A trusted name on a trusted platform does not guarantee a trustworthy listing. It could still lead to a tech support scammer.
Category: Malwarebytes
Fake Apple Pay charge brings the classic tech support scam to your phone
Built for mobile users, this tech support scam uses a fake Apple Pay alert and browser tricks to pressure victims into calling a scam number.
New Instagram and Facebook rules set a default two-hour limit for teens
Meta will pay up to $17 billion and introduce new protections for US teens to settle a landmark child safety case.
Update Chrome before you browse again
Chrome’s latest update fixes 327 security vulnerabilities, including some that malicious websites could exploit as soon as you visit them.
Popular school apps may be sharing student data with advertisers
A Utah investigation found educational apps collecting unauthorized student data and sharing information with third parties and advertisers.
Beware of fake Indeed interview apps used to install spyware
Scammers are posing as employers on Indeed to trick job seekers into installing fake Android interview apps that deliver malware.
Grok fooled into stealing user chat, location data, and more
Researchers found that prompt injection attacks can hide malicious instructions in encrypted text to get them past AI guardrails.
Encrypted instructions can fool AI assistants like Grok and Gemini
Researchers found that prompt injection attacks can hide malicious instructions in encrypted text to get them past AI guardrails.
GTA 6 leak hunt could expose data belonging to thousands of Discord users
Take-Two is demanding IP addresses, phone numbers, device IDs, and other data as it tries to identify whoever leaked GTA 6 footage.
TikTok phishing: How to spot fake login and verification pages
Scammers use fake TikTok login pages, warnings, and verification offers to trick you into handing over your account details.
Fake GTA 6 Extended Look and demo sites deliver an infostealer
Bogus “Play Now” sites are exploiting the GTA 6 leak hype to spread malware that steals passwords stored in browsers.
What happens to your data when you die? (Lock and Code S07E17)
This week on the Lock and Code podcast, we speak with Tamara Kneese about the many ways your data remains long after your die.
Fake Microsoft security scans trick victims into uninstalling their antivirus
We found fake Microsoft-branded scanners that invent security problems, tell victims to uninstall AV, and then steer them into a refund scam.
Your data doesn’t die when you do (Lock and Code S07E17)
This week on the Lock and Code podcast, we speak with Tamara Kneese about the many ways your data remains long after your die.
AliExpress caught using silent audio to fingerprint visitors’ browsers
Silent audio processing on the AliExpress website was found helping to fingerprint visitors’ browsers without relying on cookies.
ToxicPanda 2.0 can take over your Android phone and banking apps
A new version of the Android banking Trojan can seize control of infected phones and block access to Google Play and Google Play Services.
Tracking PavinLoader across ClickFix and fake download campaigns
We found PavinLoader being used across ClickFix, fake software, and RenPy campaigns to deliver Amatera Stealer and other malware.
A week in security (August 17 – August 23)
A list of topics we covered in the week of August 17 to August 23 of 2026
Zombie Card: An expired Visa credit card can be used for purchases
Scientific research showed that the expiration date on some Visa credit cards can be manipulated in so-called Zombie Card attacks.
Medical records, SSNs, and bank details exposed in CareCloud data breach
Healthcare technology provider CareCloud confirmed that 3.75 million people were affected by a March data breach.
