βΌοΈ BREAKING: The official HBO Max Reddit account was hijacked and ran malvertising with a ClickFix attack on Reddit for 48 hours, pushing macOS malware to users.
The ad led to a convincing HBO Max landing page where the download button started no download. Instead it produced a prompt telling visitors to copy a command and paste it into Terminal.
A Reddit user flagged the ad in r/cybersecurity, and admins paused it pending an investigation.
By then the account had run 108 ads, fewer than half of them HBO Max lures. Another 47 pitched AI coding tools at developers and 15 a macOS disk cleaner.
Hudson Rock and ADAMnetworks traced the pasted command to a delivery system they call PasteSwitch, which selects a payload based on the visitor.
The payloads include macOS stealers that take browser credentials, Apple Notes and saved passwords; counterfeit Ledger, Trezor and Exodus apps built to capture wallet recovery phrases; and a Windows stealer loaded straight into memory.
The ad led to a convincing HBO Max landing page where the download button started no download. Instead it produced a prompt telling visitors to copy a command and paste it into Terminal.
A Reddit user flagged the ad in r/cybersecurity, and admins paused it pending an investigation.
By then the account had run 108 ads, fewer than half of them HBO Max lures. Another 47 pitched AI coding tools at developers and 15 a macOS disk cleaner.
Hudson Rock and ADAMnetworks traced the pasted command to a delivery system they call PasteSwitch, which selects a payload based on the visitor.
The payloads include macOS stealers that take browser credentials, Apple Notes and saved passwords; counterfeit Ledger, Trezor and Exodus apps built to capture wallet recovery phrases; and a Windows stealer loaded straight into memory.
π€£25β€5
German police will do anything to protect a transgender ex-police officer who raped a 15-year-old girl in a gas station toilet and uploaded child sexual abuse material to Instagram.
They're even blurring the tattoos on today's photos.
Meanwhile, they are posing with human pups.
They're even blurring the tattoos on today's photos.
Meanwhile, they are posing with human pups.
π€¬34π©13π3π€3π1
Foreign intelligence agencies have issued a warning that Iranian state hackers are targeting dissidents, activists and journalists, tricking them into opening fake Telegram or KeePass apps or bogus MRI scan results while posing as someone the target already knows.
A convincing decoy screen appears while the file quietly installs spyware dubbed Chosen Brick.
The attackers can then take screenshots, switch on the microphone, steal email, and copy WhatsApp and Telegram data from the browser. Those screenshots can reveal a victim's contacts, location and daily routine.
They often try a work computer first. If that fails or looks too risky, they ask the target to open the file on a personal device, where corporate security can't catch it.
Some victims' personal details have already surfaced on pro-Iranian leak sites. Victims have been found in the UK, the US and the Netherlands, and the agencies say those affected have been notified.
https://www.ncsc.gov.uk/news/iranian-cyber-targeting-of-dissidents-activists-and-journalists
A convincing decoy screen appears while the file quietly installs spyware dubbed Chosen Brick.
The attackers can then take screenshots, switch on the microphone, steal email, and copy WhatsApp and Telegram data from the browser. Those screenshots can reveal a victim's contacts, location and daily routine.
They often try a work computer first. If that fails or looks too risky, they ask the target to open the file on a personal device, where corporate security can't catch it.
Some victims' personal details have already surfaced on pro-Iranian leak sites. Victims have been found in the UK, the US and the Netherlands, and the agencies say those affected have been notified.
https://www.ncsc.gov.uk/news/iranian-cyber-targeting-of-dissidents-activists-and-journalists
π’5π©1
βΌοΈ Meet transgender Maja Schmid from Rosenheim, who stood trial today for raping a 15-year-old girl, repeatedly raping a dog, and possessing and distributing child pornography.
They also have an OnlyFans with the bio "always horny and with no limits ππ₯"
All while standing trial for sexual abuse.
Maja is tall and strong, and they were also part of GSG 9 (short for Grenzschutzgruppe 9, or Border Guard Group 9), the elite counter-terrorism and special operations tactical unit of the German Federal Police (Bundespolizei).
They also have an OnlyFans with the bio "always horny and with no limits ππ₯"
All while standing trial for sexual abuse.
Maja is tall and strong, and they were also part of GSG 9 (short for Grenzschutzgruppe 9, or Border Guard Group 9), the elite counter-terrorism and special operations tactical unit of the German Federal Police (Bundespolizei).
1π€¬32π©7π€3π±2π2β€1π―1
One guy in Sweden built a search engine that doesn't run on Google or Bing. It's been online since 2021, and the bills come to about $200 a month.
Viktor LΓΆfgren says most "alternative" search engines are really powered by Google or Bing, or by authoritarian states like Russia and China.
His engine, Marginalia, has its own crawler and index, with no ads, no loans and no investors.
His argument: when nearly all search runs through a few US companies, censorship becomes easy, even by accident, and one country's cultural bias shapes what everyone finds.
He isn't trying to replace Google. He wants Marginalia to be the "minority report" that keeps the big engines honest.
So it ranks what they tend to bury: personal blogs, old university pages, text-heavy sites with nothing to sell.
Every result shows whether a page uses affiliate links or JavaScript, and you can filter those out. An "explore" mode just shows you random sites from the index.
It's keyword-based on purpose. LΓΆfgren argues that the better a search engine gets at answering questions, the worse it gets at finding websites.
It's open source under the AGPL, so you can host your own copy.
https://marginalia-search.com
Viktor LΓΆfgren says most "alternative" search engines are really powered by Google or Bing, or by authoritarian states like Russia and China.
His engine, Marginalia, has its own crawler and index, with no ads, no loans and no investors.
His argument: when nearly all search runs through a few US companies, censorship becomes easy, even by accident, and one country's cultural bias shapes what everyone finds.
He isn't trying to replace Google. He wants Marginalia to be the "minority report" that keeps the big engines honest.
So it ranks what they tend to bury: personal blogs, old university pages, text-heavy sites with nothing to sell.
Every result shows whether a page uses affiliate links or JavaScript, and you can filter those out. An "explore" mode just shows you random sites from the index.
It's keyword-based on purpose. LΓΆfgren argues that the better a search engine gets at answering questions, the worse it gets at finding websites.
It's open source under the AGPL, so you can host your own copy.
https://marginalia-search.com
π34β€9π₯9π4π©3
βΌοΈ Google has fixed critical Chrome remote code execution vulnerabilities that could let a malicious website or ad run code on a computer during normal browsing.
They're among 42 security fixes in the new release, 28 of them rated high. Google's release notes don't mention any being exploited in the wild.
https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0541751186.html
They're among 42 security fixes in the new release, 28 of them rated high. Google's release notes don't mention any being exploited in the wild.
https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0541751186.html
β€4
Valve is telling some Steam hardware buyers that the CEVA Logistics breach didn't expose their data after all.
Last month, Valve warned buyers of devices like the Steam Deck and Steam Controller that their details may have been stolen in the attack on CEVA, which ships Steam hardware across Europe.
In a new email, Valve says the part of CEVA's systems that handled their orders wasn't hit, so the attackers never viewed or took their data.
Many CEVA clients reported their customer's data was stolen.
CEVA hasn't finished its investigation, and it's unclear whether all European hardware buyers are in the clear or only those who got the new email.
Last month, Valve warned buyers of devices like the Steam Deck and Steam Controller that their details may have been stolen in the attack on CEVA, which ships Steam hardware across Europe.
In a new email, Valve says the part of CEVA's systems that handled their orders wasn't hit, so the attackers never viewed or took their data.
Many CEVA clients reported their customer's data was stolen.
CEVA hasn't finished its investigation, and it's unclear whether all European hardware buyers are in the clear or only those who got the new email.
β€2
βοΈ Meta going to release smart glasses without a camera, as multiple countries are discussing a ban on camera glasses and criticism mounts over its current models letting wearers photograph and film people without them noticing.
The glasses, codenamed Luna, still have six microphones. Wearers use them to talk to Meta AI and the company's new AI agent Muse, and hear the answers through built-in speakers.
Meta hopes to start shipping in October and could unveil them at its Connect event this week.
The glasses, codenamed Luna, still have six microphones. Wearers use them to talk to Meta AI and the company's new AI agent Muse, and hear the answers through built-in speakers.
Meta hopes to start shipping in October and could unveil them at its Connect event this week.
π€£9π©3
βΌοΈ Controversial online casino Duel is selling stolen, unredacted Revolut data in its merch store, packaged as a $29.99 "KYC kit."
The data was obtained from threat actors by one of its employees.
Duel is known for provocative rage bait, including glorifying school shooters and Nazis and stereotyping Muslim, Jewish and Black people.
This is a new low. It's unclear which country Duel operates from, but the casino could face a notice-and-takedown (NTD), and even criminal prosecution.
The data was obtained from threat actors by one of its employees.
Duel is known for provocative rage bait, including glorifying school shooters and Nazis and stereotyping Muslim, Jewish and Black people.
This is a new low. It's unclear which country Duel operates from, but the casino could face a notice-and-takedown (NTD), and even criminal prosecution.
π9β€2