Malware Bytes

Crypto customers targeted by scammers after email marketing provider breach

Malware Bytes Security - Fri, 09/11/2026 - 11:01am

An attacker breached an email marketing platform and launched targeted attacks against the newsletter subscribers of some of its customers, especially those working in cryptocurrency and adjacent fields.

The incident was a supply-chain phishing campaign carried out through Brevo, an email marketing provider used by several cryptocurrency companies and other firms.

Brevo initially said an attacker had gained access to 120 customer accounts, some of which were used to send phishing emails to the customers’ contact lists.

Brevo later said 138 customer accounts had been accessed in its postmortem:

“On September 10th at 6:30 AM UTC we identified a security issue where an attacker exploited a flaw in the way Brevo handles SAML SSO to gain access to 138 Brevo accounts. 6 of those accounts were used to send phishing emails to the contacts stored there, and for 43 accounts they exported the contacts. 93 accounts have no meaningful activity.”

According to reports, popular cryptocurrency companies Trezor, CoinTracking, and BitBox confirmed that phishing emails were sent to customers subscribed to their newsletters. Trezor warned its roughly 347,000 newsletter subscribers that a security incident at a third-party provider had resulted in a massive phishing campaign.

Trezor makes hardware wallets that store cryptocurrency private keys offline. Its customers received a phishing email titled “Critical Security Alert: STM32 Entropy Bug Identified.”

The subtitle read: “Urgent update regarding hardware microcontroller vulnerability.”

The email said:

“Dear customer,

We have some difficult news to share. Unfortunately, our engineering team has identified a critical hardware-level vulnerability in the STM32 microcontrollers used in a range of Trezor devices.

Currently we believe the majority of defective devices were initialized prior to 2023, however some newer devices also may be vulnerable. The bug is a hardware factory defect present in an estimated 1 in 4 devices.

The vulnerability results in:

  • Insufficient randomness in recovery phrase generation
  • Exposure of seeds to brute-force cracking
  • Seeds with as little as 40 bits of entropy”

That phishing email also contained a link that prompted recipients to download an app and enter their wallet backup.

CoinTracking said the attackers sent its customers an email titled “Data Breach Notice: Please refresh API Keys as soon as possible,” which also contained a malicious link. 

Because the emails came from legitimate company domains and looked convincing, some recipients may have fallen for them. The exact number is not currently known.

How to stay safe

It can be difficult to recognize a phishing email when it comes from a legitimate company domain and looks convincing. But there are a few things to keep in mind:

  • If a company emails you about an urgent security problem, check its official website or app for confirmation.
  • Do not install apps through links in unsolicited emails, no matter how urgent the message claims to be.
  • Never enter your recovery phrase anywhere other than on your physical device.
  • Reputable companies will not ask for recovery phrases, API keys, or login details by email.
  • Use Malwarebytes Scam Guard to check whether a message might be a scam and get guidance on what to do next.
  • Keep an eye out for further information about other Brevo customers that have been affected. The attackers exported contacts from 43 accounts, which could be used in future targeted phishing attacks.
What to do if you followed the link

Trezor advises moving your funds to a new wallet if you entered your wallet backup in any form. If you followed a link in a similar email from another provider, contact that company directly for advice.

Something feel off? Check it before you click.  

Malwarebytes Scam Guard helps you analyze suspicious links, texts, and screenshots instantly.  

Available with Malwarebytes Premium Security for all your devices, and in the Malwarebytes app for iOS and Android.  

Try it free → 

Categories: Malware Bytes

Android malware creates a hidden copy of your banking app

Malware Bytes Security - Fri, 09/11/2026 - 8:14am

Researchers at Group-IB found that the Android banking Trojan Gigabud can create a separate work profile on an infected phone and run a cloned banking app inside it. The attacker can then carry out fraudulent transactions in the new profile, potentially separating them from signs of malware detected elsewhere on the device.

To do this, Gigabud installs Vwork, a malicious version of the legitimate open-source tool Shelter. Shelter normally lets Android users isolate apps or run second copies of them in a work profile. Vwork modifies those functions so that Gigabud can control them remotely.

The aim is to clone a target banking app into the new work profile, then let the operator commit fraud there. Group-IB says this can break the connection between malware detected in the personal profile and a risky transaction originating from the work profile, potentially weakening bank-side anti-fraud or in-app malware-detection systems that do not correlate activity across Android profiles.

Android work profiles are normally used to keep work apps and data separate from personal ones. Because apps in different profiles are isolated from each other, a banking app or security tool may not connect malware detected in the personal profile with something taking place in a cloned app in the work profile.

How an attack works

Victims are lured into sideloading a fake airline, tax, or government app through phishing sites, messages, or social media.

To take over the device, Gigabud asks for Accessibility access, overlay permission to display over other apps, and an exemption from battery-optimization. These permissions enable remote interaction and credential-theft techniques such as overlays.

The sideloaded app checks which other apps are installed and tells the operator which relevant banking targets are present.

Fake banking-login overlays steal both banking credentials and the device’s PIN.

The operator installs Vwork, which creates a new work profile on the device and clones the selected banking app. Vwork differs from Shelter in ways that make it useful to malware. It removes protections on cross-profile interaction, exposes components that can be used to set up a profile, clone and list apps, and open apps, and hides its launcher icon.

The operator can then remotely carry out transactions from the newly created profile, with the option to hide activity behind a black screen.

This is how Gigabud turns Android’s profile separation into a fraud tool: after compromising a phone, it creates a second profile, places a cloned banking app inside it, and performs the transaction from there. The result can be a dangerous gap between a malware alert in one profile and a fraudulent banking session in another.

How to stay safe

The immediate protection advice is familiar but important:

Sideloading. Install banking and other apps only from the official store or a direct link to the publisher’s website.

Install requests. Treat unsolicited requests to install an APK as a likely scam. If you’re unsure whether something’s a scam, run it through Malwarebytes Scam Guard.

Permissions. Do not enable Accessibility or “display over other apps” for a supposed airline, tax, delivery, or government app. Overlays require explicit user approval on modern Android, so a request like this is a red flag.

Protection. Use an up-to-date real-time anti-malware solution for your Android devices. Malwarebytes detects components of Gigabud as Android/Trojan.Banker.ACR577B2BA2H61, Android/Trojan.Banker.ACRF6CE8D30H46, Android/Trojan.Banker.ACR6C67829FH20, Android/Trojan.Banker.SIB02FFFFFF1112H106, Android/Trojan.Banker.SIB0181193e44H71, Android/Trojan.Banker.AUR2f2f4fb5C95, and Android/Trojan.Spy.Gigabud.xc.

Anyone who has installed a suspicious APK and granted it Accessibility access should contact their bank through a trusted channel, revoke the app’s special permissions, uninstall it, and consider a factory reset after preserving only known-good data.

A second instance of a banking app merits particular scrutiny. A separate work profile by itself is not proof of compromise because work profiles also have legitimate uses. But the presence of a cloned banking app definitely is suspicious.

Scammers know more about you than you think. 

Malwarebytes Mobile Security protects you from phishing, scam texts, malicious sites, and more. With real-time AI-powered Scam Guard built right in. 

Download for iOS → Download for Android → 

Categories: Malware Bytes

BlueMoon exploit kit turns Chrome and Windows flaws into attacks

Malware Bytes Security - Thu, 09/10/2026 - 11:49am

BlueMoon, a shared Chrome and Windows exploit kit, shows why “patch later” is becoming a dangerous gamble.

Security updates are easy to put off. The browser still opens, Windows still works, and choosing to relaunch your browser or restart your computer later can feel harmless.

But a newly documented exploit kit called “BlueMoon” shows how quickly patching delays can become dangerous. Proofpoint Researchers found four espionage groups using the same exploit chain against Chrome browsers running on Windows within days of one another.

The campaign is a timely reminder that once a security flaw, or even its fix, becomes public, attackers may move faster than many users expect.

The attacks began with phishing emails. A victim who clicked a malicious link could be sent to a web page designed to exploit two vulnerabilities in Chrome’s V8 JavaScript engine, followed by a Windows vulnerability to break out of the browser’s protections and gain higher privileges on the computer.

The Chrome vulnerabilities used by BlueMoon were patched in the Stable channel on September 3 and September 8, 2026. The first was already actively exploited when Google released its update. Microsoft addressed the Windows vulnerability in its September Patch Tuesday updates, by which point it was also being exploited.

CISA has since added all three flaws to its Known Exploited Vulnerabilities (KEV) catalog, which lists vulnerabilities known to have been exploited in real-world attacks.

The notable part is not just that BlueMoon exploited the flaws, but how quickly the capability appears to have spread. Publicly visible upstream fixes can give attackers clues before downstream browser updates reach users, allowing a weaponized chain to be developed and adopted by multiple groups very quickly.

Does that mean that patches can no longer be tested before they are released to the public? No, but we may need to rethink how they are tested and deployed, because it appears some cybercriminals are effectively beta-testing the patches themselves.

The researchers also found clues, but no conclusive evidence, that the exploit kit was developed with AI assistance. The broader concern is credible: AI tools can help attackers interpret source-code changes, write and modify code, document test results, and learn from failed attempts.

In practical terms, the gap between “a flaw is fixed upstream” and “most people are protected” may be increasingly valuable to attackers. We should try to minimize that gap.

How to stay safe

Not every security update needs to be installed the moment it appears. In organizations especially, updates may need testing, staged deployment, and contingency plans. But vulnerabilities known to be actively exploited deserve greater priority. That is precisely why CISA’s KEV catalog is so important: It helps organizations identify the vulnerabilities they should address first.

For home users:

  • Install browser and operating-system updates promptly. Use the few minutes they take to grab a drink rather than repeatedly postponing them.
  • Don’t click links in unsolicited emails.
  • Use up-to-date, real-time anti-malware protection to help catch the malware that exploit kits attempt to deliver.

Stop threats before they can do any harm.

Malwarebytes Browser Guard blocks phishing pages and malicious sites automatically. Free, one click to install. Add it to your browser →

Categories: Malware Bytes

Will AI kill us all within the next decade?

Malware Bytes Security - Thu, 09/10/2026 - 8:18am

The Wall Street Journal reports that concerns are rising inside AI labs that competition is pushing tech companies to race toward self-improving models that could spiral out of human control.

Jacob Coxon, an AI researcher who has worked at Anthropic and OpenAI, said:

“The people building AI earnestly believe that it could kill us all by the end of the decade.”

Evan Hubinger, Anthropic’s Alignment Science lead, who also worked at OpenAI, responded in a post on X:

“We really do earnestly believe AI could kill all humans! I personally think it is >10% within the next decade.”

Hubinger added:

“What I am worried about is superintelligence arising from recursive self-improvement, as we have said is happening faster than we thought.”

That figure should be treated as Hubinger’s personal assessment. It is not a forecast, an established fact, or evidence that today’s chatbots are about to become dangerous on their own. Nor is it something I know enough about to endorse or dismiss.

Researchers are actively studying whether highly capable systems could act in unintended ways, exploit vulnerabilities, or be used to automate cyberattacks.

A BBC report notes that Hubinger described the risk from current models as low. His concerns focus on possible future systems with far greater autonomy and capability.

As companies and governments weigh the pace of AI development, we need sensible safeguards, including independent testing, limits on high-risk autonomous uses, transparency from developers, and accountability when AI systems cause harm.

Those measures should also address the problems we already face as cybercriminals use AI for fraud, privacy abuse, and other cybercrimes. Like many powerful technologies, AI can be used as a weapon, particularly when safeguards lag behind its capabilities.

Extreme predictions can be emotionally compelling, especially when made by people closely involved in the technology. But uncertainty cuts both ways: Serious warnings deserve scrutiny, not unquestioning belief.

The practical message is neither “ignore AI safety” nor “prepare for a robot apocalypse.” Companies, governments, and researchers need to work together to ensure that safety measures keep pace with rapid development.

Cooperation can complement competition, and in this case, it could be crucial.

Your name, address, and phone number may already be for sale.  

Data brokers collect and sell your personal details to anyone willing to pay. Malwarebytes Personal Data Remover finds them and gets your information removed, then keeps watch so it stays that way. 

SCAN NOW

Categories: Malware Bytes

Update Chrome now to protect against an actively exploited vulnerability

Malware Bytes Security - Thu, 09/10/2026 - 6:52am

Chrome is rolling out an update for its desktop browser. The update includes 230 security fixes, one of which is known to be actively exploited.

The stable channel has been updated to 153.0.8010.36/.37 for Windows and Mac, and 153.0.8010.36 for Linux.

How to update Chrome

If you don’t want to wait for the rollout to reach you, manually updating is easy.

The easiest option is to allow Chrome to update automatically. But you can end up lagging behind on updates if you never close your browser or if something goes wrong, such as an extension preventing the update.

To update manually, click the More menu (three dots), then go to Settings > About Chrome. If an update is available, Chrome will start downloading it automatically. Restart Chrome to complete the update, and you’ll be protected against these vulnerabilities.

Chrome 153.0.8010.36/.37 is up to date

You can find an explanation of the version numbering system and step-by-step instructions in our guide: How to update Chrome on every operating system.

Technical details

The actively exploited vulnerability is tracked as CVE-2026-87491. The description says it’s an out-of-bounds write vulnerability in Chrome’s V8 engine that could allow a remote attacker to execute arbitrary code inside the browser’s sandbox via a crafted HTML page.

This means the bug was found in the part of Chrome that runs JavaScript. A malicious website could exploit it by getting someone to load a specially designed web page, causing Chrome’s JavaScript engine to mishandle memory and run attacker-chosen instructions. Those instructions would initially run within Chrome’s security sandbox rather than with unrestricted access to the whole device.

Chrome’s sandbox is intended to limit that code’s access to the rest of the device, but the flaw is still serious because it gives an attacker a foothold simply by getting a target to view a malicious web page. Emails are unlikely to trigger the flaw because most reputable email clients sanitize incoming HTML before displaying it. They strip or disable active web features that would let a sender run code in the inbox, such as JavaScript. However, an email could contain a link that takes the recipient to a malicious website.

Besides this medium-severity flaw, the update fixes five vulnerabilities rated Critical, four of which were found in WebGL (Web Graphics Library). WebGL is a JavaScript programming interface used to render interactive 2D and 3D graphics inside the browser without needing extra plugins.

Stop threats before they can do any harm.

Malwarebytes Browser Guard blocks phishing pages and malicious sites automatically. Free, one click to install. Add it to your browser →

Categories: Malware Bytes

Copyright scammers get Instagram accounts suspended and demand payment

Malware Bytes Security - Thu, 09/10/2026 - 5:59am

Scammers are abusing Meta’s copyright-reporting system to suspend people’s Instagram accounts and then hold them for ransom, according to the BBC.

Criminals file fake copyright complaints with Instagram, claiming that an account is using material it doesn’t own. Repeated complaints can trigger a temporary account suspension from the platform, locking out the victim even though they haven’t done anything wrong. The criminal then moves the conversation to another platform, such as Telegram, and demands a ransom to withdraw the complaint.

We’ve reported on a similar scheme before. In that case, scammers abused Instagram’s reporting system to get accounts taken down and then charged their owners to restore them.

The BBC interviewed the owner of a history-focused Instagram account who said that he had been hit by copyright claims multiple times from the same email address. Repeated copyright claims can eventually result in an account being disabled, making this particularly damaging for people who use Instagram to generate income.

The account holder eventually paid $50 in cryptocurrency because he said it could take weeks for Meta to deal with his claim and that they were unhelpful to begin with. However, the scammers targeted him again immediately afterward.

Users do have free support routes, including the appeal option that comes with the copyright notification and Instagram’s in-app Help section. Paid options include the 24/7 access to a support agent that comes with Meta Verified, while Meta Business Support is available to some eligible business and advertising accounts.

The scam works because Meta has automated much of its processing of copyright complaints. It doesn’t verify the authenticity of complaints when they are filed, and repeated complaints can result in an account being temporarily taken down. Its policy says that only rights holders or their authorized representatives can file a complaint, but it doesn’t check their ID before acting. That means criminals can pretend to be rights holders or their lawyers and get away with it.

AI could make it easier for scammers to file these fraudulent complaints at scale, turning the attack into a trawling exercise. If they convince just a few victims to pay a ransom, it can become worth their while, especially if Meta takes too long to resolve the problem manually.

The BBC spoke to one Instagram account owner who said that he had lost brand contracts over the issue. Meta hadn’t been able to assure him that the problem wouldn’t happen again, he said.

This problem is drawing legal scrutiny. In India, the Delhi High Court is examining whether social media platforms can legally suspend user accounts over copyright violations. In a separate case, Meta acknowledged in court that 13 copyright strike notices against one Instagram user were fraudulent and restored the account.

Meta told the BBC that it fights deceptive behavior intended to scam people. After reviewing the accounts identified by the BBC, it restored affected content and added unspecified protections intended to prevent similar attacks. However, the company hasn’t announced any blanket protections designed to fix its “suspend first, verify later” approach.

Law enforcement advises victims not to pay the ransom because that feeds the scammers. It also doesn’t guarantee that they won’t hit you again. In fact, it might make them more likely to do so if they know that you are willing to cough up.

Copyright complaints are also commonly used as phishing lures. We have previously reported on scammers sending fake copyright warnings to X users and convincing copyright notices to YouTube creators. Those attacks tried to steal people’s login details. In this case, the scammers are abusing Instagram’s genuine complaints system to get accounts suspended.

How to protect your Instagram account
  • Turn on two-factor authentication. This will not prevent fraudulent complaints, but it can help protect your account if scammers also try to steal your login.
  • Check copyright complaints in Instagram. Don’t rely on links or screenshots sent by email, Telegram, or another messaging service.
  • Don’t pay to have a complaint withdrawn. Paying does not guarantee that the scammer will withdraw it or leave your account alone.
  • Don’t share login details or verification codes. A scammer may use the copyright complaint to steer you toward a fake Instagram login page.
  • Use Instagram’s official appeal process. Keep copies of the complaint, ransom demands, usernames, email addresses, and payment requests as evidence.

Scammers don’t need to hack you. They just need you to click once. 

Malwarebytes Identity Theft Protection catches suspicious activity before it becomes a problem.

Categories: Malware Bytes

More than 100,000 fake stores are out to steal your card details

Malware Bytes Security - Wed, 09/09/2026 - 11:02am

Researchers at German cybersecurity company Nebty have identified “DoppelCart,” a cluster of almost 119,000 domains linked to copied online stores.

The researchers describe it as the largest publicly documented fake-shop network by associated domain count. They found 118,787 .shop domains in the cluster, representing 2.72% of the .shop top-level domain (TLD) population they examined.

The operation copies legitimate retailers’ product catalogs, descriptions, branding, and images, sometimes even loading images directly from the real companies’ infrastructure.

As we have reported in the past, AI-powered website builders make it easy to clone major brands. However, Nebty’s findings are based on shared website and infrastructure characteristics, rather than evidence that every domain is operated by a single identified group.

BleepingComputer reports an important checkout-level detail: 96% of confirmed DoppelCart shops reportedly shared identical build files and used just 27 ecommerce backends.

The fake shops mimic more than 44,000 brands, with a median of two clones for each brand.

“However, some brands like SodaStream, Velasca, CurrentBody, Daniel Wellington, Dreame, Horze, MOVA, and SPARK PAWS received more attention, with over 30 shops each.”

Nebty observed advertised discounts of up to 65%, a tactic designed to encourage shoppers to act before closely checking the domain, company details, or payment process.

The fraudulent checkout pages collect cardholder data and transmit it to attacker-controlled servers over WebSockets in real time. That may include card numbers, expiry dates, CVVs (card verification values), billing information, and even one-time confirmation codes issued by banks.

Capturing an authentication code in real time can help criminals to complete a payment while the victim is still going through the checkout flow.

How shoppers can stay safe

A professional-looking store, the use of HTTPS, authentic product images, and a familiar logo do not prove that a website is legitimate. Before entering payment details, shoppers should take a few minutes to verify where they are buying from.

  • Check the web address carefully. If possible, reach the retailer through its official app, a saved bookmark, or a web address you already know, rather than sponsored search results or ads on social media.
  • Be wary of unusually large discounts. A low price does not prove that a store is fake, but it is a reason to check the site more carefully.
  • Search for the exact web address alongside terms such as “scam” or “reviews.” Check that the contact details, returns policy, and company information match the real retailer.
  • Pay by credit card or another service with buyer protection. Avoid cryptocurrency, bank transfers, gift cards, and other payments that are difficult to reverse.
  • Check every bank verification request carefully. Make sure the merchant and amount are correct, and never give a one-time code to a retailer or anyone who contacts you.
  • Use an up-to-date, real-time anti-malware solution with web protection.
  • If you’re unsure whether a store is genuine, use Malwarebytes Scam Guard to help you assess it.

If you’ve already paid, act quickly. Contact your card issuer, report the suspected fraud, ask about replacing or monitoring your card, and save screenshots, order confirmations, web addresses, and correspondence.

Stop threats before they can do any harm.

Malwarebytes Browser Guard blocks phishing pages and malicious sites automatically. Free, one click to install. Add it to your browser →

Categories: Malware Bytes

Microsoft fixes record 964 flaws, including 2 exploited zero-days

Malware Bytes Security - Wed, 09/09/2026 - 6:01am

Microsoft’s September 2026 Patch Tuesday addresses 964 CVEs, including 104 rated Critical and 860 rated Important, making it the company’s largest Patch Tuesday release on record.

Microsoft lists 974 CVEs in its full September security release. However, 10 of those affect cloud services or involve fixes that Microsoft applies itself, leaving 964 vulnerabilities that customers need to patch.

The release includes fixes for two actively exploited Windows zero-days. Both are local elevation-of-privilege vulnerabilities that could allow an attacker who already has access to a device to gain SYSTEM privileges. Neither provides remote access by itself, but SYSTEM-level access is valuable to malware operators after they gain an initial foothold through phishing, stolen credentials, or another method.

How to apply patches and check if you’re protected

These updates fix security problems and help keep your Windows PC protected. Here’s how to make sure you’re up to date:

  • Click the Start button, then open Settings.
  • Select Windows Update (usually at the bottom of the menu on the left).
  • Click Check for updates. Windows will search for the latest security updates. If you’ve enabled Get the latest updates as soon as they’re available under More options, you may be prompted to restart immediately to complete the update. Otherwise, continue to the next step.
Windows 11 up to date
  • If updates are available, they’ll start downloading automatically. When they’re ready, click Install or Restart now if prompted. Your computer may need a restart to finish the update.
  • After restarting, go back to Windows Update and check again. If it says You’re up to date, you’re all set.
Technical details

The unusually large batch also includes high-severity remote-code-execution vulnerabilities in Windows DNS Server and Remote Desktop Services, as well as fixes affecting Exchange Server, SharePoint, SQL Server, Office, and core Windows components.

Let’s take a closer look at the two zero-day vulnerabilities. Microsoft classifies a vulnerability as a zero-day if it was publicly disclosed or actively exploited before an official fix became available.

The first is a Windows Update Stack elevation-of-privilege (EoP) vulnerability with a CVSS score of 7.8 out of 10, tracked as CVE-2026-81963. The description says:

“Improper link resolution before file access (‘link following’) in Windows Update Stack allows an authorized attacker to elevate privileges locally.”

This means Windows can be persuaded to open or modify the wrong file because it follows a shortcut-like pointer without properly checking where that pointer leads. Microsoft says attackers exploited the bug before a patch was available.

The second zero-day, tracked as CVE-2026-85880, also has a CVSS score of 7.8 out of 10. Microsoft describes it as:

“heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.”

Microsoft says an attacker who can execute code in a low-privilege AppContainer could exploit the vulnerability locally to escape the sandbox and elevate their privileges on the affected system. No additional user interaction is required.

Windows ALPC is an internal messaging system in the Windows operating system that allows different programs on the same computer to communicate with each other quickly.

A buffer overflow occurs when an area of memory within a software application reaches its boundary and data spills into an adjacent memory region. The heap is a region of memory used for dynamic memory allocation.

These are not the kinds of bugs a typical victim triggers merely by opening a malicious document or visiting a website. But local privilege escalation is a critical part of many attack chains: After malware runs with limited rights, a SYSTEM-level exploit can help an intruder disable defenses, access protected data, establish persistence, or move through a network.

From reporting threats to removing them.

Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.

Categories: Malware Bytes

The push to stop algorithms controlling social media feeds has begun

Malware Bytes Security - Wed, 09/09/2026 - 4:28am

Remember when social media was filled only with posts from your friends, rather than what an algorithm decided you wanted to see? So does the Australian government, and it wants that internet back.

Yesterday, the government released draft legislation outlining a Digital Duty of Care. The proposal includes a measure that Prime Minister Anthony Albanese labeled “My Feed, My Way.” It would allow Australians over 16 to switch off the algorithmic feed that social media platforms deliver automatically to users, instead allowing them to see content from friends and creators they choose to follow.

This legislation, which is expected to reach Parliament before Christmas, would force platforms to send notifications to both new and existing users asking them to choose between the two types of feed. Platforms would then have to respect that choice unless the user changed it.

The feed controls are grabbing the headlines, but the Digital Duty of Care also includes protections for users under 18. Digital services, including social media, online games, apps, and AI chatbots, would have to protect under-18s from harmful content and design features that could negatively affect their behavior or self-esteem.

That includes content that promotes eating disorders, misogyny, crime, life-threatening stunts, pornography, or serious mental health distress.

The proposed law is the latest move from a country known for its aggressive stance on social media safety. Australia banned under-16s from using a wide range of social media platforms, although it hasn’t gone that well.

Three months after the December 2025 ban, 81% of Aussie kids were still using at least one restricted social media platform, down from 86% when the ban was introduced. Before the ban took effect, about 60% used social media at least once a day. Three months later, that figure was 58%.

Bans sound good on paper but they’re hard to enforce.

The new proposal takes a different approach by placing more responsibility on social media companies. The government promises penalties of up to $109.2 million Australian dollars (US$78.6 million) for companies that fail to comply with the Digital Duty of Care.

The Australian eSafety Commissioner would also gain the power to issue removal notices for nudify apps and websites, and streamline its existing child cyberbullying and adult cyber abuse schemes so it can deal with harmful material more quickly.

The move comes less than two weeks after Meta agreed to let teens choose a non-personalized feed as part of a multi-billion dollar settlement with US states.

Why is an opt-out from automatically curated feeds important? Companies that automatically curate your content with their own algorithms tend to show you more of what you’ve been seeing.

That can be great if you’re building a chicken coop and want as much advice as possible on nest box placement. But it can also narrow the range of content you see, making it harder to develop a well-rounded view of a subject.

Perhaps sensing a change in the political wind, social media companies have already begun offering friends-only feeds. Facebook reintroduced this capability in its Friends tab in the US and Canada in March 2025. It called this one of its “OG” Facebook experiences.

TikTok also now has a Friends tab alongside its regular For You feed, while Instagram has offered chronological Following and Favorites feeds since 2022. YouTube has its Subscriptions feed, while Snapchat created separate feeds for friends and other content creators back in 2017.

The problem is that these feeds aren’t the default. Recommended content remains the easiest option to consume.

If you use social media and want more control over what you see, look for its Friends, Following, Favorites, or Subscriptions feed. You might end up with more humblebragging, vaguebooking, or faux-wisdom memes, but at least you’ll know why you’re seeing them. And you can always get some new friends.

Scammers don’t need to hack you. They just need you to click once. 

Malwarebytes Identity Theft Protection catches suspicious activity before it becomes a problem.

Categories: Malware Bytes

Grindr settles HIV status data-sharing lawsuit for $35 million

Malware Bytes Security - Tue, 09/08/2026 - 8:51am

Grindr has reportedly agreed to pay £26 million (around $35 million) to settle a UK privacy lawsuit alleging that it shared sensitive user data, including some users’ HIV status, with advertisers.

The claim was brought by London law firm Austen Hays on behalf of roughly 12,000 UK Grindr users. It alleges that the dating app breached privacy and data-protection laws during a period ending in early 2020.

The claimants allege that Grindr shared personal and highly sensitive information with advertising companies without consent. According to Austen Hays, the shared data may have included ethnicity, HIV status, the date of a user’s last HIV test, and whether they used pre-exposure prophylaxis (PrEP).

At the time of the alleged data sharing practices, Grindr was owned and controlled by the Chinese gaming company Beijing Kunlun Tech. Grindr was sold to US owners in 2020.

According to a US regulatory filing, Grindr will make two payments of £13 million: one by December 31, 2026, and the second by March 31, 2027.

In its SEC filing, Grindr said that the settlement is not an admission of liability and, while it disputes the allegations, it:

recognizes and acknowledges the distress and loss of trust expressed by some of its UK users regarding that pre-2020 period.

The UK settlement follows a separate enforcement case in Norway. The country’s Data Protection Authority found that Grindr had shared users’ personal data with advertising partners for behavioral advertising without a valid legal basis.

These cases illustrate a crucial privacy point: information does not need to be explicitly labeled as medical information or information about sexual orientation to expose intimate details about someone. Advertising identifiers, IP addresses, locations, device information, and confirmation that a person uses a particular app can be combined to identify them or draw sensitive conclusions about their life.

Many free apps rely on advertising SDKs, analytics providers, and other third parties to make money. These integrations can receive identifiers and event data that help target or measure advertising, but they can also create extensive trails of user behavior.

How to protect your privacy on dating apps

Grindr says it has overhauled its privacy program since 2020 and remains committed to user control and responsible data practices. Even so, dating apps can hold unusually personal information about their users.

To limit what you reveal:

  • Review the app’s privacy settings and turn off optional personalized advertising where available.
  • Limit your profile to details you’re comfortable sharing with potential matches.
  • Avoid linking a dating profile to public social-media accounts unless you want identities to be easily connected.
  • Revoke location permissions when you’re not actively using the app, or choose “while using the app” rather than continuous access where your operating system offers it.
  • Keep the app, your operating system, and your security software updated.
  • Watch for romance scams and extortion attempts, particularly requests to move the conversation off the app, send money, share intimate photos, or reveal identifying information.

If you’re unsure whether a message may be part of a scam, you can check it with Malwarebytes Scam Guard, which can help you assess the conversation and decide what to do next.

Scammers don’t need to hack you. They just need you to click once. 

Malwarebytes Identity Theft Protection catches suspicious activity before it becomes a problem.

Categories: Malware Bytes

MikroTik router flaws allow takeover without a password

Malware Bytes Security - Tue, 09/08/2026 - 5:49am

CERT Polska warns that attackers are actively exploiting a chain of critical MikroTik RouterOS flaws to seize control of routers exposed to the internet.

Although the warning comes from Poland’s national cybersecurity response team, MikroTik routers are sold worldwide, including in the US. The vulnerabilities can affect users anywhere if their router is running a vulnerable version of RouterOS and its SSH remote-management service is accessible from the internet.

Attackers are exploiting two vulnerabilities, collectively dubbed “MikroTrick,” to take full control of vulnerable devices, CERT Polska says.

A compromised router is especially serious because it sits at the edge of your network. An intruder may be able to change DNS settings, redirect or capture traffic, create remote-access tunnels, alter firewall rules, or use the device as a foothold to attack other devices on the network.

Two of the six disclosed vulnerabilities form the chain of compromise known as MikroTrick. The first, tracked as CVE-2026-67276, is an SSH authentication-bypass flaw in the handling of RSA public keys. The second, CVE-2026-86060, is a privilege-escalation flaw involving a specially crafted username in the SSH login process.

Put simply, the first flaw lets attackers get in without a password, and the second lets them make themselves an administrator.

SSH (short for Secure Shell) is a network protocol that establishes encrypted connections between computers for secure remote access.

CERT Polska issued the warning because the patched RouterOS packages are already public, and their comparative analysis has allowed the community to reconstruct some of the flaws they fix. 

How to stay safe

MikroTik router owners should install the latest RouterOS security update as soon as possible. Use the router’s update mechanism or obtain the supported package directly from MikroTik. The update option should be available under Check for updates.

You should also remove public access to the router’s management services. Make sure that SSH is not accessible from untrusted networks. If remote administration is necessary, limit access to known IP addresses.

Remote management should be the exception, not the default. MikroTrick demonstrates that a strong password alone cannot protect a device from an authentication-bypass vulnerability.

MikroTik has added a detection mechanism that scans the configuration at startup for selected signs of unauthorized changes. If it finds any, RouterOS disables the recognized suspicious entries and sets the device’s Flagged status to Yes. Administrators can check this with /system/device-mode/print.

RouterOS restricts several potentially abusable functions while the device is flagged, but MikroTik stresses that the router’s full configuration still needs to be audited before the flag is cleared.

From reporting threats to removing them.

Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.

Categories: Malware Bytes

Loyalty points fraud is funding hacker holidays (Lock and Code S07E18)

Malware Bytes Security - Mon, 09/07/2026 - 2:23pm

This week on the Lock and Code podcast…

Crooks are taking a holiday. They’re counting on you to fund it.

For decades, cybercriminals have stolen roughly the same types of data. Biographical and personal details—like Social Security numbers, birthdates, addresses, and phone numbers—can be stolen to commit identity fraud. Credit card numbers, expiration dates, and CVC codes can be stolen to make fraudulent purchases. Usernames and passwords can, in the wrong hands, let a cybercriminal impersonate someone, steal sensitive photographs to later use for extortion, or abuse a reputation.

All of these attack models seek to turn sensitive or important data into currency. But an emerging form of digital fraud is targeting data that, when used strategically, practically is currency: Loyalty points.

Loyalty points programs are run by nearly every type of consumer-facing business today, from hotels to airlines to grocery stores to donut shops. As repeat customers accrue these points, they can exchange them for discounted prices on future purchases, cutting the costs of hotel stays, flights, rental cars, and even entire vacations.

But the value stored within these loyalty points makes them a high target for cybercrime, said Kim Sutherland, Global Head of Fraud and Identity at LexisNexis® Risk Solutions.

“Most loyalty currency is worth about one cent per point, and then there are premium programs that can be worth more than that,” Sutherland said, explaining that 100,000 airlines points, for example, can be worth $1,000 in the US. “Why criminals care so much about this is because most of us are not paying attention to our loyalty programs the same way we would our bank account.”

But diligence is much needed here, Sutherland said, noting that one Chicago teacher only learned that 240,000 of his airlines points had been stolen because he received a basic confirmation email about their use. In another example, a man’s airline miles were stolen and fraudulently used to book rental cars in New York and Memphis.

Today, on the Lock and Code podcast with host David Ruiz, we speak with Sutherland about loyalty points theft— how it happens, what companies are doing to protect customers, and what people can do to stay safe.

“Some of us don’t even know how to access those points, right? Or we don’t even know we’re accumulating them, but the fraudsters do.”

Tune in today to listen to the full conversation.

Show notes and credits:

Intro Music: “Spellbound” by Kevin MacLeod (incompetech.com)
Licensed under Creative Commons: By Attribution 4.0 License
http://creativecommons.org/licenses/by/4.0/
Outro Music: “Good God” by Wowa (unminus.com)

Listen up—Malwarebytes doesn’t just talk cybersecurity, we provide it.

Protect yourself from online attacks that threaten your identity, your files, your system, and your financial well-being with our exclusive offer for Malwarebytes Premium for Lock and Code listeners.

Categories: Malware Bytes

LG TV flaws could let attackers listen in, even in standby mode

Malware Bytes Security - Mon, 09/07/2026 - 9:34am

Smart TVs are internet-connected computers with microphones, app stores, advertising systems, and access to the same home networks used by your family’s phones, laptops, printers, and smart-home devices.

In the past, we reported on Samsung settling a lawsuit with the Texas Attorney General over how its smart TVs collect and monetize viewing data using Automated Content Recognition (ACR)

ACR technology samples what appears on or is heard through a TV, creates a digital fingerprint, and compares that fingerprint against a reference database. It can be used to identify programs, ads, and viewing habits.

Now, a new investigation by Gamers Nexus, carried out with Level1Techs and independent security researchers, has examined several LG TV models. The team says its found extensive device and network discovery, ACR tracking, and security weaknesses that could increase the consequences if a television were compromised.

Some findings concern LG’s intended product behavior, while others rely on vulnerabilities that researchers say are still being disclosed responsibly. But the broader lesson is clear: A smart TV deserves the same privacy and security consideration as any other internet-connected computer.

According to Gamers Nexus, packet captures and firmware analysis showed the tested LG TVs identifying devices on the local network, such as phones, PCs, printers, switches, and smart-home hardware. The investigation also says the TVs collected nearby Wi-Fi network names, signal information, and device-related identifiers.

This network information could help build a picture of the other devices in a household. Combined with ACR data, advertising IDs, and other information, it could support detailed profiles of what people watch and the devices they use.

The researchers also demonstrated how a compromised TV could capture audio through its microphone, including when the TV appeared to be off. They even showed how the TV stored audio when it was unplugged from the internet and retrieved it after the connection was restored.

The researchers also reported remote-code-execution vulnerabilities to LG. They have not disclosed full details while the responsible disclosure process is ongoing.

A compromised television could be more than a privacy issue. It might provide an attacker with a foothold on a home or business network, access to audio, or a route to probe other devices.

How to stay safe

The concerns are not limited to one brand. Smart TVs sit at the intersection of entertainment, advertising, and the home network. Treating them as security-sensitive devices—and demanding clear, meaningful privacy choices—is increasingly part of staying safe at home.

There is no need to panic, but owners can take a few practical steps to limit what their TV collects and what it can access:

  • Install firmware updates promptly, especially security updates. Check your model’s support page and the TV’s software-update settings.
  • Review the privacy controls under Settings, Privacy & Terms, or User Agreements. Turn off ACR, viewing-information collection, personalized ads, voice recognition, and other features you don’t need.
  • Don’t accept every agreement by default. Read each consent screen and decline optional advertising and voice-data features where possible.
  • Use a separate IoT or guest network for televisions, cameras, speakers, and other smart-home devices. This limits what a compromised device can reach on your main network.
  • Disable UPnP on your router unless it is genuinely needed and avoid exposing TV services directly to the internet.

Our earlier guide to disabling ACR includes instructions for several popular TV brands.

Browse like no one’s watching. 

Malwarebytes Privacy VPN encrypts your connection and never logs what you do, so the next story you read doesn’t have to feel personal. Try it free → 

Categories: Malware Bytes

Flirty OnlyFans promoters on X may be using AI to appear human

Malware Bytes Security - Mon, 09/07/2026 - 7:18am

In a recent post, we looked at reports of League of Legends players receiving suspicious friend requests shortly after matches. The accounts quickly steered the conversation toward Discord, where they promoted paid adult-content pages.

At the time, one unanswered question was how much of those conversations was automated. Were people working from scripts behind the accounts? Were they conventional, rules-based chatbots following a limited decision tree? Or were they using generative AI to produce more natural and flexible replies?

People are more likely to trust someone they believe is personally interested in them. AI can create that impression across many conversations at once, making it easier to persuade people to click links, spend money, or share personal or intimate information. The same approach could also be used for more harmful fraud, including romance scams and sextortion.

Now, developer Álvaro Martínez Majado has investigated several flirty accounts promoting OnlyFans pages on X to see whether their replies were scripted, generated by AI, or written by people. Majado, president of digital rights organization Protecció de la Frontera Electrònica, shared his evidence with Malwarebytes. Although it does not provide a definitive answer, it shows the accounts following rigid conversation scripts while also responding dynamically to unusual requests. The signs that once suggested a real person, such as an unusual reply or personalized voice note, can no longer be trusted.

The script goes on and on

Majado interacted with several accounts on X that followed a familiar pattern. They opened with similar casual, flirtatious language and asked broadly the same qualifying questions: where he lived, what he liked, and what he did for work.

That repetitive structure is exactly what we would expect from a commercially motivated messaging campaign. The goal is not necessarily to have a meaningful conversation. It is to identify people likely to respond, establish rapport, and eventually move them toward a paid page or another destination controlled by the operator.

The accounts also stayed in character when faced with obvious attempts to expose them as bots. That could be the result of hard-coded replies, guardrails around an AI system, or both.

They claimed to live in the same city as the recipient

But some later interactions were more difficult to explain as a simple bank of canned flirtatious responses.

One of the more interesting tests involved an instruction written as ASCII hexadecimal rather than ordinary text. The encoded message told the account to reply with a single word: “Pineapple.”

According to the screenshots supplied to Malwarebytes, the account responded with “Pineapple” in ordinary text.

An account followed an instruction encoded in hexadecimal

That does not conclusively prove which technology was used. It does not identify a model, a provider, or the people behind the accounts. But it is consistent with an automated system capable of interpreting an encoded instruction and changing its output accordingly.

A simple scripted bot could theoretically include a hexadecimal decoder, of course. But that would be unusual in a basic adult-content promotional bot, especially when combined with other examples of flexible and sometimes error-prone responses.

In another interaction, Majado asked an account to provide a reply of exactly 12 characters. It responded with “Imnotabotfr”—an 11-character answer—then appeared to recognize its own counting mistake.

The account failed an exact character-count test, but recognized its error

Anyone who has spent time experimenting with large language models may recognize the pattern. Language models can be very good at generating natural-sounding text while still making surprisingly basic mistakes involving character counts, word counts, and other exact constraints.

A deliberately designed bot could imitate this kind of mistake, so it is not proof of AI. But the account understood an unexpected instruction, attempted to follow it, and reacted when it got the answer wrong. That suggests it may have been generating replies dynamically rather than choosing from a list of pre-written responses. Such accounts can adapt to conversations, making them harder to identify as automated.

Voice notes do not settle the question

The accounts also sent voice notes. In one example, an account read aloud a Unix timestamp supplied during the conversation. In another, it spoke a requested username.

The accounts sent voice notes containing requested information

These responses show that the accounts could incorporate unusual information from a conversation into audio messages. They do not tell us whether a person recorded the clips or a text-to-speech tool generated them.

Text-to-speech tools can generate short, convincing clips quickly and cheaply. An operator can generate them manually, but the process can also be automated: Take a message, pass selected text to a voice-generation service, and send the resulting audio back to the recipient.

Here’s one of those voice notes. Is it a very flirty girl, or AI-generated? Have a listen and see what you think:

The supplied audio metadata offered a possible clue about the tools involved, but it is not enough to attribute the voice notes to a particular service. Platforms and other software can alter audio files and their metadata.

The more important point is that the voice notes were personalized and continued even after the interaction appeared unlikely to lead to a sale. That is consistent with a system designed to keep conversations moving without requiring a human to supervise each one.

AI does not replace the funnel

The evidence does not mean every message from every flirty spam account is written by an AI. Nor does it establish that the X accounts are operated by the same people targeting League of Legends players.

What it does suggest is a plausible hybrid model, supported by identical replies across different accounts alongside more flexible responses.

The repetitive parts of the operation can be scripted: opening messages, questions about location and interests, links, and attempts to move people to another platform. An AI-powered conversational layer could then make the exchange feel less repetitive when someone asks unexpected questions, changes the subject, or tries to test whether the account is real.

This combination makes practical sense for spammers. Scripts provide consistency and keep the conversation directed toward conversion. Generative AI helps the account handle the unpredictable parts of talking to real people.

It also means that traditional “bot tests” are becoming less useful. Asking an account to answer an unusual question, decode a message, or send a voice note may no longer distinguish a real person from a fake one.

How to stay safe

Treat unsolicited flirtatious messages with caution, especially when they quickly become transactional.

  • Do not assume a personalized response or voice message proves an account is genuine.
  • Be wary if a new contact repeatedly tries to move you to Discord, Telegram, Signal, another messaging app, or a paid-content platform.
  • Do not send money, gift cards, cryptocurrency, intimate images, identity documents, or account credentials to someone you only know online.
  • Avoid opening links or downloading files from accounts that contacted you unexpectedly.
  • Reverse-image-search profile photos and look for copied biographies, reused images, or accounts with very limited genuine activity.
  • Report suspicious accounts to the platform, particularly if they impersonate someone, send malicious links, or pressure users for money or explicit material.

Whether it’s a human, a chatbot, or an AI agent you’re talking to is an important question. AI could make these operations more convincing and much easier to scale. One operator could hold flirtatious conversations with many people, adapting the messages without personally managing every exchange.

That makes it easier to create a false sense of connection and persuade people to click links, pay for content, or share personal or intimate information.

The line between a scripted spam account and a responsive conversational partner is getting harder to see. Judge the account by what it wants you to do, not by how convincingly it talks.

Something feel off? Check it before you click.  

Malwarebytes Scam Guard helps you analyze suspicious links, texts, and screenshots instantly.  

Available with Malwarebytes Premium Security for all your devices, and in the Malwarebytes app for iOS and Android.  

Try it free → 

Categories: Malware Bytes

The hidden work of modernizing Malwarebytes

Malware Bytes Security - Fri, 09/04/2026 - 1:15pm

Most of the work that keeps a security product trustworthy is invisible. Users see a scan complete, a threat blocked, an update applied overnight. They don’t see the platform underneath. Runtimes, managed libraries, native drivers, and Windows requirements must all stay current and work together across millions of endpoints. Our migration to .NET 10 is one example of how we keep that platform moving and our focus in this article.

It would be easy to call these upgrades maintenance tasks and move on. But that is underselling them. Our code runs continuously, with elevated privileges, next to some of the most sensitive parts of Windows.

Every dependency in our stack, from the runtime and third-party libraries to native drivers and operating-system requirements, affects the environment in which our software runs. When one changes, everything that relies on it may have to change too.

The problem: platforms fall behind by standing still 

In endpoint security, the ground never stops moving. Windows evolves. Threats evolve. Hardware evolves, from ARM64 laptops to machines with far more memory and faster storage than the ones our code was first written for.  

A platform that stands still does not stay the same. It falls behind. Every skipped release of a dependency or runtime widens the gap between the ecosystem we built on and the one that is stable today.  

A modern runtime and .Net 10 in particular can give us better security, faster code paths, a smaller memory footprint, and richer diagnostics. It also gives our engineers language and tooling improvements that help them work more efficiently. 

The stakes are also particularly high for security software: 

  • A web app can be rolled back with a deployment. Software already installed on a customer’s endpoint cannot. 
  • Our code runs with high privileges, alongside kernel drivers and anti-tamper protections.   
  • A runtime regression does not affect one server. It has the potential to affect millions of machines.  

So we treat a runtime upgrade with the same rigor as a security feature. 

The challenge: everything moves together 

Malwarebytes for Windows is not a single program. It is a coordinated system: a user-facing interface, several long-running Windows services, an installer, a self-update pipeline, a plugin surface, and third-party managed dependencies.  

These sit above native drivers and our detection engine. The .NET 10 migration covered the managed parts of Malwarebytes while leaving this native core untouched. But the different layers still have to work together. 

The migration had to satisfy several requirements at once:  

  • Security-sensitive code had to behave identically before and after the change.  
  • Native drivers and anti-tamper layers had to continue working correctly with the  managed code. 
  • The installer and update pipeline had to deploy the new runtime files and clean up old ones.  
  • Plugins and third-party dependencies had to remain compatible. 
  • Existing Malwarebytes installations had to continue working.  
  • Our automated validation had to be extensive enough to trust the result without inspecting every path by hand. 

The boundary between managed and native code deserved particular attention. Managed code in our services talks to native components through interfaces such as P/Invoke and COM. A runtime change can subtly affect how these different parts of Malwarebytes communicate and work together. 

Those differences may never show up in a demo. They might only surface on one machine in 10,000. Finding them before customers do is the important part. 

Not every update looks the same 

There are three main reasons we update a dependency: We choose to, the platform underneath forces us to, or a vulnerability makes us. Each comes with a different timeline.  

Elective modernization. We may choose to move to a new runtime, a new major version of a library, or a new platform capability to take advantage of new features, fixes, or security improvements.  

Baseline shifts. As platform requirements evolve, some older compatibility constraints can hold back modernization. For example, moving to .NET 10 allowed us to update the application baseline and adopt a newer, supported runtime. As part of the same change, Windows 7 support was deprecated. 

Forced patches. Sometimes a vulnerability is disclosed in a library we ship or a system we depend on. The change is no longer optional and the timeline is not ours. What we can control is our readiness: the testing, release process, and staged rollout that allow us to respond quickly without introducing new problems. 

Different reasons and different timelines, but each requires the same careful approach. 

The .NET migration: Why we did it 

Moving to .NET 10 gives Malwarebytes a more secure, supported, and capable foundation for Windows, with several compounding benefits: 

Security. A modern runtime benefits from Microsoft’s ongoing security work, including safer defaults, stronger cryptography, and mitigations for memory and interoperability bugs. Staying on a runtime that Microsoft actively supports means we can continue to apply fixes when vulnerabilities are discovered.  

A supported foundation. It may not be a glamorous reason, but .NET 10 keeps us on a supported, actively developed platform that is better aligned with newer versions of Windows. It makes it easier to adopt future fixes, features, and improvements as routine work instead of one-off projects. 

Diagnostics and observability. Modern .NET has stronger built-in tracing, metrics, and crash diagnostics. In a security product, understanding how code behaves in the field matters. Better diagnostics help us identify and resolve reliability issues.  

Performance and memory efficiency. Recent .NET releases have improved the just-in-time compiler, garbage collector, and core libraries. Our processes run all day in the background, so how efficiently they run and manage memory matters. These capabilities give us more opportunities to improve efficiency, although the impact will vary between components. 

The .NET migration: How we did it  

The guiding principle is simple: Never advance faster than the evidence allows.  

We started by isolating the work on a dedicated branch. We retargeted the platform and refreshed every managed dependency so the new runtime and the codebase agreed on exactly which components should ship.  

That surfaced some of the less obvious consequences of the upgrade early on: libraries that had been renamed or folded into the runtime, files that were no longer needed, and new ones that had to ship in their place. 

Deployment is easy to overlook and expensive to get wrong. A runtime migration is not only about the code that runs. It is also about what lands on the customer’s disk.  

Our installer and update service had to learn the new runtime’s file layout. They had to remove dependencies the runtime now provides, stop shipping renamed files, and deliver replacements cleanly during both fresh installs and in-place updates.  

Getting deployment right is the difference between an upgrade users never notice and one that creates a support problem. 

Once the build was working correctly, the focus moved to validation. 

The migration involved: 

  • Extensive automated testing across services, install, and update paths. 
  • Compatibility validation against real-world configurations and previous installations. 
  • Performance benchmarking to catch regressions in startup, memory, and scan behavior. 
  • Canary and staged deployment, starting with small populations and expanding only when results showed it was safe to do so. 
  • Continuous monitoring and automated regression detection in the field. 
  • Cross-functional work across platform, QA, installation and update, and release engineering. 

“We never advanced faster than the evidence allowed. Every gate had to turn green on its own.” 

The .NET migration: The tradeoffs  

None of this was free, and the choices involved deliberate tradeoffs.  

The tradeoff on the branch was drift. Isolating the migration protected the main codebase, but the longer that branch existed, the more it could diverge from active development. We managed that risk through frequent integration rather than leaving one large, risky merge until the end.  

The tradeoff on rollout was speed. Staged deployment also meant customers received the update later than they would with a big-bang release. We accepted that tradeoff. Evidence from smaller populations gives us an opportunity to catch problems before an update reaches a much larger number of endpoints. 

The tradeoff on AOT was flexibility. Ahead-of-time compilation can improve startup performance but can also constrain dynamic behavior. We applied it selectively, component by component, rather than everywhere by default. 

What the .NET 10 migration means for customers

The best outcome of infrastructure work is that customers benefit from it without having to think about it.  

On .NET 10, those benefits for Malwarebytes customers include:   

  • Improved reliability on a fully supported, actively maintained runtime.  
  • A more secure foundation that benefits from the platform’s continuing security improvements.  
  • Access to new .NET features and fixes. 
  • Better support for newer versions of Windows. 
  • Newer .NET tools can help us develop and deliver new protection faster. 
Lessons worth keeping  

Every one of these updates—the runtime, the baselines, the security patches—leaves the team holding a few convictions more firmly.  

Platform upgrades are strategic investments in everything built on top of them. Modernization also works best when it is continuous: the longer a platform falls behind, the more difficult the eventual upgrade can become. 

Automation is particularly important for changes of this breadth. So are the small, unglamorous decisions made years earlier, such as maintaining clean boundaries between components and having a build process that knows precisely what it ships. 

Those foundations are what make larger changes possible.  

“Technical debt compounds like financial debt. The cheapest upgrade is the one you never postponed.”  

What comes next  

No upgrade is a finish line. Each one is a step in a longer pattern: modernize continuously, in deliberate steps, so the platform never falls behind. Baselines will shift again. Vulnerabilities will land without warning. Each will meet the same discipline: the same tests, the same staged rollout, and the same evidence before we move forward. 

That discipline is what a product trusted to run every day, on every machine, without a second thought is actually made of.  

Malwarebytes for Windows on .NET 10 shipped in version 5.6.0. It is the latest step in a long-standing commitment to invest in the platform beneath the product so the protection on top of it can keep getting better. 

“One of the best cybersecurity suites on the planet.” 

According to CNET. Read their review

Categories: Malware Bytes

X Money rollout linked to password-reset attacks

Malware Bytes Security - Fri, 09/04/2026 - 8:29am

X says attackers may be targeting accounts because its X Money payments service is now more widely available.

The company is investigating a wave of unsolicited password-reset emails sent to users. While their arrival alongside the wider X Money rollout has fueled account-takeover concerns, X says it has found no evidence of a breach or successful account takeovers so far.

X users began reporting unexpected password-reset emails and codes on September 1. In a public post, X product engineer Mridul Singhai said:

“Attackers appear to believe that, now that @XMoney is widely available, they can gain unauthorized access to accounts.”

Singhai said X was actively investigating, apologized for the repeated emails, and added that the company had found “no evidence of any breaches.”

X Money gives eligible US users access to financial services within X, including interest-bearing accounts, a Visa debit card, and peer-to-peer payments. Cross River Bank provides the banking infrastructure behind the service.

This could make some X accounts more attractive targets, particularly accounts with payment access, high follower counts, business use, or valuable social-engineering potential.

The activity itself appears consistent with attackers submitting password-reset requests in bulk against X accounts. Requesting a password reset is not the same as resetting a password, however, and neither automatically means that an account has been taken over. X’s recovery process requires access to the email address or phone number associated with the account before someone can complete the reset.

There is no evidence that anyone has accessed X Money accounts or funds. Nor has X confirmed that X Money caused the password-reset activity. The timing is notable, but it does not prove a technical connection between the two.

Earlier this year, we saw a flood of Instagram password-reset emails, showing that similar activity can happen on platforms without payment services.

It could be a cover for something more serious. Even if an attacker cannot complete a reset, large volumes of legitimate-looking reset messages can provide useful cover for scams.

Reset flooding can also be a nuisance tactic. Repeated messages may pressure someone into changing their password unnecessarily, obscure more important security notifications, or encourage them to disable security controls in an attempt to stop the alerts.

How to stay safe

If you receive an X password-reset email that you did not request:

  • Do not click links or enter codes from unexpected messages. Open the X app or type x.com into your browser yourself if you want to inspect or change account settings.
  • Do not share reset codes or two-factor authentication codes. Support staff, advertisers, and “security teams” will not contact you unexpectedly to ask for them.
  • Turn on password-reset protection. X says this setting requires additional account information, such as an email address or phone number, before it will send a reset link or code. It is available under Settings and privacy > Account > Security > Password reset protection.
  • Use two-factor authentication, preferably an authenticator app or security key where available. This adds another verification step if someone obtains or guesses your password.
  • Use a unique, strong password. If you use your X password anywhere else, change it through X’s settings, not through a link in an email.
  • Watch for signs of an actual account takeover. These include unfamiliar posts, direct messages, profile changes, login alerts, or unknown apps connected to your account.
  • Stay alert for phishing. The strongest immediate consumer risk may not be a flaw in X itself, but phishing that imitates the reset process. A fake message can look especially convincing when genuine reset emails are arriving around the same time.
  • Use protection. An up-to-date, real-time anti-malware solution with web protection can warn you about malicious and fraudulent sites.

If you’re unsure whether a message is real, use Malwarebytes Scam Guard to check it and get advice about what to do next.

Scammers don’t need to hack you. They just need you to click once. 

Malwarebytes Identity Theft Protection catches suspicious activity before it becomes a problem.

Categories: Malware Bytes

Free streaming boxes may be routing criminal traffic through your home

Malware Bytes Security - Fri, 09/04/2026 - 5:20am

“Free” movies and TV could cost you your privacy, bandwidth, and control of your home network.

We’ve warned about illegal streaming and modded Amazon Fire TV Sticks in the past. Now, researchers have found that certain SuperBox devices and apps could quietly enroll a household connection into a proxy network, allowing third parties to route traffic through it.

An earlier report identified CyberFlix TV, available through SuperBox’s custom app store, as containing Popanet proxy functionality that registers the device with a server controlled by the proxy operator.

Law enforcement agencies have warned that “foreign entities” are using residential proxies to conceal their identities and make their activity appear to come from someone else’s home network.

The FBI defines a residential proxy as follows:

“A residential proxy is an intermediary server between individuals and websites they visit to make their connections appear to originate elsewhere. Legitimate IP addresses assigned by an Internet Service Provider (ISP) to consumers’ Internet of Things (IoT) devices, such as TV streaming devices, digital picture frames, smartphones, tablets, and routers are used to route traffic. Once an internet-connected device is compromised, the device’s IP address can be used by threat actors to mask their online illegal activity, making the consumer appear responsible.”

Residential proxy networks rent out ordinary home IP addresses to customers. That makes their traffic appear as if it originates from a legitimate consumer connection rather than a data center, helping cybercriminals evade IP-based fraud controls and reputation systems.

Besides affecting connectivity, this can mean that a household’s public IP address becomes associated with activity it did not initiate, ranging from credential stuffing and account abuse to attempts to bypass enterprise security controls.

Plume’s more recent research warns that these proxy networks can also function as malware-delivery platforms. In other words, attackers may not only use a compromised streaming box as an exit node. They may use the proxy connection to reach the box itself and install additional malicious software.

The reported SuperBox configuration is especially troubling because it disables or weakens multiple Android safeguards. Researchers found exposed Android Debug Bridge (ADB) access, root-level privileges without authentication, and the removal of protections that would normally restrict untrusted app installation or prompt users to approve risky actions.

Many people assume that placing a streaming device behind a home router prevents outside access. Normally, network address translation and a firewall do make unsolicited inbound connections more difficult. But proxy-enabled devices can maintain an encrypted outbound connection to a remote server, creating a channel that the home router treats as legitimate traffic initiated from inside the network.

How to stay safe

The safest option is not to connect devices or install apps that promise unauthorized access to free movies and TV. You could be bringing a proverbial Trojan horse into your home.

If you own a SuperBox device or have installed CyberFlix TV, disconnect the device from your network. A factory reset may not be enough to make it safe to use again, so you should replace it.

When a device’s business model depends on monetizing your connection, its security choices can put your IP address, bandwidth, privacy, and local network at risk.

Network segmentation can reduce exposure for ordinary Internet of Things (IoT) devices, but it is not a complete answer here. A product that intentionally establishes a persistent proxy channel and offers weak device-level protection should not be trusted on a household network, even on a separate guest network.

From reporting threats to removing them.

Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.

Categories: Malware Bytes

StreamRat Android malware spreads through Meta and TikTok ads

Malware Bytes Security - Thu, 09/03/2026 - 12:04pm

A malicious advertising campaign promoting a fake free TV-streaming service reached roughly 570,000 Meta users.

The researchers who discovered the campaign found that its streaming-themed ads were aimed at Spanish-speaking users, with most observed victims located in Spain. One Meta campaign ran from June 11 through July 3, 2026, and the same banners were also used to distribute the malware through TikTok.

The available data shows the ads’ reach, not the number of downloads or infections, but it demonstrates how quickly paid advertising can put a scam in front of a very large audience.

The ads promoted an Android banking Trojan and infostealer called StreamRat. It can monitor what’s on screen, capture information typed into apps, show convincing fake screens to steal usernames and passwords, and allow attackers to control the device remotely.

We often warn people not to click suspicious links in unexpected texts or emails. But malicious advertising is harder to recognize because it appears in the same feeds where people expect to find promotions, videos, and recommendations.

This campaign is a perfect demonstration of why “after-the-fact” ad checks are inadequate when it comes to protecting social media users. Attackers used familiar social media advertising and carefully tailored instructions to turn casual interest in free entertainment into a risky app installation.

How the attack worked

The ad led victims to a website posing as a streaming platform. The site checked whether a visitor was using Android. Non-Android visitors were simply prevented from downloading anything, while Android users were shown an app download option. This is a common way for scammers to concentrate their efforts on devices their malware can infect.

The site also identified whether someone had arrived through Instagram, TikTok, Facebook, or a regular browser. It then displayed instructions suited to that situation, including steps to allow the browser to install apps from “unknown sources.” In other words, this was not a generic malicious download page: It was designed to coach people through the security warnings that would normally make them stop and think.

StreamRat is an Android banking Trojan and infostealer. It can monitor what’s on screen, capture information typed into apps, show convincing fake screens to collect usernames and passwords, and enable attackers to operate the device remotely. The researchers also found options to cover the screen with a black page or fake Android update screen. These can distract victims while criminals interact with the phone behind the scenes.

How to stay safe

While this campaign targeted Spanish-speaking people, primarily in Spain, the following guidelines can help anyone avoid similar attacks.

  • Avoid installing Android apps from ads, direct-download websites, social media messages, sponsored search results, or links sent by strangers.
  • Download apps through Google Play whenever possible, and check the developer’s name, reviews, and app history rather than relying on an ad.
  • Before enabling installation from “unknown sources,” read our guide, Sideloading on Android: What it is, why it’s risky, and how to do it more safely.
  • Be very cautious when an app asks for Accessibility access, screen-sharing permission, Device Admin privileges, or permission to become the default launcher. Permissions that don’t line up with the intended use of the app are very suspicious.
  • Use an up-to-date, real-time anti-malware solution on all your devices.
What to do if you installed a suspicious app

If you installed a suspicious APK and granted it Accessibility access, disconnect the phone from Wi-Fi and mobile data. If possible, revoke the app’s Accessibility access and remove it. Use another device to change relevant passwords and contact your bank if you used banking apps on the infected phone. A factory reset may be necessary if you cannot confidently remove the infection.

Malwarebytes for Android detects StreamRat as Android/PUP.Agent.ACR02DB0614H7

Scammers know more about you than you think. 

Malwarebytes Mobile Security protects you from phishing, scam texts, malicious sites, and more. With real-time AI-powered Scam Guard built right in. 

Download for iOS → Download for Android → 

Categories: Malware Bytes

Your phone or computer may soon ask how old you are

Malware Bytes Security - Thu, 09/03/2026 - 4:54am

First, the good news: If you use a Linux-based operating system, you may not be asked your age in a few months. The bad news is that Windows, macOS, iOS, and Android users in California will be.

California has passed a law that requires a range of operating systems to start collecting your age when you first set them up. Under the state’s Digital Age Assurance Act (DAAA), signed into law in October 2025, Windows, macOS, iOS, and Android will all have to do this from January 1, 2027.  Operating systems set up before that date in California will need to do the same by July 1, 2027.

Operating systems will categorize people into four age brackets: under 13, 13–15, 16–17, and 18+. They will then be able to send a non-identifying age signal to app developers. Developers must request that signal from the operating system provider or app store when someone downloads and launches an app. This makes them legally aware of the person’s age bracket.

California wants to stop children from doing things that could hurt them. Kids shouldn’t be able to download apps containing mature content meant only for adults, for example. Age assurance also goes hand in hand with social media restrictions, and Meta recently agreed to put time limits on kids’ social network use as part of a massive court settlement. Another California bill, AB1709, would restrict addictive social media features for children under 16. Measures like these need some form of age assurance to function.

This makes digital rights activists unhappy. The Electronic Frontier Foundation (EFF) isn’t a fan of age verification. It accused California of “outsourcing censorship to developers” through the DAAA rather than focusing on privacy.

The EFF was also uncomfortable with the effect of all this on open-source systems. Age verification requires time and effort from operating system developers. That’s fine if you’re Microsoft, Apple, or Google with a massive development budget. But it’s more problematic for operating systems developed by volunteers, such as Linux distributions. Those that don’t have the resources to comply, or don’t like the privacy implications, might prefer to avoid the Golden State altogether.

GrapheneOS, a privacy-focused mobile operating system that strips Android of its surveillance functions, took that option. In March, it said that it wouldn’t implement age verification, and would happily forego sales of devices running its software in certain regions, if necessary.

Assembly member Buffy Wicks, who introduced the original DAAA, has been listening. She tweaked the legislation with Bill AB1856, which would amend the law to exempt certain open-source operating system providers. California lawmakers passed the bill in late August, and it is now awaiting the governor’s decision.

AB1856 would exempt software that follows open-source rules, allowing it to be reused and built upon by others. This includes software distributed under common licenses such as GPL, MIT, BSD, and Apache. Not one single lawmaker voted against it.

California isn’t alone in mandating the collection of age brackets. Colorado’s SB26-051, now law, does something similar. Legislators there also added parallel open-source exemptions after lobbying by Linux hardware maker System76.  Illinois has also passed age assurance legislation, and New York has a bill in the works.

Exempting open-source operating systems from California and Colorado will please privacy-conscious users, but it’s worth noting that some Linux distributions are going ahead with age assurance anyway. Many have drawn a line in the sand, others, like Fedora, are reportedly planning to do it anyway.

In any case, those using more mainstream operating systems can expect a “How old are you?” or “What’s your birthdate?” question sometime soon. If you’d rather avoid that, consider an open-source operating system instead. Just check with your distribution’s maintainers to see what their plans are.

From reporting threats to removing them.

Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.

Categories: Malware Bytes

Pages