Recent Advisories

Severity ID Title Vendor Product Date Type
NONE MALWAREBYTES:4A...

Fake Claude search results lure Mac users into ClickFix attack_MALWAREBYTES:4A75C7E75226E5CC7526911F535E64FB

Researchers found that cybercriminals are using sponsored search results and shared Claude chats to lure victims into a typical ClickFix attack to ...

N/A N/A MALWAREBYTES
NONE MALWAREBYTES:CC...

1 in 8 employees have sold company logins or know someone who has_MALWAREBYTES:CC5FA18D06D919151D29206503094C84

UK anti-fraud non-profit Cifas just published research that should bother anyone who runs a business, or buys from one: One in eight workers at lar...

N/A N/A MALWAREBYTES
NONE MALWAREBYTES:92...

Stolen Canvas data was “returned” after hacker agreement, Instructure says_MALWAREBYTES:9274630BAF4A0988E459A4D4B97CB1A7

The Instructure/Canvas data breach that has dominated cybersecurity coverage recently has reached a new stage. Millions of students had personal d...

N/A N/A MALWAREBYTES
NONE MALWAREBYTES:49...

Yarbo responds to robot flaws that could mow down their owners_MALWAREBYTES:49B29ABA09490928A167FF4332A523FA

A researcher found that Yarbo yard robots came with a host of vulnerabilities which, among others, allowed an attacker to harvest WiFi passwords. ...

N/A N/A MALWAREBYTES
NONE MALWAREBYTES:42...

A week in security (May 4 – May 10)_MALWAREBYTES:42B26F60FCF89DFC46805F5BC524CA8F

Last week on Malwarebytes Labs: * Microsoft says Edge’s plaintext password behavior is "by design" * ShinyHunters escalates Canvas attacks wit...

N/A N/A MALWAREBYTES
NONE MALWAREBYTES:DE...

ShinyHunters escalates Canvas attacks with school login defacements_MALWAREBYTES:DE11220BFEE59A50990A7A149A46BBD4

Days after confirming a major data breach, Instructure is now facing a second blow. Earlier this week, Instructure confirmed a major data breach a...

N/A N/A MALWAREBYTES
NONE MALWAREBYTES:8B...

Microsoft says Edge’s plaintext password behavior is “by design”_MALWAREBYTES:8B9A141837D7256A2EB491D145ABF7BC

Some time ago, we discussed whether you should allow your browser to remember your passwords. In that article we mentioned the importance of encry...

N/A N/A MALWAREBYTES
NONE MALWAREBYTES:46...

Massive AI investment scam network spans 15,500 domains_MALWAREBYTES:464027414A683683CCC98F7C3571E167

Researchers tracked a large AI‑themed investment scam campaign involving more than 15,000 domains. It uses cloaking and deepfakes to hide from secu...

N/A N/A MALWAREBYTES
NONE MALWAREBYTES:F6...

If a fake moustache can fool age checks, is the Online Safety Act working?_MALWAREBYTES:F6ADC9486EDED75908EC3942EE314639

A report based on a survey by the UK’s Internet Matters shows that much of the responsibility for managing the online safety of children still fall...

N/A N/A MALWAREBYTES
NONE MALWAREBYTES:7A...

Google Chrome’s silent 4GB AI download problem_MALWAREBYTES:7A162BB645237304A48BE61131A011CC

Google Chrome has been quietly downloading a 4GB AI model onto users' devices without asking first. Security researcher Alexander Hanff, aka ThatP...

N/A N/A MALWAREBYTES