:

HACKERS HIJACK HBO MAX REDDIT, SPREAD MALWARE

SECURITY DESK1 MIN READ
MON, SEP 14, 2026

■ AI-SUMMARIZED FROM 2 SOURCES ▸ TIMELINE

Attackers compromised HBO Max's official Reddit account to distribute malicious ads using ClickFix exploits. The campaign targeted Windows and macOS users with information-stealing malware.

The HBO Max Reddit account was used to push fake ads directing users to ClickFix attacks, a social engineering tactic that tricks victims into downloading malware themselves. ClickFix exploits work by displaying fake system alerts claiming security issues exist. Users who click the alerts are guided through steps that appear to fix problems but actually install information-stealing malware on their devices. The malware can harvest sensitive data from infected machines. Both Windows and macOS systems were targeted in this campaign. This incident highlights how compromised official accounts amplify attack credibility. Users may trust ads from verified accounts more readily, increasing infection rates. Security researchers recommend users verify system alerts through official channels, avoid clicking ads on social media, and keep devices updated. HBO Max has not yet publicly detailed the account takeover or remediation steps.

■ SOURCES

Bleeping ComputerTechCrunch

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

OpenAI's web-crawling bots were aware of a significant caching vulnerability in RubyGems before public disclosure, raising questions about vulnerability discovery and responsible disclosure practices.

JUST NOWAI Desk

OpenAI has hundreds of contract workers reviewing real ChatGPT conversations and rating them to improve the model. The practice is enabled by default, requiring users to manually opt out.

1H AGOAI Desk

The Manhattan District Attorney's Office has seized 12 websites that created non-consensual deepfake content of celebrities, marking the largest legal action against harmful deepfake platforms to date. The sites collectively victimized approximately 1,200 people.

2H AGOIndustry Desk

A widespread scanning campaign is targeting internet-exposed Vite development servers to steal AWS and Azure credentials. The attack aims to compromise cloud infrastructure through unprotected development environments.

2H AGOSecurity Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.