The digital bank was tricked into releasing sensitive customer information, including IDs, to an attacker using a legitimate government email domain.
Category: Malwarebytes
A week in security (September 7 – September 13)
A list of topics we covered in the week of September 7 to September 13 of 2026
Google Pixel owners urged to patch actively exploited modem flaw
Google’s September Pixel update fixes 110 vulnerabilities, including a modem flaw being used in limited, targeted attacks.
AI helps scammers build convincing antivirus renewal pages
A fake Avast renewal page shows how AI is helping scammers create more convincing traps with polished designs and fluent copy.
How to opt out of AI chatbot training
ChatGPT contractors are reviewing real users’ conversations. Here’s how to stop AI companies using your chats for model training.
HBO Max’s verified Reddit account hijacked to spread malware
Cybercriminals used HBO Max’s verified Reddit account to run 108 malicious ads that tricked people into installing information stealers.
Meta AI builds detailed profiles of children from years of family posts
A mother says Meta AI pieced together names, birth details, photos, and location information about her young daughters from years of family posts.
Search results are sending people to fake Bitrefill checkouts
Fake Bitrefill checkout pages are appearing in search results and tricking people into sending cryptocurrency directly to scammers.
Google’s new search redirects make links harder to check before you click
Google says its new opaque redirects tackle evolving abuse, but they also prevent users from checking a result’s destination by hovering over it.
Revolut gave customer IDs and financial data to a government impostor
The digital bank was tricked into releasing sensitive customer information, including IDs, to an attacker using a legitimate government email domain.
A week in security (September 7 – September 13)
A list of topics we covered in the week of September 7 to September 13 of 2026
Will AI kill us all within the next decade?
AI researchers are warning that the technology could kill us all within the next decade, although they say the risk from current models is low.
Update Chrome now to protect against an actively exploited vulnerability
Chrome issues another monster update, fixing an actively exploited V8 vulnerability and 229 other flaws.
Copyright scammers get Instagram accounts suspended and demand payment
Scammers are filing fraudulent copyright complaints to suspend Instagram accounts, then demanding payment to withdraw them.
Crypto customers targeted by scammers after email marketing provider breach
A breach at email marketing company Brevo exposed Trezor, CoinTracking, and BitBox customers to phishing emails, but others may also be at risk.
More than 100,000 fake stores are out to steal your card details
DoppelCart’s fake stores copy real retailers and steal shoppers’ card details and one-time bank confirmation codes.
Android malware creates a hidden copy of your banking app
The Gigabud banking Trojan can clone a banking app into a separate work profile on an Android device to help hide fraudulent transactions.
Microsoft fixes record 964 flaws, including 2 exploited zero-days
Microsoft’s September 2026 Patch Tuesday fixes a record 964 vulnerabilities, including two actively exploited zero-days.
The push to stop algorithms controlling social media feeds has begun
Australia is proposing a law that gives people a choice over what fills their feeds. It may not be long before other countries demand the same.
Grindr settles HIV status data-sharing lawsuit for $35 million
Grindr has settled a UK lawsuit alleging that it shared sensitive user data, including HIV status, with advertising companies.
