Malware Bytes Security

Subscribe to Malware Bytes Security feed
Cyber Security Software & Anti-Malware
Updated: 1 hour 15 min ago

6.9 million driver’s license numbers stolen from AssuranceAmerica

Thu, 07/09/2026 - 11:06am

Insurance provider AssuranceAmerica has confirmed a data breach affecting the personal information and driver’s license numbers of up to 6.9 million people.

AssuranceAmerica provides car and rental insurance to customers across 14 US states through a network of over 9,500 independent agents.

TechCrunch reports:
“AssuranceAmerica said it discovered hackers in its computer systems on March 17. The company concluded its investigation on June 15, finding that the hackers had stolen customers’ names, contact information, and driver’s license numbers.“

The breach notice letter also mentions information about customers’ auto insurance policies and accounts, their drivers and vehicles, and details about customer claims. 

AssuranceAmerica has not yet released a public statement about the data breach. However, public breach notices and independent reporting indicate that the incident began with a targeted phishing attack against a single employee. An unauthorized third party accessed parts of the insurer’s IT systems and copied files containing customer policy information and driver’s license numbers. So far, no law‑enforcement or vendor report has publicly linked this activity to a specific threat group, ransomware operation, or nation‑state actor.

No public source has reported a ransom demand, negotiations, or payment, and AssuranceAmerica’s public filings are quiet about any contact with the attackers.

Protecting yourself after a data breach

There are some actions you can take if you are, or suspect you may have been, the victim of a data breach.

  • Check the vendor’s advice. Every breach is different, so check with the vendor to find out what’s happened and follow any specific advice they offer.
  • Change your password. You can make a stolen password useless to thieves by changing it. Choose a strong password that you don’t use for anything else. Better yet, let a password manager choose and store one for you.
  • Enable two-factor authentication (2FA). If you can, use a FIDO2-compliant hardware key, laptop, or phone as your second factor. Some forms of 2FA can be phished just as easily as a password. 2FA that relies on a FIDO2 device can’t be phished.
  • Watch out for impersonation scams. Criminals may contact you pretending to be the company. Check the company’s website to see how it is contacting affected customers, and verify anyone who contacts you using a different communication channel.
  • Take your time. Phishing attacks often impersonate people or brands you know, and create a false sense of urgency with messages about missed deliveries, suspended accounts, or security alerts.
  • Consider not storing your card details. It’s definitely more convenient to get sites to remember your card details for you, but we highly recommend not storing that information on websites.
  • Set up identity monitoring. Identity monitoring alerts you if your personal information is found being traded illegally online and helps you recover if your identity is stolen.
Check your personal data exposure

You can check whether any of your personal information has been exposed using our Digital Footprint portal. Enter the email address you use most often and we’ll generate a free Digital Footprint report.

Scan Please enter a valid email address

Categories: Malware Bytes

Microsoft fixes RoguePlanet zero-day in Defender

Thu, 07/09/2026 - 7:38am

Microsoft issued a security update that fixes the zero-day vulnerability known as RoguePlanet in Microsoft Defender.

RoguePlanet is tracked as CVE-2026-50656, a Microsoft Defender elevation of privilege (EoP) vulnerability. As we reported last month, if successfully exploited, RoguePlanet can allow an attacker to elevate privileges from a standard user account to NT AUTHORITY\SYSTEM, the highest privilege level on Windows.

This means an attacker who gains access to a standard user account on your computer could use the vulnerability to take complete control of the system. They don’t need advanced hacking skills or administrator permissions to do this.

Microsoft fixed the vulnerability by releasing Microsoft Malware Protection Engine version 1.1.26060.3008, an update to the core scanning engine that powers Microsoft Defender and other Microsoft security products.

How to protect your system

If Windows Security shows that another antivirus, such as Malwarebytes, is protecting your PC and Microsoft Defender Antivirus is turned off (as shown below), this particular vulnerability does not affect your system. Defender’s scanning engine isn’t running, so it can’t be exploited through this flaw.

If you’re running another antivirus and Defender is turned off, there’s nothing to worry about Most users are already protected

By default, Microsoft Defender automatically updates both its malware definitions and the Microsoft Malware Protection Engine.

But if you’re in any doubt, you can check the version of the Malware Protection Engine on your system. Here’s how:

  1. Click the Start button, type Security, and choose Windows Security from the results.
  2. Select Virus & threat protection, then under Virus & threat protection updates, click Check for updates.
  3. Click Settings (the cog icon) then select About.
  4. Look for a line called Engine Version. That number is the version of the Malware Protection Engine used by Microsoft Defender.
    • If your Engine Version is 1.1.26060.3008 or higher, your system has the patched (or newer) engine.
    • If your Engine Version is 1.1.26050.11 or lower, your system is still running a vulnerable engine. Run Windows Update and check for Defender updates again, or wait for the automatic update to complete.

Note: Version numbers are compared from left to right. For example, 1.1.26060.3008 is newer than 1.1.26050.11 because 26060 is higher than 26050.

If you use Windows Defender, leave automatic updates turned on. The Malware Protection Engine normally updates automatically, so most home users will receive the fix without doing anything. These steps are simply a way to double-check your system has the updated engine.

We don’t just report on threats—we remove them

Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.

Categories: Malware Bytes

Turn off this Meta setting before someone generates AI images of you

Thu, 07/09/2026 - 5:30am

Every consumer app has a settings menu that lets you make decisions about things like notifications or dark mode. Meta has just decided that anyone can generate AI images of you from your public Instagram account by typing your Instagram handle into a prompt.

On July 7, Meta launched its AI image generation model, Muse Image. It integrates with public Instagram accounts. Now, all someone has to do is tag your account in a prompt, and they can use Meta AI to generate an image using your likeness. According to Meta’s own policy, you won’t be notified if someone does this, making it difficult to know when or how your likeness has been used.

Meta says Muse Image is meant to make AI image generation more personal by letting people reference public Instagram accounts in their prompts. That may sound fun when you’re creating images of yourself. It’s less appealing when anyone else can do the same with your account.

Meta lets you opt out, although finding the setting is its own adventure. On Instagram, go to Settings and activity > Sharing and reuse, then turn off the setting that allows others to create AI images featuring you. Depending on your app version, the wording may vary, and the feature is still rolling out, starting in the US, so you may not see the setting yet.

You’d hope that Meta would tell you up front with a big, bold “Turn this off if you don’t want it” message when you open Instagram, but no such luck. You’d also hope that the company would retroactively remove any images that someone made of you before you opted out, but that’s not happening either.

Opting out only prevents future image generation. Any AI images that someone created before you switched the setting off still remain in circulation.

The only mechanism that comes close to comprehensive protection is switching your account to private.

What’s the risk?

There are privacy and security implications here. Anyone can now generate AI images based on your public Instagram profile without your knowledge, and Meta won’t notify you when it happens. Public Instagram photos were already being harvested by attackers to create deepfakes for identity verification fraud. Giving people an official way to generate AI images based on public profiles lowers the barrier to creating synthetic images that could be used for impersonation, scams, or other abuse.

Cybercriminals are already combining generative AI with automated tools to scale phishing and fraud. Muse Image makes it even easier to generate convincing images based on public identities.

Meta’s AI has introduced other security issues, too. Earlier this year, researchers disclosed a “confused deputy” flaw in Meta’s AI support chatbot that let it make account changes—including changing email addresses and resetting passwords—without adequately verifying who it was talking to. Enabling multi-factor authentication (MFA) appeared to mitigate that issue.

Meta also uses an opt-out approach when training its AI on European user data. The company relies on GDPR’s “legitimate interests” legal basis to process European users’ data for AI purposes, a position that privacy group NOYB has challenged.

Protect yourself
  • If your Instagram is public, open Settings and activity > Sharing and reuse and turn off the AI-generation toggle now. Remember, it only stops future image generation.
  • Turn on MFA for all your Meta accounts. It’s one of the simplest ways to protect your account if your password is compromised.
  • If you want the strongest protection Meta currently offers, switch your Instagram account to private. It’s a blunt solution, but it prevents strangers from using your public profile as source material.

Meta’s own Oversight Board has already said the company needs stronger detection tools and better labeling of AI-generated content. When Meta’s own governance body says the defenses aren’t enough, consumers should take notice.

Scammers don’t need to hack you. They just need you to click once. 

Malwarebytes Identity Theft Protection catches suspicious activity before it becomes a problem.

Categories: Malware Bytes

Pages