Reading view
The Pixel Watch 5 could help me lift heavy - and replace my top strength training app
Pixel Watch 4 vs. Pixel Watch 5: Is Google's new model worth it? It comes down to this
Google Pixel 11 vs. Pixel 9: Why I'm considering the upgrade this year
After testing the Pixel 11, I feel fine about skipping the Pro models - here's why
Google's new Pixel Tag tracker has a big advantage over AirTags (and they cost the same)
The Pixel's new 'HiLight' reminds me of the golden days of Android phones
Exposed: Woeful security at UK criminal records office that led to sensitive data leak
Akira ransomware scum blocked victim's security tools – and broke their own encryptor
GTA 6 Is Coming. So Are the Scams. Here’s What McAfee Experts Found

Millions of gamers are counting down the days until this fall’s biggest releases.
After more than a decade of anticipation, Grand Theft Auto VI is finally set to launch this November. Surprise indie hit Meccha Chameleon has exploded across Twitch and YouTube after selling millions of copies within days. And highly anticipated titles like Call of Duty: Modern Warfare 4, Minecraft Dungeons 2, Phantom Blade Zero, Marvel’s Wolverine, and dozens of others are keeping players glued to trailers, wishlists, Discord servers, and preorder pages.
Scammers are watching those trends.
Whenever millions of people rush to search for the same game, criminals quickly create fake downloads, unofficial mobile apps and servers, counterfeit storefronts, phishing pages, and cheat tools designed to steal money, credentials, or personal information.
This year is no exception.
Here’s how scammers are taking advantage of 2026’s biggest gaming moments, and how you can avoid becoming their next target, according to McAfee’s experts:
The Most Common Gaming Scams and How to Avoid Them, According to McAfee
Most gaming scams fall into a handful of predictable categories. Once you know what to look for, they’re much easier to spot.
Here are some of the most common scams McAfee protection prevents
| Scam | What it looks like | Red flags | How to protect yourself |
| Fake game downloads | “Free” copies, cracked launchers, unofficial installers | Unknown websites, requests to disable antivirus, ZIP files instead of official installers | Download games only from official publishers or trusted storefronts |
| Fake early access | Too-good-to-be-true VIP access, beta invites, playable versions before launch that don’t exist | Cryptocurrency payments, countdown timers, “exclusive” offers, unofficial websites | Verify release dates , including early access dates, and preorder information directly with the publisher |
| Cheats, mods, and trainers | Unlimited money, aimbots, unlock tools, auto-play software | Downloads shared through Discord, YouTube descriptions, file-sharing sites | Only use trusted community repositories and avoid executable files from unknown sources |
| Fake mobile versions | Mobile apps for games that don’t officially exist on Android or iPhone | Different developer names, excessive ads, cloned screenshots | Confirm that the developer has actually released a mobile version before downloading |
| YouTube and Discord scams | Videos claiming to have mods or secret builds | Shortened links, pinned download comments, Discord invite links | Visit the developer’s official website instead of getting mods or clicking links from comments or descriptions |
| Fake giveaways and free skins | Free cosmetics, DLC, battle passes, or gift cards | Requests to sign in through third-party sites or enter account credentials | Only redeem offers through official game platforms |
These tactics aren’t theoretical. They’re happening right now.
Detected by McAfee Labs: Malware Campaigns, Malicious Downloads, and Suspicious Apps
Earlier this year, McAfee Labs uncovered WeedHack, a malware campaign disguised as free Minecraft mods and game clients.
Since January 2026, the campaign has infected more than 116,000 devices, averaging roughly 2,000 to 3,000 new infections every day. Attackers lured players through fake mod websites and convincing YouTube videos before installing malware capable of stealing passwords, cryptocurrency wallets, Discord credentials, Minecraft accounts, and more.
Ultimately these gaming attacks can expose players to:
- Malware infections
- Account theft
- Password theft
- Data breaches
- Spyware monitoring cameras and microphones
- Spyware monitoring keyboard and mouse inputs
- Permanent game bans
One of the campaign’s most concerning findings wasn’t just the malware itself, it was how inexpensive and accessible the tools had become. The malware was marketed almost like legitimate software, lowering the barrier for inexperienced attackers and helping spread scams throughout gaming communities.
The lesson isn’t to avoid every cheat, unlock, or community-created project. It’s to be skeptical whenever someone promises something that seems too good to be true.
Meccha Chameleon Shows How Quickly Scammers Embrace Viral Games
Few people predicted Meccha Chameleon would become one of the biggest surprise gaming success stories of the year.
The inexpensive indie title reportedly sold more than two million copies within days, fueled largely by livestreams, social media clips, and word of mouth. Unfortunately, that kind of overnight success doesn’t just attract new players.
According to PC Gamer, players have already begun using automated “auto-paint” cheats that scan the environment and instantly camouflage characters, removing much of the creativity and skill the game was designed around.
The game’s popularity has also created confusion about where players can safely download it.
McAfee researchers recently identified multiple Android apps and an unofficial piracy site using the Meccha Chameleon name, despite the game’s independent developer not announcing an official Android release.
Here’s how we saw it play out
First a gamer might navigate to this piracy site to download a free game. The game may not come with malware, but malware is still distributed during the process.

Here we see steamgg[.]net, a piracy site to download free games. Here you see they offer a download of Meccha Chameleon (not malicious).
But when you click download, it opens a misleading new tab like this one below.

This new tab tricks the user into thinking they are downloading a game from steamgg[.]net. They are actually being redirected to a completely unrelated download.
In cases like this, unauthorized sites and apps trick users into giving unwanted access to their information and devices.

*Note: The unauthorized apps shown here have since been reported and taken down. While not confirmed to be malicious, hundreds of people had already downloaded and given security permissions to these apps.*
“Repackaged or unauthorized apps and sites are a major risk with viral games,” says McAfee Threat Researcher and lifelong gamer Charles McFarland.
“Because many players are unfamiliar with the original developer, it’s easier for unauthorized apps and copycat listings to blend into app stores,” McFarland explains. “Once installed, the app can have free access to your phone’s data, texts, contacts, and more.”
Before downloading a newly popular game, especially on mobile, take a moment to verify that the developer has actually released it for your device.
Is This GTA 6 Download Legit? How to Spot Fake Early Access Scams
If there’s one game scammers are betting people will search for this fall, it’s Grand Theft Auto VI.
Rockstar Games officially opened global preorders on June 25, and the game launches worldwide on November 19, 2026 for PlayStation 5 and Xbox Series X|S. Digital preorders can begin preloading on November 12.
That hasn’t stopped scammers from advertising:
- “Play GTA 6 today”
- VIP Early Access
- Secret beta downloads
- Discounted preorder keys
- Cryptocurrency-only purchases
- “Exclusive” launchers
The problem? Those offers promise something Rockstar isn’t selling.
If a website claims it can provide a playable version of GTA 6 before Rockstar’s official launch, treat it as a major warning sign.
Scammers know players have waited more than a decade for the next Grand Theft Auto. They’re counting on excitement to outweigh skepticism.
“Every major game launch brings a noticeable increase in gaming-themed scams. We regularly see McAfee protecting customers from malicious downloads, fake websites, and other threats that capitalize on the excitement around new releases,” McFarland says.
“As a gamer myself, I know the excitement of jumping into a long-awaited game with my son, but it’s worth taking an extra minute to download from an official or authorized source instead of rushing to be first.”
Whenever possible, verify preorder information directly through Rockstar Games or trusted digital storefronts rather than clicking links shared through social media posts, livestream chats, YouTube comments, or unsolicited messages and advertisements.
| Official storefront | Trending and Upcoming Games |
| Steam | Meccha Chameleon, Dune: Awakening, Metal Gear Solid: Master Collection Vol. 2, Silent Hill: Townfall, Call of Duty: Modern Warfare 4, Phantom Blade Zero, No Rest for the Wicked, Planet Zoo 2, Kingdom Hearts Collections, Ace Combat 8, Gears of War: E-Day (PC), Minecraft Dungeons 2 and many other PC releases |
| PlayStation Store | Grand Theft Auto VI, Marvel’s Wolverine, Phantom Blade Zero, Onimusha: Way of the Sword, Metal Gear Solid: Master Collection Vol. 2, Call of Duty: Modern Warfare 4, Dune: Awakening, Silent Hill: Townfall and other PlayStation releases |
| Xbox Store | Grand Theft Auto VI, Gears of War: E-Day, Call of Duty: Modern Warfare 4, Dune: Awakening, Ace Combat 8, Kingdom Hearts Collections and other Xbox releases |
| Nintendo eShop | Rhythm Heaven Groove, Splatoon Raiders, Fire Emblem: Fortune’s Weave, Harvest Moon: Echoes of Teradea, Nintendo Switch Sports Resort, The Legend of Zelda: Ocarina of Time Remake and other Nintendo titles |
*Availability may vary by platform as publishers announce additional releases.
If you can’t find a game on one of its official storefronts, that’s a good reason to pause before downloading it elsewhere.
How McAfee Protects Gamers
Gaming should be about exploring new worlds, not accidentally downloading malware.
McAfee helps protect players before, during, and after they click.
Web Protection helps block known malicious websites before fake downloads ever reach your device.
Award-winning antivirus detects and blocks malware hidden inside suspicious installers, cheats, and unofficial software.
If a file is flagged, Threat Explainer provides a clear, plain-language explanation of why it’s considered risky, helping you make informed decisions instead of guessing whether a warning is legitimate.
And if you’re worried additional security will slow down your games, McAfee Total Protection has repeatedly scored first place in the AV-Comparatives PC Performance Test, an independent benchmark that measures how much security software impacts your computer’s performance.
McAfee earned the lowest overall impact score among the 20 products tested and received the highest possible rating, 3 Stars ADVANCED+. In other words, you get strong protection without sacrificing performance or slowing your game.
Whether you’re preordering GTA 6, trying the latest indie hit, or installing a new Minecraft mod, slowing down long enough to verify where you’re downloading from remains one of the simplest, and most effective, ways to protect yourself.
Frequently Asked Questions
| FAQs |
| Q: Is GTA 6 early access real?
A: No. Rockstar Games has announced pre-orders and pre-loading ahead of launch, but there is no legitimate way to play GTA 6 early through unofficial websites. Be wary of any site claiming to sell “VIP access,” beta keys, or downloadable copies before the official release date. |
| Q: Is it safe to pre-order GTA 6 from any website?
A: Stick to Rockstar Games or authorized retailers and digital storefronts like the PlayStation Store and Xbox Store. Avoid unfamiliar websites advertising deep discounts, exclusive editions, or cryptocurrency-only payments. |
| Q: Does Meccha Chameleon have an official Android or iPhone app?
A: At the time of writing, the game’s developer has not announced an official mobile version. If you find Meccha Chameleon in an app store, verify that it’s published by the official developer before downloading. |
| Q: Are game cheats and trainers safe to download?
A: Not always. While some cheats simply modify gameplay, others can contain malware, steal passwords, or compromise gaming accounts. Downloading cheats from unofficial websites or Discord servers carries additional risk. |
| Q: Can Minecraft mods contain malware?
A: Yes. While many Minecraft mods are legitimate, cybercriminals have repeatedly used fake mods and clients to distribute malware. Download mods only from trusted community repositories or verified developer pages. |
| Q: How can I tell if a game download is legitimate?
A: Download games directly from the publisher’s official website or trusted digital storefronts like Steam, PlayStation Store, Xbox Store, Nintendo eShop, or Epic Games Store. Avoid links shared through YouTube comments, Discord messages, or unofficial social media posts. |
| Q: Why do scammers target popular game releases?
A: High-profile launches create excitement and urgency, making players more likely to click on fake download links, preorder scams, cheat tools, or unofficial apps without stopping to verify they’re legitimate. |
| Q: What are the biggest gaming scams to watch for in 2026?
A: Common gaming scams include fake early access offers, counterfeit game downloads, unofficial mobile apps, cheat software bundled with malware, phishing pages posing as gaming platforms, and fake giveaways promising free games or in-game items. |
| Q: Can antivirus slow down gaming performance?
A: Some security software can affect system performance, but independent testing has shown that solutions vary significantly. Look for products that perform well in third-party performance benchmarks while still providing strong protection against malware and phishing attacks. McAfee Total Protection recently took first place in the latest AV-Comparatives PC Performance Test, an independent benchmark that measures how much security software impacts your computer’s performance. In other words, McAfee provides strong protection without sacrificing performance or slowing your game. |
| Q: What’s the safest way to download new games this fall?
A: Buy or download games directly from official publishers and trusted storefronts, keep your operating system and antivirus up to date, avoid unofficial cheats or cracked versions, and verify any unexpected links before clicking. |
The post GTA 6 Is Coming. So Are the Scams. Here’s What McAfee Experts Found appeared first on McAfee Blog.
This Coin-Sized Device Can Hack a Boeing 737
Brit rail cops bring live facial recognition to the London Underground
‘The Worst I’ve Ever Seen’: Cargo Thefts Have Turned Violent in Pursuit of AI Hardware
Weekly Update 516: Live From Vietnam

A little wind noise, a little connectivity flakiness, and a little lip-sync issues from YouTube, but look at that view! 🤩 Back to business, it's the Brinks Home FAQ I found most interesting this week. I mean, how do you write your own FAQ then fail to actually answer most of the questions?! Being conscious that they're the target of criminal extortion and are genuinely the victims here, I still struggle to grasp how simple incident response questions can be so lawyer-speaked as to remove all sensible meaning from the responses. But this is how these things tend to play out these days (speaking generically, yet to be seen fully for Brinks): hacker gets data by just calling up and asking for it (vishing -> OAuth), hacker demands money, hacker gets no money so dumps the data, company gets a gazillion class actions overnight and lawyers up to the hilt, customers get notified "where legally required" (which it usually isn't) 🤷♂️
Signal adds an extra layer of security to make sure you're actually chatting with the right person
421 bugs in Microsoft's Patch Tuesday release, and the Norks have already attacked one
Microsoft Plugs Nearly 400 Security Holes
Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including one weakness that is already being actively exploited and two others that were publicly detailed prior to today.

Image: Shutterstock, Mallika Home Studio.
August’s overstuffed bundle of patch joy from Microsoft did not eclipse its recording breaking release of more than 570 security updates last month, but it is double June’s then-record batch of nearly 200 fixes. Microsoft has attributed the recent patch deluge to vulnerability discoveries aided by artificial intelligence, and experts roundly agree that Windows users should get used to the idea of Patch Tuesdays (the second Tuesday of each month) covering hundreds of newly discovered security flaws.
Fully 42 of the 398 flaws that Microsoft patched today earned Redmond’s most-dire “critical” rating, meaning they are severe enough that malware or malcontents could exploit them to gain remote control over a Windows computer with little to no help from the user.
The sole known “zero day” bug fixed by Microsoft this month is CVE-2026-68820, a privilege escalation weakness in a core Windows component called afd.sys, which the security firm Automox describes as “the driver behind Windows socket connections on effectively every endpoint.”
“This isn’t a front-door bug,” Automox’s Landon Miles wrote in a Patch Tuesday blog post. “It’s step two in a chain: an attacker phishes their way into a low-privilege foothold, then uses the driver flaw to take the box. The 7.0 score reflects the high attack complexity, because race conditions are fiddly. The exploit has to be thrown over and over until the timing lands. Someone is clearly landing it anyway.”
CVE-2026-62832 is another privilege escalation flaw that Microsoft has labeled likely to be exploited; this flaw, in the Windows User Profile Service, may be related to the recent “LegacyHive” public disclosure from the prolific bug hunter known as Nightmare Eclipse. The other publicly disclosed flaw is CVE-2026-72971, a low-impact local tampering vulnerability that Microsoft reckons is unlikely to be exploited.
Other major software makers are likewise increasing their patch volumes and cadence thanks to AI, including Adobe which last month moved to twice-monthly security bulletins published on the 2nd and 4th Tuesday of each month. Cisco, Google, Mozilla and Oracle also are shipping updates far more frequently and abundantly.
By all accounts, AI is quite good at finding security holes in software. But for now at least, patching the resulting bugpocalypse remains a heavily human-centric endeavor, and the jury is still out on whether AI technologies will turn out to be as good at fixing vulnerabilities as they are at finding and exploiting them. This is an important question when one considers that these same AI technologies also are suggesting fixes for the vulnerabilities they find.
Researchers at 1Password recently examined what happens when different large language models (LLMs) generate vulnerability patches for newly disclosed, complex vulnerabilities. They found the LLMs produced patches that failed to fix the flaw or added a new weakness in the process (or both) more than half the time.
Ed Skoudis, president of the SANS Technology Institute, said his team has seen excellent results using AI to generate patches, provided there are humans in the loop to test the suggested fixes and push for iterative improvements.
“AI is rapidly becoming astonishingly good at finding vulnerabilities, but this research shows that fixing them is a very different problem,” Skoudis wrote in a SANS newsletter today. “Don’t expect one-shot AI patching to work reliably. Instead, iterate, test, challenge, improve, and verify. AI can be an extraordinary patching partner, but today it still needs a skilled human at the keyboard.”
Tyler Reguly at Fortra says while reports of Microsoft patching hundreds of vulnerabilities in one go have prompted some organizations to try to patch faster, it’s important to bear in mind that only one of the almost 400 bugs addressed today is known to be actively exploited. Reguly suggested security leaders check in with their teams to see how they’re handling the increasing workloads, which often involve testing fixes before deploying them in production environments.
“If you’re a chief security officer talk to your teams about how they are shifting or modifying their workflows to better accommodate the patching shift that we’re seeing and support them across various organizational units by enabling the changes they want to see made,” Reguly said. “There’s no need to rush these updates, no matter what various vendors and organizations try to tell you. You need to make sure that you are rolling out safe updates that will not negatively impact your systems.”
Speaking of the humans behind the keyboards, don’t neglect to backup your system and/or data before applying this month’s monster patch load. The day after each month’s Patch Tuesday is sometimes derisively referred to as Reboot Wednesday, but it generally doesn’t hurt to wait a few days to apply these huge update bundles because it sometimes takes a couple of days for the occasional misbehaving patch to get ironed out properly by Microsoft.
For a clickable, per-patch breakdown by severity and urgency, check out this roundup from the SANS Internet Storm Center.