Giorgio

A week in security (August 25 – August 31)

Last week on Malwarebytes Labs: Microsoft wants to automatically save your Word docs to the cloud “No place in our networks”: FCC hangs up on thousands of voice operators in robocall war Claude AI chatbot abused to launch “cybercrime spree” Developer verification: a promised lift for Android security More vulnerable stalkerware victims’ data exposed in […]

A week in security (August 25 – August 31) Leggi tutto »

Microsoft wants to automatically save your Word docs to the cloud

Microsoft has revealed it plans to automatically save all Word document to the cloud. The feature is currently only available to Microsoft 365 Insiders, although it’s likely to expand this to all users in the future. Microsoft proudly announced: “We are modernizing the way files are created and stored in Word for Windows! Now you

Microsoft wants to automatically save your Word docs to the cloud Leggi tutto »

“No place in our networks”: FCC hangs up on thousands of voice operators in robocall war

Everyone hates robocalls. However, it’s difficult to track down all the scammers and spammers that make them, so the Federal Communications Commission (FCC) has taken another approach: it just disconnected over a thousand voice operators from the public telephone network for not doing their part to stop the scourge. This week, the Commission’s Enforcement Bureau

“No place in our networks”: FCC hangs up on thousands of voice operators in robocall war Leggi tutto »

Claude AI chatbot abused to launch “cybercrime spree”

Anthropic—the company behind the widely renowned coding chatbot, Claude—says it uncovered a large-scale extortion operation in which cybercriminals abused Claude to automate and orchestrate sophisticated attacks. The company issued a Threat Intelligence report in which it describes several instances of Claude abuse. In the report it states that: “Cyber threat actors leverage AI—using coding agents

Claude AI chatbot abused to launch “cybercrime spree” Leggi tutto »

Claude AI chatbot abused to launch “cybercrime spree”

Anthropic—the company behind the widely renowned coding chatbot, Claude—says it uncovered a large-scale extortion operation in which cybercriminals abused Claude to automate and orchestrate sophisticated attacks. The company issued a Threat Intelligence report in which it describes several instances of Claude abuse. In the report it states that: “Cyber threat actors leverage AI—using coding agents

Claude AI chatbot abused to launch “cybercrime spree” Leggi tutto »

Developer verification: a promised lift for Android security

To reduce the number of harmful apps targeting Android users, Google has announced that certified Android devices will require all apps to be registered by verified developers in order to be installed. But this new measure is not just about malware that’s found on the Google Play Store, it’s mainly about sideloaded apps (apps downloaded

Developer verification: a promised lift for Android security Leggi tutto »

More vulnerable stalkerware victims’ data exposed in new TheTruthSpy flaw

TheTruthSpy is at it again. A security researcher has discovered a flaw in the Android-based stalkerware that allows anyone to compromise any record in the system. TheTruthSpy stalkerware is designed to be installed surreptitiously on a victim’s Android phone. It then monitors that phone’s activities and sends the information it gathers back to a central

More vulnerable stalkerware victims’ data exposed in new TheTruthSpy flaw Leggi tutto »

77 malicious apps removed from Google Play Store

Google has removed 77 malicious apps from the Google Play Store. Before they were removed, researchers at ThreatLabz discovered the apps had been installed over 19 million times. One of the malware families discovered by the researchers is a banking Trojan known as Anatsa or TeaBot. This banking Trojan is a highly sophisticated Android malware,

77 malicious apps removed from Google Play Store Leggi tutto »

AI browsers could leave users penniless: A prompt injection warning

Artificial Intelligence (AI) browsers are gaining traction, which means we may need to start worrying about the potential dangers of something called “prompt injection.” Large language models (LLMs)—like the ones that power AI chatbots including ChatGPT, Claude, and Gemini—are designed to follow “prompts,” which are the instructions and questions that people provide when looking up

AI browsers could leave users penniless: A prompt injection warning Leggi tutto »

A week in security (August 18 – August 24)

Last week on Malwarebytes Labs: Clickjack attack steals password managers’ secrets Grok chats show up in Google searches All Apple users should update after company patches zero-day vulnerability in all platforms Google settles YouTube lawsuit over kids’ privacy invasion and data collection AI-powered stuffed animals: A good alternative for screen time? How to spot the

A week in security (August 18 – August 24) Leggi tutto »