TikTok-branded rewards pages offer cash for simple tasks and daily check-ins. But getting your hands on the money is another story.

Users are being targeted by fraudulent TikTok-branded reward pages that promise substantial cash payouts for daily check-ins, completing simple tasks, and referring friends. These sites, designed to mimic mobile shopping or loyalty applications, display a TikTok logo, a welcome message, and a tracker for daily check-ins, tasks, and referrals. They often present users with a rapidly accumulating points balance, which is then converted into a large cash sum, sometimes in the thousands, along with a countdown timer suggesting the balance is about to expire.
However, attempts to withdraw the promised funds are consistently met with new requirements. Users are typically asked to refer more friends, watch additional videos, complete sponsored offers through affiliate networks, or download a separate application for identity verification. The primary objective of these scams appears to be generating revenue for the operators through affiliate and cost-per-action (CPA) programs, where they earn money when users click ads, sign up for services, or install applications, regardless of whether the user ever receives a payout.
The on-screen balances and countdown timers are fabricated, designed to create a sense of urgency and investment, making it difficult for users to disengage. The promised cash and points do not reflect any real ledger or connection to TikTok's actual systems. The scam aims to keep users engaged in a continuous loop of tasks, always just one step away from a payout that never materializes.
While TikTok does operate a legitimate Creator Rewards Program, it functions differently from these fraudulent schemes. The official program is exclusively for eligible creators in specific countries who meet certain criteria and earn rewards for original videos, not for daily check-ins or tasks on external websites. Users are advised to verify any reward claims directly within the official TikTok platform.
To avoid falling victim, users should refrain from entering banking details, card numbers, or identification information on unverified TikTok-branded sites. If prompted to download an app outside of TikTok itself, it should not be installed. If an app has already been installed, it should be uninstalled, and a security scan should be run on the device. Users should also avoid referring friends or family to these sites, as this only perpetuates the scam. This type of "reward-mill" scam is not unique to TikTok and has been observed using other brand names, employing the same method of promising rewards to keep users engaged in a cycle of tasks.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed