NewSecurity Audit Kit — audit your business in 15 minutes.Launch $49· limited time offer
Scam news

Today’s tells.

Daily scam alerts from FTC, FBI, Krebs on Security, and more — pulled fresh, summarized, and tagged.

'Ghostcommit' hides prompt injection in images to fool AI agents, steal secrets
Latest alertAI Fraud

'Ghostcommit' hides prompt injection in images to fool AI agents, steal secrets

Researchers discovered a sneaky technique called 'Ghostcommit' that hides malicious instructions inside image files to trick AI coding assistants into stealing sensitive information, like passwords and secret keys, from software projects. Because these AI tools don't inspect image files for hidden commands, they can be manipulated without anyone noticing. If you or your business uses AI-powered code review tools, be aware that they may not be fully secure and could be fooled into exposing private data.

Yesterday·Bleeping Computer
More alerts
This new Windows malware can take over your PC and wipe it clean
Security Alert

This new Windows malware can take over your PC and wipe it clean

A dangerous new type of malware called GigaWiper is targeting Windows computers, giving attackers the ability to secretly spy on victims and, when ready, completely and permanently destroy all data on the machine. If your PC becomes infected, there may be no way to recover your files. Keep your Windows system and antivirus software fully updated, avoid downloading software from untrusted sources, and back up your important files regularly to an external or cloud location.

2 days ago·Malwarebytes Blog
Progress urges ShareFile admins to shut down servers over “credible” threat
Data Breach

Progress urges ShareFile admins to shut down servers over “credible” threat

Progress Software is urgently warning businesses using its ShareFile on-premises file-sharing software to shut down their servers immediately due to a serious and credible security threat targeting those systems. This affects organizations that host ShareFile themselves rather than using the cloud version, and a compromise could expose sensitive files shared through the platform. If your organization uses ShareFile's on-premises software, contact your IT team right away to follow Progress's guidance.

2 days ago·Bleeping Computer
Hackers exploit critical auth bypass in Gitea Docker image
Security Alert

Hackers exploit critical auth bypass in Gitea Docker image

A serious security flaw in a popular software development tool called Gitea is being actively exploited by hackers, allowing them to break in and pretend to be any user — even administrators — without a password. This primarily affects businesses and developers who host their own Gitea servers using the official Docker setup. If your organization uses Gitea, apply the latest security update immediately and check for any suspicious account activity.

2 days ago·Bleeping Computer
Money launderer accused of stealing seized crypto while in prison
Security Alert

Money launderer accused of stealing seized crypto while in prison

A Bulgarian man already serving prison time for helping launder money stolen from American fraud victims somehow managed to steal $290,000 in cryptocurrency that the government had seized as evidence. This case is a reminder that criminal networks can operate even from behind bars, and that consumers who fall victim to fraud may face additional hurdles in recovering stolen funds.

2 days ago·Bleeping Computer
The Replicant in Your Directory: AI Agents and the Identity Security Gap
AI Fraud

The Replicant in Your Directory: AI Agents and the Identity Security Gap

As companies increasingly use AI-powered tools that act on their own behalf, these systems create large numbers of hard-to-track digital accounts and access points that criminals can exploit. Organizations often lose sight of what these AI agents can access and who is responsible for them, creating significant security risks. Everyday consumers are indirectly at risk because breaches caused by these gaps can expose personal data held by businesses they trust.

2 days ago·Bleeping Computer
New U-Boot flaws could enable stealthy firmware attacks
Security Alert

New U-Boot flaws could enable stealthy firmware attacks

Security researchers found six serious weaknesses in a widely used piece of software called U-Boot, which helps devices start up properly — it's found in routers, smart home devices, and other embedded hardware. Attackers could exploit these flaws to silently install malware that survives reboots and is very difficult to remove. Most consumers won't be able to fix this themselves, but it's worth keeping an eye out for firmware update notifications from manufacturers of your home network and smart devices.

2 days ago·Bleeping Computer
Ryuk ransomware member pleads guilty in the US, faces 15 years in prison
Security Alert

Ryuk ransomware member pleads guilty in the US, faces 15 years in prison

A man linked to the Ryuk ransomware gang has pleaded guilty to hacking U.S. companies and locking up their computer systems to extort money. Ryuk was responsible for some of the largest ransomware attacks in recent years, targeting hospitals, businesses, and other organizations. While this is a law enforcement win, it's a reminder that ransomware remains a major threat — keeping your devices updated and backing up important files can help protect you.

2 days ago·Bleeping Computer
Police suspects Dutch hackers were involved in Odido breach
Data Breach

Police suspects Dutch hackers were involved in Odido breach

Dutch police believe local hackers were behind a data breach at Odido, a major telecom provider in the Netherlands, that occurred earlier this year. Breaches at telecom companies are concerning for customers because they can expose personal details like names, addresses, phone numbers, and account information. If you are an Odido customer, watch for any suspicious activity on your accounts and consider changing your passwords as a precaution.

2 days ago·Bleeping Computer
Former ransomware negotiator gets 4 years for BlackCat attacks
Security Alert

Former ransomware negotiator gets 4 years for BlackCat attacks

A cybersecurity professional who was supposed to help companies recover from ransomware attacks was secretly behind some of those attacks himself. He was sentenced to nearly six years in prison for using the BlackCat ransomware to extort U.S. businesses. This case highlights the importance of thoroughly vetting cybersecurity vendors, as not everyone offering help has honest intentions.

2 days ago·Bleeping Computer
How mule betting scams recruit ordinary people
Security Alert

How mule betting scams recruit ordinary people

Fraudsters are recruiting everyday people with promises of easy money, asking them to open gambling accounts that are then used to secretly launder criminal proceeds. If you get caught up in one of these schemes — even unknowingly — you could face serious legal consequences. Be very wary of any unsolicited offer that promises quick cash in exchange for opening an account or moving money on someone else's behalf.

2 days ago·Malwarebytes Blog
Two Chrome updates in two days fix critical vulnerabilities
Security Alert

Two Chrome updates in two days fix critical vulnerabilities

Google released two urgent security updates for its Chrome browser in just two days, meaning there are serious vulnerabilities that hackers could potentially exploit. If you use Chrome, you should check that your browser is updated to the latest version right away, as outdated versions may leave your device at risk. To update, click the three dots in the top-right corner of Chrome, go to Help, then About Google Chrome, and let it check for updates.

2 days ago·Malwarebytes Blog
Zimbra urges customers to patch critical web client XSS flaw
Data Breach

Zimbra urges customers to patch critical web client XSS flaw

A serious security flaw has been found in Zimbra, a popular email and collaboration platform used by many businesses. The vulnerability could allow attackers to run malicious code through the web interface, potentially gaining access to emails and sensitive data. If your workplace uses Zimbra, alert your IT team to apply the available security patch immediately.

2 days ago·Bleeping Computer
How World Cup crypto prediction sites take your money
Investment Scam

How World Cup crypto prediction sites take your money

Websites claiming to let you predict sports outcomes like World Cup matches using cryptocurrency may be designed to take your money rather than reward your wins. These platforms often pressure users into buying tokens or rigging the game so the house always wins. Be very skeptical of any site promising easy crypto earnings tied to sporting events, as many are outright scams.

3 days ago·Malwarebytes Blog
OpenMandriva Linux says contributor tried to sabotage the project
Security Alert

OpenMandriva Linux says contributor tried to sabotage the project

A contributor to the OpenMandriva Linux open-source project allegedly attempted to sabotage it from the inside following an internal dispute. While this does not directly affect most consumers, it serves as a reminder that even trusted software communities can face insider threats. Users of open-source software should stay updated on security announcements from the projects they rely on.

3 days ago·Bleeping Computer
Injective SDK on npm infected with cryptocurrency wallet stealer
Security Alert

Injective SDK on npm infected with cryptocurrency wallet stealer

Hackers broke into a software development project and secretly added malicious code designed to steal cryptocurrency wallet credentials, including private keys and recovery phrases. Developers who used this compromised software package may have had their crypto wallets exposed and funds stolen. If you work with cryptocurrency or know someone who does, check whether any tools you use were recently flagged for tampering.

3 days ago·Bleeping Computer
New Helix vishing group emerges in SharePoint data theft attacks
Phishing

New Helix vishing group emerges in SharePoint data theft attacks

A criminal group called Helix is tricking employees into handing over access to corporate data by impersonating trusted contacts through fake phone calls and deceptive login requests. They exploit these tactics to bypass security protections like two-factor authentication and steal sensitive files stored in Microsoft SharePoint. Consumers and employees should be very cautious about unexpected calls asking for login credentials or verification codes, as legitimate organizations will never request these over the phone.

3 days ago·Bleeping Computer
Microsoft expects more Windows security updates from AI-discovered flaws
Security Alert

Microsoft expects more Windows security updates from AI-discovered flaws

Microsoft is using artificial intelligence to find security weaknesses in Windows before criminals can exploit them, which means you may see more frequent security updates rolling out to your devices. While more updates might feel like a hassle, installing them promptly is one of the best ways to keep your computer protected. Make sure automatic updates are turned on so you don't fall behind.

3 days ago·Bleeping Computer
New Forg365 phishing platform uses AI to target Microsoft 365 accounts
Phishing

New Forg365 phishing platform uses AI to target Microsoft 365 accounts

A new criminal service is using AI to craft convincing fake login pages designed to steal Microsoft 365 usernames and passwords, making these attacks harder to spot than ever before. If you use Microsoft 365 for work or personal email, be very cautious about clicking links in unsolicited emails that ask you to sign in. Enable multi-factor authentication on your account as an important extra layer of defense.

3 days ago·Bleeping Computer
The Hidden Security Risks of Reduced Summer IT Coverage
Security Alert

The Hidden Security Risks of Reduced Summer IT Coverage

This article is aimed at businesses, warning that cyberattacks don't take a summer break even when IT staff do, and suggesting AI tools can help fill the gap. While not directly about consumer scams, it serves as a reminder that criminals actively look for moments when defenses are down. If you work somewhere with a small IT team, be extra alert to suspicious activity during holiday periods.

3 days ago·Bleeping Computer
Invited to a "job interview" with Netflix or OpenAI? Beware! Your Google password could be at risk
Phishing

Invited to a "job interview" with Netflix or OpenAI? Beware! Your Google password could be at risk

Scammers are sending fake job offer emails pretending to be recruiters from well-known companies like Netflix, Adobe, and OpenAI in order to trick people into giving up their Google account passwords. These scams are especially dangerous because they prey on people hoping for exciting career opportunities. If you receive an unexpected job offer from a big-name company, verify it directly through the company's official website before clicking any links or providing any information.

3 days ago·Graham Cluley
6.9 million driver’s license numbers stolen from AssuranceAmerica
Data Breach

6.9 million driver’s license numbers stolen from AssuranceAmerica

Insurance company AssuranceAmerica suffered a data breach that exposed the driver's license numbers and personal information of nearly 7 million customers. If you are or were an AssuranceAmerica customer, watch for notifications from the company and be alert for identity theft, since stolen driver's license numbers can be used to open fraudulent accounts in your name. Consider placing a fraud alert with the major credit bureaus as a precaution.

3 days ago·Malwarebytes Blog
Unclaimed life insurance money? It’s a scam
Security Alert

Unclaimed life insurance money? It’s a scam

Scammers are mailing fake letters pretending to be lawyers, claiming that a distant relative with your last name has died and left you millions in unclaimed life insurance money. The goal is to get you to hand over personal information or fees in exchange for a payout that does not exist. If you receive a letter like this, do not respond or provide any information — it is a scam, and you should report it to the FTC at ReportFraud.ftc.gov.

3 days ago·FTC Consumer Alerts
Turn off this Meta setting before someone generates AI images of you
AI Fraud

Turn off this Meta setting before someone generates AI images of you

Meta has quietly rolled out a new tool called Muse Image that can generate AI images of you using photos from your public Instagram profile, and it is switched on by default without notifying you. Anyone could potentially use this to create realistic fake images of you without your knowledge or consent. You should go into your Instagram settings now and turn this feature off if you are uncomfortable with your likeness being used this way.

3 days ago·Malwarebytes Blog
Microsoft fixes RoguePlanet zero-day in Defender
Security Alert

Microsoft fixes RoguePlanet zero-day in Defender

Microsoft has released a fix for a serious security flaw called 'RoguePlanet' found in its Defender antivirus software, which attackers could have exploited before a patch existed. Windows users should check that their Microsoft Defender and Windows updates are fully up to date to make sure they are protected. Keeping automatic updates turned on is the easiest way to stay covered against threats like this.

3 days ago·Malwarebytes Blog
Microsoft patches RoguePlanet Defender zero-day vulnerability
Security Alert

Microsoft patches RoguePlanet Defender zero-day vulnerability

Microsoft has released an emergency security fix for a serious flaw in its Windows Defender antivirus software that attackers could exploit before it was officially patched. Windows users should make sure their devices are set to receive automatic updates so this fix is applied as soon as possible. Leaving your system unpatched could allow hackers to bypass your security protections.

3 days ago·Bleeping Computer
AssuranceAmerica data breach exposes records of 6.9 million drivers
Data Breach

AssuranceAmerica data breach exposes records of 6.9 million drivers

Insurance company AssuranceAmerica suffered a cyberattack that exposed the personal records of nearly 7 million drivers earlier this year. If you are or were a customer of AssuranceAmerica, your personal information may be in the hands of criminals, putting you at risk of identity theft or targeted scams. You should monitor your credit reports, watch for suspicious activity, and consider placing a credit freeze as a precaution.

3 days ago·Bleeping Computer
Police arrests 5,800 suspects in global anti-fraud crackdown
Security Alert

Police arrests 5,800 suspects in global anti-fraud crackdown

In a massive worldwide operation, police across 97 countries arrested nearly 5,800 people suspected of running fraud schemes and seized $293 million in stolen funds. This is encouraging news for consumers, as it shows global authorities are actively working to shut down the scammers who target everyday people. If you have been a victim of fraud, reporting it to local authorities still matters and can contribute to these kinds of investigations.

3 days ago·Bleeping Computer
Microsoft to retire the OWA Light client in Exchange Server
Security Alert

Microsoft to retire the OWA Light client in Exchange Server

Microsoft is shutting down an older, simplified version of its web-based email tool used in business email systems. This change is primarily relevant to IT administrators and businesses, not everyday consumers, and poses no direct scam or security threat.

3 days ago·Bleeping Computer
Entra passkey enrollment vishing targets Microsoft 365 users
Phishing

Entra passkey enrollment vishing targets Microsoft 365 users

Scammers are calling Microsoft 365 users on the phone, pretending to be legitimate security personnel and tricking them into enrolling a hacker-controlled device as a trusted passkey on their account. Once this is done, the attacker can gain access to the victim's Microsoft account without needing a password. If you receive an unexpected call asking you to approve or enroll any security device or passkey, hang up and contact your IT department or Microsoft directly through official channels.

4 days ago·Bleeping Computer
3 Ways AI Powers Service Desk Attacks and How to Prevent Them
AI Fraud

3 Ways AI Powers Service Desk Attacks and How to Prevent Them

Artificial intelligence is making it much easier for criminals to impersonate employees when contacting company IT help desks, allowing them to convincingly fake identities and gain access to accounts or systems. These AI-powered attacks are becoming more targeted and harder for support staff to detect. Organizations and their employees should be aware that even a very convincing caller requesting account access could be a scammer using AI-generated voices or scripts.

4 days ago·Bleeping Computer
DuckDuckGo browser now blocks YouTube video ads
Security Alert

DuckDuckGo browser now blocks YouTube video ads

DuckDuckGo's web browser has added the ability to block most ads that appear before and during YouTube videos. This is a convenience and privacy improvement for users, not a security threat. If you want an ad-free YouTube experience, switching to or using the DuckDuckGo browser is now an option worth considering.

4 days ago·Bleeping Computer
Smashing Security podcast #475: JadePuffer – the AI that ran a ransomware attack all by itself
AI Fraud

Smashing Security podcast #475: JadePuffer – the AI that ran a ransomware attack all by itself

Researchers have recorded what appears to be the first ransomware attack carried out entirely by an AI system acting on its own, without human guidance during the attack. This is a worrying development because it means cybercriminals may soon be able to launch sophisticated attacks at greater speed and scale with minimal effort. Consumers and businesses should ensure their security software and backups are up to date, as AI-powered threats are likely to become more common.

4 days ago·Graham Cluley
Your next car could be watching your face
Security Alert

Your next car could be watching your face

New cars are increasingly being fitted with cameras and sensors that monitor drivers' faces and behavior, and this technology is set to become a legal requirement in many places. While the stated goal is to improve road safety, privacy experts warn that this data could be collected, stored, or shared in ways drivers are unaware of. If you are buying a new car, it is worth researching what data it collects and whether you can control how that information is used.

4 days ago·Malwarebytes Blog
Felons, Fraudsters Flog Offensive Cybersecurity Startup
Security Alert

Felons, Fraudsters Flog Offensive Cybersecurity Startup

A cybersecurity company claiming to pay big money for software security flaws is actually being run by convicted criminals using fake identities, according to an investigation. Consumers and security researchers should be cautious about doing business with this company, as its leaders have a history of running deceptive operations. If you have shared personal or financial information with this firm, consider whether your data may be at risk.

4 days ago·Krebs on Security
Mount Royal University confirms breach as hackers claim attack
Data Breach

Mount Royal University confirms breach as hackers claim attack

Hackers broke into the computer systems of Mount Royal University in Calgary, Canada, stealing files and then erasing them from the university's servers. If you are a student, staff member, or faculty at this institution, your personal information may have been compromised. Watch for suspicious emails or unusual account activity, and consider monitoring your credit and changing any passwords linked to university accounts.

4 days ago·Bleeping Computer
Fake Paysafe, Skrill SDKs on NPM and PyPi steal credentials
Identity Theft

Fake Paysafe, Skrill SDKs on NPM and PyPi steal credentials

Criminals created fake software packages disguised as tools for popular payment platforms like Paysafe, Skrill, and Neteller, then uploaded them to widely used developer repositories. These fake packages were designed to steal login credentials from anyone who downloaded and used them. If you use these payment services, be alert to any unauthorized account activity and change your passwords immediately, as your credentials may have been harvested.

4 days ago·Bleeping Computer
Hackers exploit Roundcube flaw to spy on academic researchers
Data Breach

Hackers exploit Roundcube flaw to spy on academic researchers

A hacking group with ties to China has been breaking into email servers used by universities in the United States and Canada, stealing login credentials and installing hidden malware to maintain access. Researchers and staff at academic institutions are particularly at risk, as attackers can read private communications and move deeper into university networks. If you work at a university, be cautious about unsolicited emails and ensure your email software is fully up to date.

4 days ago·Bleeping Computer
CISA orders feds to patch max severity ColdFusion flaw by Friday
Security Alert

CISA orders feds to patch max severity ColdFusion flaw by Friday

A severe security vulnerability in Adobe ColdFusion, a platform used to run many websites, is being actively attacked by hackers right now. Government agencies have been ordered to patch it immediately, but any website running this software could be at risk of being compromised. As a consumer, be aware that websites you use may be built on vulnerable software, which could put your personal data at risk.

4 days ago·Bleeping Computer
Ubiquiti warns of new max severity  UniFi OS vulnerability
Security Alert

Ubiquiti warns of new max severity UniFi OS vulnerability

Ubiquiti, a company that makes popular networking equipment used in homes and businesses, has discovered a critical security flaw that could allow attackers to take full control of affected devices. If you use Ubiquiti UniFi networking products, you should update your device software as soon as possible. An attacker who exploits this flaw could gain complete access to your home or office network.

4 days ago·Bleeping Computer
CISA orders feds to prioritize patching Langflow auth bypass flaw
Security Alert

CISA orders feds to prioritize patching Langflow auth bypass flaw

U.S. government agencies have been ordered to urgently fix a serious security hole in a popular tool used to build AI-powered software, because hackers are already actively exploiting it. While this order directly targets federal agencies, any organization using this AI development tool should apply the security update right away. This is a reminder that AI tools can carry serious security risks just like any other software.

4 days ago·Bleeping Computer
Telco giant KDDI says data breach affects over 12 million people
Data Breach

Telco giant KDDI says data breach affects over 12 million people

A major Japanese phone and internet company called KDDI was hacked, exposing the email addresses and passwords of more than 12 million customers. If you use any of the five internet providers connected to KDDI, your login credentials may be in the hands of criminals. You should change your passwords immediately, especially if you reuse the same password on other accounts.

4 days ago·Bleeping Computer
Fake Netflix, Coca-Cola, and FIFA job scams target marketers
Phishing

Fake Netflix, Coca-Cola, and FIFA job scams target marketers

Scammers are posing as recruiters from well-known companies like Netflix, Coca-Cola, and FIFA to lure job seekers into fake hiring processes that are actually designed to steal their account credentials. The scheme uses convincing fake Google login pages to capture victims' usernames and passwords. If you receive an unsolicited job offer from a big-name brand, verify it directly through the company's official website before clicking any links or entering any personal information.

5 days ago·Malwarebytes Blog
The GitHub Actions Attack Pattern Your CI Security Scanners Miss
Security Alert

The GitHub Actions Attack Pattern Your CI Security Scanners Miss

Security researchers are warning that a sophisticated type of cyberattack targeting software development pipelines can slip past standard security tools undetected. This is primarily a concern for businesses and developers rather than everyday consumers, but it highlights that software you use daily could potentially be compromised at its source. Consumers should keep their apps and software updated to benefit from the latest security fixes.

5 days ago·Bleeping Computer
Webinar tomorrow: Why modern email attacks require a new approach to defense
Security Alert

Webinar tomorrow: Why modern email attacks require a new approach to defense

An upcoming webinar is being promoted for IT and security professionals to learn about new AI-powered tools designed to detect advanced email-based attacks like phishing and account takeovers. This is an industry event aimed at businesses rather than individual consumers. Everyday users should still remain cautious of suspicious emails and avoid clicking unexpected links, even if they appear to come from trusted contacts.

5 days ago·Bleeping Computer
New Januscape Linux flaw allows VM escape on Intel, AMD devices
Security Alert

New Januscape Linux flaw allows VM escape on Intel, AMD devices

A serious security flaw discovered in Linux software, which has apparently gone unnoticed for 16 years, could allow hackers to break out of isolated computing environments and take control of the underlying system. This primarily affects businesses and cloud service providers rather than everyday consumers directly. However, if your data is stored with companies using affected systems, it could be at risk until patches are applied.

5 days ago·Bleeping Computer
Two arrested over credit card phishing – as the Netherlands is named Europe's worst for payment fraud
Phishing

Two arrested over credit card phishing – as the Netherlands is named Europe's worst for payment fraud

Two men in the Netherlands were caught running a scheme designed to steal victims' credit card information through fake websites or messages that appeared legitimate. The Netherlands has been identified as the worst country in Europe for this type of payment fraud, suggesting the problem is widespread. Consumers should be cautious about entering card details anywhere online and double-check that websites are genuine before making payments.

5 days ago·Graham Cluley
How the Reddit and Discord false report scam steals accounts
Phishing

How the Reddit and Discord false report scam steals accounts

Criminals are contacting Reddit and Discord users with fake warnings claiming the user has been flagged in a false report, then tricking them into sharing login verification codes to supposedly resolve the issue. Once scammers have these codes, they can take over the victim's account entirely. Never share one-time login codes with anyone, even if they claim to be from a platform's support team.

5 days ago·Malwarebytes Blog
Accenture confirms breach after hacker offers stolen data for sale
Data Breach

Accenture confirms breach after hacker offers stolen data for sale

Accenture, one of the world's largest technology consulting companies, has confirmed that a hacker broke in and stole 35 gigabytes of data including source code. While the breach appears to primarily involve company data rather than consumer records, breaches at major IT firms can have wide-reaching effects since Accenture manages systems for many large organizations. It is worth monitoring any accounts tied to services that Accenture may support for unusual activity.

5 days ago·Bleeping Computer
Chinese hackers develop LONGLEASH malware to expand ORB network
Security Alert

Chinese hackers develop LONGLEASH malware to expand ORB network

A Chinese hacking group is actively targeting home and business routers — particularly older Ruckus models that haven't received software updates — to build a secret network of compromised devices. Once infected, your router can be used as a relay point for criminal activity without your knowledge. To protect yourself, make sure your router's firmware is kept up to date and consider replacing older models that no longer receive security patches.

5 days ago·Bleeping Computer
Hidden backdoor in Tenda router firmware grants admin access
Security Alert

Hidden backdoor in Tenda router firmware grants admin access

Researchers discovered a hidden 'backdoor' built into the software of several popular Tenda router models, meaning attackers could secretly gain full control over the device without needing a password. If you own a Tenda router, your home network and connected devices could be at risk. Check Tenda's website for firmware updates and apply them immediately, or consider replacing the device if no fix is available.

5 days ago·Bleeping Computer
Spain arrests suspected member of pro-Russian hacktivist groups
Security Alert

Spain arrests suspected member of pro-Russian hacktivist groups

Spanish police arrested an individual believed to be part of pro-Russian hacker groups known for carrying out cyberattacks on government and infrastructure targets. These groups have been linked to disruptive attacks across Europe. While this is not a direct consumer scam, it serves as a reminder that state-sponsored hackers can impact public services and utilities that everyday people depend on.

5 days ago·Bleeping Computer
Microsoft to enable Windows settings backup by default for orgs
Security Alert

Microsoft to enable Windows settings backup by default for orgs

Microsoft is planning to automatically turn on a feature that backs up Windows settings for business computers running Windows 11. This is an internal enterprise change and not a scam or security threat. Regular consumers do not need to take any action.

5 days ago·Bleeping Computer
Microsoft testing new Cloud Rebuild Windows 11 recovery feature
Security Alert

Microsoft testing new Cloud Rebuild Windows 11 recovery feature

Microsoft is testing a new feature for Windows 11 that would allow users to fully restore their computer using a fresh copy downloaded from the cloud. This is a legitimate product update and not a security threat. No action is needed from consumers at this time.

5 days ago·Bleeping Computer
Claude Code’s hidden tracker was an “experiment,” says Anthropic
AI Fraud

Claude Code’s hidden tracker was an “experiment,” says Anthropic

Anthropic, the company behind the AI tool Claude Code, was found to have included a hidden tracker in the software that was secretly collecting usage data, which the company is now calling an internal experiment. This raises serious concerns about transparency and trust, as users had no knowledge they were being monitored. Developers and consumers using AI tools should review privacy policies carefully and stay alert to what data these tools may be collecting.

5 days ago·Malwarebytes Blog
Scammers are using AI to sell impossible flowers
Shopping Scam

Scammers are using AI to sell impossible flowers

Scammers are using AI-generated images to advertise and sell seeds for plants that simply do not exist, such as fake exotic orchids, tricking shoppers into paying for products that will never deliver what was promised. These convincing fake photos are being spread through social media and online shops, making it hard to spot the fraud. Before buying plants or seeds online, research the seller carefully and be skeptical of any flower or plant that looks almost too unique or beautiful to be real.

5 days ago·Malwarebytes Blog
BeyondTrust warns of critical flaws in remote access software
Security Alert

BeyondTrust warns of critical flaws in remote access software

BeyondTrust, a company that makes software used by businesses to remotely access and manage computers, has discovered serious security vulnerabilities in two of its products. These flaws could allow criminals to break into systems without a password. If your workplace uses BeyondTrust software, alert your IT department to apply the security patches immediately.

5 days ago·Bleeping Computer
Fake IT support calls on Microsoft Teams push EtherRAT malware
Tech Support Scam

Fake IT support calls on Microsoft Teams push EtherRAT malware

Criminals are calling employees through Microsoft Teams while pretending to be their company's IT support team, then convincing them to install malicious software that gives the attackers access to the entire company network. If you receive an unexpected Teams call from someone claiming to be IT support and asking you to install anything, hang up and verify the request through your company's official internal channels. Legitimate IT staff will rarely pressure you to install software during an unsolicited call.

6 days ago·Bleeping Computer
Phishing poses as big-brand job interview to steal Google accounts
Phishing

Phishing poses as big-brand job interview to steal Google accounts

Scammers are pretending to be well-known companies like Adobe, Netflix, and Coca-Cola and sending fake job interview invitations to steal people's Google account login credentials. If you receive an unexpected job offer or interview request from a big-name brand, be very cautious about clicking any links or signing into any accounts. Always verify the opportunity directly through the company's official website before providing any personal information.

6 days ago·Bleeping Computer
Vietnam arrests suspects behind HiAnime anime piracy service
Security Alert

Vietnam arrests suspects behind HiAnime anime piracy service

Vietnamese police have arrested seven people believed to be running HiAnime, a massive illegal anime streaming website that was shut down earlier this year. While this is a law enforcement win, consumers should be aware that piracy sites like this often expose visitors to malware, data theft, and malicious ads. It's safer to use legitimate streaming services to watch content online.

6 days ago·Bleeping Computer
Software Is Now Written at the Speed of Thought. Security Isn't.
AI Fraud

Software Is Now Written at the Speed of Thought. Security Isn't.

AI tools are now allowing software to be built so quickly that important security checks are being skipped along the way, creating more vulnerable apps and services. This matters for everyday consumers because the apps and websites you use may have been built with hidden security flaws that hackers can exploit. When using newer apps or services, be cautious about sharing sensitive personal or financial information until those products have an established track record.

6 days ago·Bleeping Computer
Max severity Adobe ColdFusion flaw now exploited in attacks
Data Breach

Max severity Adobe ColdFusion flaw now exploited in attacks

A critical security flaw in Adobe ColdFusion, a technology used to power many websites and web applications, is now being actively exploited by attackers. If a website or service you use runs on vulnerable ColdFusion software, your personal data could be at risk. There is nothing consumers can directly do here, but it's worth monitoring for breach notifications from companies whose services you use.

6 days ago·Bleeping Computer
How to tell if an image is AI-generated
AI Fraud

How to tell if an image is AI-generated

Scammers are increasingly using AI-generated images to make fake news stories, fake profiles, and fraudulent ads look more believable. Knowing how to spot these artificial images — such as looking for unnatural details in hands, backgrounds, or text — can help you avoid being deceived. When something looks too dramatic or perfect, take a moment to verify before trusting it.

6 days ago·Malwarebytes Blog
Choose your WhatsApp username carefully
Security Alert

Choose your WhatsApp username carefully

WhatsApp is rolling out a username feature so people can connect without sharing their phone number, which is a helpful privacy step. However, if you choose a username that includes your real name or other identifying details, you could accidentally give away personal information anyway. Pick a username that doesn't reveal who you are to keep your privacy intact.

6 days ago·Malwarebytes Blog
NetNut botnet takes a hit. Don’t be part of the next one.
Security Alert

NetNut botnet takes a hit. Don’t be part of the next one.

Law enforcement agencies including the FBI and Google recently shut down a large criminal network that had secretly hijacked millions of everyday people's devices and used them to commit crimes online. Your device could be recruited into one of these networks if it is infected with malware, making you an unknowing participant in criminal activity. Keeping your devices updated and running security software helps protect you from being caught up in these schemes.

6 days ago·Malwarebytes Blog
Can you spot debt relief scams that target the military?
Gov Impersonation

Can you spot debt relief scams that target the military?

Fraudsters are calling military members and veterans with false promises of special government debt forgiveness programs, then collecting money or personal information instead of actually helping. No legitimate program requires you to pay upfront fees or hand over sensitive details to a stranger who contacts you out of the blue. If you receive one of these calls, hang up and contact your lender or a legitimate nonprofit credit counselor directly.

6 days ago·FTC Consumer Alerts
A week in security (June 29 – July 5)
Security Alert

A week in security (June 29 – July 5)

This is a weekly roundup post from a cybersecurity blog covering security news between June 29 and July 5, 2026, but no specific details about the stories included were provided. Without knowing the individual topics covered, it's not possible to identify a specific threat or actionable advice for consumers. Check the original source directly to see if any of the week's stories are relevant to your personal security.

6 days ago·Malwarebytes Blog
Flipper Zero firmware development continues with community help
Security Alert

Flipper Zero firmware development continues with community help

Flipper Zero, a small handheld device popular with security researchers and hobbyists, will keep receiving software updates thanks to a mix of remaining staff and volunteers from the broader community. While this news is mainly relevant to people who own or are interested in the device, it's worth knowing that the tool can be used both for legitimate security testing and, in the wrong hands, for harmful activities like scanning or copying wireless signals. Consumers don't need to take any action, but should be aware that such devices exist and can interact with things like contactless cards and key fobs.

1 weeks ago·Bleeping Computer
JadePuffer ransomware used AI agent to automate entire attack
AI Fraud

JadePuffer ransomware used AI agent to automate entire attack

For the first time, researchers have discovered a ransomware attack that was planned and carried out entirely by an artificial intelligence system, with no human hacker directly controlling it. This means cybercriminals can now use AI to launch attacks faster, at greater scale, and at lower cost than before. Consumers and businesses should ensure their software is kept up to date and that important files are backed up regularly, as AI-powered attacks like this could become more common and harder to defend against.

1 weeks ago·Bleeping Computer
Verified X ad spreads Mac malware, while ConsentFix steals Microsoft accounts
Phishing

Verified X ad spreads Mac malware, while ConsentFix steals Microsoft accounts

Two separate scam campaigns are targeting everyday users — one uses fake verified ads on X (formerly Twitter) to trick Mac users into downloading malware, while another called ConsentFix manipulates people into handing over access to their Microsoft accounts. Both attacks rely on deception rather than technical hacking, meaning anyone can fall victim regardless of how secure their device is. Be very skeptical of ads on social media and never grant account permissions to a tool or website unless you are absolutely certain it is legitimate.

1 weeks ago·Malwarebytes Blog
NetNut proxy network disrupted, 2 million infected devices cut off
Security Alert

NetNut proxy network disrupted, 2 million infected devices cut off

Authorities, with help from Google, shut down a criminal network that had secretly hijacked around 2 million Android devices — including smart TVs and streaming boxes — and used them to route illegal internet traffic. If you own a budget Android TV device or streaming box, it may have been infected without your knowledge, acting as a tool for criminals while slowing down your connection. Keep your devices updated, only install apps from trusted sources, and consider a factory reset if you suspect your device has been compromised.

1 weeks ago·Bleeping Computer
ARToken PhaaS exposes EvilTokens' Microsoft 365 phishing toolkit
Phishing

ARToken PhaaS exposes EvilTokens' Microsoft 365 phishing toolkit

Cybercriminals have launched a new service called ARToken that makes it easier for even low-skilled attackers to steal Microsoft 365 account credentials on a large scale. This type of 'phishing-as-a-service' platform provides ready-made tools to trick users into handing over their login details, putting both personal and work accounts at risk. Be cautious of any email asking you to sign into Microsoft 365, and always verify the web address before entering your credentials.

1 weeks ago·Bleeping Computer
Claude Fable relaunch disappoints users with nerfed performance
Security Alert

Claude Fable relaunch disappoints users with nerfed performance

Anthropic has re-released its most powerful AI model, Claude Fable, to all users, but many are reporting that it performs significantly worse than when it first launched. Consumers who pay for this service may not be getting the same quality product they originally signed up for. If you are a subscriber, it may be worth reassessing whether the service still meets your needs.

1 weeks ago·Bleeping Computer
Claude Fable 5 isn’t permanently leaving subscriptions, Anthropic says
Security Alert

Claude Fable 5 isn’t permanently leaving subscriptions, Anthropic says

Anthropic is temporarily removing its Claude Fable 5 AI model from standard subscription plans starting July 7, though the company says this is not permanent. This means paying subscribers may temporarily lose access to a feature they are paying for. If you rely on this tool, be aware of the change and check Anthropic's website for updates on when access will be restored.

1 weeks ago·Bleeping Computer
WinRAR flaw could allow attackers to take control of your computer
Security Alert

WinRAR flaw could allow attackers to take control of your computer

A serious security vulnerability has been found in WinRAR, a popular file-compression program used by millions of people, which could allow hackers to take full control of your computer. A patch has been released, but since WinRAR does not update automatically, many users remain exposed without realizing it. If you use WinRAR, open the program and manually download the latest version from the official WinRAR website as soon as possible.

1 weeks ago·Malwarebytes Blog
ConsentFix and ClickFix: How Microsoft 365 Accounts are Hijacked in 3 Seconds
Phishing

ConsentFix and ClickFix: How Microsoft 365 Accounts are Hijacked in 3 Seconds

Hackers are using two new tricks called ConsentFix and ClickFix to break into Microsoft 365 accounts in seconds by tricking users into clicking fake prompts that hand over account access, even bypassing two-factor authentication. If you use Microsoft 365 for work or personal use, be extremely cautious about any unexpected pop-ups or login requests asking for permissions. Never approve access requests you did not initiate, and report anything suspicious to your IT department immediately.

1 weeks ago·Bleeping Computer
Microsoft fixes bug that removed Copilot buttons in Outlook
Security Alert

Microsoft fixes bug that removed Copilot buttons in Outlook

Microsoft released a fix for a glitch that caused AI assistant buttons to disappear in the Outlook email app for some Windows users. This was a software bug rather than a security threat, and affected users should see the buttons return after updating. No action is required beyond keeping your software up to date.

1 weeks ago·Bleeping Computer
The Gentlemen ransomware: what you need to know
Security Alert

The Gentlemen ransomware: what you need to know

A cybercriminal group called 'The Gentlemen' is operating ransomware attacks, which means they break into computer systems, lock up files, and demand payment to restore access. Businesses and individuals should ensure they have strong backups and up-to-date security software to reduce the damage if they are ever targeted. Ransomware attacks can result in permanent loss of personal files and sensitive data.

1 weeks ago·Graham Cluley
Apple’s Hide My Email doesn't hide it very well
Data Breach

Apple’s Hide My Email doesn't hide it very well

Apple's 'Hide My Email' feature, which is supposed to mask your real email address to protect your privacy, has a vulnerability that can expose your actual email address. A security researcher discovered this flaw over a year ago and Apple has not yet released a fix, leaving users who rely on this feature at risk. If you use Hide My Email expecting full privacy protection, be aware it may not be as secure as advertised.

1 weeks ago·Malwarebytes Blog
Fake Google and Cloudflare verification pages spread multiple malware families
Phishing

Fake Google and Cloudflare verification pages spread multiple malware families

Cybercriminals are creating fake websites that look like official Google and Cloudflare security verification pages to trick people into running malicious software on their computers. Once a user follows the on-screen instructions thinking they are completing a routine check, harmful programs are installed that can steal passwords and other personal information. Be very cautious of any webpage that asks you to copy and paste commands or run files as part of a 'verification' step.

1 weeks ago·Malwarebytes Blog
FBI Seizes NetNut Proxy Platform, Popa Botnet
Security Alert

FBI Seizes NetNut Proxy Platform, Popa Botnet

The FBI seized a large network of over two million hacked home devices that were secretly being used to route internet traffic for others without their owners' knowledge. If your home router, smart TV, or other connected device was part of this botnet, criminals may have been using your internet connection to hide illegal activity. To protect yourself, regularly update your device firmware and change default passwords on all internet-connected devices in your home.

1 weeks ago·Krebs on Security
Google loses final appeal to overturn €4.1 billion EU fine
Security Alert

Google loses final appeal to overturn €4.1 billion EU fine

Europe's highest court has upheld a nearly $5 billion fine against Google for using its Android operating system to push users toward its own search engine and Chrome browser, limiting consumer choice. This ruling confirms that regulators found Google's practices anti-competitive, which may eventually lead to more options for consumers using Android phones. No immediate action is needed, but this decision could lead to changes in how your Android device works in the future.

1 weeks ago·Bleeping Computer
CISA: Microsoft SharePoint RCE flaw now actively exploited
Data Breach

CISA: Microsoft SharePoint RCE flaw now actively exploited

A serious security flaw in Microsoft SharePoint, a tool widely used by businesses to share and store files, is now being actively exploited by attackers to take control of affected systems. Microsoft released a fix back in May, but organizations that haven't applied it are still vulnerable. If your employer uses SharePoint, urge your IT department to update it immediately to protect company and personal data.

1 weeks ago·Bleeping Computer
Opera rolls out Paste Protect feature to fight ClickFix attacks
Tech Support Scam

Opera rolls out Paste Protect feature to fight ClickFix attacks

The Opera web browser has added a new safety feature called Paste Protect to defend users against a clever scam tactic where criminals trick people into copying and pasting malicious commands into their computers, which can install malware or hand over control of the device. This type of attack, known as ClickFix, often disguises itself as a helpful instruction on a fake website. If you use Opera, updating to the latest version will give you this added layer of protection.

1 weeks ago·Bleeping Computer
Alleged Scattered Spider hacker extradited to the United States
Identity Theft

Alleged Scattered Spider hacker extradited to the United States

A person accused of being part of Scattered Spider, a notorious hacking group responsible for major cyberattacks on large companies, has been brought to the United States to face criminal charges. Scattered Spider has previously stolen large amounts of sensitive customer data from well-known businesses, putting millions of consumers at risk. This arrest is a reminder to monitor your accounts and credit reports in case your personal information was exposed in past breaches linked to this group.

1 weeks ago·Bleeping Computer
Medtronic notifies customers impacted by ShinyHunters data breach
Data Breach

Medtronic notifies customers impacted by ShinyHunters data breach

Medical device company Medtronic is contacting customers whose personal information was exposed in a data breach carried out by a hacking group known as ShinyHunters. The breach means sensitive personal details may now be in the hands of unauthorized individuals. If you are a Medtronic customer, watch for a notification from them and take recommended steps such as monitoring your accounts and considering a credit freeze.

1 weeks ago·Bleeping Computer
Cisco finally confirms attackers exploiting Unified CM flaw
Security Alert

Cisco finally confirms attackers exploiting Unified CM flaw

Cisco has confirmed that hackers are actively taking advantage of a security flaw in its Unified Communications Manager software, which businesses use to manage phone and messaging systems. Although a fix was released in early June, systems that haven't been updated remain at risk. If your workplace uses Cisco communication tools, alert your IT team to ensure the latest security patch has been applied.

1 weeks ago·Bleeping Computer
Talk about scams during Military Consumer Month 2026
Security Alert

Talk about scams during Military Consumer Month 2026

The FTC is urging people to talk openly with military members and veterans about scams during Military Consumer Month, because scammers frequently target this community to steal money, benefits, and personal information. Sharing personal scam experiences can help others in the military community recognize and avoid similar traps. If you know a servicemember or veteran, check in with them about scams and point them toward resources like the FTC's consumer protection tools.

1 weeks ago·FTC Consumer Alerts
Hackers target Microsoft 365 accounts with 81 million login attempts
Identity Theft

Hackers target Microsoft 365 accounts with 81 million login attempts

Attackers launched a massive campaign trying to break into Microsoft 365 accounts by repeatedly guessing passwords across millions of attempts over just two weeks. This type of attack, called password spraying, works by trying common passwords against many accounts to avoid triggering lockouts. If you use Microsoft 365, now is a good time to enable multi-factor authentication and make sure your password is unique and not easy to guess.

1 weeks ago·Bleeping Computer
Turning Indicators into Intelligence in OpenCTI with Criminal IP
Security Alert

Turning Indicators into Intelligence in OpenCTI with Criminal IP

This article is a technical piece aimed at cybersecurity professionals about improving threat intelligence tools used to track and analyze online dangers. It is not directly relevant to everyday consumers. No action is needed.

1 weeks ago·Bleeping Computer
Over 900 Oracle E-Business instances exposed to ongoing attacks
Data Breach

Over 900 Oracle E-Business instances exposed to ongoing attacks

Hundreds of businesses running Oracle's E-Business Suite software have left their systems exposed to the internet, and attackers are actively exploiting a serious security flaw in those systems. If your employer or a company you do business with uses Oracle EBS, their data — which may include yours — could be at risk. Consumers should watch for any breach notifications from companies they've shared personal or financial information with.

1 weeks ago·Bleeping Computer
Smashing Security podcast #474: Polymarket can predict the future. So how did it miss this hack?
Data Breach

Smashing Security podcast #474: Polymarket can predict the future. So how did it miss this hack?

This episode of a cybersecurity podcast covers several recent security incidents, including a hack of prediction market platform Polymarket and a large-scale exposure of Fortinet firewall devices that could have lasting consequences. The Fortinet issue is particularly concerning because compromised network devices can give attackers long-term access to sensitive systems. If your workplace uses Fortinet products, encourage your IT team to check whether patches have been applied.

1 weeks ago·Graham Cluley
Fake Perplexity Chrome extension spies on your searches
AI Fraud

Fake Perplexity Chrome extension spies on your searches

A fake browser extension disguised as the popular AI search tool Perplexity was secretly recording users' search activity without their knowledge. If you installed a Chrome extension called 'Search for perplexity ai,' you should remove it from your browser immediately by going to Chrome's extensions settings. This is a reminder to only install browser extensions from trusted, verified sources and to regularly review what extensions you have installed.

1 weeks ago·Malwarebytes Blog
BioShocking: when “gaming” AI agents is no longer a game
AI Fraud

BioShocking: when “gaming” AI agents is no longer a game

Security researchers discovered a technique called 'BioShocking' that can trick AI-powered tools into doing harmful things by framing the request as a game or challenge. This is concerning because more people and businesses are relying on AI agents to handle tasks automatically, and this type of manipulation could be used to steal data or bypass safety rules. Until AI companies address this flaw, be cautious about which AI tools you trust with sensitive information or important tasks.

1 weeks ago·Malwarebytes Blog
FortiBleed credential-theft campaign linked to Lynx ransomware
Data Breach

FortiBleed credential-theft campaign linked to Lynx ransomware

A large-scale attack that stole login credentials from Fortinet networking devices has been connected to criminal groups that use ransomware to lock organizations out of their own systems. This means the stolen credentials are likely being used to break into company networks, potentially affecting businesses and their customers. If you work for or use services from a company that relies on Fortinet equipment, be alert for signs of disruption or notices about data exposure.

1 weeks ago·Bleeping Computer
Kubota says hackers had month-long access to network systems
Data Breach

Kubota says hackers had month-long access to network systems

Kubota North America, the agricultural and construction equipment company, revealed that hackers were secretly inside its computer systems for over a month before being detected. Extended access like this gives attackers plenty of time to steal sensitive data, including employee or customer information. If you have done business with Kubota, watch for any official notifications they send and monitor your accounts for unusual activity.

1 weeks ago·Bleeping Computer
New ChocoPoC malware targets researchers via trojanized PoC exploits
Security Alert

New ChocoPoC malware targets researchers via trojanized PoC exploits

Fake security tools posted on GitHub are being used to secretly install malicious software on the computers of cybersecurity researchers, allowing attackers to steal data and take remote control of their machines. While this campaign targets security professionals specifically, it highlights how even technical experts can be tricked by content that appears legitimate. Anyone downloading security-related tools from GitHub should verify the source carefully before running anything.

1 weeks ago·Bleeping Computer
DHS confirms hackers breached HSIN info-sharing platform
Data Breach

DHS confirms hackers breached HSIN info-sharing platform

Hackers successfully broke into a sensitive Department of Homeland Security platform that is used by government agencies and private partners to share security information. A breach of this kind could expose confidential communications and coordination details that are meant to protect the public. While individual consumers may not be directly impacted, this incident underscores ongoing vulnerabilities in critical government infrastructure.

1 weeks ago·Bleeping Computer
Webinar: Why traditional email security is no longer enough
Security Alert

Webinar: Why traditional email security is no longer enough

This item is an advertisement for a cybersecurity industry webinar rather than a news story about a scam or security incident affecting consumers. It promotes a product discussion around email security technology and is not a consumer threat alert. No action is needed from consumers based on this item.

1 weeks ago·Bleeping Computer
Amazon fined $2.25M for withholding evidence from fraud victims
Identity Theft

Amazon fined $2.25M for withholding evidence from fraud victims

Amazon has agreed to pay a $2.25 million fine after the FTC found it was blocking identity theft victims from accessing their own transaction records, which they needed to investigate fraud. If you have ever been a victim of identity theft involving an Amazon account, you may have the right to request your transaction history — contact Amazon or the FTC for guidance on how to do so.

1 weeks ago·Bleeping Computer
Got something suspicious?

Get a second opinion.

Paste any text, link, or screenshot — Cautellus reads it for scam tells in seconds.

Try the scam scanner