Fake HBO Max Ads & Leaky Dev Servers: 2 Attacks Hitting Right Now
Two things happening in the wild today share a theme: attackers aren't breaking down doors anymore, they're getting you to open them. One tricks regular people into infecting their own computers. The other quietly vacuums up the keys to entire company cloud accounts.
Attackers Hijacked HBO Max's Ad Account — And Got Victims to Hack Themselves
Someone took over HBO Max's official Reddit advertising account and started running malicious ads under the real brand name. Clicking through led to a convincing fake HBO Max page with what looked like a routine "prove you're human" CAPTCHA — except the instructions told you to copy a line of text and paste it into Command Prompt, PowerShell, or (on a Mac) Terminal.
That copy-paste step is the attack. It's a technique called ClickFix, and it works because the victim does all the hard work voluntarily — no exploit, no malware download warning, no security prompt. The pasted command installed an infostealer that grabbed saved passwords, active login sessions, and crypto wallets.
Why it matters: this hit Mac users too, and it came wrapped in a legitimate brand on a mainstream platform. Reddit didn't pause the ads until three days after a user reported them, and nobody has explained how the account was taken over in the first place. The rule to burn into your team's brain is simple: no real website will ever ask you to paste a command into a terminal to prove you're human.
Bots Are Scanning the Internet for Dev Servers — and Walking Off With Cloud Credentials
Throughout August, attackers ran mass scans hunting for exposed Vite development servers — the local preview servers developers run while building web apps. A flaw tracked as CVE-2026-39364 let them slip past the tool's file-access protections using specially crafted web requests and read files that were supposed to be off-limits.
What they went looking for tells you everything: .env configuration files, AWS credentials, Azure profiles, Terraform state files, and database passwords. Those aren't just files — they're the master keys to a company's cloud infrastructure. The scanners even disguised themselves as ordinary search-engine crawlers to blend into normal traffic.
Why it matters: dev servers feel harmless because they're "just for testing," so they often get spun up without the security scrutiny production systems receive. But they sit on machines loaded with real credentials. If one is reachable from the internet for even a few hours, that's long enough. Patch Vite, and make sure no dev server is exposed beyond localhost.
Stay ahead of threats with GOCO Security at gocosecurity.com.
.jpg)
Comments
Post a Comment