Malwarebytes
banner
malwarebytes.com
Malwarebytes
@malwarebytes.com
All-in-one cybersecurity that's always by your side
https://www.malwarebytes.com/
RatHat can navigate infected phones while stealing bank logins, authentication codes, and screen-lock PINs.

Because of its persistence, the only way to remove it is a full factory reset of your device.
New Android malware uses AI to steal bank logins and PINs
RatHat can navigate infected phones while stealing bank logins, authentication codes, and screen-lock PINs.
www.malwarebytes.com
September 18, 2026 at 7:38 PM
The Manhattan District Attorney’s Office has seized the domains of 12 deepfake websites that hosted AI-generated videos of over 1,200 individuals.
12 celebrity deepfake websites seized by Manhattan DA
The largest known celebrity deepfake seizure has taken 12 websites offline, disrupting access to videos depicting some 1,200 people.
www.malwarebytes.com
September 17, 2026 at 11:46 AM
‼️Google Pixel users, update now‼️

Google has released an update that fixes 110 vulnerabilities, including one that could give an attacker who already has access to a phone more power than they should have.
Google Pixel owners urged to patch actively exploited modem flaw
Google’s September Pixel update fixes 110 vulnerabilities, including a modem flaw being used in limited, targeted attacks.
www.malwarebytes.com
September 16, 2026 at 12:22 PM
Cybercriminals hijacked HBO Max’s verified Reddit account to distribute ClickFix ads that tricked users into running malicious commands, infecting devices with infostealers and cryptocurrency malware.

HBO Max’s verified Reddit account hijacked to spread malware
Cybercriminals used HBO Max’s verified Reddit account to run 108 malicious ads that tricked people into installing information stealers.
bit.ly
September 15, 2026 at 7:23 PM
A mother says Meta AI pieced together names, birth details, photos, and location information about her young daughters from years of family posts she shared on Meta's platforms.
Meta AI builds detailed profiles of children from years of family posts
A mother says Meta AI pieced together names, birth details, photos, and location information about her young daughters from years of family posts.
bit.ly
September 15, 2026 at 4:17 PM
Scammers copy Bitrefill’s branding on lookalike sites that appear in search results. Victims think they’re buying gift cards, but payments go directly to the scammers’ crypto wallets.
Search results are sending people to fake Bitrefill checkouts
Fake Bitrefill checkout pages are appearing in search results and tricking people into sending cryptocurrency directly to scammers.
www.malwarebytes.com
September 15, 2026 at 11:32 AM
Revolut confirmed it accidentally shared sensitive customer data after being tricked by fake government requests from a legitimate agency domain, but says no systems were breached and funds are safe.
Revolut gave customer IDs and financial data to a government impostor
The digital bank was tricked into releasing sensitive customer information, including IDs, to an attacker using a legitimate government email domain.
bit.ly
September 14, 2026 at 2:31 PM
Email marketing provider Brevo reported that it had contained a security incident in which cybercriminals gained access to 138 accounts and used them to send phishing emails to customers’ contact lists.
Crypto customers targeted by scammers after email marketing provider breach
A breach at email marketing company Brevo exposed Trezor, CoinTracking, and BitBox customers to phishing emails, but others may also be at risk.
bit.ly
September 11, 2026 at 6:22 PM
Researchers found that the Android banking Trojan Gigabud can create a separate work profile and install a cloned banking app inside it. This allows attackers to make fraudulent transactions while potentially hiding their activity from malware detection on the main profile.
Android malware creates a hidden copy of your banking app
The Gigabud banking Trojan can clone a banking app into a separate work profile on an Android device to help hide fraudulent transactions.
bit.ly
September 11, 2026 at 3:16 PM
According to researcher Jacob Coxon, there's low chance AI could kill all humans within the next decade.

AI researchers are increasingly alarmed that competitive pressure is pushing tech companies to race towards self-improving superintelligence, which they warn could spiral out of human control.
Will AI kill us all within the next decade?
AI researchers are warning that the technology could kill us all within the next decade, although they say the risk from current models is low.
www.malwarebytes.com
September 10, 2026 at 6:26 PM
‼️ Chrome users, update now‼️

Chrome issues another monster update, fixing an actively exploited V8 vulnerability and 229 other flaws.
Update Chrome now to protect against an actively exploited vulnerability
Chrome issues another monster update, fixing an actively exploited V8 vulnerability and 229 other flaws.
bit.ly
September 10, 2026 at 2:21 PM
New Instagram scam: criminals are abusing Meta’s copyright-reporting system to suspend accounts, then demanding ransoms via Telegram to “withdraw” fake claims.
Copyright scammers get Instagram accounts suspended and demand payment
Scammers are filing fraudulent copyright complaints to suspend Instagram accounts, then demanding payment to withdraw them.
www.malwarebytes.com
September 10, 2026 at 11:32 AM
The Australian government has taken significant action to prevent algorithms from controlling social media feeds. The proposed "Digital Duty of Care" legislation would allow Australians to disable the algorithmic feeds that platforms automatically provide to users.
The push to stop algorithms controlling social media feeds has begun
Australia is proposing a law that gives people a choice over what fills their feeds. It may not be long before other countries demand the same.
bit.ly
September 9, 2026 at 9:37 AM
Grindr has reportedly agreed to pay £26 million (around $35 million) to settle a UK privacy lawsuit alleging that it shared sensitive user data, including some users’ HIV status, with advertisers.
Grindr settles HIV status data-sharing lawsuit for $35 million
Grindr has settled a UK lawsuit alleging that it shared sensitive user data, including HIV status, with advertising companies.
www.malwarebytes.com
September 8, 2026 at 4:30 PM
Poland’s national cybersecurity response team warns that MikroTik routers—sold globally, including in the US— have vulnerabilities that can allow attackers to seize full control of device
MikroTik router flaws allow takeover without a password
Attackers are exploiting critical RouterOS flaws to take control of routers with SSH exposed to the internet.
www.malwarebytes.com
September 8, 2026 at 1:30 PM
Testing found that LG smart TVs can track viewing and scan home networks, while security flaws could let attackers record conversations.
LG TV flaws could let attackers listen in, even in standby mode
Testing found that LG smart TVs can track viewing and scan home networks, while security flaws could let attackers record conversations.
www.malwarebytes.com
September 7, 2026 at 2:48 PM
Developer Álvaro Martínez Majado investigated several flirty X accounts that promote OnlyFans pages, analyzing their replies to determine whether they were scripted, AI‑generated, or written by humans.
Flirty OnlyFans promoters on X may be using AI to appear human
Personalized replies and voice notes make it increasingly difficult to tell whether you’re talking to a human, chatbot, or AI agent.
www.malwarebytes.com
September 7, 2026 at 11:43 AM
With the wider availability of the X Money payments service, X warns that attackers may target accounts.
X Money rollout linked to password-reset attacks
As X expands into payments, users are receiving password-reset emails they didn’t request. Here’s what may be happening and how to stay safe.
bit.ly
September 4, 2026 at 4:00 PM
🚨 That “free” streaming box might not just be dodgy; it could be routing criminal traffic through your home. Scammers and fraudsters use your internet connection to hide their activity, while you foot the bandwidth and the bill.
Free streaming boxes may be routing criminal traffic through your home
Researchers found that apps available on SuperBox devices could add your household connection to a residential proxy network.
www.malwarebytes.com
September 4, 2026 at 12:51 PM
California’s Digital Age Assurance Act (AB 1043) will require major operating systems to ask users for their age at setup and share an age-bracket signal with app developers, starting Jan 1st 2027 for new setups and by July 1st 2027 for existing devices in California.
Your phone or computer may soon ask how old you are
California and Colorado will require operating systems to collect users’ ages, but open-source software like Linux may be exempt.
bit.ly
September 3, 2026 at 9:59 AM
Tech support scams used to rely mainly on browser locks and fake virus warnings. Now, scammers use many more ways to reach people, including websites and platforms they trust.
Tech support scams look different now. Here’s what to watch for
Tech support scams have evolved beyond fake virus warnings. Here’s how scammers reach their targets now, and how to stay safe.
www.malwarebytes.com
September 3, 2026 at 7:49 AM
‼️Chrome users, update now‼️

Chrome is rolling out an update for its desktop browser. The update includes 26 security fixes, two of which are critical.
Two critical Chrome flaws put users at risk on malicious websites
Update Chrome now: Two critical vulnerabilities could allow a malicious website to run code on your device.
www.malwarebytes.com
September 2, 2026 at 8:39 PM
Lawyers can access your chatbot conversations from AI services like ChatGPT, as these conversations do not have the same privilege as those between you and your lawyer or doctor.
Your AI chats could be used in court
What you tell an AI chatbot could come back to haunt you in court. The Washington Post found chat histories already used in 12 legal cases.
www.malwarebytes.com
September 2, 2026 at 11:35 AM
Anthropic warns that criminals are using infostealer malware to hijack logged-in Claude browser sessions, access victims’ accounts, and deplete their credits.
Infostealers are hijacking Claude accounts at users’ expense
Anthropic has warned that infostealers are stealing Claude session cookies to access users’ accounts and consume usage at their expense.
www.malwarebytes.com
September 1, 2026 at 11:26 AM
American healthcare company McKesson Corporation has disclosed a cybersecurity incident involving unauthorized access to third-party applications and the theft of data.
McKesson confirms cyber incident after ShinyHunters claims patient-data theft
Healthcare company McKesson acknowledged a data breach. ShinyHunters claims to have stolen hundred of millions of records
www.malwarebytes.com
August 31, 2026 at 3:20 PM