Today’s Menu (30-second skim)

  • Chick-fil-A loyalty accounts were hijacked with stolen passwords: Hackers used old stolen passwords to break into rewards accounts and spend points or grab personal details.
  • A popular Adobe browser add-on could have exposed WhatsApp Web chats: A flaw in a common PDF browser add-on could let a bad website peek at WhatsApp Web chats.
  • A hidden car alarm flaw could let attackers unlock and track vehicles: A dealer-installed car alarm system may let someone nearby unlock a car or track where it has been.

1) Chick-fil-A loyalty accounts were hijacked with stolen passwords

Chick-fil-A loyalty account login

What happened (plain English): Chick-fil-A said attackers used automated login attempts on its website and app between June 17 and June 19, 2026. They were not cracking brand new passwords. They were trying usernames and passwords that had already been stolen in other breaches and seeing where they still worked. When that works, it usually means someone reused the same password on more than one account. In some affected accounts, criminals could see names, email addresses, rewards numbers, QR codes, balances, and parts of saved card details. That makes a fast food rewards account more valuable to thieves than it sounds.

Why it matters to you: If you reuse passwords, one old data leak can unlock other accounts you still use today. A criminal could spend your points or gift value before you even notice. They could also use your name, birthday, or contact details to send a scam message that feels more believable. In a real life example, someone could pretend to be customer support and mention your rewards account to trick you into giving up even more information.

How to protect yourself (do this):

  • Change the password on any account that still shares an old password, especially food, shopping, and banking apps.
  • Turn on two-factor authentication anywhere it is offered, including rewards apps with points, gift cards, or saved payment info.
  • Check your rewards and gift card balances now so you can spot surprise purchases quickly.

Published: 2026-07-22

Source: Malwarebytes


2) A popular Adobe browser add-on could have exposed WhatsApp Web chats

People reviewing a laptop screen

What happened (plain English): Researchers found a flaw in Adobe’s Acrobat PDF extension for Chrome that could let a malicious website spy on WhatsApp Web. A person did not need to download a fake file or type a password into a scam page. Just visiting the wrong site could be enough if the Adobe extension was installed and WhatsApp Web was open at the same time. The bug could reveal chat lists, contact names, profile names, messages, and the conversation on screen. Adobe says the problem was fixed in version 26.5.2.3 of the extension.

Why it matters to you: Most people think, “If I do not download malware, I am safe,” but browser add-ons can create a side door. If someone sees your chats, they may learn private plans, family details, account codes, or work information. A scammer could use those details to impersonate a friend and ask for money. They could also time a fake message for when they know you are traveling, distracted, or waiting for a package.

How to protect yourself (do this):

  • Update Chrome and your browser extensions, then remove any add-on you do not truly need.
  • Review the devices linked to your WhatsApp account and sign out of any you do not recognize.
  • Be extra careful about clicking random links while logged into web versions of messaging apps.

Published: 2026-07-23

Source: Malwarebytes


3) A hidden car alarm flaw could let attackers unlock and track vehicles

Car security on the road

What happened (plain English): Researchers said a dealer-installed KARR car alarm system used the same authentication key across many vehicles. That means one weakness may have been shared by a huge number of cars instead of staying limited to one owner. The system was reportedly installed in about 2.2 million vehicles, and many drivers may not even know it is there. Someone nearby could potentially unlock a vehicle or disable its ignition. The device also broadcast identifiers that could help build a history of where a car had been parked.

Why it matters to you: This kind of risk is easy to miss because the device may have been added at the dealership before you bought the car. In one abuse case, a thief standing nearby could use the flaw to get into the vehicle. In another, a stalker could watch for patterns and learn where someone lives, works, worships, or shops. That turns a hidden gadget into both a theft risk and a privacy risk.

How to protect yourself (do this):

  • Ask your dealership whether your car has a dealer-installed KARR or similar aftermarket alarm or tracking device.
  • If it does, ask whether a firmware fix is available and whether the device can be removed or disabled.
  • Be careful about posting detailed car information online, since small clues can make targeted abuse easier.

Published: 2026-07-23

Source: Malwarebytes


Grandma’s Firewall

Grandma's Firewall

This week’s simple rule:

If an account, app, or gadget is important, give it its own password and keep only the extras you actually use.

Two scripts you can steal:

  • “I’m not reusing that password. This account gets its own login.”
  • “Before I trust this app or browser add-on, I’m checking whether I still need it and whether it’s up to date.”

Top rated products