# Malwarebytes

Cyber Security Software & Anti-Malware

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## 12 celebrity deepfake websites seized by Manhattan DA

DevFeed: [12 celebrity deepfake websites seized by Manhattan DA](<https://devfeed.tech/articles/12-celebrity-deepfake-websites-seized-by-manhattan-da-41304.md>)

Original publisher: [Read original article](<https://www.malwarebytes.com/blog/ai/2026/09/12-celebrity-deepfake-websites-seized-by-manhattan-da>)

Author: Danny Bradbury

Published: 2026-09-17T11:20:46Z

Content type: news

Language: en

Sources: [Malwarebytes](<https://devfeed.tech/sources/malwarebytes.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [department-of-homeland-security](<https://devfeed.tech/tags/department-of-homeland-security.md>), [department-of-justice](<https://devfeed.tech/tags/department-of-justice.md>), [privacy](<https://devfeed.tech/tags/privacy.md>), [report](<https://devfeed.tech/tags/report.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

The Manhattan District Attorney's Office seized 12 websites that hosted AI-generated celebrity deepfakes, including non-consensual intimate imagery depicting more than 1,200 people. The article describes the harms of deepfake abuse and expanding legal action against its distribution.

### Source excerpt

The largest known celebrity deepfake seizure has taken 12 websites offline, disrupting access to videos depicting some 1,200 people.

## T-Mobile rewards points expiry texts are a phishing scam

DevFeed: [T-Mobile rewards points expiry texts are a phishing scam](<https://devfeed.tech/articles/t-mobile-rewards-points-expiry-texts-are-a-phishing-scam-41305.md>)

Original publisher: [Read original article](<https://www.malwarebytes.com/blog/threat-intel/2026/09/t-mobile-rewards-points-expiry-texts-are-a-phishing-scam>)

Author: Pieter Arntz

Published: 2026-09-17T10:44:01Z

Content type: news

Language: en

Sources: [Malwarebytes](<https://devfeed.tech/sources/malwarebytes.md>)

Topics: [account](<https://devfeed.tech/topics/account.md>), [App](<https://devfeed.tech/topics/app.md>)

Tags: [customer](<https://devfeed.tech/tags/customer.md>), [links](<https://devfeed.tech/tags/links.md>), [messages](<https://devfeed.tech/tags/messages.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [points](<https://devfeed.tech/tags/points.md>), [reward-points](<https://devfeed.tech/tags/reward-points.md>), [rewards-points](<https://devfeed.tech/tags/rewards-points.md>), [scam](<https://devfeed.tech/tags/scam.md>), [scams](<https://devfeed.tech/tags/scams.md>), [t-mobile](<https://devfeed.tech/tags/t-mobile.md>), [threat-intel](<https://devfeed.tech/tags/threat-intel.md>)

### AI overview

Malwarebytes reports a phishing campaign that sends fake T-Mobile rewards-point expiry messages. The messages use invented balances, urgent expiry dates, and phishing links to pressure recipients into clicking before verifying the claim.

### Source excerpt

A large phishing campaign is using fake T-Mobile rewards points and looming expiry dates to pressure recipients into clicking malicious links.

## Google's September 2026 Pixel update addresses a modem vulnerability reportedly under limited, targeted exploitation

DevFeed: [Google's September 2026 Pixel update addresses a modem vulnerability reportedly under limited, targeted exploitation](<https://devfeed.tech/articles/google-pixel-owners-urged-to-patch-actively-exploited-modem-flaw-30920.md>)

Original publisher: [Read original article](<https://www.malwarebytes.com/blog/mobile/2026/09/google-pixel-owners-urged-to-patch-actively-exploited-modem-flaw>)

Author: Pieter Arntz

Published: 2026-09-16T10:39:04Z

Content type: news

Language: en

Sources: [Malwarebytes](<https://devfeed.tech/sources/malwarebytes.md>)

Topics: [Google](<https://devfeed.tech/topics/google.md>), [pixel](<https://devfeed.tech/topics/pixel.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Android Security](<https://devfeed.tech/topics/android-security.md>), [Security & Privacy](<https://devfeed.tech/topics/security-privacy.md>), [Mobile](<https://devfeed.tech/topics/mobile.md>)

Tags: [android-security](<https://devfeed.tech/tags/android-security.md>), [bugs](<https://devfeed.tech/tags/bugs.md>), [cve-2026-58704](<https://devfeed.tech/tags/cve-2026-58704.md>), [google](<https://devfeed.tech/tags/google.md>), [mobile](<https://devfeed.tech/tags/mobile.md>), [modem](<https://devfeed.tech/tags/modem.md>), [news](<https://devfeed.tech/tags/news.md>), [pixel](<https://devfeed.tech/tags/pixel.md>), [security](<https://devfeed.tech/tags/security.md>), [update](<https://devfeed.tech/tags/update.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

Google's September 2026 Pixel security update fixes 110 vulnerabilities, including CVE-2026-58704, a high-severity cellular modem permission-bypass flaw that may be under limited, targeted exploitation. Pixel users should install the update and verify that their device shows the September 5, 2026 security patch level or later.

### Source excerpt

Google's September Pixel update fixes 110 vulnerabilities, including a modem flaw being used in limited, targeted attacks.

## AI helps scammers build convincing antivirus renewal pages

DevFeed: [AI helps scammers build convincing antivirus renewal pages](<https://devfeed.tech/articles/ai-helps-scammers-build-convincing-antivirus-renewal-pages-30921.md>)

Original publisher: [Read original article](<https://www.malwarebytes.com/blog/threat-intel/2026/09/ai-helps-scammers-build-convincing-antivirus-renewal-pages>)

Author: Stefan Dasic

Published: 2026-09-16T08:41:19Z

Content type: article

Language: en

Sources: [Malwarebytes](<https://devfeed.tech/sources/malwarebytes.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Security](<https://devfeed.tech/topics/security.md>), [remote access software](<https://devfeed.tech/topics/remote-access-software.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [remote-access-software](<https://devfeed.tech/tags/remote-access-software.md>), [scams](<https://devfeed.tech/tags/scams.md>), [security](<https://devfeed.tech/tags/security.md>), [threat-intel](<https://devfeed.tech/tags/threat-intel.md>)

### AI overview

The article examines an Avast impersonation site targeting users in Belgium with a fake EUR 129.99 antivirus renewal notice. It reports that the polished design and fluent copy showed signs of AI assistance, while a cancellation form collected names, email addresses, and Belgian mobile numbers for possible follow-up scams.

### Source excerpt

A fake Avast renewal page shows how AI is helping scammers create more convincing traps with polished designs and fluent copy.

## How to opt out of AI chatbot training

DevFeed: [How to opt out of AI chatbot training](<https://devfeed.tech/articles/how-to-opt-out-of-ai-chatbot-training-26953.md>)

Original publisher: [Read original article](<https://www.malwarebytes.com/blog/how-to/2026/09/how-to-opt-out-of-ai-chatbot-training>)

Author: Pieter Arntz

Published: 2026-09-15T15:41:44Z

Content type: tutorial

Language: en

Sources: [Malwarebytes](<https://devfeed.tech/sources/malwarebytes.md>)

Topics: [ChatGPT](<https://devfeed.tech/topics/chatgpt.md>), [OpenAI](<https://devfeed.tech/topics/openai.md>), [online privacy](<https://devfeed.tech/topics/online-privacy.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [anthropic](<https://devfeed.tech/tags/anthropic.md>), [chatgpt](<https://devfeed.tech/tags/chatgpt.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [human-review](<https://devfeed.tech/tags/human-review.md>), [news](<https://devfeed.tech/tags/news.md>), [openai](<https://devfeed.tech/tags/openai.md>), [perplexity](<https://devfeed.tech/tags/perplexity.md>), [privacy](<https://devfeed.tech/tags/privacy.md>), [privacy-filter](<https://devfeed.tech/tags/privacy-filter.md>)

### AI overview

This tutorial explains how to turn off ChatGPT's "Improve the model for everyone" setting to opt out of using chats for model improvement. It also notes that authorized personnel and trusted service providers may still access content for safety, support, troubleshooting, security, abuse investigations, or legal matters.

### Source excerpt

ChatGPT contractors are reviewing real users' conversations. Here's how to stop AI companies using your chats for model training.

## HBO Max's verified Reddit account hijacked to spread malware

DevFeed: [HBO Max's verified Reddit account hijacked to spread malware](<https://devfeed.tech/articles/hbo-max-s-verified-reddit-account-hijacked-to-spread-malware-26612.md>)

Original publisher: [Read original article](<https://www.malwarebytes.com/blog/news/2026/09/hbo-maxs-verified-reddit-account-hijacked-to-spread-malware>)

Author: Pieter Arntz

Published: 2026-09-15T11:51:03Z

Content type: news

Language: en

Sources: [Malwarebytes](<https://devfeed.tech/sources/malwarebytes.md>)

Topics: [Malware](<https://devfeed.tech/topics/malware.md>), [ClickFix](<https://devfeed.tech/topics/clickfix.md>), [Reddit](<https://devfeed.tech/topics/reddit.md>), [Social engineering](<https://devfeed.tech/topics/social-engineering.md>), [passwords](<https://devfeed.tech/topics/passwords.md>), [Cryptocurrency](<https://devfeed.tech/topics/cryptocurrency.md>), [macOS](<https://devfeed.tech/topics/macos.md>), [Windows](<https://devfeed.tech/topics/windows.md>)

Tags: [clickfix](<https://devfeed.tech/tags/clickfix.md>), [cryptocurrency](<https://devfeed.tech/tags/cryptocurrency.md>), [hbo-max](<https://devfeed.tech/tags/hbo-max.md>), [macos](<https://devfeed.tech/tags/macos.md>), [malware](<https://devfeed.tech/tags/malware.md>), [news](<https://devfeed.tech/tags/news.md>), [passwords](<https://devfeed.tech/tags/passwords.md>), [pasteswitch](<https://devfeed.tech/tags/pasteswitch.md>), [powershell](<https://devfeed.tech/tags/powershell.md>), [reddit](<https://devfeed.tech/tags/reddit.md>), [security](<https://devfeed.tech/tags/security.md>), [social-engineering](<https://devfeed.tech/tags/social-engineering.md>), [terminal](<https://devfeed.tech/tags/terminal.md>), [windows](<https://devfeed.tech/tags/windows.md>)

### AI overview

Cybercriminals hijacked HBO Max's verified Reddit account and used it to run 108 malicious ads over about 48 hours. The ads promoted fake software and used ClickFix-style instructions to distribute infostealers and cryptocurrency clipboard hijackers to macOS and Windows users.

### Source excerpt

Cybercriminals used HBO Max's verified Reddit account to run 108 malicious ads that tricked people into installing information stealers.

## Meta AI builds detailed profiles of children from years of family posts

DevFeed: [Meta AI builds detailed profiles of children from years of family posts](<https://devfeed.tech/articles/meta-ai-builds-detailed-profiles-of-children-from-years-of-family-posts-26611.md>)

Original publisher: [Read original article](<https://www.malwarebytes.com/blog/family-and-parenting/2026/09/meta-ai-builds-detailed-profiles-of-children-from-years-of-family-posts>)

Author: Danny Bradbury

Published: 2026-09-15T09:44:10Z

Content type: news

Language: en

Sources: [Malwarebytes](<https://devfeed.tech/sources/malwarebytes.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Meta](<https://devfeed.tech/topics/meta.md>), [Instagram](<https://devfeed.tech/topics/instagram.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [automated](<https://devfeed.tech/tags/automated.md>), [facebook](<https://devfeed.tech/tags/facebook.md>), [family-and-parenting](<https://devfeed.tech/tags/family-and-parenting.md>), [information](<https://devfeed.tech/tags/information.md>), [instagram](<https://devfeed.tech/tags/instagram.md>), [issue](<https://devfeed.tech/tags/issue.md>), [location](<https://devfeed.tech/tags/location.md>), [meta](<https://devfeed.tech/tags/meta.md>), [photos](<https://devfeed.tech/tags/photos.md>), [privacy](<https://devfeed.tech/tags/privacy.md>), [profile](<https://devfeed.tech/tags/profile.md>), [social-media](<https://devfeed.tech/tags/social-media.md>), [statement](<https://devfeed.tech/tags/statement.md>)

### AI overview

A mother says Meta AI assembled detailed profiles of her young daughters by connecting names, birth details, photos, videos, and location information from family posts across Facebook and Instagram. Meta acknowledged that the feature should not have prompted questions about personal topics and said it fixed the issue.

### Source excerpt

A mother says Meta AI pieced together names, birth details, photos, and location information about her young daughters from years of family posts.

## Search results are sending people to fake Bitrefill checkouts

DevFeed: [Search results are sending people to fake Bitrefill checkouts](<https://devfeed.tech/articles/search-results-are-sending-people-to-fake-bitrefill-checkouts-26613.md>)

Original publisher: [Read original article](<https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts>)

Author: Stefan Dasic

Published: 2026-09-15T08:40:22Z

Content type: news

Language: en

Sources: [Malwarebytes](<https://devfeed.tech/sources/malwarebytes.md>)

Topics: [Cryptocurrency](<https://devfeed.tech/topics/cryptocurrency.md>), [Bitcoin](<https://devfeed.tech/topics/bitcoin.md>), [Website](<https://devfeed.tech/topics/website.md>)

Tags: [bitcoin](<https://devfeed.tech/tags/bitcoin.md>), [cryptocurrency](<https://devfeed.tech/tags/cryptocurrency.md>), [fraud](<https://devfeed.tech/tags/fraud.md>), [payments](<https://devfeed.tech/tags/payments.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [qr-code](<https://devfeed.tech/tags/qr-code.md>), [scam](<https://devfeed.tech/tags/scam.md>), [scams](<https://devfeed.tech/tags/scams.md>), [search](<https://devfeed.tech/tags/search.md>), [threat-intel](<https://devfeed.tech/tags/threat-intel.md>)

### AI overview

Fake Bitrefill checkout pages are appearing in search results and copying the company's branding and payment flow. They persuade victims to send cryptocurrency to scammer-controlled addresses, with no goods delivered and little chance of recovering the payment.

### Source excerpt

Fake Bitrefill checkout pages are appearing in search results and tricking people into sending cryptocurrency directly to scammers.

## Google's new search redirects make links harder to check before you click

DevFeed: [Google's new search redirects make links harder to check before you click](<https://devfeed.tech/articles/google-s-new-search-redirects-make-links-harder-to-check-before-you-click-21602.md>)

Original publisher: [Read original article](<https://www.malwarebytes.com/blog/news/2026/09/googles-new-search-redirects-make-links-harder-to-check-before-you-click>)

Author: Pieter Arntz

Published: 2026-09-14T14:17:44Z

Content type: news

Language: en

Sources: [Malwarebytes](<https://devfeed.tech/sources/malwarebytes.md>)

Topics: [Google](<https://devfeed.tech/topics/google.md>), [Google Search](<https://devfeed.tech/topics/google-search.md>), [Search engine optimization (SEO)](<https://devfeed.tech/topics/seo.md>), [Security](<https://devfeed.tech/topics/security.md>), [Accessibility](<https://devfeed.tech/topics/accessibility.md>), [Reddit](<https://devfeed.tech/topics/reddit.md>)

Tags: [accessibility](<https://devfeed.tech/tags/accessibility.md>), [data](<https://devfeed.tech/tags/data.md>), [google](<https://devfeed.tech/tags/google.md>), [google-search](<https://devfeed.tech/tags/google-search.md>), [goto-url](<https://devfeed.tech/tags/goto-url.md>), [news](<https://devfeed.tech/tags/news.md>), [reddit](<https://devfeed.tech/tags/reddit.md>), [search](<https://devfeed.tech/tags/search.md>), [security](<https://devfeed.tech/tags/security.md>), [seo](<https://devfeed.tech/tags/seo.md>), [serp](<https://devfeed.tech/tags/serp.md>)

### AI overview

Google is routing some search result links through opaque, Google-specific redirects instead of linking directly to destinations. The change may make bulk URL extraction harder, but it also limits legitimate tools and makes it more difficult for users to verify a link's destination by hovering before clicking.

### Source excerpt

Google says its new opaque redirects tackle evolving abuse, but they also prevent users from checking a result's destination by hovering over it.

## A week in security (September 7 - September 13)

DevFeed: [A week in security (September 7 - September 13)](<https://devfeed.tech/articles/a-week-in-security-september-7-september-13-17400.md>)

Original publisher: [Read original article](<https://www.malwarebytes.com/blog/news/2026/09/a-week-in-security-september-7-september-13>)

Author: Malwarebytes Labs

Published: 2026-09-14T07:01:00Z

Content type: news

Language: en

Sources: [Malwarebytes](<https://devfeed.tech/sources/malwarebytes.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [bluemoon](<https://devfeed.tech/tags/bluemoon.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [grindr](<https://devfeed.tech/tags/grindr.md>), [lg-tvs](<https://devfeed.tech/tags/lg-tvs.md>), [news](<https://devfeed.tech/tags/news.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

A weekly security roundup covering topics discussed from September 7 to September 13, 2026.

### Source excerpt

A list of topics we covered in the week of September 7 to September 13 of 2026

## Crypto customers targeted by scammers after email marketing provider breach

DevFeed: [Crypto customers targeted by scammers after email marketing provider breach](<https://devfeed.tech/articles/crypto-customers-targeted-by-scammers-after-email-marketing-provider-breach-8437.md>)

Original publisher: [Read original article](<https://www.malwarebytes.com/blog/news/2026/09/crypto-customers-targeted-by-scammers-after-email-marketing-provider-breach>)

Author: Pieter Arntz

Published: 2026-09-11T15:01:53Z

Content type: news

Language: en

Sources: [Malwarebytes](<https://devfeed.tech/sources/malwarebytes.md>)

Topics: [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [incident](<https://devfeed.tech/topics/incident.md>), [API keys](<https://devfeed.tech/topics/api-keys.md>)

Tags: [attacks](<https://devfeed.tech/tags/attacks.md>), [breach](<https://devfeed.tech/tags/breach.md>), [cryptocurrency](<https://devfeed.tech/tags/cryptocurrency.md>), [news](<https://devfeed.tech/tags/news.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [scams](<https://devfeed.tech/tags/scams.md>), [security](<https://devfeed.tech/tags/security.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>)

### AI overview

A Brevo breach enabled phishing emails targeting cryptocurrency-company newsletter subscribers. The attacker exploited a SAML SSO handling flaw, accessed 138 accounts, and used some accounts to send phishing messages or export contacts.

### Source excerpt

A breach at email marketing company Brevo exposed Trezor, CoinTracking, and BitBox customers to phishing emails, but others may also be at risk.

## Android malware creates a hidden copy of your banking app

DevFeed: [Android malware creates a hidden copy of your banking app](<https://devfeed.tech/articles/android-malware-creates-a-hidden-copy-of-your-banking-app-8435.md>)

Original publisher: [Read original article](<https://www.malwarebytes.com/blog/mobile/2026/09/android-malware-creates-a-hidden-copy-of-your-banking-app>)

Author: Pieter Arntz

Published: 2026-09-11T12:14:55Z

Content type: news

Language: en

Sources: [Malwarebytes](<https://devfeed.tech/sources/malwarebytes.md>)

Topics: [Malware](<https://devfeed.tech/topics/malware.md>), [App](<https://devfeed.tech/topics/app.md>)

Tags: [android](<https://devfeed.tech/tags/android.md>), [app](<https://devfeed.tech/tags/app.md>), [credential-theft](<https://devfeed.tech/tags/credential-theft.md>), [fraud](<https://devfeed.tech/tags/fraud.md>), [malware](<https://devfeed.tech/tags/malware.md>), [mobile](<https://devfeed.tech/tags/mobile.md>), [news](<https://devfeed.tech/tags/news.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [profile](<https://devfeed.tech/tags/profile.md>), [security](<https://devfeed.tech/tags/security.md>), [transactions](<https://devfeed.tech/tags/transactions.md>)

### AI overview

Gigabud is an Android banking Trojan that creates a work profile and clones a banking app so operators can conduct fraudulent transactions separately from malware detected in the personal profile.

### Source excerpt

The Gigabud banking Trojan can clone a banking app into a separate work profile on an Android device to help hide fraudulent transactions.

## BlueMoon exploit kit turns Chrome and Windows flaws into attacks

DevFeed: [BlueMoon exploit kit turns Chrome and Windows flaws into attacks](<https://devfeed.tech/articles/bluemoon-exploit-kit-turns-chrome-and-windows-flaws-into-attacks-8432.md>)

Original publisher: [Read original article](<https://www.malwarebytes.com/blog/bugs/2026/09/bluemoon-exploit-kit-turns-chrome-and-windows-flaws-into-attacks>)

Author: Pieter Arntz

Published: 2026-09-10T15:49:13Z

Content type: article

Language: en

Sources: [Malwarebytes](<https://devfeed.tech/sources/malwarebytes.md>)

Topics: [BlueMoon](<https://devfeed.tech/topics/bluemoon.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Google](<https://devfeed.tech/topics/google.md>), [Microsoft](<https://devfeed.tech/topics/microsoft.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [bluemoon](<https://devfeed.tech/tags/bluemoon.md>), [bugs](<https://devfeed.tech/tags/bugs.md>), [chrome](<https://devfeed.tech/tags/chrome.md>), [news](<https://devfeed.tech/tags/news.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [update](<https://devfeed.tech/tags/update.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [windows](<https://devfeed.tech/tags/windows.md>)

### AI overview

BlueMoon is a shared exploit kit used by four espionage groups to exploit recently patched Chrome V8 and Windows vulnerabilities after phishing clicks. The article argues that attackers can weaponize public fixes quickly, making prompt patch deployment important; AI assistance is suggested only as an unproven possibility.

### Source excerpt

Four different espionage groups used the same exploit kit to target recently fixed flaws, showing why "patch later" is a dangerous gamble.

## Will AI kill us all within the next decade?

DevFeed: [Will AI kill us all within the next decade?](<https://devfeed.tech/articles/will-ai-kill-us-all-within-the-next-decade-8431.md>)

Original publisher: [Read original article](<https://www.malwarebytes.com/blog/ai/2026/09/will-ai-kill-us-all-within-the-next-decade>)

Author: Pieter Arntz

Published: 2026-09-10T12:18:51Z

Content type: opinion

Language: en

Sources: [Malwarebytes](<https://devfeed.tech/sources/malwarebytes.md>)

Topics: [Responsibility & Safety](<https://devfeed.tech/topics/responsibility-safety.md>), [AI Strategy](<https://devfeed.tech/topics/ai-strategy.md>), [AI Development](<https://devfeed.tech/topics/ai-development.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [anthropic](<https://devfeed.tech/topics/anthropic.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-safety](<https://devfeed.tech/tags/ai-safety.md>), [anthropic](<https://devfeed.tech/tags/anthropic.md>), [autonomous](<https://devfeed.tech/tags/autonomous.md>), [fraud](<https://devfeed.tech/tags/fraud.md>), [models](<https://devfeed.tech/tags/models.md>), [news](<https://devfeed.tech/tags/news.md>), [superintelligence](<https://devfeed.tech/tags/superintelligence.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

The article discusses warnings about possible future AI risks while noting that current models are described as low risk. It argues for safeguards such as independent testing, limits on high-risk autonomous uses, transparency, and accountability, alongside action against AI-enabled cybercrime.

### Source excerpt

AI researchers are warning that the technology could kill us all within the next decade, although they say the risk from current models is low.

## Update Chrome now to protect against an actively exploited vulnerability

DevFeed: [Update Chrome now to protect against an actively exploited vulnerability](<https://devfeed.tech/articles/update-chrome-now-to-protect-against-an-actively-exploited-vulnerability-8433.md>)

Original publisher: [Read original article](<https://www.malwarebytes.com/blog/bugs/2026/09/update-chrome-now-to-protect-against-an-actively-exploited-vulnerability>)

Author: Pieter Arntz

Published: 2026-09-10T10:52:08Z

Content type: news

Language: en

Sources: [Malwarebytes](<https://devfeed.tech/sources/malwarebytes.md>)

Topics: [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [bug](<https://devfeed.tech/topics/bug.md>)

Tags: [browser](<https://devfeed.tech/tags/browser.md>), [bugs](<https://devfeed.tech/tags/bugs.md>), [chrome](<https://devfeed.tech/tags/chrome.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [memory](<https://devfeed.tech/tags/memory.md>), [news](<https://devfeed.tech/tags/news.md>), [sandbox](<https://devfeed.tech/tags/sandbox.md>), [security](<https://devfeed.tech/tags/security.md>), [stable-channel](<https://devfeed.tech/tags/stable-channel.md>), [update](<https://devfeed.tech/tags/update.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [webgl](<https://devfeed.tech/tags/webgl.md>)

### AI overview

Chrome's desktop update fixes 230 security issues, including CVE-2026-87491, an actively exploited V8 out-of-bounds write flaw. The article explains how to update Chrome and describes the vulnerability's potential impact within the browser sandbox.

### Source excerpt

Chrome issues another monster update, fixing an actively exploited V8 vulnerability and 229 other flaws.

## More than 100,000 fake stores are out to steal your card details

DevFeed: [More than 100,000 fake stores are out to steal your card details](<https://devfeed.tech/articles/more-than-100-000-fake-stores-are-out-to-steal-your-card-details-8448.md>)

Original publisher: [Read original article](<https://www.malwarebytes.com/blog/scams/2026/09/more-than-100000-fake-stores-are-out-to-steal-your-card-details>)

Author: Pieter Arntz

Published: 2026-09-09T15:02:53Z

Content type: news

Language: en

Sources: [Malwarebytes](<https://devfeed.tech/sources/malwarebytes.md>)

Topics: [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Security & Privacy](<https://devfeed.tech/topics/security-privacy.md>), [WebSocket](<https://devfeed.tech/topics/websocket.md>)

Tags: [authentication](<https://devfeed.tech/tags/authentication.md>), [backends](<https://devfeed.tech/tags/backends.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [doppelcart](<https://devfeed.tech/tags/doppelcart.md>), [fake-webshops](<https://devfeed.tech/tags/fake-webshops.md>), [news](<https://devfeed.tech/tags/news.md>), [scams](<https://devfeed.tech/tags/scams.md>)

### AI overview

Researchers identified DoppelCart, a large network of cloned online stores that copies real retailers and steals card data and bank confirmation codes during checkout.

### Source excerpt

DoppelCart's fake stores copy real retailers and steal shoppers' card details and one-time bank confirmation codes.

## Microsoft fixes record 964 flaws, including 2 exploited zero-days

DevFeed: [Microsoft fixes record 964 flaws, including 2 exploited zero-days](<https://devfeed.tech/articles/microsoft-fixes-record-964-flaws-including-2-exploited-zero-days-8439.md>)

Original publisher: [Read original article](<https://www.malwarebytes.com/blog/news/2026/09/microsoft-fixes-record-964-flaws-including-2-exploited-zero-days>)

Author: Pieter Arntz

Published: 2026-09-09T10:01:08Z

Content type: news

Language: en

Sources: [Malwarebytes](<https://devfeed.tech/sources/malwarebytes.md>)

Topics: [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>)

Tags: [bugs](<https://devfeed.tech/tags/bugs.md>), [cve-2026-81963](<https://devfeed.tech/tags/cve-2026-81963.md>), [cve-2026-85880](<https://devfeed.tech/tags/cve-2026-85880.md>), [dns](<https://devfeed.tech/tags/dns.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [news](<https://devfeed.tech/tags/news.md>), [patch-tuesday](<https://devfeed.tech/tags/patch-tuesday.md>), [september-2026](<https://devfeed.tech/tags/september-2026.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [windows](<https://devfeed.tech/tags/windows.md>)

### AI overview

Microsoft's September 2026 Patch Tuesday fixes 964 customer-patched vulnerabilities, including two actively exploited Windows zero-days.

### Source excerpt

Microsoft's September 2026 Patch Tuesday fixes a record 964 vulnerabilities, including two actively exploited zero-days.

## Grindr settles HIV status data-sharing lawsuit for $35 million

DevFeed: [Grindr settles HIV status data-sharing lawsuit for $35 million](<https://devfeed.tech/articles/grindr-settles-hiv-status-data-sharing-lawsuit-for-35-million-8444.md>)

Original publisher: [Read original article](<https://www.malwarebytes.com/blog/privacy/2026/09/grindr-settles-hiv-status-data-sharing-lawsuit-for-35-million>)

Author: Pieter Arntz

Published: 2026-09-08T12:51:14Z

Content type: news

Language: en

Sources: [Malwarebytes](<https://devfeed.tech/sources/malwarebytes.md>)

Topics: [online privacy](<https://devfeed.tech/topics/online-privacy.md>), [App](<https://devfeed.tech/topics/app.md>), [SDKs](<https://devfeed.tech/topics/sdks.md>)

Tags: [advertising](<https://devfeed.tech/tags/advertising.md>), [grindr](<https://devfeed.tech/tags/grindr.md>), [lawsuit](<https://devfeed.tech/tags/lawsuit.md>), [news](<https://devfeed.tech/tags/news.md>), [norway](<https://devfeed.tech/tags/norway.md>), [privacy](<https://devfeed.tech/tags/privacy.md>), [sdks](<https://devfeed.tech/tags/sdks.md>), [uk-lawsuit](<https://devfeed.tech/tags/uk-lawsuit.md>)

### AI overview

Grindr reportedly agreed to settle a UK lawsuit alleging that it shared sensitive user data, including HIV-status information, with advertisers. The article explains privacy risks from advertising identifiers, analytics, SDKs, and other third-party app integrations.

### Source excerpt

Grindr has settled a UK lawsuit alleging that it shared sensitive user data, including HIV status, with advertising companies.

## MikroTik router flaws allow takeover without a password

DevFeed: [MikroTik router flaws allow takeover without a password](<https://devfeed.tech/articles/mikrotik-router-flaws-allow-takeover-without-a-password-8440.md>)

Original publisher: [Read original article](<https://www.malwarebytes.com/blog/news/2026/09/mikrotik-routers-can-be-taken-over-without-password>)

Author: Pieter Arntz

Published: 2026-09-08T09:49:16Z

Content type: news

Language: en

Sources: [Malwarebytes](<https://devfeed.tech/sources/malwarebytes.md>)

Topics: [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Networks](<https://devfeed.tech/topics/networks.md>), [passwords](<https://devfeed.tech/topics/passwords.md>)

Tags: [authentication](<https://devfeed.tech/tags/authentication.md>), [cve-2026-67276](<https://devfeed.tech/tags/cve-2026-67276.md>), [cve-2026-86060](<https://devfeed.tech/tags/cve-2026-86060.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [mikrotik](<https://devfeed.tech/tags/mikrotik.md>), [news](<https://devfeed.tech/tags/news.md>), [ssh](<https://devfeed.tech/tags/ssh.md>), [update](<https://devfeed.tech/tags/update.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Attackers are actively exploiting two MikroTik RouterOS flaws, dubbed MikroTrick, to bypass SSH authentication and escalate privileges on internet-exposed routers. The article recommends promptly installing RouterOS updates and restricting SSH and other remote-management access.

### Source excerpt

Attackers are exploiting critical RouterOS flaws to take control of routers with SSH exposed to the internet.

## Loyalty points fraud is funding hacker holidays (Lock and Code S07E18)

DevFeed: [Loyalty points fraud is funding hacker holidays (Lock and Code S07E18)](<https://devfeed.tech/articles/loyalty-points-fraud-is-funding-hacker-holidays-lock-and-code-s07e18-8443.md>)

Original publisher: [Read original article](<https://www.malwarebytes.com/blog/podcast/2026/09/loyalty-points-fraud-is-funding-hacker-holidays-lock-and-code-s07e18>)

Author: Malwarebytes Labs

Published: 2026-09-07T18:23:18Z

Content type: article

Language: en

Sources: [Malwarebytes](<https://devfeed.tech/sources/malwarebytes.md>)

Topics: [Cybercrime](<https://devfeed.tech/topics/cybercrime.md>), [passwords](<https://devfeed.tech/topics/passwords.md>)

Tags: [account-takeover](<https://devfeed.tech/tags/account-takeover.md>), [airline](<https://devfeed.tech/tags/airline.md>), [airline-miles](<https://devfeed.tech/tags/airline-miles.md>), [credit-card-points](<https://devfeed.tech/tags/credit-card-points.md>), [cybercrime](<https://devfeed.tech/tags/cybercrime.md>), [fraud](<https://devfeed.tech/tags/fraud.md>), [hotel-rewards](<https://devfeed.tech/tags/hotel-rewards.md>), [loyalty-account](<https://devfeed.tech/tags/loyalty-account.md>), [loyalty-points](<https://devfeed.tech/tags/loyalty-points.md>), [loyalty-points-fraud](<https://devfeed.tech/tags/loyalty-points-fraud.md>), [podcast](<https://devfeed.tech/tags/podcast.md>), [points](<https://devfeed.tech/tags/points.md>), [rewards-account](<https://devfeed.tech/tags/rewards-account.md>), [rewards-points](<https://devfeed.tech/tags/rewards-points.md>)

### AI overview

A Lock and Code podcast episode examines loyalty-points theft, why criminals target points balances, and ways companies and consumers can protect against fraud.

### Source excerpt

This week on the Lock and Code podcast, we speak with Kim Sutherland about loyalty points fraud and how everyday people can stay safe.

## LG TV flaws could let attackers listen in, even in standby mode

DevFeed: [LG TV flaws could let attackers listen in, even in standby mode](<https://devfeed.tech/articles/lg-tv-flaws-could-let-attackers-listen-in-even-in-standby-mode-8445.md>)

Original publisher: [Read original article](<https://www.malwarebytes.com/blog/privacy/2026/09/lg-tv-flaws-could-let-attackers-listen-in-even-in-standby-mode>)

Author: Pieter Arntz

Published: 2026-09-07T13:34:40Z

Content type: news

Language: en

Sources: [Malwarebytes](<https://devfeed.tech/sources/malwarebytes.md>)

Topics: [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Networks](<https://devfeed.tech/topics/networks.md>), [Embedded Software Dev](<https://devfeed.tech/topics/embedded-software-dev.md>)

Tags: [acr](<https://devfeed.tech/tags/acr.md>), [audio](<https://devfeed.tech/tags/audio.md>), [lg](<https://devfeed.tech/tags/lg.md>), [networks](<https://devfeed.tech/tags/networks.md>), [news](<https://devfeed.tech/tags/news.md>), [privacy](<https://devfeed.tech/tags/privacy.md>), [security](<https://devfeed.tech/tags/security.md>), [smart-tv](<https://devfeed.tech/tags/smart-tv.md>), [testing](<https://devfeed.tech/tags/testing.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

An investigation reported that LG smart TVs may scan local networks and collect viewing-related data, while undisclosed vulnerabilities could enable audio capture from a compromised TV.

### Source excerpt

Testing found that LG smart TVs can track viewing and scan home networks, while security flaws could let attackers record conversations.

## Flirty OnlyFans promoters on X may be using AI to appear human

DevFeed: [Flirty OnlyFans promoters on X may be using AI to appear human](<https://devfeed.tech/articles/flirty-onlyfans-promoters-on-x-may-be-using-ai-to-appear-human-8430.md>)

Original publisher: [Read original article](<https://www.malwarebytes.com/blog/ai/2026/09/flirty-onlyfans-promoters-on-x-may-be-using-ai-to-appear-human>)

Author: Pieter Arntz

Published: 2026-09-07T11:18:00Z

Content type: article

Language: en

Sources: [Malwarebytes](<https://devfeed.tech/sources/malwarebytes.md>)

Topics: [AI Chat](<https://devfeed.tech/topics/ai-chat.md>), [Script](<https://devfeed.tech/topics/script.md>), [Chat Bot](<https://devfeed.tech/topics/chatbot.md>), [Bot](<https://devfeed.tech/topics/bot.md>), [ASCII](<https://devfeed.tech/topics/ascii.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ascii](<https://devfeed.tech/tags/ascii.md>), [bots](<https://devfeed.tech/tags/bots.md>), [fraud](<https://devfeed.tech/tags/fraud.md>), [generative-ai](<https://devfeed.tech/tags/generative-ai.md>), [messaging](<https://devfeed.tech/tags/messaging.md>), [onlyfans](<https://devfeed.tech/tags/onlyfans.md>), [scam](<https://devfeed.tech/tags/scam.md>), [scams](<https://devfeed.tech/tags/scams.md>), [scripted](<https://devfeed.tech/tags/scripted.md>), [threat-intel](<https://devfeed.tech/tags/threat-intel.md>), [voice](<https://devfeed.tech/tags/voice.md>)

### AI overview

An investigation examines X accounts promoting OnlyFans pages that combine repetitive flirtatious scripts with dynamic replies, raising the possibility of generative AI-assisted messaging. It warns that personalized responses and voice notes may no longer reliably distinguish people from automated accounts.

### Source excerpt

Personalized replies and voice notes make it increasingly difficult to tell whether you're talking to a human, chatbot, or AI agent.

## The hidden work of modernizing Malwarebytes

DevFeed: [The hidden work of modernizing Malwarebytes](<https://devfeed.tech/articles/the-hidden-work-of-modernizing-malwarebytes-8434.md>)

Original publisher: [Read original article](<https://www.malwarebytes.com/blog/inside-malwarebytes/2026/09/the-hidden-work-of-modernizing-malwarebytes>)

Author: Anna Tukhtarova

Published: 2026-09-04T17:15:42Z

Content type: article

Language: en

Sources: [Malwarebytes](<https://devfeed.tech/sources/malwarebytes.md>)

Topics: [.NET](<https://devfeed.tech/topics/net.md>), [migration](<https://devfeed.tech/topics/migration.md>), [Endpoint Security & XDR](<https://devfeed.tech/topics/endpoint-security-xdr.md>), [Operating system](<https://devfeed.tech/topics/operating-system.md>)

Tags: [diagnostics](<https://devfeed.tech/tags/diagnostics.md>), [drivers](<https://devfeed.tech/tags/drivers.md>), [endpoint-security](<https://devfeed.tech/tags/endpoint-security.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [inside-malwarebytes](<https://devfeed.tech/tags/inside-malwarebytes.md>), [migration](<https://devfeed.tech/tags/migration.md>), [modernization](<https://devfeed.tech/tags/modernization.md>), [net](<https://devfeed.tech/tags/net.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

The article explains Malwarebytes' migration of its managed Windows components to .NET 10 and why runtime and dependency upgrades require security-feature-level rigor in endpoint software.

### Source excerpt

Why disciplined dependency modernization is one of the highest-leverage engineering investments a security product can make.

## X Money rollout linked to password-reset attacks

DevFeed: [X Money rollout linked to password-reset attacks](<https://devfeed.tech/articles/x-money-rollout-linked-to-password-reset-attacks-8449.md>)

Original publisher: [Read original article](<https://www.malwarebytes.com/blog/scams/2026/09/x-money-rollout-linked-to-password-reset-attacks>)

Author: Pieter Arntz

Published: 2026-09-04T12:29:41Z

Content type: news

Language: en

Sources: [Malwarebytes](<https://devfeed.tech/sources/malwarebytes.md>)

Topics: [passwords](<https://devfeed.tech/topics/passwords.md>)

Tags: [account-takeover](<https://devfeed.tech/tags/account-takeover.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [breach](<https://devfeed.tech/tags/breach.md>), [financial-services](<https://devfeed.tech/tags/financial-services.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [news](<https://devfeed.tech/tags/news.md>), [password-reset](<https://devfeed.tech/tags/password-reset.md>), [scams](<https://devfeed.tech/tags/scams.md>), [security](<https://devfeed.tech/tags/security.md>), [social-engineering](<https://devfeed.tech/tags/social-engineering.md>), [x-money](<https://devfeed.tech/tags/x-money.md>)

### AI overview

X is investigating unsolicited password-reset emails sent to users amid the wider availability of X Money. The company says it has found no evidence of a breach, successful account takeovers, or access to X Money funds.

### Source excerpt

As X expands into payments, users are receiving password-reset emails they didn't request. Here's what may be happening and how to stay safe.

[Next page](<https://devfeed.tech/sources/malwarebytes.md?cursor=WyIyMDI2LTA5LTA0VDEyOjI5OjQxKzAwOjAwIiwgIjUzNWRlNzg3LWY1MDktNDBiNi1iZGE2LTgxZGQwNjQ1ZTdjZSJd>)