Recent Advisories

Severity ID Title Vendor Product Date Type
NONE MALWAREBYTES:FF...

Fake extension crashes browsers to trick users into infecting themselves_MALWAREBYTES:FFC3F30967A34EF682C65C05142BECF3

Researchers have found another method used in the spirit of ClickFix: **CrashFix**. ClickFix campaigns use convincing lures—historically “Human Ve...

N/A N/A MALWAREBYTES
NONE MALWAREBYTES:91...

Google will pay $8.25m to settle child data-tracking allegations_MALWAREBYTES:919702582EAF5C6C212E181CFCE942F9

Google has settled yet another class-action lawsuit accusing it of collecting children’s data and using it to target them with advertising. The tec...

N/A N/A MALWAREBYTES
NONE MALWAREBYTES:21...

Firefox joins Chrome and Edge as sleeper extensions spy on users_MALWAREBYTES:21BA94F6DC0ABBA6378A38D7FB11A839

A group of cybercriminals called DarkSpectre is believed to be behind three campaigns spread by malicious browser extensions: ShadyPanda, GhostPost...

N/A N/A MALWAREBYTES
NONE MALWAREBYTES:99...

A week in security (January 12 – January 18)_MALWAREBYTES:99105FBFE32FD118AD7F64109CD4CB8E

Last week on Malwarebytes Labs: * WhisperPair exposes Bluetooth earbuds and headphones to tracking and eavesdropping * Dutch police sell fake ...

N/A N/A MALWAREBYTES
HIGH 7.1 MALWAREBYTES:AD...

WhisperPair exposes Bluetooth earbuds and headphones to tracking and eavesdropping_MALWAREBYTES:AD0AB4F60BDD7A7C6E93EC7CA8C2BBB9

WhisperPair is a set of attacks that lets an attacker hijack many popular Bluetooth audio accessories that use Google Fast Pair and, in some cases,...

N/A N/A MALWAREBYTES
NONE MALWAREBYTES:C5...

Dutch police sell fake tickets to show how easily scams work_MALWAREBYTES:C50004CDF624CFF91FEE5D1CA7050578

If you can’t beat them, copy them. That seems to be the thinking behind an unusual campaign by the Dutch police, who set up a fake ticket website s...

N/A N/A MALWAREBYTES
NONE MALWAREBYTES:34...

“Reprompt” attack lets attackers steal data from Microsoft Copilot_MALWAREBYTES:343D010EA86234D12B7C14AB001130DD

Researchers found a method to steal data which bypasses Microsoft Copilot's built-in safety mechanisms. **** The attack flow, called **Reprompt** ...

N/A N/A MALWAREBYTES
NONE MALWAREBYTES:F2...

Online shoppers at risk as Magecart skimming hits major payment networks_MALWAREBYTES:F263B261290D86C81519B0796D20806F

Researchers have been tracking a Magecart campaign that targets several major payment providers, including American Express, Diners Club, Discover,...

N/A N/A MALWAREBYTES
NONE MALWAREBYTES:3B...

Phishing scammers are posting fake “account restricted” comments on LinkedIn_MALWAREBYTES:3B3D6A3F03D00070787545DDAB028224

Recently, fake LinkedIn profiles have started posting comment replies claiming that a user has **" engaged in activities that are not in compliance...

N/A N/A MALWAREBYTES
NONE MALWAREBYTES:94...

How real software downloads can hide remote backdoors_MALWAREBYTES:94D6834859C409033C7B7159C2EE24C4

It starts with a simple search. You need to set up remote access to a colleague’s computer. You do a Google search for “RustDesk download,” click ...

N/A N/A MALWAREBYTES