A “purchase order” PDF blocked by Malwarebytes led to a credential-harvesting phishing site. So we analyzed the attack and where the data went next. This article has been indexed from Malwarebytes Read the original article: Inside a purchase order PDF…
Category: Malwarebytes
SoundCloud, Pornhub, and 700Credit all reported data breaches, but the similarities end there
We compared three incidents that surfaced today to show why the impact of a breach depends less on who was hit and more on what was taken. This article has been indexed from Malwarebytes Read the original article: SoundCloud, Pornhub,…
Android threats in 2025: When your phone becomes the main attack surface
Android users spent 2025 walking a tighter rope than ever, with malware, data-stealing apps, and SMS-borne scams all climbing sharply. This article has been indexed from Malwarebytes Read the original article: Android threats in 2025: When your phone becomes the…
Photo booth flaw exposes people’s private pictures online
A security researcher says a basic website flaw at a photo booth operator may have exposed hundreds of private customer photos. This article has been indexed from Malwarebytes Read the original article: Photo booth flaw exposes people’s private pictures online
Google is discontinuing its dark web report: why it matters
Google will discontinue its dark web report early next year, prompting mixed reactions. How does dark web monitoring actually help keep you safe? This article has been indexed from Malwarebytes Read the original article: Google is discontinuing its dark web…
Pig butchering is the next “humanitarian global crisis” (Lock and Code S06E25)
This week on the Lock and Code podcast, we speak with Erin West about pig butchering scams and the efforts to stop this new, global crisis. This article has been indexed from Malwarebytes Read the original article: Pig butchering is…
PayPal closes loophole that let scammers send real emails with fake purchase notices
Scammers exploited a PayPal subscriptions feature to send legitimate emails from service@paypal.com, using fake purchase notifications to push tech support scams. This article has been indexed from Malwarebytes Read the original article: PayPal closes loophole that let scammers send real…
A week in security (December 8 – December 14)
A list of topics we covered in the week of December 8 to December 14 of 2025 This article has been indexed from Malwarebytes Read the original article: A week in security (December 8 – December 14)
The US digital doxxing of H-1B applicants is a massive privacy misstep
By making social accounts public, the new policy exposes private data that attackers can use for targeting, impersonation, or extortion. This article has been indexed from Malwarebytes Read the original article: The US digital doxxing of H-1B applicants is a…
Google ads funnel Mac users to poisoned AI chats that spread the AMOS infostealer
Criminals make malicious ChatGPT and Grok conversations appear at the top of common Google searches—leading users straight to the Atomic macOS Stealer. This article has been indexed from Malwarebytes Read the original article: Google ads funnel Mac users to poisoned…
How private is your VPN?
After years of trying VPNs for myself, privacy-minded family members, and a few mission-critical projects, here’s what I wish everyone knew. This article has been indexed from Malwarebytes Read the original article: How private is your VPN?
DroidLock malware locks you out of your Android device and demands ransom
Researchers have found Android malware that holds your files and your device hostage until you pay the ransom. This article has been indexed from Malwarebytes Read the original article: DroidLock malware locks you out of your Android device and demands…
Malwarebytes for Mac now has smarter, deeper scans
Say hello to the upgraded Malwarebytes for Mac, with stronger protection and more control. This article has been indexed from Malwarebytes Read the original article: Malwarebytes for Mac now has smarter, deeper scans
Another Chrome zero-day under attack: update now
If we’re lucky, this update will close out 2025’s run of Chrome zero-days. This one is a V8 type-confusion issue already being exploited in the wild. This article has been indexed from Malwarebytes Read the original article: Another Chrome zero-day…
December Patch Tuesday fixes three zero-days, including one that hijacks Windows devices
The update patches three zero-days and introduces a new PowerShell warning meant to help you avoid accidentally running unsafe code from the web. This article has been indexed from Malwarebytes Read the original article: December Patch Tuesday fixes three zero-days,…
GhostFrame phishing kit fuels widespread attacks against millions
GhostFrame uses dynamic subdomains and hidden iframes to help attackers slip past basic security tools. This article has been indexed from Malwarebytes Read the original article: GhostFrame phishing kit fuels widespread attacks against millions
Prompt injection is a problem that may never be fixed, warns NCSC
The NCSC warns that prompt injection is unlikely to be mitigated in the same way SQL injection was. How do they compare? This article has been indexed from Malwarebytes Read the original article: Prompt injection is a problem that may…
EU fines X $140m, tied to verification rules that make impostor scams easier
The core problem persists: anyone can still buy a ‘verified’ checkmark from X, so don’t take their authenticity for granted. This article has been indexed from Malwarebytes Read the original article: EU fines X $140m, tied to verification rules that…
Deepfakes, AI resumes, and the growing threat of fake applicants
Attackers are blending automation, impersonation, and social engineering to get inside organizations. Here’s how to spot the signs. This article has been indexed from Malwarebytes Read the original article: Deepfakes, AI resumes, and the growing threat of fake applicants
How phishers hide banking scams behind free Cloudflare Pages
We found a campaign that hosts fake login pages on Cloudflare Pages and sends the stolen info straight to Telegram. This article has been indexed from Malwarebytes Read the original article: How phishers hide banking scams behind free Cloudflare Pages