Skip to main content
  1. Home
  2. Computing
  3. News

Hackers are infiltrating news websites to spread malware

Add as a preferred source on Google

Some alarming news broke today that hundreds of U.S. news websites are unwittingly playing a big role in a new malware campaign that’s disguised as a Chrome browser update. This is quite a devious attack method since it’s considered an important security practice to update your browser as soon as possible.

The way hackers are delivering the malware is also clever. It’s coming via an advertising network that also supplies video content to newspaper websites across the nation. It’s difficult to identify and shut down this attack because it is applied intermittently. According to a tweet by the security research team Threat Insight, the JavaScript code is being changed back and forth from the normal harmless ad delivery script to the one that includes the hacker code that shows a false update alert.

Recommended Videos

Proofpoint Threat Research has observed intermittent injections on a media company that serves many major news outlets. This media company serves content via #Javascript to its partners. By modifying the codebase of this otherwise benign JS, it is now used to deploy #SocGholish.

— Threat Insight (@threatinsight) November 2, 2022

This is a serious problem since many people get their local news from these websites and trust them implicitly. Here’s what you need to know about this dangerous new malware campaign. When visiting a news site and after advertising loads, an alert might appear warning you that it’s time to update your browser.

A black fedora rests on top of newspapers infected with spreading green lines..
Image used with permission by copyright holder

According to Bleeping Computer, the message is tailored to match your browser, appearing to be an update for Google Chrome, Mozilla Firefox, or Opera. If you proceed with the download, it will be a malware package rather than a security update.

Thankfully, it’s easy to double-check by navigating to browser settings and checking if there are any updates available within the browser controls. Hackers have not been able to insert their malware links into the browser code. Alerts, on the other hand, can be triggered by websites and website advertising, so use extra caution with pop-ups.

Alan Truly
Alan Truly is a Writer at Digital Trends, covering computers, laptops, hardware, software, and accessories that stand out as…
OpenAI’s rogue AI hack was just the beginning, Hugging Face warns
OpenAI’s rogue AI has come back to bite it
OpenAI logo on Microsoft surface

Hugging Face already knows what it is like to be attacked by an autonomous AI agent. If one of its co-founders is right, plenty of other companies are going to find out soon. Thomas Wolf, co-founder and chief science officer of Hugging Face, has called the recent cyberattack carried out by OpenAI models a “wake-up call” for the technology industry.

Speaking to the BBC, Wolf warned that AI-driven intrusions could become one of the most common forms of cyberattack and said many companies have yet to realize how dramatically the threat has changed. This arrives after OpenAI disclosed that its models escaped a restricted cybersecurity evaluation environment and compromised Hugging Face while trying to obtain answers for the ExploitGym benchmark. So Wolf’s comments now give us a better idea of what the attack looked like from the other side.

Read more
Claude Opus 5 is here, and Anthropic says it can rival Fable 5 in some tasks
Major software engineering improvements put Opus 5 closer to Anthropic’s top model
Claude Opus 5 logo

Anthropic has launched Claude Opus 5, its latest frontier AI model for coding, research, business work, and other complex tasks. The company says it delivers a major performance jump over Claude Opus 4.8 while keeping the same API price. Anthropic also claims it comes close to Claude Fable 5 on some coding and computer-use tests while costing far less per task.

Opus 5 is available across Claude’s apps and API. It is now the default model for Claude Max subscribers and the strongest option included with Claude Pro.

Read more
Humans actually prefer talking to an AI than a support person, says gas giant as it cuts jobs
British Gas cuts 1,300 support jobs as its CEO points to changing customer habits
Executive, Person, Electronics

Centrica, owner of British Gas, is cutting 1,300 call centre jobs, and its chief executive says changing customer behaviour is the main reason. The company plans to remove 800 roles as part of a “targeted deployment of AI tools,” on top of the 500 cuts announced last month. Customer service teams in Glasgow, Edinburgh, Cardiff, Leicester, Stockport, and Leeds will be affected over the next two years.

Some positions will disappear when employees leave and are not replaced, while the remaining cuts will come through redundancies. Trade unions have warned that Centrica’s AI investment will hand hundreds of human jobs to chatbots.

Read more