LIVE · cybersecurity feed
Live wire
CVE-2026-66066 · KindaRails2Shell threatens Ruby on Rails apps (CVE-2026-66066)Rails patches critical Active Storage flaw with RCE potentialCVE-2026-48449 · Adobe fixed a maximum-severity vulnerability flaw in Campaign ClassicRuby on Rails Patches Critical VulnerabilityHackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer SitesHijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance MalwareCaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theftHollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law FirmCVE-2026-33017 · Chinese Hacker Uses DeepSeek AI to Orchestrate Vulnerability ExploitsThis month in security with Tony Anscombe – July 2026 edition
security

“Adult TikTok” searches lead to scams

That "free" adult TikTok site could leave you with spam, unwanted apps, or fake verification fees.

zeroday.news · 4h ago

Users searching for adult content associated with TikTok are being targeted by scam websites that exploit the platform's name to drive traffic. These sites do not host genuine content from TikTok but instead funnel users through various advertising and data collection schemes.

The scam pages are designed to rank highly in search engine results for terms combining "TikTok" with adult content keywords. They often present themselves as solutions to users' searches, promising exclusive, uncensored videos without requiring sign-up. Visual cues typically include blurred video thumbnails, "18+ only" labels, and calls to action like "Start watching" or "Sign up for free."

Upon clicking, users are rarely presented with the promised content. Instead, they are redirected through advertising networks, prompted to provide email addresses or payment card details for "age verification," or encouraged to install applications from outside official app stores. Each interaction, from a simple click to a data submission, generates revenue for the site operators through advertising, affiliate commissions, or lead generation.

The methods of monetization vary but commonly include affiliate commissions from dating sites, adult subscriptions, or VPN services; advertising revenue from redirects and pop-ups; and lead generation through the collection and sale of email addresses for spam and phishing campaigns. A significant risk involves "subscription traps," where users provide payment card details for age verification and are then unknowingly enrolled in recurring subscription services. Some pages may also attempt to push unwanted software or malware.

A key element of these scams is their reliance on the embarrassment factor associated with searching for adult content, which makes victims less likely to report the incidents or seek advice. This allows the schemes to persist and spread more easily.

Users are advised to immediately close any tabs encountered through these searches and avoid entering personal information such as email addresses, payment card details, or dates of birth. Installing any software prompted by these pages is also strongly discouraged. If personal information has already been submitted, users should treat it as compromised, monitor for follow-up spam or phishing attempts, and change any reused passwords.

ShareXLinkedInWhatsAppFacebook

More News

view all →
ai

Public interest coalition urges Congress to investigate OpenAI, Hugging Face hack

The post Public interest coalition urges Congress to investigate OpenAI, Hugging Face hack appeared first on CyberScoop.

ai

The AI Act kicks into action, forces companies to be clear about AI chatbots

The European Union (EU) has started enforcing key parts of the AI Act, with immediate, visible consequences for chatbots, deepfakes and other consumer‑facing AI.

security

Californians can tell data brokers to DROP their information

California has launched the Delete Request and Opt‑out Platform (DROP), a state‑run portal that lets residents send deletion and opt‑out requests to all registered data brokers.

ai

New Tool Traces AI Videos Back to Their Source

Researchers dug into the root of the problem with the goal of promoting industry collaboration on improved protective measures.

breach

Anthropic: AI Attacks Result of Security Gaps, Not Model Issues

Last month's incidents in which Claude breached real-world systems derived from over-permissioning, especially with Internet access.

malware

Fake Roblox Xeno script launcher pushes infostealer, RAT malware

Fake Xeno Executor installers are infecting unsuspecting Roblox players with malware that provides remote access and steals sensitive information. [...]