malwarebytes

Video call app Huddle01 exposed 600K+ user logs

A critical data exposure incident has been identified in Huddle01, which left an Apache Kafka broker publicly accessible without authentication or encryption. This misconfiguration exposed over 621,000 log entries containing sensitive user data.

“Can you test my game?” Fake itch.io pages spread hidden malware to gamers

The campaign leverages compromised Discord accounts to send direct messages asking users to test a game. Victims are redirected to convincing fake game pages hosted on Blogspot subdomains or cloud services.

Don’t connect your wallet: Best Wallet cryptocurrency scam is making the rounds

A phishing campaign is targeting cryptocurrency users by impersonating the Best Wallet app. The attackers aim to steal wallet credentials, private keys, and seed phrases by luring victims to a fake website that closely mimics the legitimate platform.

Phishers target 1Password users with convincing fake breach alert

A recent spear-phishing campaign targeted a Malwarebytes employee with a convincing fake breach alert impersonating 1Password’s Watchtower service. The attackers aimed to steal the victim’s 1Password credentials.

Scam Facebook groups send malicious Android malware to seniors

Attackers used social engineering methods to lure targets into joining fake Facebook groups that appeared to promote travel and community activities—such as trips, dance classes, and community gatherings.

Ransomware attack at blood center: Org tells users their data’s been stolen

The New York Blood Center suffered the ransomware attack in January, in which an unauthorized party gained access to its network and acquired copies of a subset of files. This week NYBC has started notifying victims.

Nexar dashcam video database hacked

The breach compromised sensitive video recordings, including footage with clearly visible faces and potentially identifiable individuals. Organizations and government entities that had access to Nexar’s data may also be indirectly affected.

Claude AI chatbot abused to launch “cybercrime spree”

Attackers abused the Claude AI chatbot to automate and execute sophisticated extortion operations. At least 17 organizations across government, healthcare, emergency services, and religious sectors were targeted.

AI browsers could leave users penniless: A prompt injection warning

The rise of AI-powered and agentic browsers introduces a new class of cybersecurity threats—prompt injection attacks. These attacks exploit the language-processing capabilities of LLMs embedded in browsers.

Adult sites trick users into Liking Facebook posts using a clickjack Trojan

A new clickjacking campaign is exploiting adult content websites hosted on blogspot[.]com to distribute a Trojan that manipulates Facebook interactions. This campaign leverages malicious SVG files containing obfuscated JavaScript.

Defend Against Threats with Cyber Fusion

Cyware is the leading provider of cyber fusion solutions that power threat intelligence sharing , end-to-end automation and 360-degree threat response.

Trending Tags