Four different espionage groups used the same exploit kit to target recently fixed flaws, showing why “patch later” is a dangerous gamble.
Category: Malwarebytes
MikroTik router flaws allow takeover without a password
Attackers are exploiting critical RouterOS flaws to take control of routers with SSH exposed to the internet.
Will AI kill us all within the next decade?
AI researchers are warning that the technology could kill us all within the next decade, although they say the risk from current models is low.
Update Chrome now to protect against an actively exploited vulnerability
Chrome issues another monster update, fixing an actively exploited V8 vulnerability and 229 other flaws.
Copyright scammers get Instagram accounts suspended and demand payment
Scammers are filing fraudulent copyright complaints to suspend Instagram accounts, then demanding payment to withdraw them.
A week in security (August 31 – September 6)
Last week on Malwarebytes Labs: Stay safe!
More than 100,000 fake stores are out to steal your card details
DoppelCart’s fake stores copy real retailers and steal shoppers’ card details and one-time bank confirmation codes.
Microsoft fixes record 964 flaws, including 2 exploited zero-days
Microsoft’s September 2026 Patch Tuesday fixes a record 964 vulnerabilities, including two actively exploited zero-days.
The push to stop algorithms controlling social media feeds has begun
Australia is proposing a law that gives people a choice over what fills their feeds. It may not be long before other countries demand the same.
Grindr settles HIV status data-sharing lawsuit for $35 million
Grindr has settled a UK lawsuit alleging that it shared sensitive user data, including HIV status, with advertising companies.
MikroTik router flaws allow takeover without a password
Attackers are exploiting critical RouterOS flaws to take control of routers with SSH exposed to the internet.
Loyalty points fraud is funding hacker holidays (Lock and Code S07E18)
This week on the Lock and Code podcast, we speak with Kim Sutherland about loyalty points fraud and how everyday people can stay safe.
LG TV flaws could let attackers listen in, even in standby mode
Testing found that LG smart TVs can track viewing and scan home networks, while security flaws could let attackers record conversations.
Flirty OnlyFans promoters on X may be using AI to appear human
Personalized replies and voice notes make it increasingly difficult to tell whether you’re talking to a human, chatbot, or AI agent.
A week in security (August 31 – September 6)
Last week on Malwarebytes Labs: Stay safe!
The hidden work of modernizing Malwarebytes
Why disciplined dependency modernization is one of the highest-leverage engineering investments a security product can make.
X Money rollout linked to password-reset attacks
As X expands into payments, users are receiving password-reset emails they didn’t request. Here’s what may be happening and how to stay safe.
Free streaming boxes may be routing criminal traffic through your home
Researchers found that apps available on SuperBox devices could add your household connection to a residential proxy network.
StreamRat Android malware spreads through Meta and TikTok ads
Social media ads for a free streaming service exposed roughly 570,000 people to StreamRat, a banking Trojan that can take control of infected phones.
Your phone or computer may soon ask how old you are
California and Colorado will require operating systems to collect users’ ages, but open-source software like Linux may be exempt.
