Recent Advisories

Severity ID Title Vendor Product Date Type
NONE MALWAREBYTES:03...

Hacktivists claim near-total Spotify music scrape_MALWAREBYTES:03643C233C175C5A7C5DEBC5CD043A49

Hacktivist group Anna’s Archive claims to have scraped almost all of Spotify’s catalog and is now seeding it via BitTorrent, effectively turning a ...

N/A N/A MALWAREBYTES
NONE MALWAREBYTES:A4...

Pornhub tells users to expect sextortion emails after data exposure_MALWAREBYTES:A438B38EC45DB052692F4F8FF8C4B26F

After a recent data breach that affected Pornhub Premium members, Pornhub has updated its online statement to warn users about potential direct con...

N/A N/A MALWAREBYTES
NONE MALWAREBYTES:36...

A week in security (December 15 – December 21)_MALWAREBYTES:36A3173F3A2FB800FB3C7F954BEBE383

Last week on Malwarebytes Labs: * CISA warns ASUS Live Update backdoor is still exploitable, seven years on * The ghosts of WhatsApp: How Ghos...

N/A N/A MALWAREBYTES
CRITICAL 9.8 MALWAREBYTES:6D...

CISA warns ASUS Live Update backdoor is still exploitable, seven years on_MALWAREBYTES:6D624CEBFD72DA1026C67EC1CB8AB4ED

Recently, the Cybersecurity and Infrastructure Security Agency (CISA) added (along with two others) a vulnerability in ASUS Live Update to its cata...

N/A N/A MALWAREBYTES
NONE MALWAREBYTES:C4...

The ghosts of WhatsApp: How GhostPairing hijacks accounts_MALWAREBYTES:C4E3E85E467586693A69654DE5695C59

Researchers have found an active campaign aimed at taking over WhatsApp accounts. They've called this attack **GhostPairing** because it tricks the...

N/A N/A MALWAREBYTES
NONE MALWAREBYTES:3C...

Chrome extension slurps up AI chats after users installed it for privacy_MALWAREBYTES:3CD8D213FB14226F96A06505F662003A

_This case highlights a growing grey area in consumer privacy: data collection that is technically disclosed, but so far outside user expectations ...

N/A N/A MALWAREBYTES
HIGH 8.8 MALWAREBYTES:1E...

Two Chrome flaws could be triggered by simply browsing the web: Update now_MALWAREBYTES:1EA2FE3B9194D82A2F2CA95AD1E16F69

Google issued an extra patch addressing two security vulnerabilities in Chrome, both of which can be triggered remotely by an attacker when a user ...

N/A N/A MALWAREBYTES
NONE MALWAREBYTES:79...

Inside a purchase order PDF phishing campaign_MALWAREBYTES:794A60557F57FB77B84923C18276955A

_A PDF named "`NEW Purchase Order # 52177236.pdf`" turned out to be a phishing lure. So we analyzed the phishing script behind it._ A customer con...

N/A N/A MALWAREBYTES
NONE MALWAREBYTES:CB...

SoundCloud, Pornhub, and 700Credit all reported data breaches, but the similarities end there_MALWAREBYTES:CB9968E2AE60C0B5C1411C784F0DD505

Comparing data breaches is like comparing apples and oranges. They differ on many levels. To news media, the size of the brand, how many users were...

N/A N/A MALWAREBYTES
NONE MALWAREBYTES:FD...

Photo booth flaw exposes people’s private pictures online_MALWAREBYTES:FD18AAB6A41AC4E86D9725FF1C49DB2E

Photo booths are great. You press a button and get instant results. The same can’t be said, allegedly, for the security practices of at least one c...

N/A N/A MALWAREBYTES