Skip to main content
  1. Home
  2. Computing
  3. News

Typos can get you hacked in latest cybersecurity threat

Add as a preferred source on Google

Even a simple and common error like mistyping a domain name can lead to cybersecurity attacks, the latest in the ongoing barrage of malware. Known as URL hijacking or “typosquatting,” this social engineering technique is built upon the knowledge that it’s easy to hit the incorrect key and end up visiting the wrong website.

With very little effort, a hacker can copy images, fonts, and text to construct a malware website that looks like PayPal, Google Wallet, Microsoft Visual Studio, MetaMask, and other popular websites. These fake websites are also used in phishing campaigns of all sorts since the similarity of the domain name is useful for a whole variety of confidence stings.

Recommended Videos

URL hijacking and phishing campaigns aren’t new, but there has been a recent increase in them. Bleeping Computer, with a little help from the security firm Cyble, discovered over 200 domains that impersonated popular websites for Android and Windows apps, cryptocurrency and stock trading, as well as subscription services apps.

The goal of fake websites for apps would be stealing credentials and infecting your computer or phone with viruses. Any website that involves subscriptions or payments would have the more direct approach of taking your money or cryptocurrency.

A common technique with URL hijacking is to add or change one letter. Bleeping Computer gave an example of a trustworthy website for the popular Windows text editor, notepad-plus-plus.org. A malware website exists that simply adds the letter S to the end of “notepad” to create the deceptive domain name.

Here's an example of a fake website that looks real, Notepad-Plus-Plus.
Image used with permission by copyright holder

Major browsers include a degree of protection, identifying some fake websites while missing others. To protect yourself, have a close look at the domain name shown in the website address box or do an internet search for the website, app, or service you want to visit. You can’t trust that you’re at an authentic website based on appearance alone.

Alan Truly
Alan Truly is a Writer at Digital Trends, covering computers, laptops, hardware, software, and accessories that stand out as…
ChatGPT will now dole out finance tips if you connect your bank account. I won’t.
ChatGPT can now access your bank account to offer spending analysis and financial planning.
chatgpt-personal-finance

ChatGPT already knows a lot about you. OpenAI now wants to add your finances to that list. The company has launched a personal finance feature for ChatGPT, currently in preview for Pro subscribers in the US at $200 a month. OpenAI says it will expand to Plus users after gathering feedback from this early rollout.

It lets you connect your financial accounts through Plaid, a platform that bridges bank apps with third-party services and works with over 12,000 institutions, including Chase, Fidelity, Schwab, American Express, and more.

Read more
CleanShot X is my favorite Mac utility. Here are 8 features that will convince you, too.
Your Mac's built-in screenshot tool has been holding you back. It's time to upgrade.
Mac running CleanShot X

macOS has a built-in screenshot tool that gets the basics right. You can take a screenshot, record your screen, and even annotate your captures. But the moment you want something more, like scrolling capture, advanced annotation tools, or a quick way to share your screenshots via a link, it starts to fall apart.

That's where CleanShot X comes in. It's a powerful screenshot and screen recording app for Mac that replaces the built-in screenshot tool. It feels as if the developers looked at the screenshot features in macOS and added everything that was missing.

Read more
Wowed by computer-use AI agents? Research says they’re “digital disasters” even for routine tasks
Researchers tested 10 agents and models and found high rates of undesirable actions and real digital damage
ai-agent-handling-office-tasks

AI agents built to run everyday computer tasks have a serious context problem, according to new research from UC Riverside.

The team tested 10 agents and models from major developers, including OpenAI, Anthropic, Meta, Alibaba, and DeepSeek. On average, the agents took undesirable or potentially harmful actions 80% of the time and caused damage 41% of the time.

Read more