Recent Media and Entertainment Cyber Attacks

Page 2 of 6
HBO Max Reddit Hijack Pushed ClickFix Malware

HBO Max Reddit Hijack Pushed ClickFix Malware

Attackers took over the verified HBO Max Reddit account and ran over 100 malicious ads that sent people to fake download pages. The pages used a ClickFix-style trick: users were told to copy/paste a command into macOS Terminal (and similar OS-targeted lures) to install information-stealing malware.

September 14, 2026
Fake Gov Sites Lure Central Asia Users for Cash

Fake Gov Sites Lure Central Asia Users for Cash

Researchers found a large scam campaign using hundreds of fake government and news websites in Uzbekistan, Belarus, and Tajikistan. The sites lure people with promises of government-backed cash payments or passive income, then collect phone numbers and other personal data for follow-up…

September 14, 2026
Claude Linked to Real Phishing and Credential Theft

Claude Linked to Real Phishing and Credential Theft

Anthropic reports multiple real-world threat groups used Claude to support cyber operations, including credential harvesting and data theft across many victims. The report includes specific, simulation-ready lures such as a fake ESET NOD32 login portal that sends stolen passwords to Telegram and a…

September 11, 2026
Fake Reward Apps Abuse Google Play Early Access

Fake Reward Apps Abuse Google Play Early Access

Researchers say scammers are using Google Play’s “Early Access” listings to push deceptive Android apps that don’t show public ratings or warnings. Victims are lured by TikTok/Facebook ads promising cash rewards or free casino spins, but the apps primarily bombard users with ads and never deliver…

September 10, 2026
Instagram Copyright Strikes Used for Ransom

Instagram Copyright Strikes Used for Ransom

Scammers are filing fake copyright complaints to get Instagram accounts temporarily suspended, then demanding money to “withdraw” the complaint and restore access. Victims are pushed to communicate off-platform (for example, on Telegram) and asked to pay in cryptocurrency, yet even paying doesn’t…

September 10, 2026
Meta Missed Hundreds of CSAM 'Nudify' Ads

Meta Missed Hundreds of CSAM 'Nudify' Ads

Researchers found hundreds of paid ads running across Meta platforms that promoted “nudification”/face‑swap apps and included abusive sexual content involving minors, including some using real children’s photos pulled from the web. The ads used manipulative marketing text (for example, claiming…

September 8, 2026
Fake Minecraft Sites Keep Spreading WeedHack

Fake Minecraft Sites Keep Spreading WeedHack

Attackers are tricking Minecraft players into downloading malware by cloning legitimate mod/client websites and manipulating search results so the malicious pages appear highly ranked. Even after the malware’s command-and-control systems were disrupted, the fake sites and trusted file-hosting links…

September 8, 2026
Flirty X DMs Funnel Victims to Discord and Paid Pages

Flirty X DMs Funnel Victims to Discord and Paid Pages

Researchers observed flirty spam accounts on X (Twitter) using scripted conversations, and possibly AI-generated replies and voice notes, to build trust and move targets toward Discord and paid adult-content pages. The accounts asked repetitive “getting to know you” questions, handled unusual…

September 7, 2026
REVSTEALER Lures Push Fake Cheats, Drop Miners

REVSTEALER Lures Push Fake Cheats, Drop Miners

Researchers tied several new programs to the REVSTEALER Windows info-stealer that can steal crypto wallet data, hijack clipboard crypto addresses, and even disable Windows Update and Microsoft Defender to run a crypto miner. Victims are primarily pulled in through “game-cheat” downloads promoted by…

September 6, 2026
X Users Hit by Password-Reset Email Flooding

X Users Hit by Password-Reset Email Flooding

X is investigating a wave of unsolicited password-reset emails and codes being sent to users, which may be attackers trying to take over accounts as X Money becomes more available. X says it has found no evidence of a breach or successful account takeovers so far, but warns the reset-email “flood”…

September 4, 2026
X Users Hit by Password Reset Email Flood

X Users Hit by Password Reset Email Flood

Users reported getting repeated, unsolicited password-reset emails from X after the launch of X Money. The emails appear legitimate, but attackers may be using them to confuse users and then send follow-up phishing messages that lead to fake X login pages to steal credentials. There is no confirmed…

September 3, 2026
Fake Streaming Ads Push StreamRat Android Trojan

Fake Streaming Ads Push StreamRat Android Trojan

Researchers found a real malicious ad campaign on Meta platforms (and reused on TikTok) that pushed a fake “free TV streaming” service to Spanish-speaking users, mainly in Spain. Clicking the ad led to a tailored website that coached Android users through installing an app from outside Google Play,…

September 3, 2026
Fake Download Sites Push Trojanized Installers

Fake Download Sites Push Trojanized Installers

Microsoft reports a real campaign where attackers set up look-alike software download websites (impersonating known brands) to trick employees into installing trojanized “installers.” Once run, the malware persists on the device, weakens security settings, and connects to attacker-controlled…

September 3, 2026
Gambling Goblin Hijacks Gov Sites for Phishing

Gambling Goblin Hijacks Gov Sites for Phishing

Researchers say a Chinese-speaking cybercrime group compromised Brazilian government and education websites and used them as “trusted” entry points to quietly redirect visitors to attacker-run phishing pages. The fake pages impersonated well-known app stores (Google Play, Microsoft Store, Amazon)…

September 2, 2026
FBI: OAuth Consent Phishing Targets Prominent People

FBI: OAuth Consent Phishing Targets Prominent People

The FBI warns attackers are impersonating public figures on messaging apps and email to trick targets into approving a malicious OAuth app. Victims are sent links that lead to real Microsoft or Google login/consent screens, where approving access grants attackers ongoing access to emails and files.…

September 2, 2026
Scammers Shift Lures to Email, Text, and Social

Scammers Shift Lures to Email, Text, and Social

Malwarebytes reports that scammers are increasingly tailoring different scams to the platforms where they work best, like unpaid-toll lures via email/SMS, romance scams via social media, and IRS scams via phone calls. The report highlights heavy brand and celebrity impersonation (including MrBeast)…

September 2, 2026
Gov Websites Hijacked to Push Fake App Stores

Gov Websites Hijacked to Push Fake App Stores

Check Point Research reports a real campaign where a Chinese-speaking actor compromised Brazilian government and education websites and used them as stealthy “front doors” to redirect visitors to attacker-controlled phishing pages. The fake pages impersonate trusted app stores (Google Play,…

September 2, 2026
Scareware Google Ads Keep Running After Reports

Scareware Google Ads Keep Running After Reports

University researchers found large numbers of deceptive “software” ads (including scareware) running through Google’s ad system, generating over 100 million impressions in Europe. They reported some ads via Google’s “Report this ad” flow, but several ads were acknowledged as policy violations and…

September 2, 2026
Fake Download Sites Push Malware Installers

Fake Download Sites Push Malware Installers

Microsoft reports an active campaign where attackers set up counterfeit software download pages that mimic well-known brands and trick users into installing malware. Victims visit a look-alike vendor site, click “Download now,” then run a bundled installer that drops persistent malware and connects…

September 2, 2026
FBI Warns of OAuth “Consent” Phishing Trap

FBI Warns of OAuth “Consent” Phishing Trap

The FBI warns of an ongoing social-engineering campaign targeting high-profile individuals and their contacts through a commercial messaging app. Attackers impersonate trusted people (e.g., government officials, journalists) and send links that trick victims into approving OAuth access to a…

September 1, 2026
Try Mirage

Mirage simulates attacks like these against your own team, live and safely, so you can measure how your people actually respond.

Get a demo