Recent Advisories

Severity ID Title Vendor Product Date Type
NONE MALWAREBYTES:2F...

TikTok narrowly avoids a US ban by spinning up a new American joint venture_MALWAREBYTES:2FF875005CA327AF0C48B57993E6CE01

TikTok may have found a way to stay online in the US. The company announced late last week that it has set up a joint venture backed largely by US ...

N/A N/A MALWAREBYTES
NONE MALWAREBYTES:26...

Get paid to scroll TikTok? The data trade behind Freecash ads_MALWAREBYTES:2664AE06482DF8B53FABD6876E70A5E4

Loyal readers and other privacy-conscious people will be familiar with the expression, “If it’s too good to be true, it’s probably false.” Getting...

N/A N/A MALWAREBYTES
NONE MALWAREBYTES:29...

One privacy change I made for 2026 (Lock and Code S07E02)_MALWAREBYTES:29616EE80DA773CE81C05DB4D1CD742D

_This week on the Lock and Code podcast …_ When you hear the words "data privacy," what do you first imagine? Maybe you picture going into your s...

N/A N/A MALWAREBYTES
NONE MALWAREBYTES:CA...

A week in security (January 19 – January 25)_MALWAREBYTES:CAFBBD2BAC5A77427B79011A3E4B1915

Last week on Malwarebytes Labs: * Spammers abuse Zendesk to flood inboxes with legitimate-looking emails, but why? * Fake LastPass maintenance...

N/A N/A MALWAREBYTES
NONE MALWAREBYTES:7D...

Can you use too many LOLBins to drop some RATs?_MALWAREBYTES:7DB75EE503E7656F7F1BD410B5BBAEBA

Recently, our team came across an infection attempt that stood out—not for its sophistication, but for how determined the attacker was to take a “l...

N/A N/A MALWAREBYTES
NONE MALWAREBYTES:DF...

Malicious Google Calendar invites could expose private data_MALWAREBYTES:DF4B01385BC3544ED806B60FB33795C0

Researchers found a way to weaponize calendar invites. They uncovered a vulnerability that allowed them to bypass Google Calendar’s privacy control...

N/A N/A MALWAREBYTES
NONE MALWAREBYTES:FF...

Fake extension crashes browsers to trick users into infecting themselves_MALWAREBYTES:FFC3F30967A34EF682C65C05142BECF3

Researchers have found another method used in the spirit of ClickFix: **CrashFix**. ClickFix campaigns use convincing lures—historically “Human Ve...

N/A N/A MALWAREBYTES
NONE MALWAREBYTES:91...

Google will pay $8.25m to settle child data-tracking allegations_MALWAREBYTES:919702582EAF5C6C212E181CFCE942F9

Google has settled yet another class-action lawsuit accusing it of collecting children’s data and using it to target them with advertising. The tec...

N/A N/A MALWAREBYTES
NONE MALWAREBYTES:21...

Firefox joins Chrome and Edge as sleeper extensions spy on users_MALWAREBYTES:21BA94F6DC0ABBA6378A38D7FB11A839

A group of cybercriminals called DarkSpectre is believed to be behind three campaigns spread by malicious browser extensions: ShadyPanda, GhostPost...

N/A N/A MALWAREBYTES
NONE MALWAREBYTES:99...

A week in security (January 12 – January 18)_MALWAREBYTES:99105FBFE32FD118AD7F64109CD4CB8E

Last week on Malwarebytes Labs: * WhisperPair exposes Bluetooth earbuds and headphones to tracking and eavesdropping * Dutch police sell fake ...

N/A N/A MALWAREBYTES