Scammers are operating fake Microsoft-branded websites that mimic security scans to trick users into uninstalling their antivirus software. These sites present fabricated security issues, falsely claim third-party antivirus is unsupported, and then guide victims toward a refund scam. The ultimate goal is to obtain personal information, banking details, and remote access to the victim's computer.

A new refund scam is leveraging fake Microsoft-branded security scans to trick users into uninstalling their legitimate antivirus software, ultimately aiming to steal personal, banking, and remote-access information. Multiple websites, operating under names like SysScan, present convincing but fraudulent security scans that invariably conclude the user's computer has severe issues, falsely attributing these problems to their installed antivirus.
These scam sites claim that Windows no longer supports third-party antivirus products and instruct victims to uninstall them immediately. This assertion is false; Microsoft continues to support third-party antivirus solutions, and its own Microsoft Defender Antivirus can enter a passive state when another compatible product is installed, but this does not signify a lack of support.
The fake scans are designed to appear legitimate by reading some real browser data, such as operating system, screen size, and approximate location. However, the security conclusions drawn are entirely fabricated. For instance, the sites report issues like compromised browser sandboxes, inactive kernel page-table isolation, Rowhammer vulnerabilities, missing Trusted Platform Modules, WebRTC IP leaks, and thermally throttled processors—none of which a website can genuinely detect. One "security patch" check even generates a random number of days behind, producing different results with each scan.
Even genuine browser features are misrepresented as security risks. An encrypted connection might be flagged as a downgrade risk, and both enabled and disabled cookies are presented as warnings or failures. The "security score" is hardcoded to always fall between 13 and 30 out of 100, ensuring no computer ever "passes" the scan.
The instruction to uninstall antivirus software serves two critical purposes for the scammers: it removes security measures that could interfere with subsequent malicious activities, such as the installation of remote-access software, and it reveals which specific security product the victim was using from a list of 28 common antivirus solutions, including enterprise security software.
Following the fake scan, victims are prompted to fill out a customer information form. This form collects extensive personal details, including name, address, phone numbers, email, bank name, cryptocurrency username, and even the ID and password for a remote-access session, with a choice of 30 different remote-access tools. Intriguingly, the form also includes fields for "Agent ID," "Agent Name," and "Company," suggesting it is designed to be completed by an operator during a call, potentially while viewing the victim's screen. A field even asks if "explicit content" is involved, potentially to leverage embarrassment against victims.
Despite claims on the site that no data is sent or collected, the information entered into the form, along with agent and remote-access details, is bundled and sent directly to Telegram's bot API. This method makes the scam sites inexpensive to host and easy to abandon.
After submitting the form, victims are directed to a waiting page that plays a looping video of a man in an office, informing them that a "refund manager" will call within three to five minutes. This page is designed to keep the victim engaged and reassured that an official process is underway, setting the stage for the subsequent phone call where further financial and personal information is likely extracted.
Analysis of the website code reveals signs of AI generation, including extensive, self-narrating comments that explain the deliberate pacing of the scan and the terse tone of spoken lines. Some comments explicitly describe the deceptive elements, labeling blocks of invented findings as "fake" and genuine value checks as "exaggerated." One comment even falsely states that no data leaves the device, despite the function sending data to Telegram being present just a few hundred lines later. The fraud-specific elements, such as the US bank list and agent identifiers, appear to be integrated into a broader scanner template.
Users should be aware that legitimate websites cannot perform deep security scans of a computer, nor can they detect malware or memory issues. Microsoft continues to support third-party antivirus, and genuine refund processes never require uninstalling security software or installing remote-access tools. Any website making such claims should be immediately closed.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.