Connect with us

Technology

Fake ad blocker breaks PCs in new malware extension scam

Published

on

Fake ad blocker breaks PCs in new malware extension scam

NEWYou can now listen to Fox News articles!

Fake browser extensions are nothing new, but this one takes things a step further by deliberately breaking your computer to scare you into infecting it.

Security researchers have uncovered a malicious Chrome and Edge extension called NexShield that pretends to be a fast, privacy-friendly ad blocker. Once installed, it crashes your browser on purpose and then tricks you into “fixing” the problem by running dangerous commands on your own PC.

Sign up for my FREE CyberGuy Report
Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide – free when you join my CYBERGUY.COM newsletter.

MALICIOUS GOOGLE CHROME EXTENSIONS HIJACK ACCOUNTS

Advertisement

A fake Chrome and Edge extension called NexShield crashes browsers to trick users into running malicious commands. (Sina Schuldt/picture alliance via Getty Images)

How the NexShield ad blocker scam works

NexShield was promoted as a lightweight ad blocker supposedly created by Raymond Hill, the real developer behind the popular uBlock Origin extension. That claim was false, but it helped the extension look legitimate enough to spread through online ads and search results before it was taken down from the Chrome Web Store.

Once installed, NexShield immediately starts abusing Chrome or Edge in the background. Researchers at Huntress found that it opens endless internal browser connections until your system runs out of memory (via Bleeping Computer). Tabs freeze, CPU usage spikes, RAM fills up and the browser eventually hangs or crashes completely.

After you restart the browser, NexShield displays a scary pop-up warning that claims your system has serious security problems. When you click to “scan” or “fix” the issue, you’re shown instructions telling you to open Command Prompt and paste a command that’s already been copied to your clipboard.

That single paste is the trap. The command launches a hidden PowerShell script that downloads and runs malware. To make detection harder, the attackers delay the payload execution for up to an hour after installation, creating distance between the extension and the damage it causes.

Advertisement

Why this fake browser extension attack is especially dangerous

This campaign is a new variation of the well-known ClickFix scam, which relies on convincing you to run commands yourself. Huntress calls this version CrashFix because instead of faking a system failure, it causes a real one.

In corporate environments, the attack delivers a Python-based remote access tool called ModeloRAT. This malware allows attackers to spy on systems, run commands, change system settings, add more malware and maintain long-term access. Researchers say the threat group behind it, tracked as KongTuke, appears to be shifting focus toward enterprise networks where the payoff is higher.

Home users weren’t the primary target in this campaign, but that doesn’t mean they’re safe. Even if the final payload was unfinished for consumer systems, uninstalling the extension alone is not enough. Some malicious components can remain behind. The biggest danger here isn’t a browser bug. It’s trust. The attack works because it looks like a helpful fix from a trusted tool, and it pressures you to act quickly while your system feels broken.

“Microsoft Defender provides built in protections to help identify and stop malicious or unwanted browser extensions and the harmful behaviors associated with them,” Tanmay Ganacharya, VP of Microsoft Threat Protection, told CyberGuy. “Our security technologies are designed to detect and mitigate tactics like the ones described in this campaign, and they are continuously updated to help keep customers safe. We encourage consumers and organizations to follow our security best practices for reducing exposure to social engineering based threats. Guidance on strengthening your security posture against techniques like this can be found in our blog, ⁠Think Before You Click(Fix): Analyzing the ClickFix Social Engineering Technique, on the Microsoft Security blog.”

We also reached out to Google for comment.

Advertisement

7 steps you can take to stay safe from malicious browser extensions

A few smart habits and the right tools can dramatically reduce your risk, even when malicious extensions slip past official app stores.

1) Only install extensions from trusted publishers

Before installing any browser extension, check the publisher name, official website and update history. Reputable tools clearly identify their developer and have years of user reviews. Be cautious of “new” extensions that claim to come from well-known creators, especially if the name or branding looks slightly off.

2) Never run unknown commands

No legitimate browser extension will ever ask you to open Command Prompt or paste a command to fix an issue. That’s a massive red flag. If something breaks your browser and then tells you to run system commands, close it and seek help from a trusted source.

3) Use a strong antivirus

Strong antivirus software can detect malicious scripts, suspicious PowerShell activity and remote access tools like ModeloRAT. This is especially important because these attacks rely on delayed execution that basic defenses might miss.

The best way to safeguard yourself from malicious links that install malware, potentially accessing your private information, is to have strong antivirus software installed on all your devices. This protection can also alert you to phishing emails and ransomware scams, keeping your personal information and digital assets safe.

Advertisement

Get my picks for the best 2026 antivirus protection winners for your Windows, Mac, Android and iOS devices at Cyberguy.com.

MALICIOUS MAC EXTENSIONS STEAL CRYPTO WALLETS AND PASSWORDS

After freezing your browser, the rogue extension urges users to paste a PowerShell command that installs malware. (Annette Riedl/picture alliance via Getty Images)

4) Use a password manager to limit fallout

If malware gains access to your system, stored browser passwords are often the first target. A password manager keeps credentials encrypted and separate from your browser, reducing the risk of account takeover even if something slips through.

Next, see if your email has been exposed in past breaches. Our No. 1 password manager pick includes a built-in breach scanner that checks whether your email address or passwords have appeared in known leaks. If you discover a match, immediately change any reused passwords and secure those accounts with new, unique credentials.

Advertisement

Check out the best expert-reviewed password managers of 2026 at Cyberguy.com.

5) Keep Windows, Chrome and Edge fully updated

Security updates don’t just patch bugs. They also improve protection against malicious extensions, script abuse and unauthorized system changes. Turn on automatic updates so you’re not relying on memory to stay protected.

6) Consider an identity theft protection service

If malware ever runs on your system, assume personal data could be at risk. Identity protection services can monitor for misuse of your information, alert you early and help with recovery if fraud occurs.

Identity Theft companies can monitor personal information like your Social Security Number (SSN), phone number and email address, and alert you if it is being sold on the dark web or being used to open an account. They can also assist you in freezing your bank and credit card accounts to prevent further unauthorized use by criminals.

See my tips and best picks on how to protect yourself from identity theft at Cyberguy.com.

Advertisement

7) Reduce your online footprint with a data removal service

Many attacks become more effective when criminals already have your personal details. Data removal services help pull your information from broker sites, making it harder for attackers to craft convincing follow-up scams or targeted phishing.

While no service can guarantee the complete removal of your data from the internet, a data removal service is really a smart choice. They aren’t cheap, and neither is your privacy. These services do all the work for you by actively monitoring and systematically erasing your personal information from hundreds of websites. It’s what gives me peace of mind and has proven to be the most effective way to erase your personal data from the internet. By limiting the information available, you reduce the risk of scammers cross-referencing data from breaches with information they might find on the dark web, making it harder for them to target you.

Check out my top picks for data removal services and get a free scan to find out if your personal information is already out on the web by visiting Cyberguy.com.

Get a free scan to find out if your personal information is already out on the web: Cyberguy.com.

FAKE ERROR POPUPS ARE SPREADING MALWARE FAST

Advertisement

Security researchers say the NexShield ad blocker scam deliberately overloads memory to force a system crash. (Photo by Sebastian Gollnow/picture alliance via Getty Images)

Kurt’s key takeaway

Cybercriminals are getting better at blending technical tricks with psychological pressure. Instead of relying on exploits alone, they break things on purpose and wait for you to panic. If a browser extension crashes your system and then tells you to “fix” it by running commands, stop immediately. The safest response is not to fix the problem fast, but to question why you’re being asked to fix it at all.

How many browser extensions are installed on your computer right now? Let us know by writing to us at Cyberguy.com.

Sign up for my FREE CyberGuy Report
Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide – free when you join my CYBERGUY.COM newsletter.

Advertisement

Copyright 2026 CyberGuy.com. All rights reserved.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Technology

Mark Zuckerberg is taking the stand as social media goes on trial

Published

on

Mark Zuckerberg is taking the stand as social media goes on trial

Lori Schott didn’t care what it took to haul her way from her small town in Eastern Colorado to show up to a Los Angeles courtroom where Meta CEO Mark Zuckerberg is set to testify Wednesday. “I don’t care if I had to hire a pack mule to get me here, I was going to be here,” she told The Verge outside the courthouse Tuesday.

Schott’s daughter Annalee died by suicide at age 18 in 2020, after struggling with body image issues that her mother says were heightened by social media. After her death, Schott found journal entries where Annalee disparaged her own looks and compared herself to other girls’ profiles. “I was so worried about what my child was putting out online, I didn’t realize what she was receiving,” Schott said.

The way that Meta and Google-owned YouTube designed their products — allegedly luring users into a nonstop loop of taps and scrolling — is at the heart of this month’s bellwether social media trial, which sets the stage for thousands of similar lawsuits. The companies have generally denied the claims. Schott and several other self-described survivor parents have made it their mission to be in the courtroom during the several-week trial in downtown LA.

“I was so worried about what my child was putting out online, I didn’t realize what she was receiving.”

Last week, the parents heard from Instagram CEO Adam Mosseri, who used his time to carve a distinction between clinical addiction to social media and what he called “problematic use.” On the stand, Mosseri testified that using Instagram “too much” is a relative thing that can vary person-to-person, and he wouldn’t use the term addiction for using social media up to 16 hours a day. Mosseri explained why Meta had modified a prior ban on image filters that altered users’ appearance, after previously discussing their potential negative mental health effects. While the plaintiff has argued Meta is motivated by profits and engagement at the expense of users’ safety, Mosseri said that the two are aligned. “In general, we should be focused on the protection of minors, but I believe protecting minors over the long run is good for business and for profit,” he said, according to CNBC.

Advertisement

Several parents camped out overnight in the rain to make sure that they would get spots behind Mosseri while he took the stand. One of them was Julianna Arnold, whose daughter Coco died of fentanyl poisoning at 17 after allegedly meeting a dealer on Instagram she believed had sold her Percocet. The parents wore rain ponchos, played cards, drank coffee, and told stories throughout the night. “Everyone was like, you’re crazy,” she said. “But it didn’t feel like we were crazy, because we were so determined to have survivor parents in the courtroom.”

For Schott, who also stayed overnight to see Mosseri’s testimony, the reality of being in the room quickly became overwhelming. “I really hoped in my heart that it wasn’t as bad as it was,” said Schott, who left the testimony early after hearing the Instagram CEO discuss documents about engagement, profits, and internal research about girls’ mental health. “It is that bad.”

“I want him to see my face, because my face is Anna’s face.”

On Wednesday, Zuckerberg will likely expand on Mosseri’s testimony and explain the company’s choices. While Mosseri is in charge of the product at the center of the trial, Zuckerberg’s role as founder and CEO means that the plaintiff’s lawyers will likely ask him to account for choices they allege harmed young users. Zuckerberg will likely be asked about how and why his company made various design decisions, and research it conducted on user safety. But at least as important as what Zuckerberg will say, for many, is that he’ll get to see their faces. “I’d love to look him in the eye,” Schott says. “I want him to see my face, because my face is Anna’s face.”

Zuckerberg’s testimony will likely be referenced at future trials and legislative hearings. Thousands of social media cases behind this one similarly argue that products like Instagram caused various personal injuries, and that companies should be made to pay damages and change their products to make them safer.

Advertisement

Arnold isn’t sure whether she’ll get one of the limited, lottery-assigned seats inside the courthouse. Either way, “I want to see a row of survivor parents in the front row. That he has to testify to our faces, to parents of kids that died because of his lack of care and lack of accountability — that’s why it’s really important that we’re here.”

Follow topics and authors from this story to see more like this in your personalized homepage feed and to receive email updates.

Continue Reading

Technology

Don’t ignore Apple’s urgent security update

Published

on

Don’t ignore Apple’s urgent security update

NEWYou can now listen to Fox News articles!

If you use an iPhone, iPad, Mac, Apple Watch or Apple TV, listen up. Apple has released a major security update to fix a zero-day vulnerability, which is a security hole that hackers discover and exploit before the company has a chance to fix it. 

Attackers were already using it in targeted attacks. In other words, this was not just a possibility. It was happening.

The flaw, tracked as CVE-2026-20700, affects multiple Apple operating systems. If you have delayed updates lately, this is one you should not ignore.

If you own an Android or Windows PC, this is also a good reminder to check for updates. 

Advertisement

Sign up for my FREE CyberGuy Report 
Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide – free when you join my CYBERGUY.COM newsletter.

APPLE PATCHES TWO ZERO-DAY FLAWS USED IN TARGETED ATTACKS

Apple’s latest security updates affect iPhone, iPad, Mac, Apple Watch and Apple TV, so now is the time to check every device you own. (iStock)

What is CVE-2026-20700 and why it matters

CVE-2026-20700 is a memory corruption vulnerability affecting:

  • iOS 26.3
  • iPadOS 26.3
  • macOS Tahoe 26.3
  • watchOS 26.3
  • tvOS 26.3
  • visionOS 26.3

In simple terms, this bug could allow an attacker to run arbitrary code on your device. That opens the door to spyware, hidden backdoors or silent takeovers without obvious warning signs. Apple says this vulnerability was used as part of an infection chain combined with two previously patched flaws against devices running older versions of iOS. Those earlier bugs were fixed in December 2025. Devices that skipped those updates remained exposed. This is how many real attacks unfold. Hackers chain vulnerabilities together and quietly move in.

Which devices need updating?

Here is a breakdown of the available updates:

Advertisement
  • iOS 26.3 and iPadOS 26.3 for iPhone 11 and later, plus newer iPads
  • iOS 18.7.5 and iPadOS 18.7.5 for iPhone XS, XS Max, XR and iPad 7th generation
  • macOS Tahoe 26.3, Sequoia 15.7.4, Sonoma 14.8.4
  • tvOS 26.3 for Apple TV HD and Apple TV 4K
  • watchOS 26.3 for Apple Watch Series 6 and later
  • visionOS 26.3 for Apple Vision Pro
  • Safari 26.3 for supported macOS versions

If your device qualifies, update it as soon as possible.

Why this update deserves attention

Security updates can feel routine. Many of us see the notification and decide to deal with it later. This time is different. Apple confirmed the flaw was actively exploited. That means attackers already know how to use it. Running older software gives them a window of opportunity. Updating closes that window.

How to update your iPhone or iPad

Updating takes only a few minutes.

  • Go to Settings
  • Tap General
  • Tap Software Update
  • If an update appears, tap Download and Install
  • Turn on Automatic Updates so you do not miss future fixes

Keep your device connected to Wi-Fi and power during the process.

APPLE WARNS MILLIONS OF IPHONES ARE EXPOSED TO ATTACK

Once you reach this screen on your iPhone, tap Update Now to install Apple’s latest security fix immediately. (Kurt “CyberGuy” Knutsson)

How to update your Mac

  • Click the Apple menu in the upper left corner
  • Choose System Settings or System Preferences
  • Select General
  • Click Software Update
  • If an update appears, select Restart Now or Update Tonight

Your Mac may restart during the process. Keep it plugged in and connected to the internet until the update finishes.

Mac users will see options like Update Tonight or Restart Now, and installing this update closes a flaw already exploited in attacks. (Kurt “CyberGuy” Knutsson)

Advertisement

How to update Apple Watch

  • Keep your Watch on its charger and near your iPhone
  • Open the Watch app on your iPhone
  • Tap General
  • Tap Software Update
  • Tap Download and Install if available

Your Watch will restart during the update.

Your Apple Watch also receives critical security fixes, so keep it on the charger and update it just like your iPhone. (Kurt “CyberGuy” Knutsson)

How to update Apple TV

  • Open Settings on Apple TV
  • Go to System
  • Select Software Updates
  • Choose Update Software
  • Select Download and Install

Stay connected to power and Wi Fi until the update completes.

How to update Safari

Safari updates are included with macOS updates.

  • Go to the Apple menu
  • Click System Settings
  • Select General
  • Click Software Update

If Safari appears separately, click Update Now and restart your Mac.

How to update your Apple Vision Pro

  • Put on your Vision Pro and open the Settings app.
  • Select General from the sidebar.
  • Tap Software Update.
  • If an update appears for visionOS 26.3, choose Download and Install.
  • Make sure your Vision Pro stays charged and connected to Wi-Fi until the update completes.

MALICIOUS MAC EXTENSIONS STEAL CRYPTO WALLETS AND PASSWORDS

Ways to stay safe

Installing this update is the most important step. Still, there are additional habits that strengthen your protection.

  • Turn on automatic updates for every Apple device
  • Restart devices regularly to clear temporary processes
  • Avoid clicking unsolicited links or attachments, and use strong antivirus software. Get my picks for the best 2026 antivirus protection winners for your Windows, Mac, Android and iOS devices at Cyberguy.com.
  • Remember, Apple threat notifications will never ask for passwords or verification codes
  • Be cautious when viewing HTML-formatted emails in Apple Mail
  • Consider enabling Lockdown Mode if you face a higher risk

Cybercriminals rely on hesitation. They count on us assuming we will get to the update later.

Kurt’s key takeaways

Apple moved fast to fix this vulnerability, and that is reassuring. Now it is up to us to do our part. I get it. Updates interrupt your day. They force a restart. They rarely feel urgent. But here is the thing. Installing updates is still the simplest and most effective way to protect your device from active threats. A few minutes now can prevent a serious security problem later.

What is your biggest reason for delaying updates, and has it ever cost you? Let us know by writing to us at Cyberguy.com.

Advertisement

CLICK HERE TO DOWNLOAD THE FOX NEWS APP

Sign up for my FREE CyberGuy Report 
Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide – free when you join my CYBERGUY.COM newsletter.

Copyright 2026 CyberGuy.com. All rights reserved.

Continue Reading

Technology

Meta’s new deal with Nvidia buys up millions of AI chips

Published

on

Meta’s new deal with Nvidia buys up millions of AI chips

Meta has struck a multiyear deal to expand its data centers with millions of Nvidia’s Grace and Vera CPUs and Blackwell and Rubin GPUs. While Meta has long been using Nvidia’s hardware for its AI products, this deal “represents the first large-scale Nvidia Grace-only deployment,” which Nvidia says will deliver “significant performance-per-watt improvements in [Meta’s] data centers.” The deal also includes plans to add Nvidia’s next-generation Vera CPUs to Meta’s data centers in 2027.

Meta is also working on its own in-house chips for running AI models, but according to the Financial Times, it has run into “technical challenges and rollout delays” with its chip strategy. Nvidia is also dealing with concerns about depreciation and chip-back loans used to finance AI buildouts, as well as the pressure of competition. CNBC notes that Nvidia’s stock dropped four percent after a November report about Meta considering using Google’s Tensor chips for AI, and late last year, AMD announced chip arrangements with both OpenAI and Oracle.

Nvidia and Meta did not disclose how much the deal cost, but this year’s AI spending from Meta, Microsoft, Google, and Amazon is estimated to cost more than the entire Apollo space program.

Continue Reading

Trending