabled the quiet installation of a second app, WindRelay.
The attackers then opened the victim’s legitimate banking app remotely and arranged a loan in the victim’s name, while also asking them to tap their physical payment card against the phone and enter its PIN. That tap let the second app forward the card’s contactless data in real time to the criminals, allowing them to make purchases or, in some cases, withdraw cash from an ATM.
This division of tasks is the important development here. The remote-access malware (SpyNote) gets the attackers into the phone, and the NFC relay malware (WindRelay) turns the victim’s physical card into something the criminals can use elsewhere at that moment.
It’s not quite as simple as it sounds, because NFC comes in a few different “flavors.” Some produce a static code. Take the card that opens my apartment building door, for example. That kind of signal can easily be copied to a device like my Flipper Zero so I can use it to open the door. But sophisticated contactless payment cards use dynamic codes. Each time you tap to pay, your card’s chip generates a unique, one-time code (often called a cryptogram or token) that cannot be reused.
That’s why the critical feature of NFC relay malware is real-time relaying. Since payment card transactions use dynamic, transaction-specific cryptographic data, timing is central to this kind of fraud.
The telephone call isn’t just the lure. It’s also the attackers’ control channel. It lets them overcome the victim’s hesitation, respond to confusion instantly, and coordinate the precise moments when the victim installs an app, taps their card, and enters a PIN.
This is part of an established and expanding NFC relay fraud category sometimes called ghost tapping. In the past, we’ve discussed NGate and SuperCard X, which are similar malware families. But the combination with SpyNote is what makes this campaign stand out.
How to protect yourselfAs with many security threats, the best defense is you. The cybercriminals behind this attack can’t do anything unless you install the software on your phone, so they go through several steps to convince you to do so.
- Be skeptical of calls and text messages from people you don’t know, especially those claiming to be urgent. Scammers typically try to panic you into acting quickly. Once they get you on the phone, they can build trust, making it harder to think critically and say no.
- If you feel compelled to take action, check in with someone you trust first. If you’re still convinced the request is genuine, verify the message independently. Call your financial institution using an official number, not through the one in the text message or email.
- Never give personal details to anyone who contacts you unexpectedly, and never change your banking details at their request. A bank will not ask you to install an app from a link, text message, browser download, or other unofficial source to “secure” your card.
- Avoid sideloading apps (installing them from outside of the Google Play store), and treat unexpected Accessibility or device-control permissions as a serious warning sign.
- Use an up-to-date, real-time anti-malware solution to protect your devices.
Malwarebytes for Android detects SpyNote and WindRelay as:
- Android/Trojan.NGate.ACRBCF9BBC3C1
- Android/Trojan.NGate.ACR2401245FC5
Scammers know more about you than you think.
Malwarebytes Mobile Security protects you from phishing, scam texts, malicious sites, and more. With real-time AI-powered Scam Guard built right in.
Parents take on Meta, TikTok, Google, and Snap in 3,000 youth safety lawsuits
A group of big tech firms is fighting to stop roughly 3,000 youth safety lawsuits from moving forward, and they just lost a critical procedural battle in court.
The lawsuits, brought by attorneys general and families, allege that Meta, Google, ByteDance’s TikTok, and Snap knew their products were addictive to children and teens and harmful to their mental health, but continued marketing them to young users for profit.
The tech companies tried to appeal against a federal court ruling that allowed those involved to file their lawsuits in court. They argued in the 9th US Circuit Court of Appeals that a linchpin US law meant they couldn’t be sued.
That law is Section 230 of the Communications Decency Act, created 30 years ago. It says that platforms cannot be held responsible for things that their users post online. For years, social media companies treated it like a bulletproof vest. When users posted something bad, the company running it could claim it was the messenger, not the author.
That defense doesn’t seem to be working here. On August 10, the court ruled that Section 230 “provides a defense to liability, not immunity from lawsuits, so the appeal was premature.” This case revolves not so much around what people posted online as how the tech companies allegedly engineered their platforms to present that content to users.
The Nebraska Law Review explains several of the techniques the lawsuits say make these platforms more engaging, and potentially more addictive.
The article explains how certain interactions on these platforms can trigger dopamine release. Those interactions could be as simple as someone responding to your message or liking one of your photos. Dopamine plays an important role in the brain’s reward system.
The NLR article describes techniques such as making those rewards unpredictable, which encourages people to keep checking their accounts habitually. Interface features like the infinite scroll are also designed to keep you on the dopamine train. The paper cites the inventor of that particular idea, who describes it as:
“taking [behavioral] cocaine and just sprinkling it all over your interface.”
Anyone who’s spent too long in bed doomscrolling can relate.
The 9th Circuit’s denial of the appeal is procedurally narrow but strategically enormous. Section 230 is a defense you argue at trial, not a wall that keeps plaintiffs off the courthouse steps. The Third Circuit has gone further, ruling that Section 230 “does not provide immunity to platforms if they face tort lawsuits over injury caused by the algorithms they design.”
The algorithm, in other words, is the product. The product can be defective.
Behind those cases sits a growing pile of discovery material that plaintiffs argue sheds light on how the platforms approached user engagement, and a New Mexico judgment against Meta earlier this month in a case exploring similar complaints. That judgment now totals $942 million because the judge added $567 million onto the original amount, finding Meta had:
“created a public nuisance through its platform design.”
What discovery keeps dragging outDiscovery in these cases has already been unkind to Meta. A 2016 email attributed to Mark Zuckerberg said that alerting parents to teens’ live videos would “probably ruin the product from the start”. A recent court filing alleged that staff at social media giants have compared their own platforms to drugs, with one Meta employee writing that:
“we’re basically pushers.”
Snap looks no better. By late 2022, Snap employees were fielding roughly 10,000 sextortion reports per month, according to a filing in the New Mexico case. An internal investigation concluded that 70% of victims never reported abuse because “they knew no action would be taken by Snap; indeed, of the 30% that did report, none were addressed.”
That number surfaced through New Mexico’s unredacted complaint, not through any Snap disclosure.
Safety features that don’t workIf executives knew, the fixes should have followed. Mostly they didn’t. Researchers at NYU and Northeastern University tested 86 youth safety features and found 51 failed their tests. Snapchat’s failure rate was 73%, Instagram’s 66%, YouTube’s 55% and TikTok’s 50%. Nine features couldn’t even be triggered when the researchers tried. The researchers reported that every cyberbullying safeguard they tested failed.
The bypasses were quick to find. Type “eating disorder” into Instagram search and autocomplete politely offers the deliberate misspellings that pro-eating-disorder communities use to duck the platform’s own blocklist. Safety, in that instance, was doing the opposite of safety.
What parents can do nowDon’t assume in-app safety features work exactly as advertised. If your child uses social media, test the settings yourself and confirm they’re doing what you expect.
Set up a test account and check that each setting blocks what it claims to block. And think about the amount of social media time you want to grant your children, or whether you want to let them use it at all. Either way, it begins with an honest family conversation.
If your child is being harassed by people they know online, encourage them to tell you immediately. Save evidence, block and report the accounts where appropriate, and don’t hesitate to involve the school or law enforcement if the harassment includes threats, blackmail, or sexual exploitation.
You can also report sextortion to the National Center for Missing and Exploited Children’s CyberTipline directly, rather than trusting a platform’s own reporting queue.
Check back here for more details on the federal case. The next several months will decide whether the biggest platforms in history get rewritten by juries, or whether they settle their way out one confidential check at a time.
From reporting threats to removing them.
Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.
“Zoomsday” flaws could let one Zoom participant attack another
Researchers have found three vulnerabilities in the popular Zoom meeting platform that could let one meeting participant attack another through malicious collaboration data.
The vulnerabilities, tracked as CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415, affect the code Zoom uses to process annotation data shared during meetings. The researchers named the set of flaws “Zoomsday.”
Affected applications are:
- Zoom Workplace on all supported platforms before version 7.1.5 and 7.0.6, depending on the release branch
- Zoom Workplace VDI Client for Windows before versions 7.0.11 and 6.6.16, depending on the release branch
- Zoom Rooms on all supported platforms before version 7.1.5
- Zoom Meeting SDK on all supported platforms before version 7.1.5
What this means is that someone in the same Zoom meeting could send data that the Zoom app was not prepared to handle. Instead of simply displaying a drawing, text box, or other annotation, a vulnerable client could be tricked into crashing, leaking information, or even running attacker-controlled code.
Annotation features sound simple, but the underlying process is not. Your Zoom client receives structured data from another participant and turns that data into an object it can display on screen. According to the research, the annotation parser contained several memory-safety bugs. Like any software that processes data supplied by a third party, it has to be very careful about validating lengths, counts, and references before using them.
Remarkably, there is a discrepancy between the severity ratings assigned by the researchers, who rated them as Critical, and Zoom, which rated them as High.
The difference appears to come down to how the vulnerabilities are scored under the Common Vulnerability Scoring System (CVSS score). Zoom considers successful exploitation to require user interaction.
In practice, an attacker would first need to get into the same meeting as the intended victim. That could mean joining an open meeting, abusing a leaked meeting link, posing as an expected attendee, or compromising an account that already has access. Zoom considers it user interaction if the attacker persuades the target to join a meeting with the intent to compromise their machine.
How to stay safeZoom has published a security bulletin explaining which programs need to be updated and where to find the fixed versions.
To protect yourself from Zoomsday and have safe meetings:
- Update Zoom to the latest version as soon as possible.
- Restrict who can join your Zoom meetings. Use passcodes, waiting rooms, authenticated-user restrictions, and unique meeting links for sensitive calls.
- If features like annotation, whiteboards, remote control, file transfer, or third-party apps are not needed, consider turning them off, especially for meetings that have an open invitation nature.
- One crashed meeting is not proof of an attack, but if it happens on a regular basis, it’s worth investigating.
- Use an up-to-date, real-time anti-malware solution to block malicious code on your devices.
- Organizations should also check their device-management tools to make sure every deployed Zoom client is receiving updates.
From reporting threats to removing them.
Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.
Patch Tuesday: Update now to fix 421 flaws, including three zero-days
Microsoft’s August 2026 Patch Tuesday addresses 421 Microsoft vulnerabilities, including 62 rated Critical. One Windows vulnerability has been exploited in the wild by the Lazarus group to gain SYSTEM privileges.
The August update is smaller than July’s record-breaking release, but it’s still among Microsoft’s largest Patch Tuesday batches. More importantly, it includes several flaws likely to attract attacker interest: a publicly disclosed Windows privilege escalation flaw with a proof-of-concept (PoC), a newly completed unauthenticated SharePoint remote code execution (RCE) chain, and a potentially wormable Windows DNS Server flaw.
How to apply patches and check if you’re protectedThese updates fix security problems and help keep your Windows PC protected. Here’s how to make sure you’re up to date:
- Click the Start button, then open Settings.
- Select Windows Update (usually at the bottom of the menu on the left).
- Click Check for updates. Windows will search for the latest security updates. If you’ve enabled Get the latest updates as soon as they’re available under More options, you may be prompted to restart immediately to complete the update. Otherwise, continue to the next step.
- If updates are available, they’ll start downloading automatically. When they’re ready, click Install or Restart now if prompted. Your computer may need a restart to finish the update.
- After restarting, go back to Windows Update and check again. If it says You’re up to date, you’re all set.
Windows Deployment Services (WDS) users should prioritize CVE-2026-62893 (CVSS score 9.8 out of 10), an unauthenticated RCE flaw in the TFTP (Trivial File Transfer Protocol) server. TFTP normally runs on UDP port 69 and has no built-in authentication. It is primarily an enterprise and school network issue, but it could enable lateral movement where WDS is deployed.
Microsoft also fixed CVE-2026-62832, a publicly disclosed elevation of privilege (EoP) vulnerability in the Windows User Profile Service. It maps to the issue researchers called LegacyHive, for which a limited public proof of concept was released in July.
The PoC demonstrates how a local authenticated attacker could abuse the service’s registry hive handling to load another user’s hive, potentially including an administrator’s. The released demonstration is deliberately constrained and requires credentials for another user, but the availability of code and the broad Windows footprint make this one a strong candidate for exploitation attempts.
Another good reason to promptly update is the number (I counted 48) of remote code execution (RCE) fixes for Office applications and components, including Excel, Word, Outlook, PowerPoint, and the Office graphics component. Document-borne vulnerabilities are attractive to phishing operators because email attachments and shared documents provide delivery mechanisms that people are likely to open.
“One of the best cybersecurity suites on the planet.”According to CNET. Read their review →
Fake CCleaner installs GhostDesk Chrome spyware
A fake version of the popular PC cleaning tool CCleaner is being used to infect Windows users with a malicious Chrome extension called GhostDesk, which acts as spyware inside the browser.
With more than 2 billion downloads worldwide, CCleaner is one of the best-known Windows utilities, making it an attractive target for cybercriminals looking to distribute malware.
The attack starts with a website that is a convincing imitation of the CCleaner download page. Once installed, the fake application launches an attack that modifies Chrome, installs malicious extension components, and gives attackers the ability to steal credentials, capture screenshots, and log keystrokes.
The fake application likely uses the guise of a PC cleaner to make its file and system activity appear less suspicious.
Under the hood, the malware uses CScript to launch a multi-stage infection, patches Chrome’s Security Extension, establishes a command-and-control (C2) channel, and ultimately installs a malicious Chrome extension identifying itself as GhostDesk.
Technical analysis First stage: CScript loader and injectionWe found the initial infection vector, a fake CCleaner.exe, on a website designed to imitate the official CCleaner.com home page: ccleanerwind[.]top.
Although the page had a CCleaner Pro download option next to the normal download button, both buttons downloaded the same malicious executable.
The fake CCleaner.exe uses the same icon and filename as the legitimate CCleaner application, but contains unusual version information. Its internal name (svc_it7p) and original filename (rt_mxk.exe) don’t match up with any known CCleaner release. We also found other files following this version naming pattern (svc_<4 random characters> and rt_<3 random characters>.exe) that launch this infection chain.
The executable initially drops a legitimate instance of CScript (cscript.exe), then uses it to launch a series of scripts that do the following:
- System reconnaissance: Queries the registry for the machine GUID, name, and supported languages.
- Hijacked Runtime Broker: Writes to %AppData%\Microsoft\DriverStore\runtimebroker.dll, replacing it with a reflexive loader for additional malware.
- Chrome Security Extension patch: Patches the Chrome Security Extension’s manifest.json to include a service worker (background.js) and content script (content.js). These JavaScript files are then dropped in the %LocalAppData%\cse folder.
- C2 connection: Creates a local WebSocket endpoint on 192.168.100.4:49727 and upgrades this endpoint to connect to the public domain/port liderongrade.duckdns[.]org:4444. Once connected, it sends a GET request with a token and then receives regular keep-alive packets from the attacker’s server.
The two JavaScript files written by CScript, content.js and background.js, serve as the final payload. Because of the patched Chrome Security Extension (CSE) manifest, background.js runs silently in the background whenever Chrome starts, while content.js runs as the main extension.
The two scripts perform different spyware functions but are interdependent, maintaining a two-way communication through chrome.runtime.sendMessage and chrome.runtime.onMessage.addListener.
content.js performs the following:
- Keylogging: Records keystrokes entered into input fields and sends them to a buffer. After two seconds of inactivity, or when the user switches fields, the contents of the buffer are sent to background.js for handling.
- Form-based credential harvesting: The script listens for outgoing POST requests and submit events, acting as a man-in-the-middle to capture submitted data. It monitors these forms for specific keywords related to credentials, authentication tokens, and financial information. If any of these keywords are found, it sends the contents of the form to background.js for handling.
- Cryptojacking: The script monitors clipboard paste events, looking for references to cryptocurrency strings. When one is detected, it replaces the pasted result with a predefined value.
- Script injection: For pages with certain URL patterns, <script> elements are dynamically injected into the webpage and certain elements are replaced.
Meanwhile, background.js stores configuration data used for recognizing functionality-relevant strings (cryptocurrency addresses, JS injection rules, and toggles for form capture and keylogging), and does the following:
- WebSocket-based exfiltration: The script opens a local WebSocket relay on 127.0.0.1:7345/ext, sending and receiving data and commands. It has persistence capabilities, re-establishing the relay if connection is lost when Chrome starts or the extension is installed.
- Cookie theft: The script uses chrome.cookies.getAll to grab the user’s browser cookies and send them to the WebSocket relay.
- Screen capture: The captureTab function sends a screenshot of the active browser tab to the WebSocket relay.
- Arbitrary code execution: The injectJS function uses chrome.scripting.executeScript to execute arbitrary JavaScript code in the active browser tab.
These extensions label themselves as GhostDesk, which is also the name of legitimate overlay software that allows AI agents to capture and interact with the user’s screen. The choice of name may help disguise their screen-capture functionality, although the extensions don’t attempt to hide their other malicious behaviors.
How to stay safeLike many Trojans, this campaign takes advantage of the reputation of a popular app by distributing malware through a convincing lookalike website. A professional-looking download page isn’t enough to prove a site is legitimate.
Here are some tips to reduce your risk:
- Carefully check the web address before downloading software. Sponsored search results are not always trustworthy and can be abused by cybercriminals. Treat any links to software downloads on social media, SMS, and email with caution.
- If possible, verify download links through trusted sources such as the Microsoft Store or Google Play Store, or the publisher’s official website.
- Use an up-to-date, real-time anti-malware solution with web protection. Malwarebytes blocks connections to unsafe sites like this one, and detects the fake CCleaner installer described here as Trojan.Dropper.
- Keep your operating system, browser, and security software up to date.
- Domain: ccleanerwind[.]top — Fake CCleaner download site
- Domain: liderongrade.duckdns[.]org — Command-and-control server (C2)
- IP: 193.169.240[.]81 — Command-and-control server (C2)
- SHA256: c0b4a4af8a3a8c4b113d7f203fcf480cfac79160102490daf287748634b9ce23 — Fake CCleaner.exe
- SHA256: 8d921bdd1f5bc8c03209a5dfacfd9ed313497ac2e3f1b4a2000f4c474a464904 — Reflexive loader replacing runtimebroker.dll
- SHA256: 3d7411e2e445a2210dbbf061f3e8e3dd3476a4fc5d4a2135dcceb0bc705776bf — content.js GhostDesk extension
- SHA256: cfd9c0bcc89ebc68aae889b9b49bc8290c3764bce5f2c9ac8b5ba0ba58e9bf61 — background.js GhostDesk extension
While tracing this campaign, we found a series of other fake apps with identical behavior. The following programs use the same CScript loading to deliver a spyware payload:
- 590b04e35fc0b3dcd9dabe82f2e96d4d1e0fccc598911cf80f8255232ee75fcb — Fake 7-Zip
- Ecde892dbc28af620ba8e311fa9dd4c66521c7fe95e6aadacc7cd9a5bb57d32d — Fake Adobe Acrobat
- Cfa3900cefb447d89a7498224f2ecafa65b190336934811e6c1d4196d9b92452 — Fake Adobe Acrobat
All of these samples connect to the same C2 server, liderongrade.duckdns[.]org.
We also identified another fake Adobe Acrobat sample that uses wscript.exe instead of cscript.exe. Its SHA256 hash is:
0bf8f52b28291edc505a64962e6ce04387a9784fc5b18aeff53629adb1f72f56
Picked up something you shouldn’t have?Valve warns Steam hardware buyers: Expect fake delivery scams
Most of us are wise to phishing emails that don’t contain much personal information. Generic “your account is suspended” messages usually get binned on sight. But what about the phishing emails that use your real name and address, and reference the specific product you bought last month? Even for the most suspicious of people, that can be convincing.
It’s also the situation European Steam hardware buyers walked into this week. On August 10, Valve, the company behind the Steam gaming platform and Steam hardware, warned customers that a cyberattack had exposed names, home addresses, phone numbers, Steam email addresses, and details of their hardware orders.
It wasn’t Valve itself that got hacked. Rather, it was its shipping partner CEVA Logistics, which handles delivery of hardware from the gaming store. Passwords and payment information were not touched.
What got stolenThe attack window ran from July 29 to August 1, 2026. Valve learned about it on August 7 and started notifying customers three days later. CEVA stores delivery data for roughly 90 days after shipment, meaning anyone who received a Steam Deck, Steam Controller, or Steam Machine in Europe over the past three months could be affected.
The exposed information may include:
- Name
- Street address, postal code, and city
- Country
- Phone number
- Email address linked to the customer’s Steam account
- The type and price of the ordered hardware
Exact numbers are still unconfirmed. Neither Valve nor CEVA has said how many customer records were involved. Dutch retailers Bol and De Bijenkorf were reportedly told about the same CEVA incident on August 1 and warned their own customers.
Why shipping data is valuable to scammersA scammer can send an email, text, or even make a phone call that references your genuine order and delivery address before asking you to pay a small customs or redelivery fee, confirm your delivery, or sign in to “verify” your order.
Scam or legit? Scam Guard knows.Data like this is already widely traded online. Malwarebytes researchers found more than 7,500 compromised datasets containing over 8.4 billion records on the dark web during the first six months of 2026.
Not Valve’s first security incidentAlthough Valve’s own systems weren’t compromised, that doesn’t mean the consequences can’t be severe.
In May 2025, a threat actor called Machine1337 tried to sell what looked like a dataset of 89 million Steam user records for $5,000. The data turned out to be older SMS messages carrying expired two-factor codes, routed through a third-party intermediary Valve says it never partnered with.
Valve has suffered a direct breach in the past though. November 2011 saw one that exposed records from 35 million users, including usernames, emails, and encrypted credit card details.
What affected buyers should doIn an email to customers, Valve advises them to assume that any message referencing their recent Steam hardware order is fake. That covers email, SMS, and phone calls, even the ones that quote your address correctly.
Steam Support never contacts users through email, Steam Chat, or Discord, and only handles account problems through its help page.
So you don’t need to rush to reset your password, although it never hurts to use a strong, unique password and enable Steam Guard’s two-factor authentication. Instead, be skeptical of any unsolicited emails, texts, or calls about a recent Steam hardware delivery, even if they include details only a real customer would know.
Something feel off? Check it before you click.Malwarebytes Scam Guard helps you analyze suspicious links, texts, and screenshots instantly.
Available with Malwarebytes Premium Security for all your devices, and in the Malwarebytes app for iOS and Android.
Social media platforms crack down on drone factory recruiting game
A video game about drone warfare may look like an unusual cybersecurity story. But cybersecurity isn’t only about malware or stolen passwords. Sometimes it’s about understanding how online platforms are used to influence decisions, build trust, and persuade people to share personal information or take actions they otherwise wouldn’t.
According to Straight Arrow News, the online game Drone Battle: Ukraine is linked to Russia’s Alabuga Special Economic Zone in Tatarstan, a site associated with the production of attack drones used in the war against Ukraine. Investigators say the game is the latest part of a broader campaign that has used major social media platforms, including YouTube, TikTok, Instagram, and X to reach young people.
The game is just the lure. Investigators say it forms the entry point to a recruitment funnel that markets education, careers, travel, community, and technological opportunity to young people before ultimately steering some recruits toward jobs assembling drones at Alabuga.
Available in English, Russian, and Chinese, Drone Battle: Ukraine presents a stylized conflict between Russia and NATO. But investigators say the game is only one part of a larger campaign that combines games, esports tournaments, influencers, and career messaging to recruit young people globally into Russia’s drone industry.
This campaign is not limited to drone combat. The same channels have also promoted games that frame construction work, teamwork, strategy, and professional development as challenges to be completed and levels to be unlocked.
That’s gamification serving a recruitment purpose. The game doesn’t have to persuade someone to take a job on its own. It only needs to make participation feel like a game, make a military-industrial workplace appear modern and exciting, and make the transition between the two seem natural.
Gamification itself isn’t unusual. Companies use games, quizzes, competitions, and rewards in education, training, and recruitment every day. The concern here is how those familiar techniques are combined with social engineering to influence decisions while obscuring the true nature of what’s being offered.
Social engineeringSocial engineering is often described as a way of tricking people into giving up a password or opening a malicious attachment. But at its core, social engineering is the manipulation of human decisions. This campaign appears to use several familiar techniques at once.
- Targeting: Investigators say Drone Battle: Ukraine is described in a registered patent as an “assessment tool in game form.” Rather than simply entertaining players, the game appears designed to engage people who may be receptive to later recruitment.
- Baiting: The campaign advertises scholarships, training, free travel, housing, and career opportunities while, according to investigators, downplaying or concealing the true nature of the work.
- Influencers: Social media promotions and seemingly personal testimonials make the campaign more persuasive than a straight-up advertisement.
- Normalization: A drone in a game is a tool to use for victory and fun. Researchers have warned that game-like recruitment can make militarized narratives feel routine, technical, and emotionally distant.
- Small steps: It starts with playing a game or following an account. People may then join a tournament, communicate with a recruiter, submit personal details, travel, and only later discover the full nature of the work. As with many social engineering campaigns, each interaction asks for a little more commitment, making the next step feel less significant than it really is.
US-based social media platforms have increasingly taken action against Alabuga-linked accounts after investigations alleged deceptive recruitment practices and human rights abuses associated with the campaign.
Social media platforms have been trying to disrupt the campaign for nearly two years. Following an Associated Press investigation in 2024, Google, Meta, and TikTok removed accounts linked to Alabuga Start for violating their policies. But according to the Foundation for Defense of Democracies (FDD), the organizers later created new accounts and continued recruiting across multiple platforms.
More recently, Ukraine’s Minister of Foreign Affairs, Andrii Sybiha, said that roughly 600 videos promoting Alabuga were removed from YouTube. The videos had been posted across hundreds of channels with a combined audience of more than 500 million subscribers. He wrote:
“The work does not end with removals. We will be now pursuing sanctions against individual bloggers who accepted payment to promote a sanctioned weapons manufacturer to millions of viewers.”
According to the Straight Arrow News investigation, however, the campaign remains active on X and Telegram.
How to stay safeFor home users, the traditional scam advice still applies: Independently verify a prospective employer, search for complaints and reporting, discuss an offer with someone you trust, and never pay to get a job.
Gamers should treat unsolicited career, travel, competition, and “exclusive training” offers with the same caution they would apply to any job pitch that feels unusually generous or vague. Offers to turn your gaming into a paid job should also be treated as “too good to be true.”
Other actions that might go a long wayFriends, families, educators, and youth organizations should talk openly about recruitment tactics without assuming that people targeted by them are naïve. They are often drawn in through a series of small steps that feel natural.
Platforms should investigate networks, influencer relationships, referral links, and coordinated messaging, not just individual posts or game titles.
Game developers and community platforms need reporting systems that are easy to find and will cater to recruitment concerns, not just cheating or abusive chat.
Governments and civil society groups in targeted countries need practical awareness campaigns that explain the specific promises being used and offer credible alternatives for education and employment.
Something feel off? Check it before you click.Malwarebytes Scam Guard helps you analyze suspicious links, texts, and screenshots instantly.
Available with Malwarebytes Premium Security for all your devices, and in the Malwarebytes app for iOS and Android.
Sexual predators targeting online accounts for intimate images, FBI warns
The FBI has issued a Public Service Announcement (PSA) warning that criminals are breaking into social media and personal accounts to steal and distribute intimate images and videos without consent. The FBI refers to this type of content as non-consensual intimate images (NCII).
The stolen material may be posted or sold on criminal marketplaces alongside victims’ names, phone numbers, email addresses, and social media handles, creating opportunities for harassment, stalking, and sextortion.
According to the FBI, criminals use a mix of account takeover and social engineering tactics:
- Password and PIN guessing: Criminals make high-volume login attempts using data from breaches, public social media profiles, leak sites, and other publicly available sources. Known victims may be targeted using name variations, birth dates, and other predictable personal details.
- Fake customer service texts: Victims receive a message claiming their social media account will be locked or disabled. The criminal triggers a legitimate password reset request, then persuades the victim to hand over the resulting verification code.
- Phishing emails: Lookalike support domains and email addresses warn of a “new login” and direct victims to a fake password change page designed to steal credentials.
This is different from the familiar “I recorded you” sextortion email, which typically relies on intimidation rather than a real account compromise. Still, if such an email includes a password you still use, change it immediately wherever it remains in use.
How to stay safeThere are several ways to reduce the risk of becoming a victim:
- Avoid storing sensitive images on social media platforms or other internet-connected services when possible. Breaches and leaks happen, and those images can end up in the wrong hands.
- Use a password manager to create a unique, long password for every account. Don’t base passwords or PINs on names, birthdays, or other public information.
- Turn on multi-factor authentication (MFA), preferably with passkeys or hardware security keys where available. MFA is valuable, but criminals can still phish one-time codes and session cookies, so never approve an unexpected prompt or share a verification code.
- Treat unexpected “account warning” links in texts and emails as suspicious. Open the service’s official app or type the known web address yourself instead. Don’t trust sponsored search results to take you to the correct website.
If you discover that intimate content has been stolen or shared, preserve any relevant links and evidence, secure the affected accounts, and report it through the FBI’s NCII reporting portal at ncii.ic3.gov.
Scammers don’t need to hack you. They just need you to click once.
Malwarebytes Identity Theft Protection catches suspicious activity before it becomes a problem.
Love/hate relationship: The AI affair. Young people love AI, but it’s breaking their trust
Young people use AI for everything. From schoolwork to interview prep, relationship advice to shopping decisions, the technology has become part of how young people live. For the most digitally fluent generation ever, AI is a competitive edge, a creative partner, and an always-on assistant.
But the same technology making young people’s lives easier is also making the internet harder to navigate. AI is making scams more convincing, identities easier to manipulate, and online content harder to trust. Seven in ten (70%) 18-to-22-year-olds have experienced an AI-related scam in the last year, compared to half of the general population. And nearly every young person worries AI will be used against them.
This isn’t happening because young people are reckless. It’s happening because the online platforms they rely on for everyday life now double as entry points for AI threats: social feeds where manipulated content and real content sit side by side, online marketplaces filled with fake storefronts and reviews, messaging channels where threats can be personalized, and AI tools that can make false information feel like the truth.
That creates a new kind of safety burden. Young people are being asked to use AI, judge its output, protect their identities, and avoid increasingly personalized scams all at once. The result is a digital life that feels more powerful, but also more vulnerable to abuse.
The internet is getting harder for young people to trustThe internet young people grew up with isn’t the same one they’re facing today. AI has changed the landscape, making it harder for even these digital natives to know what information is credible and safe. Half of 18-to-22-year-olds strongly agree that it’s becoming harder to tell what content is genuinely human or real.
Young people have had a front row seat to how AI can bend the truth. Nearly half have seen AI provide information they knew or later found out was wrong or misleading (44% versus 30% of the general population). Nearly one in four (23%) have suffered negative consequences because of AI advice, compared with 16% of the general population, and 18% say they have suffered emotionally from AI advice, compared with 12% of the general population. For a generation using AI in every corner of their lives, bad information can have lasting effects on their credibility, reputation, and relationships.
Many young people have changed how they engage online as a result:
- 47% of young people say AI has changed how much they trust reviews or content, compared with 37% of the general population
- 35% say AI has changed how they shop online, compared with 26%
- 32% say AI has changed how they present themselves professionally, compared with 20%
- 19% say AI has changed how they date or communicate romantically, compared with 10%
As one young person said about online dating:
“Dating isn’t an option for me online anymore. You just never know what is or isn’t AI, and I don’t want to spend a lot of time on someone fake.”
AI is making it easier for scams to reach young peopleThe harder it becomes to tell what is real, the easier it becomes for scams to work. For young people, AI is fueling a wave of scams that are more personal and invasive than ever before.
- Nearly one in four young people have been a victim of an extortion scam of some kind (24% versus 17% of the general population).
- Nearly one in five have been a victim of a deepfake or virtual kidnapping scam (19% versus 8%).
- Nearly one in ten have been a victim of sextortion (8% versus 7%).
- More than one in ten have been a victim of an impersonation scam (14% versus 10%).
- More than one in ten have been a victim of a romance scam (12% versus 10%).
What’s striking isn’t just how many young people have been victimized—it’s how many have been targeted:
- More than half have been the target of an extortion scam (56% versus 42% of the general population).
- 47% have encountered an impersonation scam (versus 35%)
- 46% have encountered a romance scam (versus 33%).
- More than four in ten have been targeted by a deepfake or virtual kidnapping scam (43% versus 26%).
- Nearly four in ten have encountered sextortion (38% versus 24%).
These scams may look different on the surface, but they all work the same way: they exploit fear, trust, shame, and intimacy. The more often young people encounter them, the more chances scammers have to find exactly which emotional triggers work.
This exposure isn’t random. Young people are on social platforms at rates up to three times those of the general population: 89% use Instagram (versus 55% of the general population), 78% use TikTok (versus 38%), 68% use Snapchat (versus 26%), and 49% use Pinterest (versus 25%). Scammers can use these platforms to get everything they need to make their threats more convincing: public photos, friend networks, school affiliations, relationship clues, and everyday posts containing personal information. With AI, scammers can use that content to create explicit images, clone voices, impersonate profiles, and create threats personalized with details that are hard to ignore.
One young person shared their experience:
“I had someone make fake nudes of me using AI on my photos from my social media and threaten to post them on Facebook after I realized that they had scammed me. I decided to be more careful with my personal information.”
Young people fear AI will steal what money cannot replace: identity, reputation, and sense of selfAI-fueled scams aren’t just scams in the traditional sense. They are forms of identity abuse. This is different from traditional identity theft. For young people, the risk isn’t only that someone steals a password or money. It’s that scammers can use AI to make them appear to say, do, or share something they never did, with consequences that can follow them in their personal and professional lives.
That’s why young people are so concerned about AI being used against them. The fears that hit hardest:
- 88% worry about AI being used to harm their professional or personal reputation versus 77% of the general population
- 82% worry about someone creating a fake profile pretending to be them versus 76%
- 81% worry about someone creating fake nude or sexually explicit photos or videos of them versus 62%; 15% say it’s happened to them already (versus 10%)
- 80% worry about being deceived by someone using AI to fake their identity in an online relationship versus 67%
These threats are especially powerful at a life stage where young people are still building their personal and professional reputations. A fake profile, manipulated image, or AI-generated explicit video can affect how everyone from classmates and professors to potential employers and romantic partners see them for years to come.
Young people are pulling back online, but protection is still too manualMany young people are responding by retreating. 80% are sharing or posting less online than they were a year ago, versus 61% of the general population. Compared to the general population, more 18–22-year-olds have also taken AI-related protective measures like tightening privacy settings, removing unknown followers, using reverse image search to verify content, requesting data removal, and watermarking their own photos and videos.
Those actions matter, but they also show how much responsibility has been pushed onto individuals. Staying safer online now means constantly reviewing settings, checking sources, questioning content, and so much more. That’s a lot to ask of anyone, and the fatigue is showing: 42% of young people say they receive so many warnings they have stopped paying attention, compared with 36% of the general population. It’s hard to sustain vigilance when new risks are always emerging.
At the same time, completely opting out isn’t realistic. Young people remain deeply embedded in digital life, and they’re still some of AI’s most enthusiastic adopters: 74% say AI has had a positive impact on their lives, compared with 57% of the general population. They aren’t rejecting AI or the internet, but they are carrying more of the safety burden than they should have to.
What young people can do to help decrease their risk right now- Know the scams targeting you. Extortion, sextortion, deepfakes, and romance scams disproportionately target young people. If someone contacts you with threats of any kind, do not pay. Report it to the platform and to authorities.
- Button up your social media. Everything you post publicly is available to anyone, including scammers. Tighten privacy settings on the platforms you use most and review your followers regularly.
- Don’t trust product images alone. Before buying from an unfamiliar retailer, use reverse image search on product photos and look for independent reviews off the retailer’s own site.
- Create a family code word. Make sure you agree on this word in person, not online. If you receive a panicked call from someone you know asking for money or information, verify they are who they say they are with the code word.
- Don’t reuse passwords. If one password gets stolen in a data breach, it will likely get tried on all other accounts you might have. Use a different password for every account to keep your accounts locked down.
- Turn on two-factor authentication on all your important accounts. Only 30% of young people have done this. It is one of the highest-impact protections available and takes under five minutes to set up.
- Protect your devices. Use security software on all your devices, and keep all your software up to date to make sure you’re patched against all known security holes.
If you’re a student or work at a university, Malwarebytes Student Protection Program provides two years of free Premium Security for three devices for all US college or university students, staff and faculty.
This includes Malwarebytes device protection for laptops, tablets, and mobile phones with built-in scam protection. It protects against creepy trackers and ads, and blocks malware, ransomware, and cybercriminals themselves.
Sign up at malwarebytes.com/student.
About the researchThe research in this article is based on a March 2026 survey about AI, identity, and the collapse of digital trust and was conducted among 1,500 respondents in the United States, United Kingdom, Germany, Austria, and Switzerland. This article focuses on student-aged adults, defined as respondents ages 18 to 22, compared with the general population.
Additional context comes from Malwarebytes’ 2025 research Tap, Swipe, Scam: How Everyday Mobile Habits Carry Real Risk, which looked at mobile scams and scam-related behaviors across the same markets. Both research studies were prepared by an independent research consultant and distributed via Forsta.
Watch out for fake TikTok Shops trying to steal your money
TikTok Shop is a real, functioning e-commerce feature built into the TikTok app, allowing users to buy goods without ever leaving TikTok. As it’s grown in popularity, scammers have begun cloning its appearance.Storefronts that reproduce its look, its trust badges, and its category layout closely enough to pass a quick glance are showing up as entirely separate, unverified websites.
The short versionIf a shopping site looks like TikTok Shop but you didn’t reach it from inside the actual TikTok app, treat it as an unknown third-party store, not an extension of TikTok. It might look like TikTok, but it’s the same risks as any sketchy online shop: paying for something that never arrives, or handing over card details to a site with no accountability behind it.
Fake TikTok ShopsClone sites in this category tend to reproduce TikTok Shop’s homepage design closely enough that, at a glance, they could pass for the real thing.
They have matching color schemes, matching layout, and language borrowed directly from the platform, such as “curated products,” “trusted sellers,” and “secure service.”
Underneath, they typically show the same kind of reassurance badges the real platform uses: claims of platform-verified sellers, local delivery guarantees, and after-sales support windows.
None of that trust signaling is backed by anything. It’s copied language and copied visual design sitting on top of a site with no verified relationship to TikTok at all. Scammers borrow the legitimacy that TikTok Shop has built up, then use it to move products—or simply take payment—through a storefront TikTok has no oversight of.
Wholesale stores and fake loan offersA related version of this scam leans into bulk or wholesale pricing, offering goods across categories like fashion, home, and beauty, again wrapped in TikTok’s name and logo. Some of these sites go a step further and add a consumer credit or “loan service” option directly into the site navigation, sitting alongside ordinary shopping categories.
A legitimate wholesale marketplace doesn’t typically need to offer consumer credit as a checkout feature. When it does, it’s worth treating as a separate red flag from the shopping itself. Loan applications typically ask for far more sensitive information than a purchase does, including identity documents, banking details, and other personal data. Handing that information to a site that’s already impersonating a major platform significantly increases the risk of fraud or identity theft.
The checkout is the real riskBoth scams point to the same underlying concern: it’s not really about whether the products are real. It’s about what happens when you enter payment information into a storefront with a fake identity and no accountability. The order may never arrive, leaving you out of pocket, and your payment details themselves could be stolen, reused, or resold.
How to stay safe- Only use TikTok Shop from inside the official TikTok app, not a link from an ad, DM, or search result.
- Always check a website’s address before entering any payment information. A convincing homepage doesn’t mean a legitimate business sits behind it.
- Be skeptical of any shopping site that also pushes a loan, credit line, or financing offer at checkout.
- Pay with a credit card rather than a bank transfer where possible. It gives you a dispute path if the order never shows up.
Brand impersonation is one of the oldest tricks in e-commerce fraud. TikTok Shop’s badge system and trust language are simply the latest assets being borrowed.
Stop threats before they can do any harm.
Malwarebytes Browser Guard blocks phishing pages and malicious sites automatically. Free, one click to install. Add it to your browser →
