HACKERS HIJACK HBO MAX REDDIT, SPREAD MALWARE
■ AI-SUMMARIZED FROM 2 SOURCES ▸ TIMELINE
Attackers compromised HBO Max's official Reddit account to distribute malicious ads using ClickFix exploits. The campaign targeted Windows and macOS users with information-stealing malware.
■ MORE FROM THE SECURITY DESK
A browser extension with 30,000 installs available on Chrome and Firefox stores transmits users' Twitch OAuth session tokens to a commercial bot service, exposing sensitive authentication credentials.
OpenAI's web-crawling bots were aware of a significant caching vulnerability in RubyGems before public disclosure, raising questions about vulnerability discovery and responsible disclosure practices.
OpenAI has hundreds of contract workers reviewing real ChatGPT conversations and rating them to improve the model. The practice is enabled by default, requiring users to manually opt out.
The Manhattan District Attorney's Office has seized 12 websites that created non-consensual deepfake content of celebrities, marking the largest legal action against harmful deepfake platforms to date. The sites collectively victimized approximately 1,200 people.