ALL POSTS A week in security (November 24 – November 30) Malwarebytes Labs December 1, 2025 0 Comments A list of topics we covered in the week of November 24 to November 30 of 2025 How CVSS v4.0 works: characterizing and scoring vulnerabilities Pieter Arntz November 28, 2025 0 Comments This blog explains why vulnerability scoring matters, how CVSS works, and what’s new in version 4.0. Millions at risk after nationwide CodeRED alert system outage and data breach Pieter Arntz November 27, 2025 0 Comments A ransomware attack against the CodeRED emergency alert platform has triggered warnings across the US. Holiday shoppers targeted as Amazon and FBI warn of surge in account takeover attacks Danny Bradbury November 27, 2025 0 Comments Scammers are stepping up their game for the holidays, impersonating brands to trick people into handing over their accounts. Fake LinkedIn jobs trick Mac users into downloading Flexible Ferret malware Pieter Arntz November 26, 2025 0 Comments Scammers are using fake jobs and a phony video update to infect Mac users with a multi-stage stealer designed for long-term access and data theft. New ClickFix wave infects users with hidden malware in images and fake Windows updates Pieter Arntz November 25, 2025 0 Comments ClickFix just got more convincing, hiding malware in PNG images and faking Windows updates to make users run dangerous commands. WhatsApp closes loophole that let researchers collect data on 3.5B accounts Danny Bradbury November 25, 2025 0 Comments A weak spot in WhatsApp’s API allowed researchers to scrape data linked to 3.5 billion registered accounts, including profile photos and “about” text. The hidden costs of illegal streaming and modded Amazon Fire TV Sticks Pieter Arntz November 24, 2025 0 Comments New research shows that "modded Amazon Fire TV Sticks" and piracy apps often lead to scams, stolen data, and financial loss. Black Friday scammers offer fake gifts from big-name brands to empty bank accounts Stefan Dasic November 24, 2025 0 Comments Inside a massive malicious ad campaign that mimics brands like LEGO, Lululemon, and Louis Vuitton to trick shoppers into handing over bank details. Previous 1 2 3 4 5 6 … 592 Next Contributors Threat Center Podcast Glossary Scams