Skip to main content
  1. Home
  2. Computing
  3. Apple
  4. Web
  5. News

Don’t mistype that URL, as it could lead to malware

Add as a preferred source on Google

Typo prone? You may want to clean up your act. In a malicious trend known as typosquatting, hackers are now taking advantage of our fast fingers and careless errors, attempting to send malware onto Macs by way of mistyped URLs. According to the security company Endgame, a whopping 300 popular .com sites have been registered in Oman, whose top level domain is .om. But this is only a cover — the .om sites try to load OS X malware known as Genieo onto the Apple devices of unsuspecting users.

Endgame first came across typosquatting when an employee made a typo in “www.netflix.com,” instead typing, “netflix.om.” As Endgame notes, “He did not get a DNS resolution error, which would have indicated the domain he typed doesn’t exist.  Instead, due to the registration of “netflix.om” by a malicious actor, the domain resolved successfully.” Luckily, being an Endgamer, he was able to spot the malware, and “retreated swiftly, avoiding harm.”

Recommended Videos

Other less savvy users, however, may not have been as lucky. The malware Genieo, Endgame notes, is a rather “common OS X malware/adware variant” that “typically infiltrates the user’s system by posing as an Adobe Flash update.” If the user accepts the update, then Genieo “entrenches itself on the host by installing itself as an extension on various supported browsers (Chrome, Firefox, Safari).”

Typosquatting isn’t all that new — indeed, malware has previously been delivered by way of mistyped addresses. But Endgame does say that it hasn’t previously come across “.om abuse.” So how concerned should we be? The security firm suggests, “Our research also indicates that .om domains associated with the vast majority of major brands may be unregistered. It does not appear that are widely including the .om in their typosquatting mitigation strategies. We strongly recommend doing so.”

So be careful when you’re typing, friends. This is one type of “om” you want nothing to do with.

Lulu Chang
Fascinated by the effects of technology on human interaction, Lulu believes that if her parents can use your new app…
A harmless-looking ChatGPT prompt opened the door to gruesome AI images
The findings show how image safety systems can fail without explicit graphic instructions.
ChatGPT

A harmless-looking ChatGPT prompt pushed the latest public version of ChatGPT into generating sexualized and violent images, AI security researchers told the BBC. The finding puts new pressure on OpenAI’s image safety systems, since the request wasn’t described as plainly graphic.

Mindgard, a British AI security startup, said it reached the results by altering a widely shared instruction that had been used for comedy. OpenAI added safeguards after the BBC contacted it, but the researchers said small wording changes still produced concerning images.

Read more
ChatGPT’s new Scheduled page puts all your automated tasks in one place
The update also brings smarter monitoring tasks that can search the web and connected apps automatically.
ChatGPT Scheduled hub featured

OpenAI is rolling out a dedicated home for ChatGPT's scheduled tasks, giving users a single place to view, manage, and monitor automated work. The new Scheduled page can be accessed from the sidebar, and it shows all active tasks alongside their next run times.

What the update adds

Read more
Claude Design will now stick to your brand guidelines instead of generic AI mockups
Claude Design connects to Adobe, Canva, and more tools now.
Claude desktop.

Anthropic just rolled out a big update to Claude Design, its AI-powered visual creation tool that first launched in research preview. The tool already lets you turn a simple prompt into prototypes, decks, and marketing assets, and now it does even more.

The latest update brings design system support, a smooth handoff to Claude Code, a redesigned editor, and a bunch of new app integrations.

Read more