Malware Bytes
Be careful what you put in “anyone with the link” Google Docs
The next time you type something sensitive into a Google Doc—or any other online tool with a sharing feature—be careful about the permissions you grant.
Speaking with The Register, the founder of QR generation service Pageloot said that he learned that the hard way. Siim Kostabi recalled how a contractor working for the company accidentally exposed login details for its staging environment—credentials that were never meant to leave an internal testing setup.
The hapless developer had access to a staging environment (used to test new software code before it goes live). They stored the login details in a Google Doc and then set it to “anyone with the link can view.”
It turns out Google Search can index Google Docs with that setting if the link becomes discoverable on the public web. “Anyone with the link” files aren’t automatically indexed, so we don’t know exactly how Google discovered this particular document. What we do know is that it did: The credentials file ended up in Google Search.
A Pageloot developer typed the company’s domain into Google while debugging, and Google’s autocomplete feature surfaced a staging hostname followed by what looked like a credential string. Sure enough, the document was accessible online. Google Search was surfacing information from a document that had been shared too widely.
To its credit, Pageloot moved quickly. It cut the contractor’s access and changed every affected credential. It also banned password storage in Google Docs, Slack, Notion, and any other shared workspace.
The problem is that none of those fixes existed before autocomplete surfaced the password. If nobody had spotted it, the credentials could have remained exposed.
People share private data in online tools all the timeIf there was ever an example of why you should use a password manager, this is it. Instead, the contractor typed their login details into a Google Doc, presumably to keep them handy.
Pageloot isn’t alone in dealing with this problem. Ateam, a Japanese Android game developer, left a Google Drive instance set to “Anyone on the internet with the link can view” from March 2017 until November 2023. That single misconfiguration exposed 1,369 files and personal data for 935,779 people. Ateam said it had seen no evidence anything was taken, though seven years of open access is hardly reassuring.
Scale AI, the data-labeling company central to Meta’s AI ambitions, also left 85 Google Docs with training material for Meta, Google, and xAI editable to anyone with a link. Contractors called the setup “incredibly janky”. Scale later disabled users’ ability to share managed documents publicly.
This is a trend. Three years ago, AI security company Metomic scanned approximately 6.5 million Google Drive files and found that 40.2% contained sensitive information. Just over a third were shared externally, while 0.5% were fully public.
That 0.5% might not sound like a lot, but across 6.5 million files, it still represents thousands of publicly accessible files.
This isn’t just a Google problem, though. People accidentally share sensitive information through other tools too, like the Trello project management system. Making a Trello board public makes it viewable to everyone, which was unfortunate for government users when they exposed passwords and security plans that way in 2018.
The problem is that as tools become increasingly collaborative, people can’t keep up. They make mistakes. Verizon’s 2025 Data Breach Investigations Report attributes around 60% of breaches to human factors including misconfiguration and misuse of valid credentials.
What the checkbox costPageloot encountered another access-control failure involving a customer. A disgruntled former employee whose access had never been revoked used it to redirect the customer’s QR codes to a competitor’s site. It was the same root cause: nobody was watching who had access to what.
Kostabi learned his lesson, which is to keep an eye on who has access to what.
Consumers can take a few simple precautions too. Don’t store passwords or other highly sensitive information in ordinary shared documents. Use a password manager for passwords, and before hitting Share in any online service, check exactly who will be able to access what you’re sharing.
“One of the best cybersecurity suites on the planet.”According to CNET. Read their review →
Heights Finance data breach: What customers need to know
Heights Finance Holdings’ online data breach notification says an unauthorized party accessed a third-party cloud platform containing customer data, potentially exposing highly sensitive personal, banking, and identity information.
Heights Finance is a consumer lender that offers personal installment loans. Reportedly, the company filed a report with Texas regulators mentioning 734,828 affected people, though that figure should not automatically be read as a confirmed nationwide total, since Heights Finance operates dozens of personal loan companies across Alabama, Tennessee, Georgia, Texas, and South Carolina.
The company is associated with the former CURO Management business and related brands. The breach notice covers not only some Heights Finance customers, but potentially people connected to certain current or former CURO-related brands.
On May 7, Heights Finance discovered that an unauthorized party had gained access to a cloud-based platform run by a third party and used to store certain customer information. The company says its investigation found that the intruder may have viewed or copied information in that environment.
Heights says affected people may include:
- People who received a loan through Heights Finance.
- People who inquired about or applied for a loan product, including through a third party.
- Some customers of former parent company CURO Management and its present or former related brands.
What makes the incident especially concerning is the nature of the potentially exposed records, which can include the combination of information criminals need to impersonate someone, target their bank accounts, or create highly convincing phishing attempts.
Breaches happen every day. Don’t be the last to know.Potentially exposed data includes:
- Contact information: Name, home address, phone number, and email address.
- Financial information: Account details, bank name, bank account number, routing number, and related financial information.
- Government identifiers: Social Security number (SSN), tax identification number, driver’s license number, or state ID number.
- Other personal data: Date of birth and personal circumstances voluntarily disclosed during customer service interactions.
The combination of a Social Security number, date of birth, address, and bank account details can create a much more serious risk than a breach exposing only email addresses. It can support identity fraud, financial fraud, account takeover attempts, and tailored social engineering scams.
The personal circumstances customers may have shared with support staff could also make scams more persuasive or potentially more harmful, particularly for people who discussed financial distress, repayment problems, or other sensitive subjects.
What affected customers should doPeople who receive a letter from Heights Finance should follow the company’s instructions and enroll in the offered protection service. Exact instructions can be found on Heights Finance’s website.
Since people who were not actual customers could also be affected, there may be some uncertainty about whether someone’s information was included in the data breach. If you believe you fall into one of the listed groups but do not receive a notice, use contact details published by Heights Finance for inquiries. Do not use a number provided in an unexpected email, text, phone call, or even sponsored search result to ask whether your information was involved.
More general advice on what to do is available in our article Involved in a data breach? Here’s what you need to know.
What do cybercriminals know about you?
Use Malwarebytes’ free Digital Footprint scan to see whether your personal information has been exposed online.
ShieldBreak bypasses Microsoft’s patch for earlier Defender flaw
Microsoft Defender’s latest patch bypass shows a familiar problem.
A newly disclosed Microsoft Defender flaw called ShieldBreak shows that fixing one attack path doesn’t always close every route to the same result.
Microsoft has assigned ShieldBreak the identifier CVE-2026-69414 and confirmed it is an elevation of privilege (EoP) vulnerability in the Microsoft Malware Protection Engine. Microsoft says it is still working on a security update.
If that sounds somehow familiar, you’re probably thinking of RoguePlanet, another vulnerability in Defender that Microsoft acknowledged on June 16 and patched on July 8.
A short timelineAt the time, the published exploit for RoguePlanet was described as depending on a race condition, meaning it was not guaranteed to work the same way on every machine. That was one reason the vulnerability was concerning but still somewhat limited from a practical point of view.
Microsoft’s July fix should have closed the door on that problem. But security fixes do not always eliminate a weakness at the root of the problem. Sometimes they block one known attack path, while a researcher later finds a different route to reach the same end result.
That appears to be what happened here. ShieldBreak has been described as a patch bypass because it reportedly sidesteps the earlier RoguePlanet fix, although it uses a different exploitation method rather than simply repeating the original attack.
In August, the same researcher disclosed ShieldBreak, and Microsoft responded by publishing a new advisory for CVE-2026-69414.
The advisory says the issue has been publicly disclosed, proof-of-concept (PoC) exploit code exists, exploitation is considered more likely, and no official fix is available yet. Microsoft says it is working on one.
How to stay safeUntil Microsoft releases a fix, the most important protection is preventing untrusted code from running on your computer in the first place. ShieldBreak is a local privilege escalation issue, so an attacker first needs some level of access to the machine.
Based on the best public reporting available right now, ShieldBreak appears to require Microsoft Defender to be enabled in order to work. Public testing indicates that the exploit does not succeed when Defender is off or when another product is registered as the active antivirus provider.
So, narrowly speaking, disabling Defender appears to stop this specific ShieldBreak chain from working. However, that is not a good safety recommendation for most people. Turning off your antivirus removes an important layer of protection and could leave your computer exposed to other attacks.
For home users, all that means:
- Install Microsoft’s security updates as soon as they become available.
- Be very careful with downloads, email attachments, cracked software, and “fix” tools from random websites.
- Keep backups of important files somewhere not directly connected to the PC.
- Use an up-to-date, real-time anti-malware solution to alert you about and remove threats from your computer.
According to CNET. Read their review →
Fake TikTok rewards promise cash you’ll never get
TikTok-branded “rewards” pages are promising users cash for checking in every day, completing small tasks, and earning points. Those points supposedly convert into real money, and the balances look enormous. A countdown timer usually warns that your balance is about to expire. But when you try to withdraw it, there’s always something else you need to do first.
If you just want the short versionTikTok does have a legitimate Creator Rewards Program, but it doesn’t work like the sites we’re talking about here. Creator Rewards is for eligible creators in certain countries who meet specific requirements. They earn rewards for eligible original videos, not for checking in every day or completing tasks on a separate rewards website.
If you find a TikTok-branded site offering large cash rewards for check-ins, referrals, or simple tasks, don’t assume it’s legitimate just because TikTok has its own rewards program.
You can end up chasing a payout that was never coming, handing over personal or banking details, or installing an unwanted app.
How these pages typically workMost versions of this scam are built to look like a mobile shopping or loyalty app. There’s a TikTok logo, a “welcome back” greeting, a daily check-in tracker, and tabs for tasks, referrals, and your profile. At first glance, it can easily look like an official rewards program connected to TikTok.
When you tap through to the “redeem” screen, the numbers can show a cash balance in the thousands, converted from a huge pile of points, along with a countdown warning that your balance is about to expire. The minimum withdrawal is usually low enough to make cashing out look easy.
It isn’t.
Sites like this tend to introduce one more requirement every time you get close to actually withdrawing the cash. Refer more friends, watch more videos, complete a sponsored offer through an affiliate network, or download a separate app to “verify” your identity.
The app download may be the real goal, particularly if the operator gets paid for generating installs. The app could also be adware or other unwanted software.
Big numbers don’t mean real moneyNothing on these pages reflects a real ledger. A balance on the screen doesn’t mean there’s money waiting for you.
On a fake rewards site, the points, cash balance, and countdown can simply be numbers generated by the site itself, with no connection to TikTok’s actual systems.
The operator simply invents a sum that feels too good to walk away from.
So who is making money?These sites tend to make money the same way most ad-funnel scams do: through affiliate and CPA (cost-per-action) programs.
CPA means the site operator can get paid when you do something, such as clicking an ad, signing up for a service, or installing an app. So even if you never receive the promised reward, your clicks, sign-ups, and downloads can still make money for someone else.
Why it’s easy to get pulled inA daily check-in streak creates a small sense of investment. Walking away means giving up your streak and the money you think you’ve already earned.
Then there’s the big balance sitting on the screen and a countdown telling you it’ll disappear if you don’t act soon. Together, they give you plenty of reasons to keep going and very little time to question whether any of it is real.
What to do if you find one- Don’t enter banking details, card numbers, or ID information unless you’ve confirmed you’re using an official TikTok service.
- If you were prompted to download an app outside TikTok itself, don’t install it. If you already have, uninstall it and run a security scan on your device.
- Don’t refer friends or family to keep a streak going or unlock a withdrawal. You’d just be pulling them into the same funnel.
- Check rewards in TikTok itself. TikTok’s Creator Rewards Program is for eligible creators and is managed through TikTok. If a separate website claims you can earn TikTok cash rewards through check-ins or simple tasks, don’t assume it’s part of the same program.
Reward-mill scams like this aren’t unique to TikTok. The same check-in-and-cash-out formula appears with other brand names too. The name may change, but the trick is much the same: Keep you clicking with the promise that your money is just one more task away.
Something feel off? Check it before you click.Malwarebytes Scam Guard helps you analyze suspicious links, texts, and screenshots instantly.
Available with Malwarebytes Premium Security for all your devices, and in the Malwarebytes app for iOS and Android.
Update your Mac: Screen Sharing vulnerability exploited in the wild
The Dutch National Cyber Security Centre (NCSC) issued a warning after being notified of several incidents where a vulnerability in Apple’s Screen Sharing feature was exploited to install Monero cryptominers.
The vulnerability, tracked as CVE-2026-65400, was patched by Apple on August 6. It is an authentication-bypass flaw in macOS Screen Sharing that can let an attacker on the network connect without valid credentials.
macOS’s built-in Screen Sharing service is a remote-control feature commonly associated with port 5900. Successful exploitation can allow a remote attacker on a reachable network to authenticate to the service without legitimate credentials.
Apple said the bug was fixed through “improved state management,” which suggests an authentication-flow or session-state validation failure rather than a cryptographic break.
The patch was issued for macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9. Practical exposure requires Screen Sharing to be enabled, so the highest-risk systems are those where port 5900 is internet-accessible, typically through a router port-forward, public IP assignment, or hosting-provider setup. Hosts reachable only from an internal network are still potentially exposed, but attackers would have to gain a position on that network.
An attacker could view and control the Mac remotely because that is the function Screen Sharing provides. NCSC says active cases involved attackers gaining root access and installing cryptomining software, specifically for Monero mining.
The criminals likely chose Monero mining because it does not depend on heavily specialized, application-specific integrated circuits (ASICs), but can be done with any CPU or GPU.
Cryptomining isn’t necessarily the worst an attacker could do. With a root-level compromise an attacker could enable persistence, data theft, credential and key harvesting, deployment of additional malware, and lateral movement.
How to stay safe Install the updateThe best way to protect your Mac is to install the update.
To update macOS on any supported Mac, use the Software Update feature, which Apple designed to work consistently across all recent versions. Here are the steps:
- Click the Apple menu in the upper-left corner of your screen.
- Choose System Settings (or System Preferences on older versions).
- Select General in the sidebar, then click Software Update on the right. On older macOS, just look for Software Update directly.
- Your Mac will check for updates automatically. If updates are available, click Update Now (or Upgrade Now for major new versions) and follow the on-screen instructions. Before you upgrade to macOS Tahoe 26, please read these instructions.
- Enter your administrator password if prompted, then let your Mac finish the update (it might need to restart during this process).
- Make sure your Mac stays plugged in and connected to the internet until the update is done.
If you can’t update immediately, check whether Screen Sharing is enabled and turn it off if you don’t use it.
- Click the Apple menu in the top-left corner of the screen.
- Select System Settings.
- In the left sidebar, click General.
- Click Sharing on the right; you may need to scroll down.
- Find Screen Sharing:
- If the switch is off/grey, it is disabled.
- If the switch is on/colored, click it to switch it off.
Also check Remote Management on that same Sharing page. It provides another remote-control route and should be off unless the owner knowingly uses it for work or IT support.
Macs need protection too
Malwarebytes Premium Security for Mac stops threats and protects your Mac and personal files from hackers and cybercriminals.
Why Facebook’s war on ad blockers could help scammers
Reports that uBlock Origin is stepping back from the never-ending effort to filter Facebook ads are a reminder that ad blocking is no longer only an argument about inconvenience, publishers, and lost advertising revenue.
It is also an issue of security.
For years, ad blockers have occupied an uncomfortable place in the web economy. Publishers and platforms rely on advertising to fund their services, while users install blockers to escape intrusive banners, autoplay videos, tracking scripts, and feeds that increasingly feel designed around monetization rather than the people using them.
That debate is usually framed as a contest between a platform’s right to make money and a user’s desire for a cleaner browsing experience. But it leaves out an important detail: Ads are not always merely ads.
Malwarebytes General Manager Mark Beare stated:
“While it’s easy to look at ad blockers solely as a way of hurting monetization for these businesses, the other thing that ad blockers are doing is blocking malicious and scam ads.”
Sometimes ads are scams. At other times, they lead to malicious sites. And often, they impersonate trusted brands, promise fictional government payments, promote fake investment opportunities, or send victims into private messaging channels where the fraud continues.
In those cases, an ad blocker is not simply removing something annoying. It’s removing a route into a scam.
The advantage lies with the platformsThe reported decision by uBlock Origin’s team to stop continually chasing changes to Facebook ads highlights a structural advantage held by large platforms.
An ad blocker generally works by identifying requests, scripts, page elements, and patterns associated with advertising or tracking. A platform that controls the entire delivery stack can alter those patterns: It can change element names, move content into new components, serve ads through first-party infrastructure, or make sponsored content look more like ordinary posts.
This creates a familiar cat and mouse game. Filter-list maintainers identify a new method, the platform changes its implementation, users receive an update, and then the cycle starts all over. Again and again.
It’s the difference in resources that matters. A major platform can deploy changes on an enormous scale and has dedicated teams working on its products, advertising systems, and infrastructure. Open-source filter maintainers and independent blocking tools do not have the same staffing, telemetry, or ability to anticipate upcoming changes in how ads are delivered or how the platform will modify its systems.
That does not mean platforms should be expected to design their products around every third-party extension. Nor does it mean every attempt to detect or resist blocking is malicious. Advertising funds a great deal of the online content and services people use every day.
Not every blocked ad is harmlessA platform’s ability to make ads harder to distinguish from ordinary content should come with a corresponding responsibility: Make sure the ads being delivered deserve the trust implied by that integration.
Internal Meta documents reviewed by Reuters showed that the company projected about 10% of its 2024 revenue, or $16 billion, would come from ads for scams and banned goods. Meta said the estimate was “rough and overly-inclusive,” and that the true figure was lower.
That is a clear mismatch with Meta’s advertising rules, which explicitly prohibit deceptive and misleading ads, including schemes intended to scam people. Meta said its ad-review system examines ads before they go live and can re-review them later, but Meta also acknowledges that an ad may begin delivering before it has been reviewed against every policy.
That time gap is important. Scam campaigns are built to exploit speed and scale. Fraudsters can test new creatives, swap landing pages, impersonate a brand or public figure, and adapt when enforcement catches up. Meta disputed Reuters’ characterization of its anti-fraud efforts.
This is not an argument that every ad on Facebook, Instagram, or another large platform is dangerous. Most are not. The problem is that users cannot reliably tell, at a glance, which ad is a legitimate offer and which one is an attempt to steal money, credentials, or personal data.
Better moderation of ads is better for everyoneRather than treating every blocker as a threat to revenue, a more productive response to ad blocking is to make the advertising experience safer, less invasive, and more accountable.
That starts with focusing less on defeating filters and more on preventing harmful ads from being approved or reaching users in the first place.
Some practical priorities include:
- Verify advertisers more consistently, especially in high-risk categories such as financial services, cryptocurrency, health products, job offers, and government-benefit claims.
- Review not only the visible creative, but also the destination page, redirects, tracking behavior, and later changes to the advertiser’s site.
- Detect and act on coordinated impersonation campaigns quickly, rather than treating each fraudulent ad account as an isolated incident.
- Make it easy for users to report ads and give them useful feedback when action has been taken.
- Tackle ads before they can direct people into private messages, where scammers can continue the conversation outside public scrutiny.
- Treat repeat offenders, cloned campaigns, and accounts linked to known fraud infrastructure as a network problem, which is much more effective than moderating them one ad at a time.
- Give users meaningful controls over ad personalization, tracking, and the volume of ads they see.
Meta has policies against scams in place, continues to remove ads that violate those policies, and has announced additional anti-scam measures. Those are necessary steps. The question is whether they are sufficient for an environment where criminals are motivated, well-funded, and able to adapt rapidly.
No ad-review system will catch everything. Criminals will continue to use deception, compromised advertising accounts, and fast-changing infrastructure to get around automated checks.
That is why layered protection matters here as well.
Users should be able to choose tools that reduce tracking, block intrusive advertising, and stop access to known malicious sites. They should also be able to use browser protections, security software, and healthy skepticism when an ad promises easy money, a surprise refund, a miracle product, or a deal that seems too good to be true.
If ad blockers and the platforms that rely on advertising can find ways to work together, allowing security tools to intercept the malicious content their moderation systems miss, we can make the internet safer for everyone.
Stop threats before they can do any harm.
Malwarebytes Browser Guard blocks phishing pages and malicious sites automatically. Free, one click to install. Add it to your browser →
A week in security (August 10 – August 16)
Last week on Malwarebytes Labs:
- Apple now uses iPhone alerts for targets of mercenary spyware
- WhatsApp is testing a new warning for scam messages
- New Android malware lets criminals use your bank card in real time
- Parents take on Meta, TikTok, Google, and Snap in 3,000 youth safety lawsuits
- “Zoomsday” flaws could let one Zoom participant attack another
- Patch Tuesday: Update now to fix 421 flaws, including three zero-days
- Fake CCleaner installs GhostDesk Chrome spyware
- Valve warns Steam hardware buyers: Expect fake delivery scams
- Social media platforms crack down on drone factory recruiting game
- Sexual predators targeting online accounts for intimate images, FBI warns
- Love/hate relationship: The AI affair. Young people love AI, but it’s breaking their trust
- Watch out for fake TikTok Shops trying to steal your money
- Fake popular sites offer a free app, instead take over PCs
- How to fake a data trail (and maybe lower prices) (Lock and Code S07E16)
- New turnkey kit makes it easy for anyone to become a scammer
- Edge is dropping older extensions, affecting popular privacy tools
Stay safe!
From reporting threats to removing them.
Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.
Pages
- « first
- ‹ previous
- 1
- 2
- 3
- 4
