Normal view
-
Security – Cisco Blog
- Assuming Failure: The Mindset Shift That Actually Improves Your Defensive Outcomes
DHS Official Resigns, Citing ‘War on Immigrants’
Private Claude Chats Exposed in Google and Bing Search Results
The OpenAI Models That Hacked Hugging Face Were ‘Active on the Internet’ for Days
Chick-fil-A Data Breach Explained: What Customers Need to Know
This week in scams and cybersecurity news,
Chick-fil-A disclosed that hackers may have accessed customer loyalty accounts using stolen usernames and passwords leaked in previous breaches.
It’s a reminder that reusing passwords across websites can be dangerous and allow one breach to snowball into many others.
Here’s what happened and what customers need to know:
So How Did Hackers Breach Chick-fil-A?
Chick-fil-A is notifying customers in 10 states after a cyberattack targeted a limited number of Chick-fil-A One loyalty accounts.
According to multiple reports, attackers used a technique known as credential stuffing, in which criminals take usernames and passwords stolen in previous data breaches and automatically test them across other websites and apps.
If someone has reused the same password, attackers may be able to access additional accounts without ever hacking the company directly.
Chick-fil-A said the attackers may have accessed customer information including:
- Names and email addresses
- Chick-fil-A One membership numbers
- Mobile Pay numbers and QR codes
- The last four digits of stored payment cards
- Gift card balances
- Birth dates, phone numbers, and addresses (if customers stored them)
The company says it has logged affected users out of their accounts, removed stored payment methods, restored impacted rewards balances, and is notifying customers who may have been affected.
| Credential stuffing: |
| A cyberattack where criminals use usernames and passwords stolen in previous data breaches to automatically sign in to other websites and apps. If you’ve reused the same password across multiple accounts, one breach can give attackers access to many of them. |
| How to Protect Yourself: Use a unique password for every account, enable multi-factor authentication, and use a password manager to securely create and store strong passwords. |
How McAfee Helps Before, During, and After a Data Breach
Before a breach
Personal Data Cleanup reduces your digital footprint by removing your personal information from many data broker sites, making it harder for scammers to find and target you.
Online Account Cleanup scans for accounts you no longer use and helps you delete them, along with your personal info.
Password Manager helps you create and securely store strong, unique passwords for every account, reducing the risk that one stolen password can unlock multiple accounts.
During a breach
Identity Monitoring watches for your personal information, including email addresses, driver’s license numbers, passport numbers, bank accounts, credit cards, Social Security numbers, phone numbers, and more, across the dark web and known data leaks.
Plus, we alert users on average up to 10 months earlier than similar services, so you can act fast when your personal information appears where it shouldn’t.
After a breach
Scam Detector identifies suspicious texts, emails, and links that often follow major breaches, while web protection blocks malicious websites designed to steal even more of your information.
Other Scam News This Week
Student loan scams are on the rise. Experts warn that changing federal student loan repayment rules are creating confusion that scammers are exploiting with fake debt relief offers, phishing emails, and identity theft schemes targeting borrowers. (PBS News)
AI agent reportedly carried out a cyberattack. AI platform Hugging Face says an autonomous AI agent executed a sophisticated attack against its internal systems from start to finish; an early example of AI taking on an active role in cyberattacks rather than simply assisting human hackers. (Axios)
Paidwork breach reportedly exposes 23 million users. Security researchers say data from the microtask platform may include names, addresses, phone numbers, bank account details, and password hashes, highlighting how even smaller online accounts can become valuable targets for cybercriminals. (Malwarebytes)
And we’ll be back next week with more news.
The post Chick-fil-A Data Breach Explained: What Customers Need to Know appeared first on McAfee Blog.
The Journey towards Logically Air-Gapped Deployment
Satellite Images Reveal How Suspected Scam Compounds Appear Out of Nowhere
For Taylor Swift, Madison Square Garden’s Controversial Cameras Briefly Went Dark
-
Security – Cisco Blog
- Cisco Firewall Migration Manager: A Faster, Simpler, More Confident Path to Secure Firewall
Cisco Firewall Migration Manager: A Faster, Simpler, More Confident Path to Secure Firewall
States Want ICE Agents to Show Their Faces. The Trump Administration Is Blocking Them
OpenAI Models Escaped Containment and Hacked Hugging Face
A Sneaky Hacking Tool Targeting AI Infrastructure Is Lurking in Victims’ Blind Spots
-
WIRED
- A Device Hidden in Cars Across the US Leaves Them Vulnerable to Hacking and Paralysis. Patch It Now
A Device Hidden in Cars Across the US Leaves Them Vulnerable to Hacking and Paralysis. Patch It Now
How to Use Claude with McAfee to Check “Is This a Scam?”
Scam messages are getting smarter and faster.
According to McAfee’s 2026 State of the Scamiverse report, Americans now spend 114 hours a year trying to figure out what’s real and what’s fake online. That’s nearly three full workweeks lost to second-guessing messages, alerts, and links.
And when scams do succeed, they move quickly. The typical scam unfolds in about 38 minutes, leaving little room for hesitation.
That creates a gap: People want to check before they act, but the tools haven’t always met them in that moment.
Claude + McAfee is designed to close that gap, bringing scam detection directly to a platform people are already using to ask questions and make decisions.
And it’s available to anyone. You don’t have to be a McAfee subscriber.
This isn’t just detection. It’s guidance in the exact moment you’re deciding what to do.
Instead of guessing, you can paste a message or drop in a screenshot and get a clear explanation of what’s risky, and what to do next, powered by McAfee’s threat intelligence.
How to Use McAfee in Claude
With this integration, checking something suspicious becomes as simple as asking a question.
Paste a message. Drop in a link. Upload a screenshot. And just make sure to @McAfee when you’re asking a question.
McAfee analyzes it and explains what’s going on clearly and in context.
For example, I got this suspicious “job offer” message over the weekend:
So I uploaded it in Claude and asked @McAfee, which caught it right away. You can even see I’m using the free plan.
Here’s how it works:
| Feature | What it does | How it protects you |
| Link safety check | Paste a suspicious URL and get a reputational analysis based on McAfee threat intelligence | Scam links are often designed to look legitimate. A quick check helps avoid phishing and malware |
| Message analysis | Submit texts, emails, or social messages for evaluation | Many scams now rely on urgency and tone. Analysis helps surface subtle red flags |
| Screenshot uploads | Upload screenshots of messages or emails for review | Scams don’t always come as clean text. This makes it easier to check what you’re seeing |
| Clear explanations | Get a breakdown of why something is flagged as risky or safe | Not just a warning—an explanation that helps you recognize patterns next time |
| Guided next steps | Receive recommendations on what to do next | Helps prevent escalation, especially in moments of uncertainty |
It’s a quick, accessible way to get answers in the moment. But it’s just one part of a broader system designed to protect you more comprehensively.
How do I set up McAfee in Claude?
Add the Connector to your Claude account here.
And make sure to go into “manage connections” to give McAfee permissions to review the texts, emails, and URLs you upload to Claude.


Need help getting the extension installed? Check out our step-by-step guide.
Built on McAfee’s Threat Intelligence
Behind the scenes, Claude + McAfee is powered by the same intelligence that fuels McAfee’s broader scam protection ecosystem.
When you submit something for review:
- Links are checked against known threat signals
- Messages are analyzed for scam patterns and language cues
- Results are translated into clear, human-readable explanations
The goal isn’t just to flag risk. It’s to help you understand it.
A New Way to Stay Ahead of Scams
Scams aren’t slowing down. If anything, they’re becoming more convincing, more personalized, and harder to detect.
That’s where Claude + McAfee comes in. But this is only one part of a much bigger system designed to protect you before, during, and after a scam attempt.
With McAfee+ Advanced, multiple layers work together so you’re not left figuring it out after the damage is done:
- Identity Monitoring alerts you if your personal info shows up where it should not, so you can act fast
- Personal Data Cleanup helps remove your information from sites selling it.
- Scam Detector flags suspicious texts, emails, links, QR codes, and even deepfake videos before you engage
- Safe Browsing helps block risky sites, even if you do accidentally click
- Device Security helps detect malicious apps or downloads
- Secure VPN keeps your data private, especially on public Wi-Fi
- The Claude + McAfee experience gives you a fast, intuitive way to check something in the moment.
McAfee+ Advanced makes sure you’re protected across everything else.
The post How to Use Claude with McAfee to Check “Is This a Scam?” appeared first on McAfee Blog.
The ACLU Is Arming Lawyers to Expose State Surveillance Secrets
Apps Marketed to US Troops Are Shipping Chinese and Russian Code
The FaceTime Bank Scam That Can Expose Your Passwords in Real Time: This Week in Scams
Scammers don’t always need sophisticated malware to steal your money. Increasingly, they’re relying on something much simpler: your trust.
This week, fraudsters were reported using FaceTime to watch victims log into their online banking accounts in real time, while Arizona authorities warned about fake QR codes exploiting the disappearance of 84-year-old Nancy Guthrie.
Here’s what happened, and how to protect yourself.
Scammers Are Using FaceTime to Watch Victims Log Into Their Bank Accounts
A growing scam is turning one of Apple’s most familiar apps into a tool for financial fraud.
According to CBS News, scammers first contact victims by text or phone while pretending to represent their bank or credit card company. They claim there’s suspicious activity on the account and that additional verification is needed.
Instead of keeping the conversation on a regular phone call, they switch to FaceTime.
Victims are then convinced to share their screens while logging into online banking. As they do, scammers can watch account numbers, passwords, and even one-time security codes appear in real time.
How the scam works
- You receive a text or phone call claiming there’s fraud on your account.
- The caller directs you to continue the conversation over FaceTime.
- You’re asked to share your screen while logging into your bank.
- The scammer watches your passwords and verification codes as you enter them.
Remember: Your bank should never ask you to share your screen or reveal one-time authentication codes. If you receive an unexpected call, hang up and contact your bank using the number on the back of your card or through its official app.
Fake QR Codes Are Exploiting the Search for Nancy Guthrie
Authorities in Arizona are warning the public about another scam—this time involving the disappearance of 84-year-old Nancy Guthrie, mother of Today show host Savannah Guthrie.
According to the Pima County Sheriff’s Department, scammers have been circulating social media posts containing QR codes requesting donations connected to the investigation.
The department says it will never ask the public for money related to this case or any investigation and urged people not to scan QR codes requesting payment.
The warning comes as investigators continue to search for Nancy Guthrie, whose disappearance remains under investigation.
How to spot QR code scams
- Verify who posted the QR code before scanning.
- Be cautious of emotional appeals tied to breaking news or missing persons cases.
- Never send money to someone you don’t know based solely on a social media post.
- Confirm donation requests through an organization’s official website instead of relying on shared posts.
Scammers know that people want to help during emergencies. Unfortunately, they also know that urgency and emotion can cause people to act before verifying where their money is going.
Other Scam and Security News This Week
Even scam reporters can be targeted. A CBS News correspondent shared how he nearly withdrew money from his own bank after falling for a sophisticated imposter scam before realizing something didn’t add up. (Yahoo Finance)
India investigates reported nuclear plant-related data breach. Reuters reported that ransomware group World Leaks published files allegedly connected to contractors working on India’s Kudankulam Nuclear Power Plant. Officials say no nuclear security systems were exposed. (Reuters/Al Jazeera)
Cyberattack disrupts KFC Japan supply chain. A cyberattack on food logistics provider Nichirei Co. disrupted frozen food deliveries to KFC Japan, leading the company to warn of possible menu restrictions, shorter hours, and temporary pauses to online ordering. Nichirei said it has found no evidence that customer or personal information was exposed. (TechRadar)
Your Safety Checklist This Week
Before you trust a call, text, or QR code:
Never share your screen with someone claiming to be your bank.
Don’t scan QR codes requesting money unless you’ve verified the source.
Contact organizations directly using their official website or phone number—not the contact information provided in a text or social media post.
Slow down when someone creates urgency. Whether it’s a missing person case or a frozen bank account, scammers rely on emotional reactions.
How McAfee Can Help
Scammers often begin with a text, phone call, or malicious link designed to earn your trust before stealing your information.
Before a breach: Personal Data Cleanup helps reduce your digital footprint by removing your personal information from many data broker sites, limiting what scammers can easily find about you.
During a breach: Identity Monitoring alerts you if your personal information appears on the dark web or in known data leaks, helping you respond faster if your information is exposed.
After a breach: Scam Detector helps identify suspicious texts, emails, and links that often follow major breaches, while Web Protection helps block malicious websites designed to steal additional information or credentials.
And we’ll be back next week with more news and safety tips.
The post The FaceTime Bank Scam That Can Expose Your Passwords in Real Time: This Week in Scams appeared first on McAfee Blog.
Your Period Tracker Is (Probably) Spying on You
Prompt Injection Attacks Are Thwarting AI Hacking Agents
San Francisco Demands Apple and Google Delete AI ‘Nudify’ Apps From App Stores