Search/tiktok
Vendor

tiktok

Known CVEs
0
Highest CVSS
In KEV
0
Vendor
tiktok
Connections
109 relationships
Fake TikTok rewards promise cash you’ll never get
TikTok-branded “rewards” pages are promising users cash for checking in every day, completing small tasks, and earning points. Those points supposedly convert into real money, and the balances look enormous. A countdown timer usually warns that your balance is about to expire. But when you try to withdraw it, there’s always something else you need to do first. If you just want the short version TikTok does have a legitimate Creator Rewards Program, but it doesn’t work like the sites we’re talking about here. Creator Rewards is for eligible creators in certain countries who meet specific requirements. They earn rewards for eligible original videos, not for checking in every day or completing tasks on a separate rewards website. If you find a TikTok-branded site offering large cash rewards for check-ins, referrals, or simple tasks, don’t assume it’s legitimate just because TikTok has its own rewards program. You can end up chasing a payout that was never coming, handing over personal or banking details, or installing an unwanted app. Fake TikTok rewards sites Fake TikTok rewards sites Fake TikTok rewards sites Fake TikTok rewards sites Fake TikTok rewards sites How these pages typically work Most versions of this scam are built to look like a mobile shopping or loyalty app. There’s a TikTok logo, a “welcome back” greeting, a daily check-in tracker, and tabs for tasks, referrals, and your profile. At first glance, it can easily look like an official rewards program connected to TikTok. When you tap through to the “redeem” screen, the numbers can show a cash balance in the thousands, converted from a huge pile of points, along with a countdown warning that your balance is about to expire. The minimum withdrawal is usually low enough to make cashing out look easy. It isn’t. Sites like this tend to introduce one more requirement every time you get close to actually withdrawing the cash. Refer more friends, watch more videos, complete a sponsored offer through an affiliate network, or download a separate app to “verify” your identity. The app download may be the real goal, particularly if the operator gets paid for generating installs. The app could also be adware or other unwanted software. Big numbers don’t mean real money Nothing on these pages reflects a real ledger. A balance on the screen doesn’t mean there’s money waiting for you. On a fake rewards site, the points, cash balance, and countdown can simply be numbers generated by the site itself, with no connection to TikTok’s actual systems. The operator simply invents a sum that feels too good to walk away from. So who is making money? These sites tend to make money the same way most ad-funnel scams do: through affiliate and CPA (cost-per-action) programs. CPA means the site operator can get paid when you do something, such as clicking an ad, signing up for a service, or installing an app. So even if you never receive the promised reward, your clicks, sign-ups, and downloads can still make money for someone else. Why it’s easy to get pulled in A daily check-in streak creates a small sense of investment. Walking away means giving up your streak and the money you think you’ve already earned. Then there’s the big balance sitting on the screen and a countdown telling you it’ll disappear if you don’t act soon. Together, they give you plenty of reasons to keep going and very little time to question whether any of it is real. What to do if you find one Don’t enter banking details, card numbers, or ID information unless you’ve confirmed you’re using an official TikTok service. If you were prompted to download an app outside TikTok itself, don’t install it. If you already have, uninstall it and run a security scan on your device. Don’t refer friends or family to keep a streak going or unlock a withdrawal. You’d just be pulling them into the same funnel. Check rewards in TikTok itself. TikTok’s Creator Rewards Program is for eligible creators and is managed through TikTok. If a separate website claims you can earn TikTok cash rewards through check-ins or simple tasks, don’t assume it’s part of the same program. Reward-mill scams like this aren’t unique to TikTok. The same check-in-and-cash-out formula appears with other brand names too. The name may change, but the trick is much the same: Keep you clicking with the promise that your money is just one more task away. Something feel off? Check it before you click.    Malwarebytes Scam Guard  helps you analyze suspicious links, texts, and screenshots instantly.   Available with  Malwarebytes Premium Security  for all your devices, and in the  Malwarebytes app for iOS and Android .   Try it free →  
malwarebytes.comAug 17, 2026extracted
Parents take on Meta, TikTok, Google, and Snap in 3,000 youth safety lawsuits
A group of big tech firms is fighting to stop roughly 3,000 youth safety lawsuits from moving forward, and they just lost a critical procedural battle in court. The lawsuits, brought by attorneys general and families, allege that Meta, Google, ByteDance’s TikTok, and Snap knew their products were addictive to children and teens and harmful to their mental health, but continued marketing them to young users for profit. The tech companies tried to appeal against a federal court ruling that allowed those involved to file their lawsuits in court. They argued in the 9th US Circuit Court of Appeals that a linchpin US law meant they couldn’t be sued. That law is Section 230 of the Communications Decency Act, created 30 years ago. It says that platforms cannot be held responsible for things that their users post online. For years, social media companies treated it like a bulletproof vest. When users posted something bad, the company running it could claim it was the messenger, not the author. That defense doesn’t seem to be working here. On August 10, the court ruled that Section 230 “provides a defense to liability, not immunity from lawsuits, so the appeal was premature.” This case revolves not so much around what people posted online as how the tech companies allegedly engineered their platforms to present that content to users. The Nebraska Law Review explains several of the techniques the lawsuits say make these platforms more engaging, and potentially more addictive. The article explains how certain interactions on these platforms can trigger dopamine release. Those interactions could be as simple as someone responding to your message or liking one of your photos. Dopamine plays an important role in the brain’s reward system. The NLR article describes techniques such as making those rewards unpredictable, which encourages people to keep checking their accounts habitually. Interface features like the infinite scroll are also designed to keep you on the dopamine train. The paper cites the inventor of that particular idea, who describes it as: “taking [behavioral] cocaine and just sprinkling it all over your interface.” Anyone who’s spent too long in bed doomscrolling can relate. The 9th Circuit’s denial of the appeal is procedurally narrow but strategically enormous. Section 230 is a defense you argue at trial, not a wall that keeps plaintiffs off the courthouse steps. The Third Circuit has gone further, ruling that Section 230 “does not provide immunity to platforms if they face tort lawsuits over injury caused by the algorithms they design.” The algorithm, in other words, is the product. The product can be defective. Behind those cases sits a growing pile of discovery material that plaintiffs argue sheds light on how the platforms approached user engagement, and a New Mexico judgment against Meta earlier this month in a case exploring similar complaints. That judgment now totals $942 million because the judge added $567 million onto the original amount, finding Meta had: “created a public nuisance through its platform design.” What discovery keeps dragging out Discovery in these cases has already been unkind to Meta. A 2016 email attributed to Mark Zuckerberg said that alerting parents to teens’ live videos would “probably ruin the product from the start”. A recent court filing alleged that staff at social media giants have compared their own platforms to drugs, with one Meta employee writing that: “we’re basically pushers.” Snap looks no better. By late 2022, Snap employees were fielding roughly 10,000 sextortion reports per month, according to a filing in the New Mexico case. An internal investigation concluded that 70% of victims never reported abuse because “they knew no action would be taken by Snap; indeed, of the 30% that did report, none were addressed.” That number surfaced through New Mexico’s unredacted complaint, not through any Snap disclosure. Safety features that don’t work If executives knew, the fixes should have followed. Mostly they didn’t. Researchers at NYU and Northeastern University tested 86 youth safety features and found 51 failed their tests. Snapchat’s failure rate was 73%, Instagram’s 66%, YouTube’s 55% and TikTok’s 50%. Nine features couldn’t even be triggered when the researchers tried. The researchers reported that every cyberbullying safeguard they tested failed. The bypasses were quick to find. Type “eating disorder” into Instagram search and autocomplete politely offers the deliberate misspellings that pro-eating-disorder communities use to duck the platform’s own blocklist. Safety, in that instance, was doing the opposite of safety. What parents can do now Don’t assume in-app safety features work exactly as advertised. If your child uses social media, test the settings yourself and confirm they’re doing what you expect. Set up a test account and check that each setting blocks what it claims to block. And think about the amount of social media time you want to grant your children, or whether you want to let them use it at all. Either way, it begins with an honest family conversation. If your child is being harassed by people they know online, encourage them to tell you immediately. Save evidence, block and report the accounts where appropriate, and don’t hesitate to involve the school or law enforcement if the harassment includes threats, blackmail, or sexual exploitation. You can also report sextortion to the National Center for Missing and Exploited Children’s CyberTipline directly, rather than trusting a platform’s own reporting queue. Check back here for more details on the federal case. The next several months will decide whether the biggest platforms in history get rewritten by juries, or whether they settle their way out one confidential check at a time. From reporting threats to removing them. Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.
malwarebytes.comAug 13, 2026extracted
Love/hate relationship: The AI affair. Young people love AI, but it’s breaking their trust
Young people use AI for everything. From schoolwork to interview prep, relationship advice to shopping decisions, the technology has become part of how young people live. For the most digitally fluent generation ever, AI is a competitive edge, a creative partner, and an always-on assistant. But the same technology making young people’s lives easier is also making the internet harder to navigate. AI is making scams more convincing, identities easier to manipulate, and online content harder to trust. Seven in ten (70%) 18-to-22-year-olds have experienced an AI-related scam in the last year, compared to half of the general population. And nearly every young person worries AI will be used against them. This isn’t happening because young people are reckless. It’s happening because the online platforms they rely on for everyday life now double as entry points for AI threats: social feeds where manipulated content and real content sit side by side, online marketplaces filled with fake storefronts and reviews, messaging channels where threats can be personalized, and AI tools that can make false information feel like the truth. That creates a new kind of safety burden. Young people are being asked to use AI, judge its output, protect their identities, and avoid increasingly personalized scams all at once. The result is a digital life that feels more powerful, but also more vulnerable to abuse. The internet is getting harder for young people to trust The internet young people grew up with isn’t the same one they’re facing today. AI has changed the landscape, making it harder for even these digital natives to know what information is credible and safe. Half of 18-to-22-year-olds strongly agree that it’s becoming harder to tell what content is genuinely human or real. Young people have had a front row seat to how AI can bend the truth. Nearly half have seen AI provide information they knew or later found out was wrong or misleading (44% versus 30% of the general population). Nearly one in four (23%) have suffered negative consequences because of AI advice, compared with 16% of the general population, and 18% say they have suffered emotionally from AI advice, compared with 12% of the general population. For a generation using AI in every corner of their lives, bad information can have lasting effects on their credibility, reputation, and relationships. Many young people have changed how they engage online as a result: 47% of young people say AI has changed how much they trust reviews or content, compared with 37% of the general population 35% say AI has changed how they shop online, compared with 26% 32% say AI has changed how they present themselves professionally, compared with 20% 19% say AI has changed how they date or communicate romantically, compared with 10% As one young person said about online dating: “Dating isn’t an option for me online anymore. You just never know what is or isn’t AI, and I don’t want to spend a lot of time on someone fake.” AI is making it easier for scams to reach young people The harder it becomes to tell what is real, the easier it becomes for scams to work. For young people, AI is fueling a wave of scams that are more personal and invasive than ever before. Nearly one in four young people have been a victim of an extortion scam of some kind (24% versus 17% of the general population). Nearly one in five have been a victim of a deepfake or virtual kidnapping scam (19% versus 8%). Nearly one in ten have been a victim of sextortion (8% versus 7%). More than one in ten have been a victim of an impersonation scam (14% versus 10%). More than one in ten have been a victim of a romance scam (12% versus 10%). What’s striking isn’t just how many young people have been victimized—it’s how many have been targeted: More than half have been the target of an extortion scam (56% versus 42% of the general population). 47% have encountered an impersonation scam (versus 35%) 46% have encountered a romance scam (versus 33%). More than four in ten have been targeted by a deepfake or virtual kidnapping scam (43% versus 26%). Nearly four in ten have encountered sextortion (38% versus 24%). These scams may look different on the surface, but they all work the same way: they exploit fear, trust, shame, and intimacy. The more often young people encounter them, the more chances scammers have to find exactly which emotional triggers work. This exposure isn’t random. Young people are on social platforms at rates up to three times those of the general population: 89% use Instagram (versus 55% of the general population), 78% use TikTok (versus 38%), 68% use Snapchat (versus 26%), and 49% use Pinterest (versus 25%). Scammers can use these platforms to get everything they need to make their threats more convincing: public photos, friend networks, school affiliations, relationship clues, and everyday posts containing personal information. With AI, scammers can use that content to create explicit images, clone voices, impersonate profiles, and create threats personalized with details that are hard to ignore. One young person shared their experience: “I had someone make fake nudes of me using AI on my photos from my social media and threaten to post them on Facebook after I realized that they had scammed me. I decided to be more careful with my personal information.” Young people fear AI will steal what money cannot replace: identity, reputation, and sense of self AI-fueled scams aren’t just scams in the traditional sense. They are forms of identity abuse. This is different from traditional identity theft. For young people, the risk isn’t only that someone steals a password or money. It’s that scammers can use AI to make them appear to say, do, or share something they never did, with consequences that can follow them in their personal and professional lives. That’s why young people are so concerned about AI being used against them. The fears that hit hardest: 88% worry about AI being used to harm their professional or personal reputation versus 77% of the general population 82% worry about someone creating a fake profile pretending to be them versus 76% 81% worry about someone creating fake nude or sexually explicit photos or videos of them versus 62%; 15% say it’s happened to them already (versus 10%) 80% worry about being deceived by someone using AI to fake their identity in an online relationship versus 67% These threats are especially powerful at a life stage where young people are still building their personal and professional reputations. A fake profile, manipulated image, or AI-generated explicit video can affect how everyone from classmates and professors to potential employers and romantic partners see them for years to come. Young people are pulling back online, but protection is still too manual Many young people are responding by retreating. 80% are sharing or posting less online than they were a year ago, versus 61% of the general population. Compared to the general population, more 18–22-year-olds have also taken AI-related protective measures like tightening privacy settings, removing unknown followers, using reverse image search to verify content, requesting data removal, and watermarking their own photos and videos. Those actions matter, but they also show how much responsibility has been pushed onto individuals. Staying safer online now means constantly reviewing settings, checking sources, questioning content, and so much more. That’s a lot to ask of anyone, and the fatigue is showing: 42% of young people say they receive so many warnings they have stopped paying attention, compared with 36% of the general population. It’s hard to sustain vigilance when new risks are always emerging. At the same time, completely opting out isn’t realistic. Young people remain deeply embedded in digital life, and they’re still some of AI’s most enthusiastic adopters: 74% say AI has had a positive impact on their lives, compared with 57% of the general population. They aren’t rejecting AI or the internet, but they are carrying more of the safety burden than they should have to. What young people can do to help decrease their risk right now Know the scams targeting you. Extortion, sextortion, deepfakes, and romance scams disproportionately target young people. If someone contacts you with threats of any kind, do not pay. Report it to the platform and to authorities. Button up your social media. Everything you post publicly is available to anyone, including scammers. Tighten privacy settings on the platforms you use most and review your followers regularly. Don’t trust product images alone. Before buying from an unfamiliar retailer, use reverse image search on product photos and look for independent reviews off the retailer’s own site. Create a family code word. Make sure you agree on this word in person, not online. If you receive a panicked call from someone you know asking for money or information, verify they are who they say they are with the code word. Don’t reuse passwords. If one password gets stolen in a data breach, it will likely get tried on all other accounts you might have. Use a different password for every account to keep your accounts locked down. Turn on two-factor authentication on all your important accounts. Only 30% of young people have done this. It is one of the highest-impact protections available and takes under five minutes to set up. Protect your devices. Use security software on all your devices, and keep all your software up to date to make sure you’re patched against all known security holes. Malwarebytes Student Protection Program If you’re a student or work at a university, Malwarebytes Student Protection Program provides two years of free Premium Security for three devices for all US college or university students, staff and faculty. This includes Malwarebytes device protection for laptops, tablets, and mobile phones with built-in scam protection. It protects against creepy trackers and ads, and blocks malware, ransomware, and cybercriminals themselves. Sign up at malwarebytes.com/student. About the research The research in this article is based on a March 2026 survey about AI, identity, and the collapse of digital trust and was conducted among 1,500 respondents in the United States, United Kingdom, Germany, Austria, and Switzerland. This article focuses on student-aged adults, defined as respondents ages 18 to 22, compared with the general population. Additional context comes from Malwarebytes’ 2025 research Tap, Swipe, Scam: How Everyday Mobile Habits Carry Real Risk, which looked at mobile scams and scam-related behaviors across the same markets. Both research studies were prepared by an independent research consultant and distributed via Forsta.
malwarebytes.comAug 11, 2026extracted
Watch out for fake TikTok Shops trying to steal your money
TikTok Shop is a real, functioning e-commerce feature built into the TikTok app, allowing users to buy goods without ever leaving TikTok. As it’s grown in popularity, scammers have begun cloning its appearance.Storefronts that reproduce its look, its trust badges, and its category layout closely enough to pass a quick glance are showing up as entirely separate, unverified websites. The short version If a shopping site looks like TikTok Shop but you didn’t reach it from inside the actual TikTok app, treat it as an unknown third-party store, not an extension of TikTok. It might look like TikTok, but it’s the same risks as any sketchy online shop: paying for something that never arrives, or handing over card details to a site with no accountability behind it. Fake TikTok Shops Clone sites in this category tend to reproduce TikTok Shop’s homepage design closely enough that, at a glance, they could pass for the real thing. They have matching color schemes, matching layout, and language borrowed directly from the platform, such as “curated products,” “trusted sellers,” and “secure service.” Underneath, they typically show the same kind of reassurance badges the real platform uses: claims of platform-verified sellers, local delivery guarantees, and after-sales support windows. None of that trust signaling is backed by anything. It’s copied language and copied visual design sitting on top of a site with no verified relationship to TikTok at all. Scammers borrow the legitimacy that TikTok Shop has built up, then use it to move products—or simply take payment—through a storefront TikTok has no oversight of. Wholesale stores and fake loan offers A related version of this scam leans into bulk or wholesale pricing, offering goods across categories like fashion, home, and beauty, again wrapped in TikTok’s name and logo. Some of these sites go a step further and add a consumer credit or “loan service” option directly into the site navigation, sitting alongside ordinary shopping categories. A legitimate wholesale marketplace doesn’t typically need to offer consumer credit as a checkout feature. When it does, it’s worth treating as a separate red flag from the shopping itself. Loan applications typically ask for far more sensitive information than a purchase does, including identity documents, banking details, and other personal data. Handing that information to a site that’s already impersonating a major platform significantly increases the risk of fraud or identity theft. The checkout is the real risk Both scams point to the same underlying concern: it’s not really about whether the products are real. It’s about what happens when you enter payment information into a storefront with a fake identity and no accountability. The order may never arrive, leaving you out of pocket, and your payment details themselves could be stolen, reused, or resold. How to stay safe Only use TikTok Shop from inside the official TikTok app, not a link from an ad, DM, or search result. Always check a website’s address before entering any payment information. A convincing homepage doesn’t mean a legitimate business sits behind it. Be skeptical of any shopping site that also pushes a loan, credit line, or financing offer at checkout. Pay with a credit card rather than a bank transfer where possible. It gives you a dispute path if the order never shows up. Brand impersonation is one of the oldest tricks in e-commerce fraud. TikTok Shop’s badge system and trust language are simply the latest assets being borrowed. Stop threats before they can do any harm. Malwarebytes Browser Guard blocks phishing pages and malicious sites automatically. Free, one click to install. Add it to your browser →
malwarebytes.comAug 11, 2026extracted
“Adult TikTok” searches lead to scams
Search for certain combinations of “TikTok” and adult content, and sooner or later you’ll land on a page promising exactly what you searched for: an endless feed of explicit clips, no signup required, just tap and watch. There isn’t one. On the other side of that click is an ad funnel dressed up as exclusive content. These pages aren’t connected to TikTok itself. They simply exploit the platform’s name to attract search traffic. TikTok’s huge user base, and the number of people searching for adult content associated with the platform, make it an attractive lure both for advertisers and scammers. What you need to know right away Nothing on these pages is genuine content pulled from TikTok. Their entire business model is get you to click, sign up, or install something. The operators don’t need to host any videos to make money. The promise of exclusive content is enough to generate clicks, signups, and downloads. Although you’re probably not going to lose your life savings here, you could well end up on a spam list, installing an unwanted app, or paying for an “age verification” that doesn’t verify anything. A pitch built around your search These pages are designed to match exactly what you searched for. Many are built to rank for popular search terms in Google and other search engines, rather than relying on visitors coming from TikTok itself. They often acknowledge the frustrating hunt for working links before presenting themselves as the solution. Below that, you’ll usually find a deliberately blurred video thumbnail, reassuring labels like “18+ only” and “HD clips,” and one or two buttons inviting you to Start watching or Sign up for free. Mirroring the visitor’s own search behavior back at them is a common tactic in this category of ad-lure page. It’s designed to make the offer feel more relevant rather than generic. What happens after you click varies from site to site, but you rarely get the content you were promised. Instead, you’re likely to be redirected through advertising networks, asked to hand over an email address or payment card for “age verification,” or prompted to install an app from outside the official app stores. Each click or redirect can earn the site operator money through advertising or affiliate commissions, even if you never sign up or download anything. Every step of the journey has value: A click can generate advertising revenue, a signup can earn an affiliate commission, and an email address can be sold or added to marketing lists. A payment card entered for “age verification” can lead to recurring subscription charges. Whether you ever see a video is irrelevant because the site has already achieved its goal. Legitimate websites don’t normally need your payment card to prove you’re over 18. Fake “age verification” pages often use the process to collect card details, sign people up for recurring subscriptions, or both. There’s no content, but there is a funnel The blurred thumbnail is the entire “product.” It’s designed to look like a legitimate preview, suggesting there’s something just behind the next click, even though there usually isn’t. The site makes money from the clicks, signups, and downloads, not from any videos. Depending on the page, the operator makes money in several ways: Affiliate commissions. You click through to a dating site, adult subscription, VPN, app, or other offer. If you sign up, the site owner gets paid. Advertising revenue. Every redirect, pop-up, or ad impression earns money. Lead generation. Your email address is collected and sold or used for spam and phishing. Subscription traps. “Age verification” asks for a payment card, then quietly enrolls you in a recurring subscription. Potential malware. Some pages push unwanted software or even malware outside official app stores. Why this lure works Adult content lures carry a built-in advantage most scams don’t have: embarrassment. People are less likely to mention it to a friend, ask for a second opinion, or report it, which means fewer eyes catch the scam before it spreads further. What to do Close the tab. There isn’t any exclusive TikTok content waiting behind Start watching. Don’t enter your email address, payment card, or date of birth to verify access. It isn’t verifying anything, it’s collecting data. Don’t install anything you were prompted to download from a page like this. If you’ve already entered information, treat it as exposed. Watch for follow-up spam or phishing emails, and change any passwords you may have reused. Adult-content lures are one of the oldest tricks in malvertising. Using TikTok’s name just makes them feel more relevant to today’s searches. Something feel off? Check it before you click. Malwarebytes Scam Guard helps you analyze suspicious links, texts, and screenshots instantly. Available with Malwarebytes Premium Security for all your devices, and in the Malwarebytes app for iOS and Android.
malwarebytes.comAug 3, 2026extracted
Buying TikTok followers can expose users to scams and account theft
Buying TikTok followers can expose users to scams and account theft Buying TikTok followers, likes, or views could do more than inflate engagement metrics. According to Malwarebytes, many services selling social media growth operate through deceptive practices that can expose customers to scams, stolen accounts, and financial loss. The market for artificial social media engagement also creates security risks for both buyers and other platform users. Behind the promises of instant engagement Websites selling bulk engagement present themselves as legitimate marketing companies, offering likes, comments, followers, or the ability to message large numbers of accounts in a short period. Many advertise identical packages for TikTok, YouTube, Instagram, and other platforms. Engagement is typically generated through bots, click farms, or hijacked TikTok accounts, despite many of these sites claiming otherwise. “Even if your engagement numbers increase initially, TikTok’s fraud detection systems can remove artificial engagement, and accounts that repeatedly use these services risk being flagged or restricted,” Stefan Dasic, Senior Malware Research Engineer at Malwarebytes, explained. Some providers ask customers to supply more than a TikTok username. They request account credentials or encourage users to authorize third-party access in exchange for followers or views. Providing that information gives the provider access to the account and creates an opportunity for misuse if the service is fraudulent or its systems are compromised. Buy Tiktok Ads Accounts (Source: Malwarebytes) Many of these websites also sell TikTok Ads accounts advertised as established and trusted. Sellers claim buyers can begin running advertising campaigns immediately without creating a new account or completing TikTok’s verification process. Many also promise a replacement account if the original is suspended or stops working. Buyers have no way of verifying how these accounts were obtained. They may have been created using stolen identities, fake personal information, compromised payment cards, or other fraudulent methods. If TikTok identifies an account as suspicious, it may suspend it along with any active advertising campaigns. A replacement account does not restore lost campaigns, advertising spend, or business continuity. Offers that collect more than payments Some websites promote guides or services that claim to help users earn money on TikTok. Their landing pages typically advertise a proven strategy for growing an account or increasing sales, often supported by success stories that cannot be independently verified. Before revealing what they are selling, these sites usually ask visitors to provide an email address or phone number. The offer may then turn out to be a paid course, an account management service, or a request for access to the user’s TikTok Shop or TikTok Ads account. Malwarebytes says these offers require users to place significant trust in companies whose legitimacy may be difficult to verify. Depending on the service, customers may end up sharing personal information, making payments, or granting third parties access to their TikTok accounts. Fake growth comes with risks Malwarebytes notes that fake engagement does little to build a genuine audience. Purchased followers and automated views do not represent interest in a creator’s content, making engagement metrics a poor reflection of actual reach or community growth. The company also says platforms actively look for inauthentic behavior, creating additional risks for accounts associated with artificial engagement. Beyond individual customers, Malwarebytes says the industry supports a broader underground market. Revenue from engagement-selling services may help sustain operations involved in account theft, bot activity, and other forms of cybercrime.
helpnetsecurity.comAug 3, 2026extracted
Buying TikTok views or followers? Here’s what you’re really getting
A whole industry has sprung up around selling TikTok “growth.” Cheap views by the hundred, pre-made ad accounts, and polished sales pages promising a repeatable path to serious revenue. None of it is officially sanctioned by TikTok, and depending on what you’re buying, you could end up wasting money, losing your account, or handing your login details to scammers. Scam 1: Sites selling cheap likes and engagement Sites selling bulk engagement all look remarkably similar. They offer small bundles of views, likes, or followers for a few pounds, usually alongside identical packages for YouTube, Instagram, and other platforms. The sales pitch is almost always the same: “100% real profiles,” “no bots, no click farms,” and “completely safe.” Those claims are worth reading carefully because they’re addressing the biggest concern buyers already have. At this price point, bulk engagement is usually generated through bots, click farms, or other artificial means—the very thing these sites insist they don’t use. Even if your engagement numbers increase initially, TikTok’s fraud detection systems can remove artificial engagement, and accounts that repeatedly use these services risk being flagged or restricted. Scam 2: The “aged” ad account marketplace Another common offer is bulk TikTok Ads accounts sold as “aged” or “trusted,” often bundled with a replacement guarantee if an account stops working. The pitch is that you skip the hassle of setting up and verifying a new advertising account. The problem is that you don’t know how those accounts were created. Many are built using stolen or synthetic identities, compromised payment details, or other deceptive methods. Buying one means inheriting that history—and the very real risk that TikTok detects it and suspends the account, along with any campaigns or ad budget attached to it. A replacement guarantee won’t help if your advertising is suddenly brought to a halt. Scam 3: The growth framework A third type of offer is less obviously a scam and more of a marketing funnel. Slick landing pages—often hosted on free platforms and paired with an embedded video—promise a “proven blueprint” for turning TikTok into a major source of income, usually backed by impressive but unverifiable claims about past clients. The immediate goal is usually to collect your email address, and sometimes your phone number, before revealing what’s actually for sale. That might be a paid course, a “done-for-you” management service, or a request for direct access to your TikTok Shop or Ads account. What happens next varies, but the common thread is the same: you’re being asked to trust an unverified third party with your business, your money, or your account. What you’re really signing up for Not every TikTok marketing service is a scam. But if someone’s offering thousands of views for a few pounds, bulk “aged” ad accounts, or guaranteed growth, you’re in a very different part of the market. These services promise shortcuts. What they often deliver is fake engagement, accounts with questionable histories, or requests for access to your own account. At best, you’ve wasted your money on engagement TikTok later strips away. At worst, you’re buying an account built on stolen information or giving an untrusted third party full access to your own. Our advice Don’t pay for views, likes, or followers. Artificial engagement isn’t real growth and can put your account at risk under TikTok’s rules. Never share your TikTok username and password with a “boosting” service, regardless of how it’s presented. Don’t buy or sell TikTok Ads or Business accounts outside TikTok’s own account creation process. Treat “guaranteed revenue” frameworks and courses like any other business opportunity: they’re sales pages first, educational content second. None of this is unique to TikTok. The platform’s explosive growth has simply given a familiar ecosystem of low-effort scams a new audience. Scammers don’t need to hack you. They just need you to click once. Malwarebytes Identity Theft Protection catches suspicious activity before it becomes a problem.
malwarebytes.comJul 29, 2026extracted
Don’t get fooled by TikTok resin art scams
Resin art has become a popular corner of TikTok, with some videos attracting millions of views. But not every glossy, colorful post is what it claims to be. Scammers are using the look of handmade resin art to trick buyers, collectors, and even fellow artists into sending money for work that either doesn’t exist or wasn’t created by the person posting it. There are plenty of genuine resin artists on TikTok. Unfortunately, the platform has also attracted scammers who steal videos and impersonate legitimate creators. The scam is fairly straightforward. A TikTok account presents itself as a resin artist, posts satisfying videos, and invites people to “DM to order.” In some cases, the videos are stolen from other creators, the account has no real process footage, and the seller disappears after receiving payment. One resin artist discovered that scammers were using their videos to impersonate them and scam TikTok users. They shared the following comment: Ridiculous TikTok scammer…lol. Profile says they’re a resin artist and to DM them to order, but none of the videos are theirs. When I wrote to them asking them to take down the many videos of mine that they posted, passing them off as their own with no credit, their answer was that they aren’t a resin artist and are just sharing videos they like 🤣🤣 Literally about 1/4 of “their” videos are mine 🙄 These scams often rely on trust and urgency. The account may show polished clips of poured resin, finished coasters, trays, jewelry, or wall art, then push buyers to move the conversation into direct messages. Once the buyer moves to a different platform, the scammer typically requests a deposit, full payment, or personal details with little chance of being held accountable. And real artists don’t just get their work ripped off. A scammer may contact a creator claiming to want to buy, feature, or license their work, but the real goal is to extract fees, banking information, or other sensitive data. Social media art scams are often repetitive because they are built from the same templates and scripts. How to spot a TikTok resin art scam The safest approach is the boring one: verify before you pay. If the artwork looks amazing but the seller’s identity is vague, the risk is real. Check the TikTok account Before ordering, look for signs that the artist is genuine: The account didn’t appear overnight and has a history of original posts. The same videos don’t appear under multiple creator names or belong to another artist. The creator shows themselves making the artwork, with consistent process videos, a recognizable workspace, and works in progress. The videos don’t contain obvious AI artifacts, such as impossible resin effects or objects moving after they’ve supposedly been sealed inside hardened resin. Comments raising concerns haven’t been deleted or buried under generic praise. The seller isn’t pushing you to order only through direct messages or asking for payment before you’ve verified who they are. Check the website If you do click through to a website, spend a few minutes checking it before you buy: Look for a genuine returns and refunds policy, a physical business address, company or VAT details (where applicable), and consistent contact information. Check how old the website is. Scam sites often use domains that were registered only weeks or months ago, especially when they claim to have been selling handmade products for years. Search for recent independent reviews rather than relying on testimonials published on the site itself. Run a reverse image search on the product photos to see whether they’ve been copied from another artist. Only pay using a method that offers buyer protection, such as a credit card or PayPal. If a seller insists on a bank transfer, cryptocurrency, or another irreversible payment method, walk away. Not every resin art account is a scam. Many belong to genuine artists, and that’s why impersonation scams can be so convincing. If you’re unsure, paste the website address into Malwarebytes Scam Guard and ask whether it shows signs of being fraudulent. It can help identify suspiciously new domains and other common scam indicators. Use real-time web protection to block known fraudulent and malicious websites, like Browser Guard did for this web shop: Both are free—making them much cheaper than sending money to a scammer. Something feel off? Check it before you click. Malwarebytes Scam Guard helps you analyze suspicious links, texts, and screenshots instantly. Available with Malwarebytes Premium Security for all your devices, and in the Malwarebytes app for iOS and Android.
malwarebytes.comJul 24, 2026extracted
UK investigates TikTok for alleged age-verification lapses, exposing kids to online harms
UK investigates TikTok for alleged age-verification lapses, exposing kids to online harms TikTok is under investigation for allegedly failing to effectively verify users’ ages and thus inadequately protecting children online, the U.K.’s communications regulator announced Wednesday. Ofcom alleges that the social media platform may be violating Britain’s Online Safety Act. Age inference models, including those TikTok deploys, may have “failed to correctly identify a significant proportion of children, putting them at risk of exposure to harmful content,” Ofcom said in a press release. TikTok’s procedures may have failed to correctly estimate the ages of “a significant proportion of children,” Ofcom said. TikTok and other social media firms rely primarily on age inference methods even though the Online Safety Act does not include the tool on a list of “highly effective” age verification models companies are required to use, according to Ofcom. Age inference tech works not by directly verifying a person’s age with ID, biometrics or document submission, but by analyzing users’ browsing habits, online interactions and other internet activity. Ofcom has “particular concerns” about TikTok’s age assurance practices, according to the press release. “Our message to social media companies is clear: those which use age inference models to comply with their child protection duties should switch to other methods listed in our guidance as highly effective without delay,” Ofcom said. Under the Online Safety Act, companies violating the rules can be fined £18 million ($21 million) or 10% of qualifying worldwide revenue. In cases of egregious conduct, the British government also can attempt to ban sites and platforms from operating in the country. The Online Safety Act includes pornography and posts about suicide and eating disorders in its checklist for harmful content. “Age checks are a cornerstone of the UK’s online safety laws,” Ofcom’s Chief Executive, Melanie Dawes, said in a statement. “Too many services have no or inadequate age checks in place, which is not good enough.” The U.K.’s current Labour Party government wants to bar children under 16 from social media. The proposed legislation will apply to “user-to-user platforms” like Facebook, Instagram, TikTok, X, YouTube and Snapchat if lawmakers approve it. The government plans to send it to Parliament before Christmas, officials said. Ofcom plans to send Parliament an analysis of what “highly effective age checks look like in practice,” the regulator said. The coming social media restrictions will require even more robust age checks, which Dawes said are “already shifting towards a stronger, whole-of-system approach.” A spokesperson for TikTok said in a statement that the company “strictly enforce[s] age-appropriate experiences through expert-informed platform rules and advanced age inference technologies, in line with major industry peers.” “In the eight years since TikTok launched in the UK, we have invested billions in platform safety,” the statement said. “We are confident that we meet our Online Safety Act obligations and will work with Ofcom to demonstrate this." Ofcom will update the public on the status of the investigation in October. Suzanne Smalley is a reporter covering digital privacy, surveillance technologies and cybersecurity policy for The Record. She was previously a cybersecurity reporter at CyberScoop. Earlier in her career Suzanne covered the Boston Police Department for the Boston Globe and two presidential campaign cycles for Newsweek. She lives in Washington with her husband and three children.
therecord.mediaJul 16, 2026extracted
Week in review: 74k Fortinet firewall credentials stolen, Splunk Enterprise RCE under active attack
Week in review: 74k Fortinet firewall credentials stolen, Splunk Enterprise RCE under active attack Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: A hardware neural network backdoor that hides in plain sight Deep learning systems on edge devices often rely on third-party-designed FPGAs and ASICs for performance and efficiency, creating supply chain risks. Researchers from the University of Tennessee and the University of Florida developed HAMLOCK, a backdoor attack that splits malicious functionality between hardware and software, making detection more difficult. Onspring CISO on where automated GRC systems fall short In this interview with Help Net Security, Nichole Windholz, CISO at Onspring, talks about the limits of automated GRC systems and continuous control monitoring. She explains why color-coded dashboards can hide nuance, how teams can check the data feeding their tools, and which risks resist measurement, such as insider behavior and vendor concentration. AI vulnerability discovery is pushing 2026 CVEs toward 66,000 Vulnerability disclosures are piling up faster in 2026 than anyone expected at the start of the year. The running count for the first few months sits well above the original projection, and the Forum of Incident Response and Security Teams (FIRST) now expects the year to land near 66,000 CVEs. Reachability makes AI threat modeling worth the trust In this interview with Help Net Security, Oscar Andersson, CTO at Oplane, explains why most scanning tools fail. They cry wolf, flagging threats that cannot run in real code. The argument centers on reachability. A finding counts only when someone walks the path to impact on a working build. The SOC’s visibility gap comes down to staffing AI has settled into security operations centers faster than any earlier wave of technology. Around four in five practitioners report reaching for AI or machine learning tools in their daily work. The catch shows up one layer down. Roughly a third of those same teams have built these tools into a defined workflow with structure, governance, and consistent validation. The rest pick up AI on their own, case by case, with no shared playbook for how it gets used or checked. The Chainguard Athena coalition already shipped 2,000 patches across 500 open source projects Chainguard launched Athena, an industry coalition that pools open source vulnerability findings and remediates them under embargo before public disclosure. The group went live with more than two dozen member organizations. Founding members include BNY, Chainguard, Cisco, Cloudflare, Corridor, DepthFirst, Docker, JPMorganChase, Kyndryl, LTIMindtree, and PwC. What happens to oversight when AI agents write a lab’s own code Inside the labs building frontier AI, a growing share of the coding gets done by the AI itself. These agents write, edit, and run software with light human oversight between steps, and they reach into production infrastructure, research pipelines, and potentially the systems that train and evaluate future models. Securing digital keys when your phone unlocks the car In this interview with Help Net Security, Alysia Johnson, President of the Car Connectivity Consortium (CCC), explains how the CCC Digital Key has grown from a single-brand feature into a standard meant to work across phones, automakers, and suppliers. Your browser tab could become encrypted storage for someone else’s files Decentralized storage networks already hand pieces of people’s data to strangers’ machines. The lasting question across these networks is whether the machine holding the data can read it. A research paper by Gregory Magarshak, a professor at IENYC, describes a system called Safecloud built on one design rule: the nodes that store data see only ciphertext, and the nodes that route data hold no keys. PhishLumos: Exposing phishing campaigns that evade detection by hiding content Phishing remains one of the most stubbornly persistent threats in cybersecurity: humans are tired, distracted, trusting, and susceptible to urgency and authority in ways that no amount of awareness training can completely overcome. The security community has largely accepted this reality and shifted focus toward automated detection systems that can intercept and block phishing threats before users see them. China-linked spies backdoored authentication stack to stay hidden for years A China-linked cyber espionage group known as Velvet Ant spent nearly a decade inside the internal network of an unnamed organization without being detected, according to the results of a forensic investigation published by cybersecurity firm Sygnia. Cisco discloses second exploited SD-WAN vulnerability in two weeks (CVE-2026-20262) Cisco has revealed another Catalyst SD-WAN Manager vulnerability (CVE-2026-20262) that its Product Security Incident Response Team observed being exploited by attackers. But the associated security advisory also states that “the vulnerability was found during internal security testing”, raising the question of how attackers came to exploit it before Cisco had disclosed it publicly. SimpleHelp RMM flaw could give attackers full access to managed endpoints (CVE-2026-48558) A critical vulnerability (CVE-2026-48558) in SimpleHelp, a popular remote monitoring and management (RMM) tool, can be exploited remotely by unauthenticated attackers to create a new “Technician” account and use it to remote into managed endpoints, execute scripts, and more. Attackers are exploiting FortiSandbox vulnerabilities Attackers have been spotted exploiting three vulnerabilities (CVE-2026-39813, CVE-2026-39808, CVE-2026-25089) in FortiSandbox, a platform that other Fortinet security products depend on for threat verdicts to enforce blocking decisions and trigger automated responses. The warning came on Monday from threat intelligence company Defused, which said that the exploit for one of the flaws is vibecoded, and likely faulty. Microsoft working on patch for RoguePlanet Defender zero-day (CVE-2026-50656) Microsoft has acknowledged the local elevation of privilege issue in Microsoft Defender that can be triggered via the “RoguePlanet” exploit, and is “working to provide a high quality security update that addresses this vulnerability.” The vulnerability, which has been assigned the CVE-2026-50656 identifier, stems from improper link resolution before file access, and can be exploited in low complexity attacks by authenticated attackers, with no user interaction required. Low-skilled attacker used Claude, Codex to breach 14 companies Researchers have long warned that AI agents could lower the skill floor for offensive cyber operations, and a recent report by OALABS (Open Analysis) researchers bears that out. After recovering and analyzing over 1,000 agent sessions from a compromised server on which an attacker deployed Anthropic’s Claude Code and OpenAI’s Codex agents, the researchers discovered how easily the attacker was able to bypass most of the agents’ guardrails, and how little he actually needed to know and do himself. 74,000 Fortinet firewall credentials exposed in FortiBleed data leak A Russian-speaking cybercriminal group has stolen credentials contained in the configuration files of nearly 74,000 Fortinet firewalls and VPN gateways around the world. The data was accidentally exposed by the group on a server, along with other artifacts and tools, and the exposure was noticed by security researcher Volodymyr “Bob” Diachenko. Law enforcement hits SocGholish: 106 servers down, 15,000 sites cleaned SocGholish, an operation that’s been delivering malware to users via fake software updates, has suffered a major blow: the international law enforcement coalition behind Operation Endgame has taken down 106 of its servers and domains, and cleaned up nearly 15,000 websites compromised to serve their malicious payloads. The result of this most recent multinational law enforcement action was announced today by the Dutch National Police and on the operation’s website. Unauthenticated RCE in Splunk Enterprise under active attack (CVE-2026-20253) CISA has added CVE-2026-20253, a critical, remotely exploitable vulnerability in Splunk Enterprise, to its Known Exploited Vulnerabilities catalog, and ordered US federal civilian agencies to apply mitigations by June 21, 2026. EU Cybersecurity Act 2.0: When good regulation goes bad Over recent years we’ve witnessed the EU becoming increasingly serious about cybersecurity. After years of watching high profile breaches, many resulting from supply chain attacks targeting our critical infrastructure, that seriousness is welcome. But good intentions and good policy are not the same thing, and the proposed EU Cybersecurity Act 2.0 is starting to look a lot more like the former than the latter. Navigating SEC, NIS2, and DORA incident disclosure timelines under pressure In this Help Net Security video, Rick Goud, Global Field CTO at Kiteworks, discusses how to handle SEC, NIS2, and DORA disclosure timelines during a security incident. Proving what a military AI model will do is the real problem Defense contractors build AI systems that task drones automatically and propose kill-chains to support soldiers. Several of these contractors have partnered with frontier AI companies to put advanced models into military tools. The systems coming out of these partnerships carry a security problem that sits outside the methods of arms control diplomacy: confirming what an AI model will do. Open-source CI/CD abuse detector guards against stolen credential attacks CI/CD Abuse Detector is an open-source project that uses a large language model to flag suspicious changes to continuous integration and continuous deployment pipelines, workflows, and automation configurations. The repository contains drop-in templates for GitHub Actions, GitLab CI, and Azure DevOps. Ukrainian national pleads guilty in connection with Conti ransomware A Ukrainian national pleaded guilty to conspiracy to commit wire fraud in connection with the deployment of Conti ransomware, which targeted more than 1,000 victims worldwide. Chinese hackers breached North American research institutions via REDCap servers A China-linked cyber espionage operation targeted North American medical research institutions through compromised REDCap servers, using custom malware to gain persistent access and collect sensitive information, Google’s Threat Intelligence Group (GTIG) researchers found. Planning a trip? Fake travel sites are multiplying this summer Cyberattacks against hospitality, travel, and recreation organizations rose 24% year over year, reaching an average of 2,291 incidents per organization each week in May 2026, according to Check Point. Crypto scammers are sending couriers to victims’ homes to collect cash Scammers behind cryptocurrency investment schemes are dispatching couriers to pick up cash from victims in person, the FBI warns. According to the agency, scammers usually approach victims through social media, text messages, or fake investment personas, luring them into cryptocurrency schemes that use fraudulent trading platforms and fabricated returns to encourage additional deposits. Cybercriminals mask malicious communications through Microsoft Teams relays The DragonForce ransomware group used a custom malware called Backdoor.Turn to hide command-and-control traffic inside Microsoft Teams relay infrastructure during an intrusion at a U.S. services company, according to Symantec. Apple is bringing Hide My Email and Sign in with Apple under one domain Apple will unify the email domains used by Sign in with Apple and iCloud+ Hide My Email under a shared domain, private.icloud.com, later this summer. Hide My Email is a service included with iCloud+, Apple’s subscription service. It allows users to generate one-time-use or reusable email addresses that forward messages to their personal inbox without revealing their actual email address. Rokarolla Android trojan targets banking and crypto users, enables device takeover A newly discovered Android banking trojan, dubbed Rokarolla, targets 217 banking and cryptocurrency applications and can execute 137 commands on infected devices, according to researchers at Zimperium. Named after its command-and-control (C2) infrastructure, Rokarolla is primarily distributed through malicious websites that impersonate popular applications such as TikTok and Google Chrome, fooling users into downloading what appears to be a legitimate app. Another healthcare firm attacked days after Novo Nordisk breach Medical technology company iRhythm Holdings disclosed a cyberattack involving certain third-party-hosted business applications that resulted in the theft of patient protected health information, proprietary data, and other personal data. The company discovered unauthorized activity on June 8, 2026, and launched an investigation with the assistance of external cybersecurity experts. AWS Continuum brings AI models to code vulnerability management AWS Continuum for code vulnerabilities, a system built to handle a vulnerability across its lifecycle, from discovery through to a fix, is now available in gated preview. It reasons over a customer’s environment, confirms which findings are real, and works toward resolution. It is model agnostic and draws on multiple frontier models, assigning each to the work where it performs best. AWS designed it to take in newer models as they become available. Malware attacks strip Roblox developers of entire games Hackers who once focused on stealing valuable Roblox items are now taking over entire games. Although Roblox operates the service, users can create and publish their own games on it. Successful games can generate substantial revenue through in-game purchases. Some developers have earned millions of dollars and built dedicated studios around their creations. Klue breach lead to Salesforce data theft, Huntress affected Cybersecurity vendor Huntress was among multiple companies hit by a breach originating at Klue, a market intelligence platform used to integrate CRM and sales data across various business tools. Senior engineers are spending their week cleaning up AI-generated code At most U.S. technology companies, machines now write the bulk of the code that ships each week. The engineer’s job has shifted toward reviewing what the AI produces, and that review gives the code high marks. Leaders rate AI-generated code as higher quality than the code their own people write, praising its clean structure, consistent style, and low count of obvious bugs at submission time. Microsoft’s workplace check-in via Wi-Fi tracks who’s in the office, and not everyone’s happy Microsoft is rolling out workplace check-in via Wi-Fi for Teams and Microsoft Places. Connect to your office network and your in-office presence updates automatically, no manual status change needed. A $2 trillion revenue shift hinges on AI data governance Across large enterprises, a single question keeps surfacing when teams want to put customer data to work. Can this record be used for a given purpose, and does the consent behind it still hold? The data sits in warehouses and customer databases, and the ability to answer that question often lags behind. That delay carries a cost. GitHub releases an open dataset for multilingual developer content Developers coordinate code across README files, issue threads, and pull request discussions. Much of that exchange happens in English, and a large share happens in other languages. GitHub has released a dataset built to help researchers and developers locate public repositories that carry non-English natural-language content. Software supply chains are heading for a transparency test Software supply chain visibility is becoming part of product security work as the EU Cyber Resilience Act (CRA) moves toward application in December 2027. ENISA’s SBOM Adoption State of Play 2026 shows organizations preparing for CRA obligations through SBOM tooling, automation, and changes to software development practices. The checklist problem behind critical infrastructure cyber safety An asset owner can meet major federal cyber compliance standards and still run equipment that lacks the engineering to withstand an attack or a failure. New research from George Mason University examines how United States cyber policy defines reasonable care for systems that control physical processes, and it finds that compliance has become a stand-in for safety. Product showcase: From phishing texts to risky Wi-Fi, Norton 360 Deluxe watches the gaps Norton 360 Deluxe combines device security, scam detection, web protection, and VPN privacy in a single subscription that covers up to five devices. It is available for Windows, macOS, Android, and iOS. Microsoft AntiSSRF open-source library helps block server-side request forgery AntiSSRF is an open-source code library from Microsoft that validates URLs and network connections to reduce server-side request forgery (SSRF) risks in web applications. It supports .NET and Node.js applications and is distributed under the MIT license. The library works as a drop-in component, giving developers a way to check untrusted input before their applications make outbound requests. Ukraine can now tap EU cyber support during major attacks Ukraine can now call on emergency cyber support from the European Union during large-scale cybersecurity incidents. The move follows a decision by the Council of the European Union to add the country to the EU Cybersecurity Reserve. What’s new in Android 17? Anti-theft tools, scam detection, and parental controls The Android 17 rollout has started for supported Pixel devices, delivering new security and privacy capabilities before expanding to other devices later this year. Most agentic AI projects in production have stalled over data problems Enterprises are connecting AI agents to live data feeds and putting them to work on tasks that once required human review, from IT operations to software development. The number doing this in production reached 32 percent in 2026, up from 29 percent the year before, according to Confluent’s annual Data Streaming Report, which surveyed 4,625 IT leaders across 14 countries. Homebrew tightens tap security, begins work on its interface Anyone who installs software through a third-party Homebrew tap runs Ruby code written by people outside the project, and that code runs without a sandbox. That risk sits at the center of Homebrew 6.0.0. It now requires a tap, along with any tap-qualified formula or cask, to be trusted before its code is evaluated or run. Google’s open standard for AI agents to discover and verify tools AI agents rely on tools, services, and other agents distributed across different teams, organizations, and platforms. Because these resources are often isolated in separate systems, agents have limited ability to discover and connect to capabilities outside their own environment. Google aims to solve this with Agentic Resource Discovery, an open specification for publishing, discovering, and verifying AI capabilities across the web, regardless of framework, protocol, or provider. GentleKiller targets more than 400 security processes across 48 products Most ransomware operations leave the work of disabling endpoint security software to their affiliates. The ransomware-as-a-service gang Gentlemen runs a different model. Its operators develop and maintain a set of tools for shutting down endpoint detection and response (EDR) products, then provide these tools directly to the affiliates who rent the gang’s encryptors. Asia-Pacific scam networks generate nearly $40 billion a year Cybercrime is taking a larger share of criminal activity in Asia and the Pacific. More than half of surveyed jurisdictions reported that cybercrime accounts for over 30% of all crimes recorded nationally, according to INTERPOL’s 2025/2026 Asia and South Pacific Cyberthreat Assessment Report. Companies are discarding the logs they need to catch a breach Many large enterprises discard most of the log data their systems generate, and they do it on purpose to keep costs down. A Dynatrace survey of 450 senior IT leaders at large enterprises found that half of organizations drop or never collect an average of 86 percent of their logs, even after filtering and aggregation. Many also limit how long they retain the logs they do keep. The rise of machine identities and agentic AI: Securing trust in the next era of digital autonomy For years, identity security has been centered on humans, ensuring that the right person has the right level of access to the right resources. But now, the same principle applies to non-human entities: machines, APIs, bots, and increasingly, AI agents. These new “digital actors” authenticate, access sensitive information, execute workflows, and even make decisions, often faster and at greater scale than any human ever could. How security teams are getting credential visibility into developer endpoints Attackers increasingly target developer machines to steal credentials. Recent supply chain attacks, including Megalodon, TrapDoor, and Miasma, focused on compromising developer environments where secrets often reside in shell histories, .env files, cloud CLI configs, local caches, and AI agent directories. To address this risk, GitGuardian has introduced Developer Endpoint Protection in ggshield, enabling organizations to discover credentials on developer workstations. Google sets timeline for Android developer verification enforcement Android’s developer verification protections will take effect on September 30, 2026, starting with users in Brazil, Indonesia, Singapore, and Thailand. Developers distributing apps through participating stores in those markets must complete the verification process by the deadline. Mastodon 4.6 adds profile Collections and two-factor controls People who run accounts on the open source social network Mastodon can now group profiles together and share those groups across the web. The 4.6 release centers on a feature called Collections, along with reworked profiles, email newsletters, server administration controls, and a set of accessibility changes. Forget traffic lights, Google’s reCAPTCHA may ask for hand gestures Google has introduced hand gesture verification for reCAPTCHA, a new method for verifying that a user is human. Google’s reCAPTCHA is part of Google Cloud Fraud Defense, a fraud and abuse prevention platform for bot, account, and transaction protection. It uses risk analysis and challenge-based verification to help organizations identify automated activity and suspicious behavior. Cybersecurity jobs available right now: June 16, 2026 We’ve scoured the market to bring you a selection of roles that span various skill levels within the cybersecurity field. Check out this weekly selection of cybersecurity jobs available right now. New infosec products of the week: June 19, 2026 Here’s a look at the most interesting products from the past week, featuring releases from ArmorCode, Barracuda Networks, Blue Planet, Flip, Fortinet, Legit Security, Tigera, and WitnessAI.
helpnetsecurity.comJun 21, 2026extracted
Rokarolla Banking Trojan Targets 200 Applications
Mobile security firm Zimperium is warning Android users about Rokarolla, a new banking trojan capable of targeting more than 200 cryptocurrency and bank applications. The malware has been distributed via malicious websites that serve it disguised as popular apps such as Chrome and TikTok. These applications deliver the main payload by impersonating Google Play Protect. Once it has infected a device, Rokarolla requests a wide range of permissions and can even collect an Android phone’s lockscreen credentials (PIN, pattern, or password), enabling device takeover and the theft of sensitive data even when the phone is locked. According to Zimperium, the trojan can steal data from 217 banking and cryptocurrency applications, leveraging screen overlays to phish credentials for these apps. The malware can also harvest WhatsApp contact information by abusing Accessibility Services to capture the active screen’s structure. It can also exfiltrate SMS messages and hijack calls. Rokarolla also includes keylogger capabilities that enable it to capture everything the victim types. It can also manipulate the clipboard to replace the user’s cryptocurrency addresses with ones controlled by the attacker. In addition, Zimperium noted, “The malware systematically captures screenshots of the victim’s device, compresses them into PNG format, and exfiltrates the image data alongside a precise timestamp.” The malware uses various methods to evade detection, including disabling Google Play Protect. “It initially hides its application icon from the device’s app drawer to avoid visual detection,” Zimperium explained. “Complementing this visual evasion, the malware is capable of muting all device audio and vibrations, ensuring it operates in complete silence during fraudulent activities. This audio suppression effectively masks critical cues, such as security alert notifications or incoming verification calls from banking institutions, significantly reducing the likelihood of the user noticing or interrupting the transaction process.” Related: Microsoft Teams Relay Servers Abused in DragonForce Ransomware Attack Related: Atomic Arch Supply Chain Attack Hits 1,500 AUR Packages Related: OnyxC2 Stealer Offers Cybercriminals Enterprise-Grade Theft for $250 a Month
securityweek.comJun 18, 2026extracted
Rokarolla Android trojan targets banking and crypto users, enables device takeover
Rokarolla Android trojan targets banking and crypto users, enables device takeover A newly discovered Android banking trojan, dubbed Rokarolla, targets 217 banking and cryptocurrency applications and can execute 137 commands on infected devices, according to researchers at Zimperium. Named after its command-and-control (C2) infrastructure, Rokarolla is primarily distributed through malicious websites that impersonate popular applications such as TikTok and Google Chrome, fooling users into downloading what appears to be a legitimate app. Banker malware impersonating a legitimate app and requesting accessibility service (Source: Zimperium) Zimperium said Rokarolla is designed to steal financial information while giving attackers broad control over compromised devices. “Its malicious capabilities include harvesting lock screen credentials, exfiltrating sensitive contact lists and SMS data, and utilizing keyloggers to continuously record user input,” the researchers said. “Furthermore, the trojan actively conceals its operations and disrupts user intervention by blocking incoming calls, deploying fraudulent screen overlays, suppressing device audio, and deactivating Google Play Protect.” The attack begins with a dropper that poses as Google Play Protect, Google’s Android security service. Once installed, it delivers a second-stage payload containing the Rokarolla malware. When launched on the device, Rokarolla requests access to Android Accessibility Services, along with permissions for notifications and SMS messages. Rokarolla uses phishing overlays to steal financial data The malware then checks infected devices for any of the 217 banking and cryptocurrency applications on its target list. When it finds one, Rokarolla downloads a phishing page that is displayed as an overlay when the victim opens the legitimate app, allowing attackers to collect credentials, credit card information, and other financial data. Fake Overlay process of Imagin bank (Source: Zimperium) Rokarolla exchanges data with its C2 infrastructure, sending details about the device, Android version, locale, battery status, and available storage. According to Zimperium, this information is used to generate a unique botID for each infected device. The malware can receive commands from its operators and switch to alternative C2 domains through remote configuration. The researchers identified 137 commands used to control infected devices. SMS interception and device surveillance capabilities “The malware has the capability of exfiltrating all SMS messages from the infected device and can also send SMS on behalf of the victim, which can be used to intercept sensitive information such as bank OTPs,” the researchers said. Rokarolla can also extract text displayed on the screen and gather information from messaging applications. The researchers found that it can modify clipboard contents without user interaction, a capability that can be used to replace cryptocurrency wallet addresses and other copied data. Instead of relying on continuous screen streaming, Rokarolla periodically captures screenshots of infected devices and sends them to its operators. This provides visibility into user activity and information displayed on the screen. Another capability allows Rokarolla to block and intercept phone calls, giving attackers a way to disrupt fraud alerts and other security-related communications from banks. “Complementing this visual evasion, the malware is capable of muting all device audio and vibrations, ensuring it operates in complete silence during fraudulent activities,” they added. Zimperium published a list of indicators of compromise (IoCs) on a GitHub page. The company also included a complete list of MITRE ATT&CK tactics and techniques associated with the Rokarolla attack chain.
helpnetsecurity.comJun 17, 2026extracted
UK to require ID or face scan before you can make social media accounts
The UK government will ban under-16s from social media, with regulations due before Christmas and the rules taking effect in spring 2027. To enforce it, platforms must age-check their users. In practice that means anyone opening a new account will likely have to prove they're over 16 by uploading an ID or passing a facial age scan, the same checks that adult sites serving UK visitors have implemented since July 2025 under the Online Safety Act. Long-standing accounts are largely exempt, but signing up fresh now triggers verification, effectively ending anonymous account creation in the UK. Security and privacy experts warn the checks are easy to circumvent, put everyone's ID and biometric data at risk of breaches, and were rushed in with little political scrutiny. The announcement Prime Minister Keir Starmer set out the plan on June 15, following a national consultation that drew more than 116,000 responses from parents, children and experts. The government says nine in ten parents backed an under-16 ban, and two-thirds of young people agreed that under-16s should be kept off at least some platforms. "That's why we're going further than any country in the world by banning social media for under-16s and putting wider protections in place to give kids their childhood back," Starmer said. "This is a line in the sand. Tech giants had their chance and failed." Technology Secretary Liz Kendall framed it as a fight with the platforms: "Tech companies have had countless opportunities to keep children safe, yet they have failed to act. That is why we are taking power away from the tech giants and putting it back in parents' hands." What's covered The ban is modelled on Australia's, which took effect in December 2025 and was the first of its kind. It will cover user-to-user platforms "whose purpose is to enable social interaction" and that run algorithmic feeds. The government names Instagram, YouTube, TikTok, Snapchat, Facebook and X. Messaging services such as WhatsApp and Signal are explicitly excluded, as is YouTube Kids. There will be a narrowly defined exemption list for educational services, e-commerce and music streaming. The UK says it will go further than Australia. High-risk features, such as livestreaming and strangers being able to contact children, will be restricted across a wider range of services, including gaming sites like Roblox (the platform stays, but features such as chat get locked down). To avoid a "cliff-edge at 16," those stranger-contact and livestreaming restrictions will be on by default for 16- and 17-year-olds too. Separately, AI "romantic companion" chatbots that simulate sexual or roleplay relationships will have to enforce an 18+ minimum, with intimate functions restricted for under-18s on AI chatbots more broadly. The government is also consulting on overnight curfews and breaks in infinite scrolling for under-18s, with detail promised in July. The catch for adults: it's the new accounts The government's reassurance is that most adults won't face a fresh check. According to a fact sheet, an account is treated as low-risk if it has been open for more than 16 years, has a credit card attached, or is linked to an email already age-verified elsewhere. Anyone who's already verified under the existing Online Safety Act wouldn't need to do it again. But that carve-out is essentially a grandfather clause, and it does nothing for new accounts. If you create a social media account from scratch after the rules land—say you want a fresh, pseudonymous handle, or you're simply a new user—none of those passive signals apply, and the fallback is exactly what the fact sheet describes: a facial recognition check, or an ID upload. In practice the regime quietly converts what's billed as child protection into a rule that no adult can open a new account without proving their age. It's a lighter touch than the adult-content regime, for now. Since July 25, 2025, the Online Safety Act has required adult and other sensitive sites to run "highly effective" age checks (typically an ID upload or a facial-age selfie) for every user, with no grandfathering. Enforcement has also been aggressive. By February 2026, Ofcom had opened investigations into more than 90 platforms and issued six fines, and its remit had stretched to Reddit, X, Discord, Bluesky and AI services. The social media age-gate doesn't go that far yet, but it normalises the same plumbing. Ofcom has been asked to run a rapid study on how to verify whether someone is over 16. The aforementioned fact sheet also notes proving you're over 18 "could be as simple as a facial recognition check." The VPN loophole The well-documented weakness is that a VPN defeats all of it. The Online Safety Act targets sites, not users, so connecting through a server outside the UK sidesteps the check. Some VPN providers reported signup spikes of up to 1,800% when adult-site enforcement began. Any social media age-gate inherits the same gap, and Australia's experience bears it out. Research there found more than 60% of children were still using social media months after that country's ban. The UK government has limited room to close the loophole. A blanket VPN ban for the whole population has been ruled out. In October 2025 a tech minister, Baroness Lloyd, told the Lords there were "no current plans to ban the use of VPNs," citing their legitimate uses. A children-specific clampdown is a different story. In February 2026 the government said its wellbeing consultation would examine "options to age restrict or limit children's VPN use," and in January 2026 the House of Lords inflicted a government defeat, voting 207 to 159 for an amendment to the then Children's Wellbeing and Schools Bill that would require ministers to prohibit VPN providers from serving UK children. To sort children from adults, that measure would in practice force providers to age-check every user. The amendment drew public petitions against it. The Commons rejected it across several rounds of parliamentary 'ping-pong,' and the Act that received Royal Assent (became law) in April instead handed ministers a broad power to restrict children's online access by regulation. For now, nothing stops a determined adult, or a determined 15-year-old, from getting around it. What security and privacy researchers are saying The cybersecurity objection isn't to the goal, but that the enforcement mechanism creates new risks while the controls themselves don't hold up. Dr. Siamak Shahandashti, a senior lecturer in cyber security and privacy at the University of York, pointed to fresh empirical work from Politecnico di Milano testing age-verification methods deployed on adult sites. The researchers found low-to-medium robustness for nearly every method except credit-card checks. Most could be bypassed with tools and know-how within reach of "motivated minors." Their blunt conclusion, which Shahandashti quoted: mandated age verification currently functions as "compliance theatre." He added that checks linked to real, physical ID could be made robust enough if clear standards were set. Dr. Richard Gomer, a lecturer in computer science at the University of Southampton, zeroed in on the second-order risk. Enforcing an under-16 ban means age-gating everyone, and that process is itself dangerous. Handing a passport or driving licence to platforms, he warned, exposes people to identity theft or blackmail when those records inevitably leak, something already seen under the Online Safety Act rollout. He also flagged the quieter cost of the regulation pushing the web further from its original ideals of anonymous, open communication. That data-breach risk is not hypothetical either. Responding to the ban, the Open Rights Group (ORG) warned that over-16s will now have to surrender identity documents or biometric data to unregulated age-verification companies, pointing to Discord as a platform that already suffered a major data leak after introducing age checks. James Baker, who runs ORG's Platform Power and Freedom of Expression programme, argues the measures chase symptoms rather than the cause, namely the engagement-driven business models that reward harmful content, and has previously warned that the underlying powers were "rushed through without proper time for political scrutiny." Platforms aren't on side either. Meta and YouTube both argue that bans push teenagers toward less-regulated spaces rather than making them safer, with Meta making the case that age checks should sit on the device so users aren't handing ID to every service separately. The wider direction of travel It's worth noting where this sits. Since January 2025 the government has been building a GOV.UK Wallet and a digital driving licence, pitched partly as a way to prove your age online and in person using the facial-recognition features built into modern phones. That's separate from this announcement and predates it. But together they sketch a direction of travel, where proving your age is increasingly a precondition for being online in the UK. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comJun 16, 2026extracted
Fake Spotify Premium tutorials on TikTok and Instagram Reels spread malware
Fake Spotify Premium tutorials on TikTok and Instagram Reels spread malware Cybercriminals are using TikTok and Instagram Reels videos to spread Vidar, an infostealer malware, through fake downloads for popular paid software, according to ReversingLabs. The researchers uncovered two campaigns behind the activity, each using a different approach to draw in viewers before sending them to external download sites. One campaign centered on fake software installation tutorials featuring polished graphics and voiceovers. The second built audiences through a stream of videos promoting free access to premium software before directing viewers to a central tutorial containing download instructions. “Either approach is a means to a different end, and the differences demonstrate how attackers can leverage different aspects of social media engagement to reach more potential victims,” the researchers wrote. Fake software tutorials deliver Vidar The first campaign relied on a network of accounts masquerading as technology support pages. Researchers observed profiles using names such as “windows.tips” and “windows.insights,” along with blue-and-white profile images that resembled Microsoft’s branding. Screenshot of the malicious user, showing their profile picture (Source: ReversingLabs) The accounts posted short tutorials claiming to show users how to unlock paid software at no cost. In one example, viewers were instructed to open PowerShell from the Windows menu and run a command that supposedly unlocked Spotify Premium. “A non-technical user does not know any better, and may assume it is legitimate. Attackers are relying on this lack of understanding,” the researchers noted. Presented as a simple software tip, the command instead downloaded a file identified as Vidar. Some of the videos gained significant traction. One tutorial amassed more than 100,000 views and generated thousands of saves, shares and likes. Saves, shares and comments carry greater weight than likes because users are more selective when using those forms of engagement, helping boost a video’s visibility in recommendation algorithms. Vidar, first identified in 2018, is an information-stealing malware family used to collect credentials, financial information and authentication tokens from infected devices. The malware received an update in October 2025 that improved its stability and evasion capabilities. Access to the service has also been advertised through a $300 lifetime license. Building engagement before the pitch The second campaign took a less polished approach. The accounts posted short videos featuring services such as Spotify Premium, claiming the premium features had been unlocked for free. Rather than providing instructions upfront, the videos encouraged viewers to leave comments or visit other posts to learn how the software had been obtained. Users were then directed to tutorial videos, direct messages or links in account profiles that led to websites advertising free software, games and AI tools. Some of the sites required visitors to complete surveys and navigate a series of redirects before they could access the promised downloads. Download screen for Spotify Premium, with a list of 5 tasks to do to unlock the download (Source: ReversingLabs) Because they were unable to complete the required surveys, the researchers could not determine the final payload delivered through the links. A moderation challenge Malicious videos can be difficult to contain once they begin attracting views. “Users who catch onto the malicious intent, either through research or falling for it themselves, may try to warn others in the comments. However, most platforms allow for creators to delete comments and block commenters, so diligent attackers can snuff out this resistance.” Reporting the content does not always result in its removal. During the investigation, attempts to report some of the videos to Instagram as scams were rejected, allowing the content to remain accessible to users. Even when videos or accounts are removed, new accounts can quickly appear and continue posting similar content, making enforcement an ongoing challenge. ReversingLabs has published a list of indicators of compromise (IoCs) associated with the campaigns to help defenders identify related activity.
helpnetsecurity.comJun 11, 2026extracted
Free Spotify Premium hacks on social media are spreading infostealers
Short-form video platforms like TikTok and Instagram Reels have become the latest way cybercriminals spread malware. We’ve already seen attackers move away from traditional phishing emails and toward tactics that trick people into installing malware themselves. Now they’re being lured with slick social media videos that promise free Spotify Premium, free Windows activation, or free Microsoft Office, but instead leave people with infostealers on their Windows devices. Researchers at ReversingLabs uncovered two active campaigns that use short videos to trick users into running dangerous PowerShell commands or visiting malicious download sites. Similar campaigns have been reported by other researchers and national cybersecurity agencies, suggesting a growing trend: Cybercriminals are learning how to use social media algorithms just as effectively as marketers. In true social media fashion, the videos on platforms like TikTok and Instagram Reels claim to solve a problem you didn’t know you had. The catch is that following the instructions delivers malware to your device. How the scam works The first campaign looks deceptively professional. Accounts with names like “windows.tips” or “windows.insights” use Windows-style branding and post polished tutorial videos that resemble genuine tech support content. The videos are tagged with Windows and Office-related keywords so they appear alongside legitimate troubleshooting and tips content. The videos promise to unlock Spotify Premium, Microsoft Office, or Windows for free. Viewers are then guided through step-by-step instructions that include opening Powershell, a legitimate Windows admin tool, and pasting in commands. Those commands download and run malware, much like the ClickFix scams we’ve covered before. The malware was identified as Vidar, an infostealer designed to steal sensitive informtion from infected devices. Vidar commonly targets: Saved browser passwords Autofill data Browser cookies Cryptocurrency wallets Two-factor authentication (2FA) data TOR browser data The stolen information is then sent back to servers controlled by the attackers. How to stay safe Research into similar TikTok-based attacks shows these scripts commonly add exclusions to Windows Defender, making it harder for security software to detect future malicious activity. Fortunately, there are a few simple ways to protect yourself: Only download software from official vendor websites. Be skeptical of “free”, cracked, or unofficial versions of paid software. Don’t follow instructions on a webpage without thinking them through, especially if the page asks you to run commands on your device or copy and paste code. Many ClickFix pages use countdowns, fake user counters, or other pressure tactics to make you act quickly. Check that downloaded files match what you expected to download. Verify a file’s publisher and digital signature before you run it. On Windows, you can usually check this by right-clicking the file, selecting Properties > Digital Signatures. Keep in mind that a valid signature does not guarantee a file is safe, but missing or suspicious signatures are often a red flag. Use a real-time, up-to-date anti-malware solution to block malware like infostealers before it runs. Pro tip: If you’re unsure whether a video, message, or website is legitimate, you can ask Malwarebytes Scam Guard about it. It can help identify suspicious content and advise you on what to do next. Image courtesy of ReversingLabs From reporting threats to removing them. Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.
malwarebytes.comJun 10, 2026extracted
Fake Software Tutorials on TikTok Spread Vidar Stealer
Threat actors have been using short-form videos on TikTok and Instagram Reels to push the Vidar infostealer, disguising the attacks as tutorials for unlocking premium software for free. New analysis from ReversingLabs describes two campaigns that game the platforms' recommendation algorithms to reach large audiences, both funneling viewers to sites peddling fake free software such as Spotify Premium. Vidar is a long-running infostealer sold as a service for a $300 lifetime license, harvesting credentials, financial data and authentication tokens. A refresh last October made it stealthier. The clips racked up real traction, with one tutorial drawing more than 100,000 views. The first campaign ran through near-identical accounts with names like "windows.tips" and a blue-and-white crown icon that aped the official Windows profile. An AI-voiced clip walked viewers through opening PowerShell and pasting a command. That PowerShell command silently downloaded and ran a script from a lookalike domain, msget[.]run, that some mistook for a Microsoft address. The file it pulled down is Vidar. To climb the algorithm, the accounts chased saves and shares rather than likes, the interactions platforms weigh most heavily. One video logged nearly 1700 saves alongside its six-figure view count. Curiosity Bait in the Comments The second campaign looked less polished, ReversingLabs said. Ordinary-looking accounts post music-backed clips flaunted free Spotify Premium, then baited the comments, sometimes asking viewers to reply with a word like "ok" to trigger a direct message with instructions. Those instructions pointed to sites such as d4ug[.]site that promised free games and AI tools but gate the download behind survey after survey. ReversingLabs could not get past them, so the final payload here stayed unconfirmed. The approach is sticky, and like any social engineering, it is hard to police: creators can delete comments that warn others, and the firm's attempts to report the posts to Instagram were rejected. To defend against this threat, ReversingLabs urged organizations to: Audit who holds software-install privileges and what they are installing Refresh phishing training to cover social feeds, not just email and text Encourage staff to report suspicious posts, even on personal accounts "The more reports, the more likely it is that the accounts are taken down, which does slow down the momentum of these attackers," the company wrote. "Remaining diligent can help everyone be safer."
infosecurity-magazine.comJun 10, 2026extracted
Meta settles school district lawsuit claiming addictive design harmed students' mental health
Meta settles school district lawsuit claiming addictive design harmed students' mental health Meta on Thursday agreed to settle with a Kentucky school district that sued it over alleged addictive design practices that harmed students’ mental health. The bellwether lawsuit was the first of at least 1,200 to be brought by a school district against Meta, Snap, YouTube and TikTok for similar alleged harms. The other cases have not yet been tried. The Breathitt County School District had asked for more than $60 million to help it establish a long-term program to combat mental health and academic problems posed by students’ excessive social media usage. The amount that Meta will pay under the terms of the settlement is not public. Snap, TikTok and YouTube settled with the school district late last week. A jury trial had been expected to launch in June. Platforms have recently lost in court when facing similar lawsuits. In March, Meta and YouTube were found liable by a jury for a young California girl’s social media addiction, which allegedly caused her mental health problems. The jury ordered Meta to pay the girl $6 million. A New Mexico jury also sided against Meta in March, awarding the state $375 million after the attorney general sued, claiming the tech giant threatens children’s safety and mental health. A Meta spokesperson did not immediately respond to a request for comment. The plaintiffs have said that Meta intentionally designs its platforms to be addictive by using harmful algorithms, sending push notifications and encouraging infinite scrolling. Those design decisions and the ensuing addiction have cost schools significant money to combat, plaintiffs have said. The settlement agreement is an about face for Meta, which took the New Mexico and California cases to trial and asserted the lawsuits were frivolous. In its complaint, the Breathitt County School District condemned Meta and the other platforms for operating their business to “exploit the neurophysiology of the brain’s reward systems.” It alleged that the platforms prey on young people because their profits increase as time spent on platforms spikes. “America’s youth lack the emotional maturity, impulse control, and psychological resiliency to perceive, understand and combat the manipulation and harm that is occurring through the social media platforms.” The school district said it has had to spend significant sums tracking and treating the results of social media addiction, which it said has manifested in suicides, cyber bullying and other cyber abuses. “Despite plaintiff’s best efforts, the mental health crisis persists, and the budget is not adequate to take the steps needed to fully address this crisis,” the complaint said. “Plaintiff needs significantly more funding than it has to implement potentially lifesaving programs in the face of this ever-increasing mental health crisis that the defendants helped create.” Suzanne Smalley is a reporter covering digital privacy, surveillance technologies and cybersecurity policy for The Record. She was previously a cybersecurity reporter at CyberScoop. Earlier in her career Suzanne covered the Boston Police Department for the Boston Globe and two presidential campaign cycles for Newsweek. She lives in Washington with her husband and three children.
therecord.mediaMay 22, 2026extracted
Tech giants promise British regulator they will tweak platforms to protect kids online
Tech giants promise British regulator they will tweak platforms to protect kids online Several major tech firms promised a British regulator they will make significant changes to their platforms to better protect children. The regulator, Ofcom, had required Roblox, Snapchat, Instagram, Facebook, YouTube and TikTok to answer questions about their efforts to remove harmful algorithms, check kids’ ages and protect them from sexual predators by the end of April. All of the companies, except for YouTube and TikTok, said they would commit to certain changes. Snap told Ofcom that it will adopt every one of the agency’s recommended grooming protection steps outlined in the Illegal Harms Codes. For example, the platform will restrict how adults can contact children on Snapchat, and the platform will stop pushing children to grow their friendship groups by connecting with people they don’t know. The new protections apply only to children accessing Snapchat in the UK. Roblox told Ofcom it will give parents the ability to turn off direct chats for children under age 16, and Meta has said it will build a new setting that will hide teens’ lists of connections on Instagram by default. Meta also will begin using AI to find “likely sexualized conversations between adults and teens in Instagram direct messages.” The tech giant told Ofcom that it will report any offenses it detects to the National Center for Missing and Exploited Children and will take action against offenders. Ofcom said it wants Meta to do more to protect against grooming and is pushing the tech giant to adhere to additional safety measures laid out in the Illegal Harms Code. “We are clear that these commitments must now translate into action,” an Ofcom press release said. “We’ve set clear deadlines by when we expect to see these changes in place and will be scrutinizing how effectively they are implemented.” “If these promised improvements happen too slowly, or are not properly implemented, we will not hesitate to act.” The UK government is currently conducting a “consultation” on whether to implement a social media ban for young teenagers and is exploring other potential reforms that it has been testing in a pilot program launched in March. The consultation will conclude on Tuesday and next steps are expected to be announced shortly thereafter. Ofcom indicated that it will ratchet up its efforts to get platforms to comply more fully. “We are determined to force through further changes, using the full extent of our powers and influence,” the press release said. “We will also bring our evidence and experience to bear as the government considers responses to its national conversation on children’s safety and social media.” The regulator also said it is not happy with the answers it received from TikTok and YouTube. “TikTok and YouTube failed to commit to any significant changes to reduce harmful content being served to children, maintaining their feeds are already safe for children,” Ofcom said in a press release. “Our wealth of evidence, published today, suggests they are still not safe enough.” TikTok did not immediately respond to a request for comment. A spokesperson for YouTube said in a statement that the platform “provides industry-leading, age-appropriate, high-quality experiences for young viewers, working with child safety experts to deliver protections that support millions of families across the UK.” “We welcome today’s news that others across the industry are committing to adopt features similar to those we already have available.” Suzanne Smalley is a reporter covering digital privacy, surveillance technologies and cybersecurity policy for The Record. She was previously a cybersecurity reporter at CyberScoop. Earlier in her career Suzanne covered the Boston Police Department for the Boston Globe and two presidential campaign cycles for Newsweek. She lives in Washington with her husband and three children.
therecord.mediaMay 21, 2026extracted
TikTok, YouTube, and Roblox face scrutiny, but age gates won’t fix child safety
A damaging new report from Ofcom, the UK’s communications regulator, has delivered a stark verdict: TikTok and YouTube’s content feeds are “not safe enough” for children. This isn’t just another regulatory slap on the wrist. Ofcom is putting out a wake-up call for anyone working in cybersecurity, threat intelligence, and online safety. In its own words: “Notably, TikTok and YouTube failed to commit to any significant changes to reduce harmful content being served to children, maintaining their feeds are already safe for children.” On the positive side, Snap, Meta, and Roblox agreed to adopt further safety measures to protect children from online grooming and “stranger danger.” The BBC reports that an Ofcom survey found 84% of children aged 8 to 12 were still using at least one major service with a minimum age of 13. We reported earlier about how easy it was to fool some of the age verification methods. Researchers using under-13 accounts also reported encountering sexual content and offensive language shortly after entering specific Roblox games. Speaking of Roblox, The Guardian reports that US advocacy groups have formally requested the Federal Trade Commission (FTC) investigate Roblox for what they call “unfair and deceptive” practices. The complaint focuses on: In-game purchases pressuring children to spend money Chat functionality exposing children to strangers Features designed to maximize engagement, which critics argue may be addictive Drew Benvie, CEO of Battenhall and founder of youth safety nonprofit Raise, noted: “Although Roblox is implementing new age-based safety measures, young players are adept at circumventing these protections.” The cybersecurity point of view What keeps cybersecurity researchers up at night is another angle to this problem. Many proposed age assurance solutions require users to hand over government IDs or biometric selfie data. We already talked about this in our blog, Age verification: Child protection or privacy risk? Age verification systems create massive data collection opportunities that become prime targets for: Data breaches exposing sensitive personally identifiable information (PII) Identity theft facilitated by centralized ID databases Biometric data theft, which cannot be changed like passwords Malware and scams targeting users on less-secure platforms When restrictions push young users toward smaller or less secure sites, they encounter: No basic safety protections Higher exposure to malware Increased phishing and scam risks Unmoderated harmful content This is exactly what we see in threat intelligence: As defenders secure one vector, cybercriminals adapt and move elsewhere. Safer systems beat stricter age gates Protecting children should focus on building safer digital experiences overall. This is the only viable path forward because: Stronger moderation actually removes harmful content rather than just blocking access Safer recommendation systems prevent algorithmic amplification of harmful content Better platform accountability means companies can’t prioritize engagement over safety Avoiding invasive data collection prevents creating massive honeypots for attackers As someone who analyzes malware and threats daily, I can tell you: security through obscurity (age gates) doesn’t work. Security through robust system design (moderation, safer algorithms, accountability) does. Scammers don’t need to hack you. They just need you to click once. Malwarebytes Identity Theft Protection catches suspicious activity before it becomes a problem.
malwarebytes.comMay 21, 2026extracted
Discord migrates all users to end-to-end encryption by default
Discord migrates all users to end-to-end encryption by default The social and messaging platform Discord announced Tuesday that video and voice messages sent through the service will be end-to-end encrypted with no opt-in required. The move comes as other major social media platforms are killing end-to-end encryption for messaging. In recent months, Instagram and TikTok both announced they will no longer offer the feature. However, Google and Apple announced last week that they are expanding end-to-end encryption to cover conversations between Android and iPhone by default. Discord, used by hundreds of millions, began experimenting with end-to-end encryption in August 2023 and has spent nearly three years building the system. In September 2024, the platform began offering “audited end-to-end encryption protocol” for audio and video. As of this week, the feature is available to all users across all surfaces other than stage channels, which are voice channels used to host live events. The feature is notable because of the wide range of devices it can be used on. “The thing that makes Discord's voice and video infrastructure unusual isn't just scale — it's diversity,” vice president of core technology Mark Smith said in a blog post. “A single Discord call can have someone on a laptop, someone on their phone, someone on a PlayStation, someone on an Xbox, and someone in a web browser, all in the same conversation at the same time.” There is no other end-to-end encryption protocol available across all of those functions, according to the blog post. Suzanne Smalley is a reporter covering digital privacy, surveillance technologies and cybersecurity policy for The Record. She was previously a cybersecurity reporter at CyberScoop. Earlier in her career Suzanne covered the Boston Police Department for the Boston Globe and two presidential campaign cycles for Newsweek. She lives in Washington with her husband and three children.
therecord.mediaMay 20, 2026extracted
TikTok removes covert networks ahead of Hungary vote as disinformation concerns grow
TikTok removes covert networks ahead of Hungary vote as disinformation concerns grow Days before polls open in Hungary’s closely-watched parliamentary elections, the social media platform TikTok said it removed covert networks attempting to sway the result — highlighting concerns about disinformation ahead of a consequential vote. The company said the networks used fake accounts to post and amplify political content aimed at Hungarian users, including material critical of opposition leader Péter Magyar and his Tisza Party as well as content targeting Prime Minister Viktor Orbán’s ruling Fidesz. TikTok said it also removed hundreds of impersonating accounts and thousands of videos that violated its election policies. TikTok told Recorded Future News it had since December banned more than 300 accounts for impersonating Hungarian election candidates and elected officials. It said it had also taken action against six covert influence networks, the majority of which TikTok said spread narratives favourable to the Fidesz political party, with some of the smaller networks targeting Hungarian audiences with narratives critical of Fidesz and Orbán. The disclosures come as campaigning enters its final phase ahead of what analysts say will be a geopolitically significant vote that could reshape Hungary’s position within the European Union and influence Western unity over Russia’s war in Ukraine. Orbán, in power since 2010, faces what many observers describe as the most serious electoral challenge of his tenure. His main rival, Magyar, is a former Fidesz insider who has rallied support among opposition voters and is leading in some pre-election polls, as reported by Reuters. More than a quarter of voters remain undecided. Hungarian fact-checkers and researchers say misleading or fabricated political content, often targeting Magyar, has circulated widely during the campaign. Fact-checking outlet Lakmusz detailed false narratives about the opposition leader appearing on fake websites impersonating legitimate sources, including claims he plans a “coup” if defeated and that his party would reinstate compulsory military service. Lakmusz said the activity showed similarities to earlier influence operations that researchers have linked to Russian actors, including coordinated messaging and the use of deceptive online infrastructure. It did not present direct evidence that the current activity was directed by the Kremlin. Separately, investigative outlet Direkt36 reported what it described as a “well-organized operation” targeting the Tisza Party’s IT systems. According to Direkt36, individuals connected to the party attempted to expose the activity, after which authorities opened a criminal investigation into those individuals and carried out searches at the homes of IT specialists assisting the party. Hungarian authorities have not publicly detailed the full basis for the investigation. Government spokesperson Zoltán Kovács said on social media that Ukrainian intelligence, in cooperation with members of the opposition and a journalist, was responsible. He did not provide evidence for the claim. The IT Army of Ukraine told Recorded Future News it denied all allegations of involvement. Fidesz party campaign chief Balázs Orbán has also accused social media platforms of suppressing campaign materials, alleging “some users have been unable to like Fidesz-related content on Facebook for the past few days,” as reported by Euro News. Fact checkers have disputed his claims. Hungarian media have also reported influence activity in the other direction. Independent outlet Telex identified “troll farm” networks supporting Fidesz, while domestic groups critical of Orbán said they had tracked AI-generated content targeting the opposition. A spokesperson for Meta said it had imposed “no restrictions on the Prime Minister’s accounts, nor have any posts been removed. Our Community Standards and policies apply equally to everybody and we have systems in place to detect any coordinated efforts to abuse our reporting systems.” Foreign influence During a visit to Budapest this week, U.S. Vice President JD Vance accused the European Union of interfering in Hungary’s election and voiced support for Orbán, drawing criticism from opposition figures who described the remarks as inappropriate intervention in a domestic vote. Hungarian officials and pro-government voices have similarly accused EU institutions and Western actors of attempting to shape Hungary’s political direction, often pointing to funding for civil society groups and criticism from Brussels over rule-of-law concerns as evidence of outside pressure. Hungary’s relationship with Russia has become a central issue in the campaign. Orbán has maintained closer political and economic ties with Moscow than most EU leaders, including long-term energy agreements, and has opposed some EU measures supporting Ukraine. Orbán has defended that approach as pragmatic, citing Hungary’s reliance on Russian energy and the need to protect national economic interests. Analysts say the election could have implications beyond Hungary, particularly in EU decision-making, where Budapest has at times delayed or blocked consensus on sanctions and military assistance for Ukraine. Recent reporting has pointed to continued efforts by Orbán to deepen bilateral cooperation with the Kremlin. Documents recently reported by Politico indicate Hungary and Russia agreed on a 12-point plan covering areas including energy, education and cultural ties, underscoring the strategic importance both sides place on the relationship. The New York Times reported that Orbán’s stance on Russia and the war in Ukraine has become a defining dividing line in the campaign, quoting analyst Péter Krekó as saying Hungary’s relationship with Moscow reflects “open Russian cooperation” rather than covert interference. Hungarians go to the polls on Sunday. Alexander Martin is the UK Editor for Recorded Future News. He was previously a technology reporter for Sky News and a fellow at the European Cyber Conflict Research Initiative, now Virtual Routes. He can be reached securely using Signal on: AlexanderMartin.79
therecord.mediaApr 8, 2026extracted
FBI Warns of Data Security Risks From China-Made Mobile Apps
The FBI issued an alert on Tuesday warning users about the data security risks associated with foreign-developed mobile applications. The alert says many of the top-grossing and most-downloaded apps in the US are created by foreign companies, particularly those from China. The agency pointed out that apps maintaining digital infrastructure in China are subject to local laws, and the Chinese government could gain access to the data of mobile app users. The FBI’s alert does not name any specific applications, but prominent examples include TikTok and the shopping apps Shein and Temu — all widely used in the United States. The DeepSeek AI chatbot also fits the profile. US authorities have taken action against TikTok, Temu, and DeepSeek over national security or data security concerns. TikTok, which is used by more than 200 million Americans, recently finalized a deal to create a new entity that would help it avoid a ban in the United States. The FBI’s new alert warns users that the risky apps could collect their personal information, store user data in China, and some may even contain malware. “This could include malicious code and hard-to-remove malware designed to exploit known vulnerabilities in various operating systems and insert a backdoor for escalated privileges, such as enabling the download and execution of additional malicious packages designed to provide unauthorized access to users’ data,” the alert reads. The FBI has advised individuals to report suspicious activity related to foreign apps to the agency’s Internet Crime Complaint Center (IC3). This comes shortly after the FCC announced a ban on the acquisition of new consumer routers made outside the United States. Related: Cybersecurity Firms React to China’s Reported Software Ban Related: Canada Gives Hikvision the Boot on National Security Grounds Related: Google Disrupts Chinese Hackers Targeting Telecoms, Governments
securityweek.comApr 1, 2026extracted
30th March – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 30th March, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Iranian state-affiliated threat group Handala Hack has breached FBI director’s Patel’s personal Gmail account and leaked many personal photos and documents. This follows the FBI’s seizure of domains related to Handala Hack’s activity last week, due to the group’s sustained targeting of Israeli and American entities, which increased during the ongoing Iran conflict. Spain’s Port of Vigo in Galicia has suffered a ransomware attack that forced officials to disconnect parts of its network and switch cargo handling to manual processes. The incident locked equipment and disrupted digital logistics, while physical ship movement could continue without digital communication. The Netherlands’ Ministry of Finance has confirmed a March 19 cyberattack that breached internal systems in its policy department and disrupted work for some employees. Authorities blocked access to affected environments, while tax, customs, and benefits services remained unaffected and no threat actor publicly claimed responsibility for the attack. Decentralized finance platform Resolv has suffered a cyberattack after a compromised private key let an attacker mint about $80 million in uncollateralized USR tokens and swap them for 11,408 ETH worth $24.5 million. Resolv confirmed the incident, paused the app, and offered a 10% bounty for returned funds. AI THREATS Researchers demonstrated a supply chain compromise of LiteLLM, a Python library linking apps to major AI services, after attackers hijacked a security tool and pushed malicious releases on March 24. The tainted packages harvested API keys and cloud credentials, creating downstream exposure for widely used AI projects. Researchers outlined three high-severity vulnerabilities in LangChain and LangGraph, open-source frameworks for building AI assistants, that could expose files, environment secrets, and prior conversations. The flaws enabled arbitrary file access, secret leakage, and SQL injection in checkpointing, and patches were issued in updated components. Researchers identified a zero-click flaw in Anthropic’s Claude Chrome extension that let any website silently inject prompts and control the assistant. The attack combined an overly permissive trusted domain list with a scripting bug in Arkose Labs CAPTCHA handling, enabling token theft, chat access, and email actions. VULNERABILITIES AND PATCHES Cisco has addressed CVE-2026-20131, a CVSS 10 vulnerability in Secure Firewall Management Center that lets unauthenticated attackers execute code as root through the web interface. Cisco confirmed attempted exploitation in March 2026 and released fixes, while on-premises customers have no workaround beyond applying the updates. Check Point IPS provides protection against this threat (Cisco Secure Firewall Management Center Insecure Deserialization (CVE-2026-20131)) TP-Link has issued firmware updates addressing CVE-2025-15517 and related critical flaws in Archer NX200, NX210, NX500, and NX600 5G Wi-Fi routers. Attackers could access administrative functions without logging in, upload rogue firmware, execute system commands, and more. Citrix has released patches for CVE-2026-3055 and CVE-2026-4368 affecting NetScaler ADC and Gateway. The critical memory flaw can expose sensitive data in SAML Identity Provider deployments, while the second bug can mix up user sessions on gateways, creating confidentiality and access risks. Check Point IPS provides protection against this threat (Citrix NetScaler Out Of Bounds Read (CVE-2026-3055)) Researchers warn that a leaked ‘DarkSword’ iOS exploit chain enables no-click attacks via Safari, threatening up to 270 million unpatched iPhones and iPads. The code eases copycat attacks and has seen use, while Apple issued fixes, including March 11 emergency updates for iOS 15 and 16. THREAT INTELLIGENCE REPORTS Researchers revealed that cybercriminals are abusing Keitaro, a commercial adtech tracker, to distribute phishing, scams, and malware at scale. Infoblox linked the platform to major malvertising and spam operations, including campaigns impersonating Canadian banks, logistics brands, government services, and high-trust retail providers. Researchers analyzed three China-aligned activity clusters targeting a Southeast Asian government in a coordinated espionage operation. The campaign combined USB propagation, the Hypnosis loader, and the FluffyGh0st RAT, showing how distinct threat clusters can converge on one high-value government target with complementary tooling. Researchers have analyzed the activity of Russian threat group APT28 (aka Fancy Bear). The group has recently targeted Ukraine as well as its European defense supply chain partners with a toolset dubbed PRIXMES, which holds both espionage and sabotage capabilities. APT28 exploited multiple vulnerabilities, including zero-days, in its attacks. Researchers identified a coordinated adversary-in-the-middle phishing campaign targeting TikTok for Business users who sign in with Google. Attackers deployed proxy login pages that captured passwords and session cookies to bypass multi-factor authentication, with newly registered domains and Cloudflare-hosted infrastructure used to scale impersonation.
research.checkpoint.comMar 30, 2026extracted
European Parliament rejects extension of CSAM scanning rules for tech platforms
European Parliament rejects extension of CSAM scanning rules for tech platforms The European Parliament on Thursday voted against extending rules that have let tech companies hunt for child sexual abuse material (CSAM) by scanning their services. The law, which exempts platforms from strict privacy rules so they can scan for CSAM, lapses next Friday. When it does, tech companies will no longer be able to use certain scanning tools to detect the material and turn it over to law enforcement. The 311 members of Parliament who voted against an extension did so despite strong support from law enforcement, children’s rights groups, German Chancellor Friedrich Merz, several European commissioners and a half dozen big tech companies to allow the scans to continue. Critics have long held that scanning for CSAM allows mass surveillance and violates Europeans’ privacy rights, an argument that apparently resonated with many lawmakers. “This is actually just enabling big tech companies to scan all of our private messages, our most intimate details, all our private chats so it constitutes a really, really serious interference with our right to privacy,” said Ella Jakubowska, head of policy at the digital rights nonprofit eDRI. “It's not targeted against people that are suspected of child abuse — It's just targeting everyone, potentially all of the time.” Jakubowska also said there are no credible statistics showing that scanning is effective and cited cases where innocent people have been falsely accused of spreading CSAM because scanning tools are not as “robust as the developers of them claim they are.” Catherine De Bolle, the executive director of Europol, expressed alarm over Parliament’s vote, saying there has been a sharp increase in online CSAM recently and law enforcement will now be severely hindered when investigating it. De Bolle said in a statement that she is “deeply concerned about the potential operational impact” of the vote. Last year, Europol processed around 1.1 million so-called CyberTips alerting authorities to potential CSAM that were sourced as a result of the scanning, De Bolle said. She predicted a “serious reduction” in CyberTips moving forward and said Parliament’s actions will “undermine the capability to detect relevant investigative leads on CSAM, which in turn will severely impair the EU’s security interests of identifying victims and safeguarding children.” “From a law enforcement perspective, enabling online service providers to continue detecting and reporting suspected CSAM to the competent authorities is vital for the protection of children,” De Bolle said. The vote was the culmination of several weeks of infighting between Parliament and national governments and European commissioners who wanted the rules extended. The rule that Parliament failed to extend is a temporary one that has been in place since voluntary CSAM detection was last extended in 2024. Parliament has been negotiating a permanent framework since November 2023, but an agreement has been elusive due to strong disagreements. Tech companies are strong proponents of the scanning, saying it is a vital tool for protecting children. On March 19, tech giants including Google, Snapchat, Microsoft, TikTok and Meta released a statement saying they are “deeply concerned.” “Failure to act will reduce the legal clarity that has enabled companies for nearly 20 years to voluntarily detect and report known child sexual abuse material (CSAM) in interpersonal communication services, leaving children across Europe and around the world with fewer protections than they had before,” the statement said. The tech companies portrayed their tools for detecting CSAM as highly effective, saying they use hash matching to create digital fingerprints that identify known CSAM and match the “unique” hashes to previously identified material stored in a secure database. “The system ensures high-precision detection while adhering to privacy principles,” the statement said. Suzanne Smalley is a reporter covering digital privacy, surveillance technologies and cybersecurity policy for The Record. She was previously a cybersecurity reporter at CyberScoop. Earlier in her career Suzanne covered the Boston Police Department for the Boston Globe and two presidential campaign cycles for Newsweek. She lives in Washington with her husband and three children.
therecord.mediaMar 27, 2026extracted
New Wave of AiTM Phishing Targets TikTok for Business
Cybercriminals have recently deployed a new set of phishing pages designed to target TikTok for Business accounts by using TikTok- or Google-themed content. Push Security said it had identified a new wave of an Adversary-in-the-Middle (AiTM) phishing pages registered on March 24 within a nine-second window. The cluster of pages were all hosted behind Cloudflare with the same registrar, Nicenic International Group, which Push Security said is commonly abused for bulk phishing domain registration. The pages feature a common naming convention, being various derivations of welcome.careers*[.]com. The list of malicious domains in this style is expected to grow as the campaign ramps up, according to Push Security researchers. While the initial delivery mechanism has not been confirmed, Push Security said it is likely similar to a previously identified campaign reported by Sublime in October, which used dynamically generated emails and featured a cloned Google Careers page. When clicked, the link initially redirects users through a legitimate Google Cloud Storage site before loading the malicious page. The site employs a Cloudflare Turnstile check to prevent security bots from analyzing the page. Victims are presented with either TikTok- or Google-themed content. As users progress through the workflow, they are ultimately directed to an AiTM phishing page. In this instance the victim is required to complete a basic information form before being served with a malicious login page that is in fact fronting a reverse proxy AiTM phishing kit. Why Threat Actors Target TikTok TikTok for Business accounts commonly are used by company marketing teams to manage advertising campaigns. Push Security said the development of targeting TikTok is “notable” given most phishing pages the threat researchers intercept ten to replicate SSO platforms like Google and Microsoft. “TikTok seems a weird choice at first glance. But it makes more sense when we consider that TikTok has been historically abused to distribute malicious links and social engineering instructions,” Push Security said in a blog published on March 26. The platform has been used to deliver infostealers via ClickFix-style instruction with AI-generated videos posed as activation guides for Windows, Spotify and CapCut. The social media platform is also a “common hunting ground” for crypto scammers. It was noted that since most users will opt to “log in with Google” anyone using Google to login to their TikTok account will effectively have both accounts used to distribute ads compromised in one go. This could start a Google Ad Manager exploitation chain where cybercriminals target ad manager accounts to power malvertising scams. Update, April 1, 2026: TikTok confirmed to Infosecurity that the domains mentioned in the report have been officially taken down and are no longer active. Image credit: JarTee / Shutterstock.com
infosecurity-magazine.comMar 27, 2026extracted
AitM Phishing Targets TikTok Business Accounts Using Cloudflare Turnstile Evasion
Threat actors are using adversary-in-the-middle (AitM) phishing pages to seize control of TikTok for Business accounts in a new campaign, according to a report from Push Security. Business accounts associated with social media platforms are a lucrative target, as they can be weaponized by bad actors for malvertising and distributing malware. "TikTok has been historically abused to distribute malicious links and social engineering instructions," Push Security said. "This includes multiple infostealers like Vidar, StealC, and Aura Stealer delivered via ClickFix-style instructions with AI-generated videos posed as activation guides for Windows, Spotify, and CapCut." The campaign begins with tricking victims into clicking on a malicious link that directs them to either a lookalike page impersonating TikTok for Business or a page that's designed to impersonate Google Careers, along with an option to schedule a call to discuss the opportunity. It's worth noting that a prior iteration of this credential phishing campaign was flagged by Sublime Security in October 2025, with emails masquerading as outreach messages used as a social engineering tactic. Regardless of the type of page served, the end goal is the same: perform a Cloudflare Turnstile check to block bots and automated scanners from analyzing the contents of the page and serve a malicious AitM phishing page login page that's designed to steal their credentials. The phishing pages are hosted on the following domains - welcome.careerscrews[.]com welcome.careerstaffer[.]com welcome.careersworkflow[.]com welcome.careerstransform[.]com welcome.careersupskill[.]com welcome.careerssuccess[.]com welcome.careersstaffgrid[.]com welcome.careersprogress[.]com welcome.careersgrower[.]com welcome.careersengage[.]com welcome.careerscrews[.]com The development comes as another phishing campaign has been observed using Scalable Vector Graphics (SVG) file attachments to deliver malware to targets located in Venezuela. According to a report published by WatchGuard, the messages have SVG files with file names in Spanish, masquerading as invoices, receipts, or budgets. "When these malicious SVGs are opened, they communicate with a URL that downloads the malicious artifact," the company said. "This campaign uses ja.cat to shorten URLs from legitimate domains that have a vulnerability that allows redirects to any URL, so they point to the original domain where the malware is downloaded." The downloaded artifact is a malware written in Go that shares overlaps with a BianLian ransomware sample detailed by SecurityScorecard in January 2024. "This campaign is a strong reminder that even seemingly harmless file types like SVGs can be used to deliver serious threats," WatchGuard said. "In this case, malicious SVG attachments were used to initiate a phishing chain that led to malware delivery associated with BianLian activity."
thehackernews.comMar 27, 2026extracted
TikTok for Business accounts targeted in new phishing campaign
Threat actors are targeting TikTok for Business accounts in a phishing campaign that prevents security bots from analyzing malicious pages. TikTok Business accounts may be targeted due to their high potential for abuse in malvertising campaigns, ad fraud, and the distribution of malicious content. Browser threat detection and response company Push Security links the campaign to one documented last year, which targeted Google Ad Manager accounts. TikTok has previously been used to spread information-stealing malware via malicious videos, as well as cryptocurrency scams via fake promotions. TikTok for Business accounts are ideal for such purposes due to their increased reach and perceived legitimacy. In a report shared with BleepingComputer, Push Security says that victims are lured to Cloudflare-hosted phishing pages registered on March 24 via NiceNIC, a registrar often reported by cybersecurity researcher for being used for cybercriminal activities. Push Security could not determine the initial delivery mechanism, but believes that the threat actor uses a similar method as observed in activity reported by Sublime Security. The initial link redirects via a legitimate Google Storage URL, blocks bots using a Cloudflare Turnstile check, and then redirects to the malicious pages. The domains (now taken down) feature similar names, and are all hosted on the same Google Storage bucket: welcome.careerscrews[.]com welcome.careerstaffer[.]com welcome.careersworkflow[.]com welcome.careerstransform[.]com welcome.careersupskill[.]com welcome.careerssuccess[.]com welcome.careersstaffgrid[.]com welcome.careersprogress[.]com welcome.careersgrower[.]com welcome.careersengage[.]com welcome.careerscrews[.]com The malicious pages impersonate TikTok for Business and Google Careers “Schedule a Call” pages, requesting visitors to enter basic information in a form to validate they’re using a business email address. After this step, victims are served a fake login page, which is a reverse proxy designed to capture credentials and session cookies, and to exfiltrate them to the attacker. Since the page acts as an intermediary between the legitimate user and the service, the threat actor can hijack accounts even when the two-factor authentication (2FA) protection is active. Push Security also notes that business account holders often log into TikTok via Google single sign-on (SSO) service. "This means that anyone using Google to login to their TikTok account will effectively have both accounts used to distribute ads compromised in one go." Users should be extremely cautious with suspicious invites and job offers, and never trust links sent from unknown contacts. Always check the domain before entering credentials, and use passkeys to protect valuable accounts. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comMar 26, 2026extracted
UK pilot program to test social media restrictions on families before government decides on ban
UK pilot program to test social media restrictions on families before government decides on ban The U.K. government will try out various social media restrictions on certain families as part of a pilot program to inform its decisionmaking about a potential social media ban for some teens. The move comes amid an ongoing public consultation to determine how to move forward with potential social media restrictions, whether to raise the digital age of consent and how to use age assurance technologies most effectively. In January, Prime Minister Keir Starmer promised action, saying that “for too many today, [social media use] means being pulled into a world of endless scrolling, anxiety and comparison.” The four pilot programs announced Wednesday will involve hundreds of families from all four nations of the U.K. Each of the four pilot groups will be assigned a different intervention and will participate in the pilot for six weeks. One group of parents will be taught how to use parental controls “to remove or entirely disable access to selected social media apps, practically mimicking the enforcement of a social media ban at home,” the U.K.’s Department for Science, Innovation and Technology (DSIT) said in a press release. A second group will impose a one-hour-per-day limit on the most popular social media apps for teenagers, including Instagram, TikTok and Snapchat. A third group will disable social media for their children between 9 p.m. and 7 a.m, and the final group will serve as a control and will give children the same access to social media as always. Parents and children will be interviewed at the start and finish of the pilots to “understand the impact limiting social media has had on their family life, sleep and schoolwork,” the press release said. The government also will be able to learn from parents about the challenges faced when setting up parental controls or about whether their teens found ways around the restrictions. DSIT launched its consultation about potential social media restrictions on March 2 and has said it will end on May 26. Nearly 30,000 parents and children have already responded to the consultation survey, the department said. The government has said it is “committed to taking swift action on its findings.” In February, Starmer announced new legal powers that will give the government the ability to move quickly after the consultation process ends, with action expected without waiting for new legislation. The government has said it will announce its plans this summer. Suzanne Smalley is a reporter covering digital privacy, surveillance technologies and cybersecurity policy for The Record. She was previously a cybersecurity reporter at CyberScoop. Earlier in her career Suzanne covered the Boston Police Department for the Boston Globe and two presidential campaign cycles for Newsweek. She lives in Washington with her husband and three children.
therecord.mediaMar 24, 2026extracted
FriendlyDealer mimics official app stores to push unvetted gambling apps
We’ve identified a huge social-engineering campaign designed to steer people into online gambling sites under the impression they’re installing a legitimate app. We’re calling it FriendlyDealer. It’s been observed across at least 1,500 domains, each hosting a website that impersonates the Google Play or Apple App Store. Users think they’re downloading a gambling app from a trusted source, with all the checks, reviews, and safeguards that implies. But they’re actually still on a website, installing a web app that then redirects them to casino offers through affiliate links. The campaign doesn’t steal passwords or install traditional malware. Instead, it makes money through commissions every time someone signs up or deposits money at one of these sites. That might sound less serious than a banking Trojan, but the end result is people being funneled into unregulated gambling sites with no age verification, no deposit limits, and no consumer protections. And it comes at a time when gambling addiction is being called the fastest explosion of gambling the country has ever seen. One kit, dozens of apps, built to mimic real app stores FriendlyDealer is built as a single, reusable kit that can generate many different fake app listings. The kit detects what device you’re using and shows you a different fake store accordingly. Android users see a fake Google Play Store. iPhone users see a fake Apple App Store. The kit even loads the correct system fonts for each platform (Google Sans on Android, San Francisco on iOS) so the typography matches what you’d expect on your own phone. Under the hood, it’s a single web application that reads all of its content from one configuration file embedded in the page. Change that file, and you get a completely different app listing running on the same code. The operators have used this to spin up at least twenty casino brands, from “Tower Rush” (189 deployments) to “Chicken Road” (97) to “BEAST GAMES: ICE FISHING” (43), which impersonates YouTube creator MrBeast. (It’s worth noting that some skins reuse the names of some legitimate gambling brands but none of these are affiliated with the operation.) The reviews are fake. Different apps reuse identical usernames, profile photos, text, and developer replies, and they’re repeated across multiple brands. Before showing the fake store, the kit can also display a simple casino mini-game to build engagement. The fake “Install” button on Android relies on a Chrome feature that only works on mobile. It captures Chrome’s install prompt and triggers it when tapped, so a real installation dialog appears. The usual warning about installing apps from unknown sources does not appear. Previous research has shown that apps installed this way can even display “Installed from Google Play Store” in your phone’s settings. The code goes to extraordinary lengths to get you into the right browser. If you arrive through a Facebook or Instagram ad, you’re inside those apps’ built-in browser, which can’t trigger the install. On Android, the kit generates a special link that forces the page to reopen in Chrome. On iOS, it does the same thing but for Safari. If Chrome isn’t installed, the fallback sends you to the real Play Store to download it. There’s even a separate handler for Samsung’s browser. The browser-specific engineering is unusually detailed. The page disables zooming, making close inspection harder. The kit assigns a per-user tracking ID and reuses it across analytics, event, push-registration, and offer-routing flows. The kit is wired for paid advertising. The configuration includes empty slots for tracking pixels from four ad platforms: Google, Yandex, Facebook, and TikTok. The app and background script can forward Facebook-style ad identifiers (_fbc / _fbp) when those values are available. The code references Yandex telemetry fields and ships with Russian-language comments and debug strings, which is consistent with a Russian-speaking development context, though those artefacts could also have been inherited from a reused or purchased kit. The flow is straightforward: buy ad traffic, detect the device, show a fake app store, trigger a real-looking install, and redirect to a casino through an affiliate link. You’re not installing an app When a user taps Install, the page doesn’t actually download an app. Instead, the browser creates what’s called a Progressive Web App (PWA). It’s essentially a website that behaves like an app, with its own icon on your home screen and its own splash screen. To most people it’s indistinguishable from a real app. Once installed, the app can keep running in the background using browser features called service workers (keeping a persistent connection to your device). The samples include the main PWA worker and code to register a separate push worker (to send you notifications) when enabled. The kit also knows when you’ve already installed it. It checks your device for its own PWA, and if it finds it, it skips the fake store entirely and sends you straight to the casino. One domain ties it all together Every FriendlyDealer deployment phones home to the same domain: ihavefriendseverywhere[.]xyz. This is the campaign’s data-collection server, and the name that inspired our tracking name for the operation. The background script and app code send telemetry to this domain including browser language, timezone, user-agent data, optional user-agent client hints, campaign identifiers, and ad identifiers when those values are available. Much of this is sent via custom request headers. Some requests use the HEAD method to stay lightweight. The application code also sends something the background script doesn’t: JavaScript error reports. Every crash, every failed resource load, every unhandled exception that occurs on the victim’s device is caught, packaged into a structured error object with a timestamp and context, and posted to ihavefriendseverywhere[.]xyz/api/log_standard_err. In effect, the operators are collecting both user data and production error telemetry from real devices. If a request fails (for example, due to poor signal), the background script stores it locally and retries later. Once the connection returns, the data is sent automatically. The fake app also asks for notification permission. If the user grants it, the kit can register a push subscription and create a direct channel for future notifications. These appear like normal app notifications, giving the operators a direct line back to the user even after the app is closed. Follow the money: affiliate commissions, not malware FriendlyDealer doesn’t spread viruses or take over devices. The entire operation runs on affiliate commissions. Each fake app store page contains a hidden redirect to an affiliate tracking network. When a user signs up or deposits money, the operator gets paid. We found multiple affiliate tracking networks in the code. A per-user ID appears across the kit’s analytics, event, push, and offer-routing logic, allowing activity to be correlated across multiple stages of the funnel. This model explains the campaign’s enormous scale. Each domain is disposable. The kit is a template; change one configuration file and you have a new casino brand on a new domain in minutes. With gambling affiliate payouts reportedly ranging from $50 to $400 per depositing user, even a small conversion rate across a thousand domains adds up fast. Who’s behind this? We can’t attribute the campaign to a specific group, but there are clues. The source code contains Russian-language comments (for example, “Создаем таймер для измерения времени загрузки Vue “). One of the builds shipped with unstripped Russian debug strings that were scrubbed from the production version. The code integrates with Yandex Metrica, which is popular in Russia and the former Soviet states. These point to a Russian-speaking development context, although the code could have been reused or purchased. The code also contains affiliate marketing tags—preland-alias and preland-final-action—where a “pre-lander” is the page a visitor sees before the actual offer. The application code shows this tag controls the kit’s behavior: a value of 0 triggers a PWA install, while 1 redirects to an app store. Combined with plug-and-play ad pixel slots, per-deployment configuration, and staging/production logic, this strongly suggests a reusable kit built for multiple campaigns or operators, not a one-off project. We found multiple builds of the same kit. The production version has debug messages removed, but other builds include full Russian-language error messages and support for Arabic numerals across the interface—download counts, ratings, review dates, and more. This does not look like a kit built for a single market; it appears designed to support regional variants at build time. A familiar trick with a different payoff Fake app store pages are a known technique, often used to steal banking credentials or deliver spyware. FriendlyDealer uses the same playbook, a convincing fake store and a real-looking install flow, but with a different goal. It doesn’t take over your phone or steal your passwords. It steers you toward gambling platforms and earns a commission when you spend money. The harm is financial rather than technical: victims are funneled toward gambling offers through deceptive install and redirect flows, and may end up depositing money at sites they did not intentionally choose. It’s also s a reminder that not every scam is after your passwords. Affiliate fraud, especially in online gambling, can fund enormous operations without ever touching a single credential. The people behind this built a factory: one template, twenty brands, more than 1,500 domains. Paid ads bring the traffic. The fake app stores seal the deal. The affiliate network pays the bills. What makes this effective is that it abuses things that are supposed to be trustworthy. Chrome’s app installation flow on Android and Safari’s “Add to Home Screen” on iPhone are both legitimate features, doing what they were designed to do. The problem is that the page triggering the install is a lie. The kit is carefully engineered so only the right users, on the right devices, coming from the right ads, ever see it. What to do if you installed one of these apps On Android: Remove the app: Long-press the icon and tap Uninstall, or go to Settings > Apps and remove anything you don’t recognize. Clear the site data in Chrome: The app may leave data behind in your browser. Open Chrome > Settings > Site settings > All sites, find the site, and tap Clear & reset. Check notification permissions: Go to Chrome > Settings > Notifications and remove any sites you don’t recognize. Uninstalling the app does not remove notification access. Check other browsers: If you use Edge, Brave, or another Chromium-based browser, repeat the same steps there. On iPhone: Remove the app: Long-press the app icon on your home screen and tap Remove App. On iOS, PWAs don’t install a background script the way they do on Android, so removing the icon also removes the cached site data. Clear the site data in Safari: Go to Settings > Safari > Advanced > Website Data, and search for the domain. Swipe to delete it. This clears any remaining cookies and stored data. Check notification permissions: Go to Settings > Apps > Safari. Scroll to the Settings for Websites section and tap Notifications. Find the site and remove or deny access. If you deposited money after being routed through one of these pages and believe you were deceived, contact your bank or payment provider promptly. Indicators of Compromise (IOCs) Domains ihavefriendseverywhere[.]xyz —Data exfiltration and error-logging server valor[.]bet —Gate/checkpoint URL (/__pwa_gate path) wikis[.]lifestyle —Hardcoded domain reference in application code Scammers know more about you than you think. Malwarebytes Mobile Security protects you from phishing, scam texts, malicious sites, and more. With real-time AI-powered Scam Guard built right in.
malwarebytes.comMar 23, 2026extracted
90% of people don’t trust AI with their data
AI didn’t sneak into our lives. It burst through the door, took a seat at the table, and started finishing our sentences. Instead of a helpful list of links, Google now tries to answer your question. Microsoft’s Copilot drafts replies to your boss before you’ve had coffee. Your phone summarizes conversations you don’t even remember having. Every major tech company is racing to add AI to its products because no one wants to be left behind. And the public is often forced to accommodate such corporate whims because of the increasing effects of “enshittification,” as explained by Cory Doctorow on the Lock and Code podcast. People are using AI. But they don’t trust it. In our latest privacy pulse survey, in which we gathered 1,200 responses from readers of the Malwarebytes newsletter earlier this year, 90% of respondents said they’re worried about AI using their data without consent. Ninety per cent. That’s not a few skeptics. That’s nearly everyone we asked. We admit, our sample is probably skewed towards the privacy conscious. But 90% of people who follow Malwarebytes are worried about how much personal data AI is slurping up, and what it’s going to do with it, so that’s a good barometer for how much everyone should care. That concern is changing the way people are using the internet: 88% do not “freely share personal information with AI tools like ChatGPT and Gemini” 84% have not “shared personal health information with AI tools” 43% have “stopped using ChatGPT” 42% have “stopped using Gemini” This distrust didn’t start with AI Of course, AI gets all the headlines. We write about many of them. But people have been concerned about holding onto their personal information for a long time. From the survey: 92% are concerned about their “personal data being used inappropriately by corporations,” which is up slightly from last year (89% in 2025) 74% are concerned about their “personal data being accessed and used inappropriately by the government” (up from 72%) Years of data breaches, shady tracking practices, and dangerous misuse by data brokers have chipped away at our confidence in organizations to protect our data. Over the past year, healthcare organizations have continued to report major security lapses affecting sensitive patient data. The FTC warned about “staggering” commercial surveillance practices that most consumers never agreed to, and, according to our survey, 49% of people reported that their personal info has been used in scams that target them or their family. Is AI really any different to, say, social media? When people use social media, they generally understand their clicks and likes are being tracked. When they shop online, they expect the shop to store their purchase histories or track the items they were interested in. They understand the concept of advertising and see how it slots into social or commercial websites. AI tools are different because we use them differently. When we share ideas, client meeting notes, personal dilemmas, and health questions with an AI assistant, we are treating them as a confidant. Maybe we’ve paid for an access level that promises not to train its models on our data. Even when we’re chatting about flat-packs and missing screws with a site’s AI chatbot, we behave as if we’re talking to another person, and not broadcasting that conversation to the world. The interaction with AI feels intimate and conversational, even though we’re all aware we’re talking with a bot. That makes the uncertainty around how that AI handles the data we’ve fed it more personal, more immediate. We know that AI assistants from a company are often plugged into other tools. We know GPTs can be created by any developer or scammer. (Check out Malwarebytes in ChatGPT—we’re one of the good guys). We know nearly every business or personal platform now has some form of AI-based data-gathering element. What the average person doesn’t know about AI feels scary. Where are our prompts stored? Are those prompts are used to train the AI? How long are they kept? Can anyone inside the company read them? Can they be bought? Used for advertising? Leaked?… Yes, companies publish policies, but who in the real and busy world reads all those before we use the tool? Fewer than half, but a growing number, with 48% said they now read privacy policies and reports—up from 43% in 2025. Besides, we know from recent headlines that companies are rushing out AI features before they’ve had time to properly security-check them. A glimmer of hope: People are taking action This result from the survey caught our eye. 63% of respondents agreed with the statement: “I feel resigned that my personal data is already out there, and I can’t get it back.” Last year, that number was 74%. So, while concern about data misuse is still high, fewer people feel entirely helpless. Respondents reported taking practical steps to limit their data exposure. Some have reduced or stopped their use of certain platforms entirely because of privacy concerns, including social media (44% have stopped using Instagram, 37% have stopped using Facebook, and 49% have stopped using Tiktok) and AI tools (43% have stopped using ChatGPT, 42% have stopped using Gemini). Others reported sharing less personal information online or avoiding sensitive topics in digital conversations (88% said they do not freely share personal information with AI tools). There is also increased use of privacy-protective tools for their data, devices, and identities. 46% use a VPN (up from 42% in 2025) 40% have an identity theft protection solution (down from 43%) 25% use a personal data removal service or solution (up from 23%) 71% use an ad blocker for online browsing (up from 69%) 48% read privacy policies and reports (up from 43%) 76% use MFA (up from 69%) 82% opt-out of data collection, as possible (up from 75%) 38% use fake/dummy data online whenever possible (up from 33%) None of these actions erase historical data trails, but they do limit new exposure. David Ruiz, senior privacy advocate at Malwarebytes, said: “Twenty years of online innovation have pointed too many companies in the same direction—against everyday people. For most people today, the corporations that are pressing AI tools into their daily lives are the same corporations that have monetized their attention spans, invaded their privacy, and lost their data to breaches. But a counterforce is emerging. The small changes in user behavior should encourage others to understand that, even now, privacy remains possible and worthwhile.” Privacy protection can feel binary: either everything is exposed or everything is secure. But it’s incremental, and the survey responses reflect how people are starting to take back control of their data. What this means for companies Organizations adding AI into their products face a more complex audience than they might have first assumed. For years, product teams have assumed users would trade more data for more convenience. But when nearly nine in ten people said they’re concerned about AI using their data without consent, trust becomes part of the product itself. Mozilla jumped on this and added a simple “turn off AI” button to Firefox. It’s no longer enough to highlight what AI can do. Users want to understand what happens after they press “submit.” We the People… want strong privacy laws When concern reaches the sort of level we’ve seen in our survey, it inevitably raises the thorny question of regulation. 91% of respondents said they “support national laws regulating how companies can collect, store, share, or use our personal data.” The issue is less about one tool and more about a sense that the guardrails are unclear. Generative AI systems can draft legal documents, write emails, and process sensitive data at speed. Much of the existing privacy frameworks in the US, EU, and other regions were written before AI was commonplace. Regulators are trying to catch up. The European Union’s AI Act, passed in 2024, introduced a risk-based approach to governing certain AI systems. In the US, federal agencies including the FTC have issued guidance and warnings around commercial surveillance and automated decision-making, but it does not yet have a comprehensive AI-specific privacy statute. Desire for national laws and regulation is at an all-time high. Consumers want boundaries that are understandable and enforceable. What you can do We’re clearly not going to abandon all technology. AI isn’t going to eat itself out of existence. It can be pretty useful. We use AI to find threats and scams no one’s seen before, which leads to far better protection. We also use generative AI in Scam Guard to provide 24/7 chat assistance (paired with our deep threat research expertise, of course). Many people use them to save time, draft documents, or explore ideas. Also, sadly, to create little caricatures of themselves. The key here is thoughtful use. Limit what information you give to public AI tools, especially health details, financial data, and client-sensitive information. Review the privacy and data retention policies of AI tools you use regularly. Delete accounts and apps you no longer need. Audit app permissions at least twice a year. Use a VPN to reduce tracking by your internet service provider. Remove your information from major data broker sites. Check whether your personal info is exposed with a Digital Footprint scan. Use a reputable password manager and avoid reusing passwords across services. At Malwarebytes, we believe privacy is a human right. Protecting personal data is inseparable from protecting personal security. The more information that circulates without oversight, the greater the opportunity for misuse, fraud, and harm. AI will continue to develop. That trajectory is unlikely to slow. The question is whether trust will grow alongside it. Survey information Malwarebytes conducted a pulse survey of its newsletter readers between January 26 and February 3, 2026, via the Alchemer Survey platform. In total, 1,235 people responded from 72 counties, with most respondents from the US, UK, Canada and Australia.
malwarebytes.comMar 17, 2026extracted
⚡ Weekly Recap: Chrome 0-Days, Router Botnets, AWS Breach, Rogue AI Agents & More
Some weeks in security feel normal. Then you read a few tabs and get that immediate “ah, great, we’re doing this now” feeling. This week has that energy. Fresh messes, old problems getting sharper, and research that stops feeling theoretical real fast. A few bits hit a little too close to real life, too. There’s a good mix here: weird abuse of trusted stuff, quiet infrastructure ugliness, sketchy chatter, and the usual reminder that attackers will use anything that works. Scroll on. You’ll see what I mean. ⚡ Threat of the Week Google Patches 2 Actively Exploited Chrome 0-Days — Google released security updates for its Chrome web browser to address two high-severity vulnerabilities that it said have been exploited in the wild. The vulnerabilities related to an out-of-bounds write vulnerability in the Skia 2D graphics library (CVE-2026-3909) and an inappropriate implementation vulnerability in the V8 JavaScript and WebAssembly engine (CVE-2026-3910) that could result in out-of-bounds memory access or code execution, respectively. Google did not share additional details about the flaws, but acknowledged that there exist exploits for both of them. The issues were addressed in Chrome versions 146.0.7680.75/76 for Windows and Apple macOS, and 146.0.7680.75 for Linux. Detection Starts the Clock. Response Decisions Shape the Outcome When incidents escalate, early decisions determine containment and impact. Join this SANS IR Command Roundtable to learn how experienced teams avoid investigation drift, improve coordination, and execute faster response across cloud, enterprise, and operational environments. Watch the Webcast ➝ 🔔 Top News Meta to Discontinue Instagram E2EE in May 2026 — Meta announced plans to discontinue support for end-to-end encryption (E2EE) for chats on Instagram after May 8, 2026. In a statement shared with The Hacker News, a Meta spokesperson said, "Very few people were opting in to end-to-end encrypted messaging in DMs, so we're removing this option from Instagram in the coming months. Anyone who wants to keep messaging with end-to-end encryption can easily do that on WhatsApp." Authorities Disrupt SocksEscort Service — A court-authorized international law enforcement operation dismantled a criminal proxy service named SocksEscort that enslaved thousands of residential routers worldwide into a botnet for committing large-scale fraud. "The malware allowed SocksEscort to direct internet traffic through the infected routers. SocksEscort sold this access to its customers," the U.S. Justice Department said. The main thing to note here is that SocksEscort was powered by AVrecon, a malware written in C to explicitly target MIPS and ARM architectures via known security flaws in edge network devices. The malware also featured a novel persistence mechanism that involved flashing custom firmware, which intentionally disables future updates, permanently transforming SOHO routers into SocksEscort proxy nodes to blindside corporate monitoring. UNC6426 Exploits nx npm Supply Chain Attack to Gain AWS Admin Access in 72 Hours — A threat actor known as UNC6426 leveraged keys stolen following the supply chain compromise of the nx npm package in August 2025 to completely breach a victim's AWS environment within 72 hours. UNC6426 used the access to abuse the GitHub-to-AWS OpenID Connect (OIDC) trust and create a new administrator role in the cloud environment, Google said. Subsequently, this role was abused to exfiltrate files from the client's Amazon Web Services (AWS) Simple Storage Service (S3) buckets and perform data destruction in their production cloud environments. KadNap Enslaves Network Devices to Fuel Illegal Proxy — A takedown-resistant botnet comprising more than 14,000 routers and other network devices has been conscripted into a proxy network that anonymously ferries traffic used for cybercrime. The botnet, named KadNap, exploits known vulnerabilities in Asus routers (among others), leveraging the initial access to drop shell scripts that reach out to a peer-to-peer network based on Kademlia for decentralized control. Infected devices are being used to fuel a proxy service named Doppelganger that, for a fee, tunnels customers' internet traffic through residential IP addresses, offering a way for attackers to blend in and make it harder to differentiate malicious traffic from legitimate activity. APT28 Strikes with Sophisticated Toolkit — The Russian threat actor known as APT28 has been observed using a bespoke toolkit in recent cyber espionage campaigns targeting Ukrainian cyber assets. The primary components of the toolkit are two implants, one of which employs techniques from a malware framework the threat actor used in 2010s, while the other is a heavily modified version of the COVENANT framework for long-term spying. COVENANT is used in concert with BEARDSHELL to facilitate data exfiltration, lateral movement, and execution of PowerShell commands. Also alongside these tools is a malware named SLIMAGENT that shares overlaps with XAgent. ️🔥 Trending CVEs New vulnerabilities show up every week, and the window between disclosure and exploitation keeps getting shorter. The flaws below are this week's most critical — high-severity, widely used software, or already drawing attention from the security community. Check these first, patch what applies, and don't wait on the ones marked urgent — CVE-2026-3909, CVE-2026-3910, CVE-2026-3913 (Google Chrome), CVE-2026-21666, CVE-2026-21667, CVE-2026-21668, CVE-2026-21672, CVE-2026-21708, CVE-2026-21669, CVE-2026-21671 (Veeam Backup & Replication), CVE-2026-27577, CVE-2026-27493, CVE-2026-27495, CVE-2026-27497 (n8n), CVE-2026-26127, CVE-2026-21262 (Microsoft Windows), CVE-2019-17571, CVE-2026-27685 (SAP), CVE-2026-3102 (ExifTool for macOS), CVE-2026-27944 (Nginx UI), CVE-2025-67826 (K7 Ultimate Security), CVE-2026-26224, CVE-2026-26225 (Intego X9), CVE-2026-29000 (pac4j-jwt), CVE-2026-23813 (HPE Aruba Networking AOS-CX), CVE-2025-12818 (PostgreSQL), CVE-2026-2413 (Ally WordPress plugin), CVE-2026-0953 (Tutor LMS Pro WordPress plugin), CVE-2026-25921 (Gogs), CVE-2026-2833, CVE-2026-2835, CVE-2026-2836 (Cloudflare Pingora), CVE-2026-24308 (Apache ZooKeeper), CVE-2026-3059, CVE-2026-3060, CVE-2026-3989 (SGLang), CVE-2026-0231 (Palo Alto Networks Cortex XDR Broker VM), CVE-2026-20040, CVE-2026-20046 (Cisco IOS XR Software), CVE-2025-65587 (graphql-upload-minimal), CVE-2026-3497 (OpenSSH), CVE-2026-26123 (Microsoft Authenticator for Android and iOS), and CVE-2025-61915 (CUPS). 🎥 Cybersecurity Webinars Stop Guessing: Automate Your Defense Against Real-World Attacks → Learn how to move beyond basic security checklists by using automation to test your defenses against real-world attacks. Experts will show you why traditional testing often fails and how to use continuous, data-driven tools to find and fix gaps in your protection. You will learn how to prove your security actually works without increasing your manual workload. Fix Your Identity Security: Closing the Gaps Before Hackers Find Them → This webinar covers a new study about why many companies are struggling to keep their user accounts and digital identities safe. Experts share findings from the Ponemon Institute on the biggest security gaps, such as disconnected apps and the new risks created by AI. You will learn simple, practical steps to fix these problems and get better control over who has access to your company's data. The Ghost in the Machine: Securing the Secret Identities of Your AI Agents → As artificial intelligence (AI) begins to act on its own, businesses face a new challenge: how to give these "AI agents" the right digital IDs. This webinar explains why current security for humans doesn't work for autonomous bots and how to build a better system to track what they do. You will learn simple, real-world steps to give AI agents secure identities and clear rules, ensuring they don't accidentally expose your private company data. 📰 Around the Cyber World Fake Google Security Check Drops Browser RAT — A web page mimicking a Google Account security page has been spotted delivering a fully featured browser-based surveillance toolkit that takes the form of a Progressive Web App (PWA). "Disguised as a routine security checkup, it walks victims through a four-step flow that grants the attacker push notification access, the device's contact list, real-time GPS location, and clipboard contents—all without installing a traditional app," Malwarebytes said. "For victims who follow every prompt, the site also delivers an Android companion package introducing a native implant that includes a custom keyboard (enabling keystroke capture), accessibility-based screen reading capabilities, and permissions consistent with call log access and microphone recording." Forbidden Hyena Delivers BlackReaperRAT — A hacktivist group known as Forbidden Hyena (aka 4B1D) has distributed RAR archives in December 2025 and January 2026 in attacks targeting Russia that led to the deployment of a previously undocumented remote access trojan called BlackReaperRAT and an updated version of the Blackout Locker ransomware, referred to as Milkyway by the threat actors. BlackReaperRAT is capable of running commands via "cmd.exe," uploading/downloading files, spawning an HTTP shell to receive commands, and spreading the malware to connected removable media. "It carries out destructive attacks against organizations across various sectors located within the Russian Federation," BI.ZONE said. "The group publishes information regarding successful attacks on its Telegram channel. It collaborates with the groups Cobalt Werewolf and Hoody Hyena." Chinese Hackers Target the Persian Gulf region with PlugX — A China-nexus threat actor, likely suspected to be Mustang Panda, has targeted countries in the Persian Gulf region. The activity took place within the first 24 hours of the ongoing conflict in the Middle East late last month. The campaign used a multi-stage attack chain that ultimately deployed a PlugX backdoor variant. "The shellcode and PlugX backdoor used obfuscation techniques such as control flow flattening (CFF) and mixed boolean arithmetic (MBA) to hinder reverse engineering," Zscaler said. "The PlugX variant in this campaign supports HTTPS for command-and-control (C2) communication and DNS-over-HTTPS (DOH) for domain resolution." Phishing Campaign Uses SEO Poisoning to Steal Data — A phishing campaign has employed SEO poisoning to direct search engine results to fake traffic ticket portals that impersonate the Government of Canada and specific provincial agencies. "The campaign lures victims to a fake 'Traffic Ticket Search Portal' under the pretense of paying outstanding traffic violations," Palo Alto Networks Unit 42 said. "Submitted data includes license plates, address, date of birth, phone/email, and credit card numbers." The phishing pages utilize a "waiting room" tactic where the victim's browser polls the server every two seconds and triggers redirects based on specific status codes. Roundcube Exploitation Toolkit Discovered — Hunt.io said it discovered a Roundcube exploitation toolkit on an internet-exposed directory on 203.161.50[.]145. It's worth noting that Russian threat actors like APT28, Winter Vivern, and TAG-70 have repeatedly targeted Roundcube vulnerabilities to breach Ukrainian organizations. "The directory included development and production XSS payloads, a Flask-based command-and-control server, CSS-injection tooling, operator bash history, and a Go-based implant deployed on a compromised Ukrainian web application," the company said, attributing it with medium to high confidence to APT28, citing overlaps with Operation RoundPress. The toolkit, dubbed Roundish, supports credential harvesting, persistent mail forwarding, bulk email exfiltration, address book theft, and two-factor authentication (2FA) secret extraction, mirroring a feature present in MDAEMON. One of the primary targets of the attack is mail.dmsu.gov[.]ua, a Roundcube webmail instance associated with Ukraine's State Migration Service (DMSU). Besides the possibility of a shared development lineage, Roundish introduces four new components not previously documented in APT28 webmail activity, including a CSS-based side-channel module, browser credential stealer, and a Go-based backdoor that provides persistence via cron, systemd, and SELinux. The CSS injection component is designed to progressively extract characters from Roundcube's document object model (DOM) without injecting any JavaScript into the victim's page. The technique is likely used for targeting Cross-Site Request Forgery (CSRF) tokens or email UIDs. Central to the Roundish toolkit is an XSS payload that's engineered to steal the victim's email address, harvest account credentials, redirect all incoming emails to a Proton Mail address, export mailbox data from the victim's Inbox and Sent folders, and gather the victim's complete address book. "The combination of hidden autofill credential harvesting, server-side mail forwarding persistence, bulk mailbox exfiltration, and browser credential theft reflects a modular approach designed for sustained access," Hunt.io said. "From a defensive perspective, password resets alone are not sufficient in cases like this. Mail forwarding rules, Sieve filters, and multi-factor authentication secrets must be audited and reset." Phishing Campaign Targeting AWS Console Credentials — An active adversary-in-the-middle (AiTM) phishing campaign is using fake security alert emails to steal AWS Console credentials, per Datadog. "The phishing kit proxies authentication to the legitimate AWS sign-in endpoint in real time, validating credentials before redirecting victims and likely capturing one-time password (OTP) codes," the company said. "This campaign does not exploit AWS vulnerabilities or abuse AWS infrastructure." Post-compromise console access has been observed within 20 minutes of credential submission. These efforts originated from Mullvad VPN infrastructure. Malicious npm Packages Deliver Cipher stealer — Two new malicious npm packages, bluelite-bot-manager and test-logsmodule-v-zisko, were found to deliver via Dropbox a Windows executable designed to siphon sensitive data, including Discord totems, credentials from Chrome, Edge, Opera, Brave, and Yandex browsers, and seed files from cryptocurrency wallet apps like Exodus. from compromised hosts using a stealer named Cipher stealer. "The stealer also uses an embedded Python script and a secondary payload downloaded from GitHub," JFrog said. GIBCRYPTO Ransomware Detailed — A new ransomware called GIBCRYPTO comes with the ability to capture keystrokes and corrupt the Master Boot Record (MBR) so that any attempt to restart the system will cause the system to run into an error. The ransomware uses the Salsa20 algorithm for encryption. It's suspected to be part of Snake Keylogger, indicating the malware authors' attempts to diversify beyond information theft. The development comes as Sygnia highlighted SafePay's OneDrive-based data exfiltration technique during a ransomware attack after breaching a victim by leveraging a FortiGate firewall flaw and a misconfigured administrative account. "SafePay gained initial access by exploiting a firewall misconfiguration, which enabled them to obtain local administrative credentials," the company said. "They rapidly escalated discovery and enumeration activities to identify high-value targets for lateral movement, demonstrating a structured and methodical approach to mapping the environment. Within a matter of hours, SafePay escalated to domain administrator access." The attack culminated in the deployment of ransomware, encrypting more than 60 servers. Fraudulent Account Registration Activity Originating from Vietnam — A sprawling cybercrime ecosystem based in Vietnam has been linked to a cluster of fraudulent account registration activity on platforms like LinkedIn, Instagram, Facebook, and TikTok. In these attacks, attributed to O-UNC-036, the threat actors rely on disposable email addresses in order to execute SMS pumping attacks, also called International Revenue Sharing Fraud (IRSF). "In this scheme, malicious actors automate the creation of puppet accounts in a targeted service provider," Okta said. "Fraudsters use these account registrations to trigger SMS messages to premium rate phone numbers and profit from charges incurred. This activity can prove costly for service providers who use SMS to verify registration information in customer accounts or to send multi-factor authentication (MFA) security codes." O-UNC-036 has also been linked to a cybercrime-as–a-service (CaaS) ecosystem that provides paid infrastructure and services to facilitate online fraud. The web-based storefronts are hosted in Vietnam and specialize in the sales of web-based accounts. Hijacked AppsFlyer SDK Distributes Crypto Clipper — The AppsFlyer Web SDK was briefly hijacked to serve malicious code to steal cryptocurrency in a supply chain attack. The clipper malware payload came with capabilities to intercept cryptocurrency wallet addresses entered on websites and replace them with attacker-controlled addresses to divert funds to the threat actor. "The AppsFlyer Web SDK was observed serving obfuscated malicious JavaScript instead of the legitimate SDK from websdk.appsflyer[.]com," Profero said. "The malicious payload appears to have been designed for stealth and compatibility, preserving legitimate SDK functionality while adding hidden browser hooks and wallet-hijacking logic." The incident has since been resolved by AppsFlyer. Operation CamelClone Targets Government and Defense Entities — A new cyber espionage campaign dubbed Operation CamelClone has targeted governments and defense entities in Algeria, Mongolia, Ukraine, and Kuwait using malicious ZIP archives that contain a Windows shortcut (LNK) file, which, when executed, delivers a JavaScript loader named HOPPINGANT. The loader then delivers additional payloads for establishing C2 and exfiltrating data to the MEGA cloud storage service. "One interesting aspect of this campaign is that the threat actor does not rely on traditional command-and-control infrastructure," Seqrite Labs said. "Instead, the payloads are hosted on a public file-sharing service, filebulldogs[.]com, while stolen data is uploaded to MEGA storage using the legitimate tool Rclone." The activity has not been attributed to any known threat group. How Threat Actors Exfiltrate Credentials Using Telegram Bots — Threat actors are abusing the Telegram Bot API to exfiltrate data via text messages or arbitrary file uploads, highlighting how legitimate services can be weaponized to evade detection. Agent Tesla Keylogger is by far the most prominent example of a malware family that uses Telegram for C2. "In general, Telegram C2s appear to be most popular among information stealers, possibly due to Telegram's technically legitimate nature and because information stealers typically only need to exfiltrate data passively rather than provide complex communications beyond simple message or file transfers," Cofense said. Microsoft Launches Copilot Health — Microsoft has become the latest company after OpenAI and Anthropic to launch a dedicated "secure space" called Copilot Health that integrates medical records, biometric data from wearables, and lab test results to give personalized advice in the U.S. "Copilot Health brings together your health records, wearable data, and health history into one place, then applies intelligence to turn them into a coherent story," the company said. Like OpenAI and Anthropic, Microsoft emphasized that Copilot Health isn't meant to replace professional medical care. Rogue AI Agents Can Work Together to Engage in Offensive Behaviors — According to a new report from artificial intelligence (AI) security company Irregular, agents can work together to hack into systems, escalate privileges, disable endpoint protection, and steal sensitive data while evading pattern-matching defenses. What's notable is that the experiment did not rely on adversarial prompting or deliberately unsafe system design. "In one case, an agent convinced another agent to carry out an offensive action, a form of inter-agent collusion that emerged with no external manipulation," Irregular said. "This scenario demonstrates two compounding risks: inter-agent persuasion can erode safety boundaries, and agents can independently develop techniques to circumvent security controls. When an agent is given access to tools or data, particularly but not exclusively shell or code access, the threat model should assume that the agent will use them, and that it will do so in unexpected and possibly malicious ways." 🔧 Cybersecurity Tools Dev Machine Guard → It is a free, open-source tool that scans your computer to show you exactly what developer tools and scripts are running. It creates a simple list of your AI coding assistants, code editor extensions, and software packages to help you find anything suspicious or outdated. It is a single script that works in seconds to give you better visibility into the security of your local coding environment. Trajan → It is an automated security tool designed to find hidden vulnerabilities in "service meshes," which are the systems that manage how different parts of a large software application talk to each other. Because these systems are complex, it is easy for engineers to make small mistakes in the settings that allow hackers to bypass security or steal data. Trajan works by scanning these configurations to spot those specific errors and helping developers fix them before they can be exploited. Disclaimer: For research and educational use only. Not security-audited. Review all code before use, test in isolated environments, and ensure compliance with applicable laws. Conclusion There’s a lot packed in here, and not in a neat way. Some of it is the usual recycled chaos, some of it feels a little more deliberate, and some of it has that nasty “this is going to show up everywhere by next week” energy. Anyway — enough throat-clearing. Here’s the stuff worth your attention.
thehackernews.comMar 16, 2026extracted
Meta ditches end-to-end encrypted messaging on Instagram
Meta ditches end-to-end encrypted messaging on Instagram End-to-end encrypted messaging on Instagram will no longer be supported after May 8, 2026. Meta justified the move by saying the feature was rarely used, with only a small fraction of Instagram users enabling encryption. The company advised users seeking end-to-end encryption to switch to WhatsApp, where it is enabled by default. Unlike WhatsApp, Instagram never rolled out encryption to all users and the feature remained optional. Users with affected chats will see instructions on how to download messages or media they want to keep. Those using older versions of the app may need to update Instagram first, the company said on its Help Center page. The decision comes two weeks after TikTok announced it would not introduce end-to-end encryption for direct messages, arguing that the technology could make users less safe by limiting the ability to detect harmful activity. End-to-end encryption ensures that only the sender and recipient can read a message, a feature praised by privacy advocates. Law enforcement and child safety groups argue that the same protection can make investigations harder, since companies cannot access message content even when authorities present legal warrants. The debate over encrypted communications is also playing out in Europe. Last week, the European Parliament voted to extend temporary rules allowing online platforms to voluntarily detect child sexual abuse material (CSAM) until August 2027 while negotiations on permanent legislation continue. Meta, TikTok, and other social media platforms have faced growing criticism in recent years over their impact on young users and broader concerns about privacy and online safety.
helpnetsecurity.comMar 16, 2026extracted
Meta to Shut Down Instagram End-to-End Encrypted Chat Support Starting May 2026
Meta has announced plans to discontinue support for end-to-end encryption (E2EE) for chats on Instagram after May 8, 2026. "If you have chats that are impacted by this change, you will see instructions on how you can download any media or messages you may want to keep," the social media giant said in a help document. "If you're on an older version of Instagram, you may also need to update the app before you can download your affected chats." When reached for comment, this is what Meta had to say: "Very few people were opting in to end-to-end encrypted messaging in DMs, so we're removing this option from Instagram in the coming months. Anyone who wants to keep messaging with end-to-end encryption can easily do that on WhatsApp." The American company first began testing E2EE for Instagram direct messages in 2021 as part of CEO Mark Zuckerberg's "privacy-focused vision for social networking." The feature is currently "only available in some areas" and is not enabled by default. Weeks into the Russo-Ukrainian war in February 2022, the company made encrypted direct messaging available to all adult users in both countries. The development comes days after TikTok said it does not plan to introduce E2EE to secure direct messages on the platform, telling BBC News that the technology makes users less safe and that it wants to protect users, especially young people, from harm. Late last month, Reuters also reported that Meta proceeded with plans to adopt encryption to secure messages in Facebook and Instagram despite internal warnings in 2019 that doing so would hinder the company's ability to detect illegal activities, such as child sexual abuse material (CSAM) or terrorist propaganda, and flag them to law enforcement. E2EE has been hailed as a win for privacy, as it ensures that only communicating users can decrypt and read messages, thereby locking out service providers, bad actors, and other third parties from accessing or intercepting the data. However, law enforcement and child safety advocates have argued that the technology creates a safe space for criminals, as it prevents companies from complying with warrants to turn over message content – a problem referred to as the "Going Dark" phenomenon. This year, the European Commission is expected to present a Technology Roadmap on encryption to identify and evaluate solutions that enable lawful access to encrypted data by law enforcement, while safeguarding cybersecurity and fundamental rights. (The story was updated after publication to include a response from Meta.)
thehackernews.comMar 13, 2026extracted
UK regulators demand social media platforms make it harder for kids under 13 to access sites
UK regulators demand social media platforms make it harder for kids under 13 to access sites Two U.K. regulators on Thursday published warnings demanding that Facebook, Instagram, Snapchat, TikTok, YouTube and other large platforms used by children “take urgent steps” to integrate robust age assurance tools into their sites. The Information Commissioner’s Office (ICO) and Ofcom stressed that they expect immediate action, with Ofcom saying that firms have until the end of April to report back on their plans. The ICO said that it has “started direct engagement with some of the highest risk services and expect them to work directly with us to strengthen their age assurance measures over the next two months.” The regulators’ public call to action comes at a time when countries across Europe are considering or are implementing social media bans for children and are generally laser-focused on child safety online. In January, the British government announced it is considering a social media ban for children under age 16 and said it is consulting with Australia to learn about the impact and efficacy of its own ban, which took effect in December. On Monday members of Parliament voted down a ban, but it could still take effect after the British government finishes an ongoing “consultation” process. In its open letter, the ICO said it is considering “further regulatory action” if platforms do not do more to ensure that children under age 13 cannot access their platforms. The ICO said it has found that many platforms set a minimum age of 13 but rely on children to honestly report their ages as their sole enforcement mechanism. “As self-declaration is easily circumvented, this means underage children can easily access services that have not been designed for them,” the ICO letter said. “This puts under-13s at risk by allowing their information to be collected and used unlawfully, without the protections they are entitled to.” The regulator emphasized that age assurance technologies have become much more effective in recent years but that many services have failed to begin using the technology. Ofcom’s warning said that social media platforms and Roblox have privately assured it that they are committed to creating safe online ecosystems for kids. The regulator said it plans to make the companies’ responses to its demand for action public in May and will then “announce any next steps for regulatory action.” “These online services are household names, but they’re failing to put children’s safety at the heart of their products,” Dame Melanie Dawes, Ofcom’s chief executive, said in a statement. “There is a gap between what tech companies promise in private, and what they’re doing publicly to keep children safe on their platforms.” Ofcom’s four demands include a call for platforms to implement effective age assurance protocols, “failsafe” grooming protections, safer feeds and no more product testing on children. The regulator said its research shows that 72% of children aged 8-12 are accessing the platforms’ sites and apps. Suzanne Smalley is a reporter covering digital privacy, surveillance technologies and cybersecurity policy for The Record. She was previously a cybersecurity reporter at CyberScoop. Earlier in her career Suzanne covered the Boston Police Department for the Boston Globe and two presidential campaign cycles for Newsweek. She lives in Washington with her husband and three children.
therecord.mediaMar 12, 2026extracted
ThreatsDay Bulletin: OAuth Trap, EDR Killer, Signal Phishing, Zombie ZIP, AI Platform Hack & More
Another Thursday, another pile of weird security stuff that somehow happened in just seven days. Some of it is clever. Some of it is lazy. A few bits fall into that uncomfortable category of “yeah… this is probably going to show up in real incidents sooner than we’d like.” The pattern this week feels familiar in a slightly annoying way. Old tricks are getting polished. New research shows how flimsy certain assumptions really are. A couple of things that make you stop mid-scroll and think, “wait… people are actually pulling this off?” There’s also the usual mix of strange corners of the ecosystem doing strange things — infrastructure behaving a little too professionally for comfort, tools showing up where they absolutely shouldn’t, and a few cases where the weakest link is still just… people clicking stuff they probably shouldn’t. Anyway. If you’ve got five minutes and a mild curiosity about what attackers, researchers, and the broader internet gremlins were up to lately, this week’s ThreatsDay Bulletin on The Hacker News has the quick hits. Scroll on. OAuth consent abuseCloud security firm Wiz has warned of the dangers posed by malicious OAuth applications, highlighting how "consent fatigue" could open the door for attackers to gain access to a victim's sensitive data by giving their malicious apps a legitimate-looking name. By accepting the permissions requested by a rogue OAuth application, the user is "adding" the attacker's app into their company's tenant. "Once 'Accept' is clicked, the sign-in process is complete," Wiz said. "But instead of going to a normal landing page, the access token is sent to the attacker's Redirect URL. With that token, the attacker now has access to the user's files or emails without ever needing to know their password." The Google-owned company also said it detected a large-scale campaign active in early 2025 that involved 19 distinct OAuth applications impersonating well-known brands such as Adobe, DocuSign, and OneDrive, and targeted multiple organizations. Details of the activity were documented by Proofpoint in August 2025. Messaging account takeoverRussian-linked hackers are trying to break into the Signal and WhatsApp accounts of government officials, journalists, and military personnel globally with an aim to get unauthorized access – not by breaking encryption, but by simply tricking people into handing over the security verification codes or PINs. "The most frequently observed method used by the Russian hackers is to masquerade as a Signal Support chatbot in order to induce their targets to divulge their codes," the Netherlands Defence Intelligence and Security Service (MIVD) and the General Intelligence and Security Service (AIVD) said. "The hackers can then use these codes to take over the user's account. Another method used by the Russian actors takes advantage of the 'linked devices' function within Signal and WhatsApp." It's worth noting that a similar warning was issued by Germany last month. "These attacks were executed via sophisticated phishing campaigns, designed to trick users into sharing information – SMS codes and/or Signal PIN – to gain access to users' accounts," Signal said. Google warned last year that Signal's widespread use among Ukrainian soldiers, politicians, and journalists had made it a frequent target for Russian espionage operations. Cloud breach via software flawsGoogle has revealed that threat actors are increasingly exploiting vulnerabilities in third-party software to breach cloud environments. "The window between vulnerability disclosure and mass exploitation collapsed by an order of magnitude, from weeks to days," the tech giant's cloud division said. "While software-based exploits increased, initial access by threat actors using misconfiguration, which accounted for 29.4% of incidents in the first half of 2025, dropped to 21% in H2 2025. Similarly, exposed sensitive UI or APIs continued a downward trend, falling from 11.8% in H1 to 4.9% in H2. This decline suggests that automated guardrails are making identity and configuration errors harder to exploit and that threat actors are being driven toward more sophisticated and costly vectors that specifically target software vulnerabilities to gain a foothold." In most attacks investigated by Google, the actor's objective was silent exfiltration of high volumes of data without immediate extortion and long-term persistence. Microcontroller debug bypassNew research from Quarkslab has found that it's possible to bypass the 16-byte password protection required for debug access on several variants of the RH850 microcontroller family using voltage fault injection in under one minute. "Voltage glitching technique is performed by underpowering or overpowering the chip for a controlled amount of time to alter its behavior," the security company said. "The crowbar attack is a specific type of voltage glitch where the power supply is shorted to the ground instead of injecting a specific voltage, using a MOSFET, for example." Solar Spider suspects arrestedTwo Nigerian nationals have been arrested by authorities in the Indian state of Uttar Pradesh for their alleged involvement in an e-crime operation known as Solar Spider. The suspects are believed to have been planning to siphon large amounts of money by leveraging security flaws in Indian cooperative banking systems. According to a report from The420.in, the individuals have been identified as Okechukwu Imeka and Chinedu Okafor. The duo is suspected to be part of an international fraud syndicate involved in targeting financial institutions. Solar Spider has a history of targeting banking systems across India and the Middle East, often through spear-phishing campaigns. In a report published in July 2025, Tata Communications revealed that threat actors leverage their initial access to steal credentials, tamper with NEFT/RTGS transactions, and focus on Structured Financial Messaging System (SFMS) and Host-to-Host (H2H) infrastructures. The group is also known for deploying a sophisticated attack framework dubbed JSOutProx since at least 2019. PlugX malware campaignCheck Point has disclosed targeted campaigns against entities in Qatar using conflict-related content as lures to deliver malware families like PlugX and Cobalt Strike. The attack chain uses Windows shortcut (LNK) files contained within ZIP archives, which, when opened, cause it to download a next-stage payload from a compromised server. The payload then displays the decoy document while using DLL side-loading to deploy PlugX. The activity, detected on March 1, 2026, has been attributed to Mustang Panda (aka Camaro Dragon). A second attack has been observed using a password-protected archive to execute a previously undocumented Rust loader that's responsible for deploying Cobalt Strike using DLL side-loading. "This loader exploits DLL hijacking of nvdaHelperRemote.dll, a component of the open-source screen reader NVDA. Abuse of this component has previously been observed in only a limited number of Chinese-nexus campaigns, including China-aligned activity associated with a campaign delivering Voldemort backdoor, as well as a wave of attacks targeting the Philippines and Myanmar back in 2025," Check Point said. While this attack is assessed as China-aligned, it has not been attributed to a specific threat actor. "The attackers leveraged the ongoing war in the Middle East to make their lures more credible and engaging, demonstrating the ability to rapidly adapt to major developments and breaking news," the company said. Teen DDoS kit sellersPolish police have referred seven suspected minor cybercriminals to family court over an alleged scheme to sell distributed denial-of-service (DDoS) kits online. The suspects, aged between 12 and 16 at the time of the alleged offenses, face charges related to selling DDoS tools as part of a profit-driven scheme designed to target popular websites, including auction and sales portals, IT domains, hosting services, and accommodation booking sites. "Using the tools they administer, popular websites such as auction and sales portals, IT domains, hosting services, and accommodation booking services were attacked," Poland's Central Bureau for Combating Cybercrime (CBZC) said. Phishing-resistant Windows loginMicrosoft is rolling out passkey support for Microsoft Entra on Windows devices, adding phishing-resistant passwordless authentication via Windows Hello. "We're introducing Microsoft Entra passkeys on Windows to enable phishing-resistant sign-in to Entra-protected resources. This update allows users to create device-bound passkeys stored in the Windows Hello container and authenticate using Windows Hello methods (face, fingerprint, or PIN)," Microsoft said. "It also expands passwordless authentication to Windows devices that aren't Entra-joined or registered, helping organizations strengthen security and reduce reliance on passwords." Sysmon built into WindowsMicrosoft has natively integrated System Monitor (Sysmon) functionality directly into Windows 11 and Windows Server 2025 as an optional built-in feature as of Windows 11's March feature update (KB5079473). It's disabled by default. The company announced the integration in November 2025. "You no longer need to package it dynamically; you can simply enable it programmatically via PowerShell," Nick Carroll, cyber incident response manager at Nightwing, said. "Coupled with Microsoft's simultaneous announcement that Windows Intune will enable 'hotpatching' by default in May 2026, this drastically lowers the barrier to entry for deep endpoint visibility and represents a massive operational win for network defenders." Canada phishing campaignAn active phishing campaign is targeting Canadian residents (and possibly present in other countries) using fraudulent domains impersonating trusted institutions, including the Government of British Columbia and Hydro-Québec, with the goal of collecting personal information and credit card details, Flare said. The hosting infrastructure behind this campaign is linked to RouterHosting LLC (aka Cloudzy), a provider that was publicly accused in 2023 of supplying services to at least 17 state-sponsored hacking groups from countries including Iran, China, Russia, and North Korea. Private link safety in chatsMeta has detailed the workings of Advanced Browsing Protection (ABP) in Messenger, which protects the privacy of the links clicked on within chats while still warning people about malicious links. "In its standard setting, Safe Browsing uses on-device models to analyze malicious links shared in chats," the company said. "But we've extended this further with an advanced setting called Advanced Browsing Protection (ABP) that leverages a continually updated watchlist of millions more potentially malicious websites." ABP leverages an approach called private information retrieval (PIR) to implement a privacy-preserving "URL-matching" scheme between the client's query and the server hosting the database, along with Oblivious HTTP, AMD SEV-SNP, and Path ORAM for added privacy guarantees. BlackSanta EDR killerA sophisticated attack campaign targeting HR departments and job recruiters has combined social engineering with advanced evasion techniques to stealthily compromise systems by avoiding analysis environments and leveraging a specialized module designed to kill antivirus and endpoint detection software. The attack begins with a resume-themed ISO file delivered likely through spam or phishing emails, which then drops next-stage payloads, including a DLL that's launched via DLL side-loading to gather basic system information, initiate communication with a remote server, run sandbox checks, employ geographic filtering to avoid running in restricted regions, and drop additional payloads, such as BlackSanta EDR that employs legitimate but vulnerable kernel drivers to impair system defenses, a known tactic referred to as Bring Your Own Vulnerable Driver (BYOVD). "Rather than functioning as a simple auxiliary payload, BlackSanta acts as a dedicated defense-neutralization module that programmatically identifies and interferes with protection and monitoring processes prior to the deployment of follow-on stages," Aryaka said. "By targeting endpoint security engines alongside telemetry and logging agents, it directly reduces alert generation, limits behavioral logging, and weakens investigative visibility on compromised hosts." It's currently not known what the follow-on payloads are or how widespread the campaign is. Phishing campaigns don't just target HR teams, but also impersonate them in attacks. "Impersonating HR provides many benefits to threat actors. Tasks from HR are typically mandatory, so HR emails carry authority," Cofense said. "Legitimate HR tasks can also have strict deadlines, which a threat actor can use to impose urgency. Finally, regular HR tasks are expected by employees." ZIP evasion techniqueA new technique dubbed Zombie ZIP allows attackers to conceal payloads in specially crafted compressed files that can bypass security tools. "Malformed ZIP headers can cause antivirus and endpoint detection and response software (EDR) to produce false negatives," the CERT Coordination Center (CERT/CC) said. "Despite the presence of malformed headers, some extraction software is still able to decompress the ZIP archive, allowing potentially malicious payloads to run upon file decompression." The vulnerability, tracked as CVE-2026-0866, has been codenamed Zombie Zip by researcher Christopher Aziz, who discovered it. The technique was demonstrated by Bombadil Systems security researcher Chris Aziz. AI agent breaches platformResearchers at autonomous offensive security startup CodeWall said their AI agent hacked McKinsey's internal AI platform Lili and gained full read and write access to the chatbot platform in just two hours. This enabled access to the entire production database, including 46.5 million chat messages about strategy, mergers and acquisitions, and client engagements, all in plaintext, along with 728,000 files containing confidential client data, 57,800 user accounts, and 95 system prompts controlling the AI's behavior. The development is an indicator that agentic AI tools are becoming more effective for conducting cyber attacks. The agent said it found over 200 endpoints that were totally exposed, out of which 22 were unprotected. One of these endpoints, which wrote user search queries to the database, suffered from an SQL injection that could have made it possible to access sensitive data and rewrite the system prompts silently. McKinsey has since addressed the problem. There is no evidence that the issue was exploited in the wild. Teams social engineering malwareHackers have contacted employees at financial and healthcare organizations over Microsoft Teams to trick them into granting remote access through Quick Assist and deploy a new piece of malware called A0Backdoor. The modus operandi, which aligns with the playbook of Storm-1811 (aka STAC5777 or Blitz Brigantine), employs social engineering to gain the employee's trust by first flooding their inbox with spam and then contacting them over Teams, pretending to be the company's IT staff and offering assistance with the problem. To obtain access to the target machine, the threat actor instructs the user to start a Quick Assist remote session, which is used to deploy a malicious toolset that includes digitally signed MSI packages, some of which were hosted on Microsoft cloud storage tied to personal accounts. The installers serve as a conduit for launching a DLL that, in turn, decrypts and runs shellcode responsible for running anti-analysis checks and dropping A0Backdoor, which establishes contact to a remote server using DNS tunnelling to receive commands. The activity has been active since at least August 2025 through late February 2026. Industrialized disinformation networkThe Russian influence operation known as Doppelgänger has been described as industrialized and prioritizing infrastructure resilience, scalability, and operational continuity over short-term visibility. "Rather than functioning as a loose collection of spoofed websites or transient propaganda outlets, the network exhibits the hallmarks of a coordinated, professionally managed influence apparatus," DomainTools said. "At its core, the ecosystem relies on systematic media brand impersonation executed at scale." Campaigns mounted as part of the operation exhibit deliberate geographic micro-targeting across European Union member states and the U.S. Pentagon AI disputeAnthropic has filed a lawsuit to block the Pentagon from placing it on a national security blocklist, stating the supply chain risk designation was unlawful and violated its free speech and due process rights. The development comes after the Pentagon formally branded the artificial intelligence (AI) company a supply chain risk after it refused to remove guardrails against using its technology for autonomous weapons or domestic surveillance. In its own statement, Anthropic said "we had been having productive conversations with the Department of War over the last several days, both about ways we could serve the Department that adhere to our two narrow exceptions, and ways for us to ensure a smooth transition if that is not possible." However, the Pentagon said there is no active negotiation happening with Anthropic. It also reiterated that the department "does not do and will not do domestic mass surveillance." The development follows OpenAI's own deal with the U.S. Department of Defense, with CEO Sam Altman stating the defense contract would include protections against the same red lines that Anthropic had insisted on. The company has since amended its contract to ensure "the AI system shall not be intentionally used for domestic surveillance of U.S. persons and nationals." Anthropic's CEO Dario Amodei has called OpenAI's messaging "safety theater" and "straight up lies." GitHub SEO malwareA new information stealer campaign distributing BoryptGrab is leveraging a network of more than 100 public GitHub repositories that claim to offer software tools for free, using search engine optimization (SEO) keywords to lure victims. The multi-stage infection chain begins when a ZIP file is downloaded from a fake GitHub download page. BoryptGrab can harvest browser data, cryptocurrency wallet information, and system information. It's also capable of capturing screenshots, collecting common files, and extracting Telegram information, Discord tokens, and passwords. Also delivered as part of the attack is a backdoor called TunnesshClient that establishes a reverse SSH tunnel to communicate with the attacker and acts as a SOCKS5 proxy. The earliest ZIP file dates back to late 2025. Certain iterations of the campaign have been found to deliver Vidar Stealer or a Golang downloader dubbed HeaconLoad, which then downloads and runs additional payloads. RAT campaign against IndiaThe Pakistan-aligned threat actor known as Transparent Tribe has been attributed to a fresh set of attacks targeting Indian government entities to infect systems with a RAT that enables remote command execution, process monitoring and termination, remote program execution, file upload/download, file enumeration, screenshot capture, and live screen monitoring capabilities. "The campaign primarily relies on social engineering techniques, distributing a malicious ZIP archive disguised as examination-related documents to persuade recipients to interact with the files," CYFIRMA said. "Upon extraction, the archive delivers deceptive shortcut files along with a macro-enabled PowerPoint add-in, which collectively initiate the infection chain. The threat actors employ multiple layers of obfuscation and redundant execution mechanisms to enhance the probability of successful compromise while reducing the likelihood of user suspicion." Signed phishing malwareMicrosoft is warning of multiple phishing campaigns using workplace meeting lures, PDF attachments, and abuse of legitimate binaries to deliver signed malware. The activity, observed in February 2026, has not been attributed to a specific threat actor or group. "Phishing emails directed users to download malicious executables masquerading as legitimate software," the company said. "The files were digitally signed using an Extended Validation (EV) certificate issued to TrustConnect Software PTY LTD. Once executed, the applications installed remote monitoring and management (RMM) tools that enabled the attacker to establish persistent access on compromised systems." Some of the deployed RMM tools include ScreenConnect, Tactical RMM, and MeshAgent. The use of the TrustConnect branding was disclosed by Proofpoint last week. Furthermore, the deployment of multiple RMM frameworks within a single intrusion indicates a deliberate strategy to ensure continuous access and ensure operational resilience even if one access mechanism is detected or removed. "These campaigns demonstrate how familiar branding and trusted digital signatures can be abused to bypass user suspicion and gain an initial foothold in enterprise environments," Microsoft added. TikTok allowed in CanadaFollowing a national security review of TikTok, Canada's Minister of Industry, Mélanie Joly, said the company can keep its business operational. "TikTok will implement enhanced protection for Canadians’ personal information, including new security gateways and privacy-enhancing technologies to control access to Canadian user data in order to reduce the risk of unauthorized or prohibited access," the government said. "TikTok will implement enhanced protections for minors." The development marks a complete 180 from a 2024 decision, when it was ordered to shut down its operations, citing unspecified "national security risks." However, that order was paused in early 2025. Vulnerabilities rise 12%Flashpoint said it catalogued 44,509 vulnerability disclosures in 2025, a 12% increase year-over-year (YoY). Of those, 466 were confirmed as exploited in the wild. Nearly 33%, or 14,593 vulnerabilities, had publicly available exploit code. Ransomware attacks also increased 53% YoY in 2025, with 8,835 total attacks recorded. The top RaaS groups by attack volume in 2025 were Qilin at 1,213 attacks, Akira at 1,044, Cl0p at 529, Safepay at 452, and Play at 395. Manufacturing was the most targeted industry with 1,564 attacks, followed by technology at 987 and healthcare at 905. The U.S. accounted for approximately 53% of named victim organizations. Botnet exploiting 174 flawsThe RondoDox DDoS botnet has been found to implement 174 different exploits between May 25, 2025, and February 16, 2026, peaking at 15,000 exploitation attempts in a single day between December 2025 and January 2026. It's believed that the threat actors are using compromised residential IP addresses as hosting infrastructure. "The operators of RondoDox have been using a shotgun approach, where they send multiple exploits to the same endpoint, hoping for one to work," Bitsight said. Of the 174 different vulnerabilities, 15 have a public proof-of-concept (PoC), but no CVE, and 11 do not have PoC code at all. RondoDox is notable for its fast addition of recently disclosed vulnerabilities, in some cases incorporating the PoC even before the CVE was published (e.g., CVE-2025-62593). Memory-only keylogger attackPhishing emails bearing purchase order lures are being used to distribute an executable within RAR archives. Once launched, the binary extracts and runs VIP Keylogger in memory without touching the disk. "This keylogger captures either browser cookies, logins, credit card details, autofills, visited URLs, downloads, or top sites from the appropriate files in each of the application's designated folders," K7 Labs said. It's also capable of targeting a wide range of web browsers, stealing the email accounts from Outlook, Foxmail, Thunderbird, and Postbox, and collecting Discord tokens. Cloudflare-shielded phishingA new Microsoft 365 credential harvesting campaign has been observed abusing Cloudflare's services to delay detection and risk profiling. The gatekeeping is designed to ensure the visitor is a real target and not a security scanner or bot. "The campaign implemented multiple anti-detection techniques, including the use of CloudFlare human verification, hardcoded IP block lists, user agent checks, and multiple sites and redirects," DomainTools said. Some of the stuff in this week’s list feels a little too practical. Not big flashy hacks — just simple tricks used in the right place at the right time. The kind of things that make defenders sigh because… yeah, that’ll probably work. There’s also a bit of the usual theme: tools and features doing exactly what they were designed to do… just not for the people who built them. Add some creative thinking, and suddenly normal workflows start looking like attack paths. Anyway — quick reads, strange ideas, and a few reminders that security problems rarely disappear… they just change shape. Scroll on.
thehackernews.comMar 12, 2026extracted
Mental health apps are leaking your private thoughts. How do you protect yourself? | Kaspersky official blog
In February 2026, the cybersecurity firm Oversecured published a report that makes you want to factory reset your phone and move into a remote cabin in the woods. Researchers audited 10 popular Android mental health apps — ranging from mood trackers and AI therapists to tools for managing depression and anxiety — and uncovered… 1575 vulnerabilities! Fifty-four of those flaws were classified as critical. Given the download stats on Google Play, as many as 15 million people could be affected. The real kicker? Six out of the ten apps tested explicitly promised users that their data was “fully encrypted and securely protected”. We’re breaking down this scandalous “brain drain”: what exactly could leak, how it’s happening, and why “anonymity” in these services is usually just a marketing myth. What was found in the apps Oversecured is a mobile app security firm that uses a specialized scanner to analyze APK files for known vulnerability patterns across dozens of categories. In January 2026, researchers ran ten mental health monitoring apps from Google Play through the scanner — and the results were, shall we say, “spectacular”. The anatomy of the flaws The discovered vulnerabilities are diverse, but they all boil down to one thing: giving attackers access to data that should be under lock and key. For starters, one of the vulnerabilities allows an attacker to access any internal activity of the app — even that never intended for external eyes. This opens the door to hijacking authentication tokens and user session data. Once an attacker has those, they essentially could gain access to a user’s therapy records. Another issue is insecure local data storage with read permissions granted to any other app on the device. In other words, that random flashlight app or calculator on your smartphone could potentially read your cognitive behavioral therapy (CBT) logs, personal notes, and mood assessments. The researchers also found unencrypted configuration data baked right into the APK installation files. This included backend API endpoints and hardcoded URLs for Firebase databases. Furthermore, several apps were caught using the cryptographically weak java.util.Random class to generate session tokens and encryption keys. Finally, most of the tested apps lacked root/jailbreak detection. On a rooted device, any third-party app with root privileges could gain total access to every bit of locally stored medical data. Shockingly, of the 10 apps analyzed, only four received updates in February 2026. The rest haven’t seen a patch since November 2025, and one hasn’t been touched since September 2024. Going 18 months without a security patch is a lifetime in this industry — especially for an app housing mood journals, therapy transcripts, and medication schedules. Here’s a quick reminder of just how dangerous the misuse of this type of data gets. In 2024, the tech world was rocked by a sophisticated attack on XZ Utils, a critical component found in virtually every operating system based on the Linux kernel. The attacker successfully pressured the maintainer into handing over code commit permissions by exploiting the developer’s public admission of burnout and a lack of motivation to carry on with the project. Had the attack been completed, the damage would have been mind-boggling given that roughly 80% of the world’s servers run on Linux. What could leak? What do these apps collect and store? It’s the kind of stuff you’d likely only share with a trusted clinician: therapy session transcripts, mood logs, medication schedules, self-harm indicators, CBT notes, and various clinical assessment scales. As far back as 2021, complete medical records were selling on the dark web for US$1000 each. For comparison, a stolen credit card number goes for anywhere between US$5 and US$30. Medical records contain a full identity package: name, address, insurance details, and diagnostic history. Unlike a credit card, you can’t exactly “reissue” your medical history. Furthermore, medical fraud is notoriously difficult to spot. While a bank might flag a suspicious transaction in hours, a fraudulent insurance claim for a phantom treatment can go unnoticed for years. We’ve seen this movie before The Oversecured study isn’t just an isolated horror story. Back in 2020, Julius Kivimäki hacked the database of the Finnish psychotherapy clinic Vastaamo, making off with the records of 33 000 patients. When the clinic refused to cough up a €400 000 ransom, Kivimäki began sending direct threats to patients: “Pay €200 in Bitcoin within 24 hours, or else your records go public”. Ultimately, he leaked the entire database onto the dark web anyway. At least two people died by suicide, and the clinic was forced into bankruptcy. Kivimäki was eventually sentenced to six years and three months in prison, marking a record-breaking trial in Finland for the sheer number of victims involved. In 2023, the U.S. Federal Trade Commission (FTC) slapped the online therapy giant BetterHelp with a US$7.8 million fine. Despite stating on their sign-up page that your data was strictly confidential, the company was caught funneling user info — including mental health questionnaire responses, emails, and IP addresses — to Facebook, Snapchat, Criteo, and Pinterest for targeted advertising. After the dust settled, 800 000 affected users received a grand total of… US$10 each in compensation. By 2024, the FTC set its sights on the telehealth firm Cerebral, tagging them with a US$7 million fine. Through tracking pixels, Cerebral leaked the data of 3.2 million users to LinkedIn, Snapchat, and TikTok. The haul included names, medical histories, prescriptions, appointment dates, and insurance info. And the cherry on top? The company sent promotional postcards (sans envelopes) to 6000 patients, which effectively broadcasted that the recipients were undergoing psychiatric treatment. In September 2024, security researcher Jeremiah Fowler stumbled upon an exposed database belonging to Confidant Health, a provider specializing in addiction recovery and mental health services. The database contained audio and video recordings of therapy sessions, transcripts, psychiatric notes, drug test results, and even copies of driver’s licenses. In total, 5.3 terabytes of data, 126 000 files, or 1.7 million records were sitting there without a password. Why anonymity is an illusion Developers love to drop the line: “We never share your personal data with anyone.” Technically, that might be true — instead, they share “anonymized profiles”. The catch? De-anonymizing that data isn’t exactly rocket science anymore. Recent research highlights that using LLMs to strip away anonymity has become a routine reality. Even the “anonymization” process itself is often a mess. A study by Duke University revealed that data brokers are openly hawking the mental health data of Americans. Out of 37 brokers surveyed, 11 agreed to sell data linked to specific diagnoses (like depression, anxiety, and bipolar disorder), demographic parameters, and in some cases, even names and home addresses. Prices started as low as US$275 for 5000 aggregated records. According to the Mozilla Foundation, by 2023, 59% of popular mental health apps failed to meet even the most basic privacy standards, and 40% had actually become less secure than the previous year. These apps allowed account creation via third-party services (like Google, Apple, and Facebook), featured suspiciously brief privacy policies that glossed over data collection details, and employed a clever little loophole: some privacy policies applied strictly to the company’s website, but not the app itself. In short, your clicks on the site were “protected”, but your actions within the app were fair game. How to protect yourself Cutting these apps out of your life entirely is, of course, the most foolproof option — but it’s not the most realistic one. Besides, there’s no guarantee you can actually nuke the data already collected — even if you delete your account. We previously covered the grueling process of scrubbing your info from data broker databases; it’s possible, but prepare for a headache. So, how can you stay safe? Check permissions before you hit “Install”. In Google Play, navigate to App description → About this app → Permissions. A mood tracker has no business asking for access to your camera, microphone, contacts, or precise GPS location. If it does, it’s not looking out for your well-being — it’s harvesting data. Actually read the privacy policy. We get it — nobody reads these multi-page manifestos. But when a service is vacuuming up your most intimate thoughts, it’s worth a skim. Look for the red flags: does the company share data with third parties? Can you manually delete your records? Does the policy explicitly cover the app itself, or just the website? You can always feed the policy text into an AI and ask it to flag any privacy deal-breakers. Check the last updated date. An app that hasn’t seen an update in over six months is likely a playground for unpatched vulnerabilities. Remember: six out of the 10 apps Oversecured tested hadn’t been touched in months. Disable everything non-essential in your phone’s privacy settings. Whenever prompted, always select “ask not to track”. When an app pleads with you to enable a specific type of tracking — claiming it’s for “internal optimization” — it’s almost always a marketing ploy rather than a functional necessity. After all, if the app truly won’t work without a certain permission, you can always go back and toggle it on later. Don’t use “Sign in with…” services. Authenticating via Facebook, Apple, Google, or Microsoft creates additional identifiers and gives companies a golden opportunity to link your data across different platforms. Treat everything you type like a public social media post. If you wouldn’t want a random stranger on the internet reading it, you probably shouldn’t be typing it into an app with over 150 vulnerabilities that hasn’t seen a patch since the year before last. What else you should know about privacy settings and controlling your personal data online:
kaspersky.comMar 10, 2026extracted
Loading 40 more…