Normal view
-
ZDNet | security RSS
- Chrome stops hackers from stealing your browser cookies now - how its new security feature works
GTA cheat service Atlas Menu hacked as attacker alleges screenshot spying
-
The Hacker News
- โก Weekly Recap: New Linux Flaw, PAN-OS Exploit, AI-Powered Attacks, OAuth Phishing and More
โก Weekly Recap: New Linux Flaw, PAN-OS Exploit, AI-Powered Attacks, OAuth Phishing and More
r/netsec monthly discussion & tool thread
Questions regarding netsec and discussion related directly to netsec are welcome here, as is sharing tool links.
Rules & Guidelines
- Always maintain civil discourse. Be awesome to one another - moderator intervention will occur if necessary.
- Avoid NSFW content unless absolutely necessary. If used, mark it as being NSFW. If left unmarked, the comment will be removed entirely.
- If linking to classified content, mark it as such. If left unmarked, the comment will be removed entirely.
- Avoid use of memes. If you have something to say, say it with real words.
- All discussions and questions should directly relate to netsec.
- No tech support is to be requested or provided on r/netsec.
As always, the content & discussion guidelines should also be observed on r/netsec.
Feedback
Feedback and suggestions are welcome, but don't post it here. Please send it to the moderator inbox.
[link] [comments]
-
/r/netsec - Information Security News & Discussion
- Poisoning Claude Code: One GitHub Issue to Break the Supply Chain
Poisoning Claude Code: One GitHub Issue to Break the Supply Chain
-
ZDNet | security RSS
- How I built my own DIY cyberdeck straight out of 80s sci-fi - and all the cool things it can do
How I built my own DIY cyberdeck straight out of 80s sci-fi - and all the cool things it can do
Are Your World Cup Tickets Legit? 40% of Fans May Risk Unofficial Sellers
Whetherย youโreย planning a once-in-a-lifetime trip or just hoping to catch a match whileย itโsย in your city, the 2026 FIFA World Cup is already driving a surge in ticket searches, travel bookings, and last-minute plans.ย
But where thereโs high demand and big money,ย scammersย arenโtย far behind.ย
Letโs break down the new McAfee research, what scams to watch for, and how McAfeeโs tools help you stay safe.
New McAfee Research Finds a Gap Between Awareness and Riskย
New research from McAfee shows that while most fans are aware of World Cup-relatedย scams, many are still willing to take risks to secure tickets.ย ย
In fact,ย 40% say they would consider buying from an unofficial source if theyย canโtย get tickets throughย theย officialย FIFA site,ย as many expect tickets to sell out and hope to find affordable resale options.ย
That tension is what makes events like the World Cup especially vulnerable forย scams.ย
With limited ticket availability, rising prices, and the pressure to act quickly, even informed fans can find themselves making decisions they normallyย wouldnโt, like buying tickets from a reseller on TikTok.ย ย
And scammers are counting on it.ย
Survey takeaways:ย
- 76% of fans are interested in getting World Cup ticketsย
- 35% have already started searching onlineย
- 43% are willing to spend over $500 on ticketsย
- 66% sayย theyโreย aware of World Cup-relatedย scamsย
- 66% sayย theyโreย concerned about beingย scammedย
- 40% would consider buying tickets from unofficial sourcesย
The Most Common World Cup Scams to Watch Forย
Below is a comprehensive breakdown of the most commonย scamsย tied to major global sporting events like the World Cup, including how they work and what to look for.ย
McAfeeโsย Scamย Detector,ย ย Safe Browsingย tools,ย VPN, andย Password Managerย work together to help you spotย scamsย like theseย as they happen by flagging suspicious messages, blocking risky websites, and helping you make safer decisions before you click, pay, or share information.ย
| ย |
ย What It Isย | ย How It Worksย | ย Red Flagsย |
| Fake Ticket Resale Scamย | Fraudulent tickets sold through unofficial sites or individualsย | Scammers create fake listings or duplicate real tickets and sell them to multiple buyersย | Prices far below or above market, refusal to use official transfer systems, pressure to act fastย |
| Social Media Ticket Scamย | Tickets sold through platforms like Instagram, Facebook,ย TikTok,ย or Xย | Fake or hacked accounts post โlast-minuteโ ticket offers and move conversations to DMsย | Urgent language (โonly 2ย leftโ), new or suspicious profiles, requests to pay outside the platformย |
| Duplicate QR Code Scamย | One legitimate ticket is resold multiple timesย | Multiple buyers receive the same QR code, but only the first scan worksย | Screenshots instead of official transfers, identical tickets sold repeatedlyย |
| Fake Ticket Website Scamย | Websites designed to look like official ticket platformsย | Victims enter payment info or purchase tickets thatย donโtย existย | Slightly misspelled URLs, unfamiliar domains, lack of official branding verificationย |
| Travel & Accommodation Scamย | Fake hotels, rentals, or travel packagesย | Listings appear legitimate but eitherย donโtย exist or are already bookedย | Prices that seem unusually low, requests for upfront payment, lack of verified reviewsย |
| Booking Impersonation Scamย | Fraudsters pose as airlines, hotels, or booking platformsย | Victims receive messages about โissuesโ with bookings and are asked to click links or provide infoย | Unexpected messages, requests for login or payment details, links thatย donโtย match official sitesย |
| Public Wi-Fi & Phishing Scamย | Data theft through unsecured networks while travelingย | Scammers intercept data or create fake login portals on public Wi-Fiย | Open networks with no password, login pages asking for unnecessary informationย |
| Fake Giveaway Scamย | Promotions claiming free tickets or VIP accessย | Victims are asked to enter personal data, click links, or pay โprocessing feesโย | โYouโve wonโ messages youย didnโtย enter, requests for payment to claim prizesย |
| Betting & Prediction Scamย | Fake betting tips or โguaranteed winsโ tied to matchesย | Scammers sell fake predictions or direct users to malicious betting sitesย | Claims of guaranteed outcomes, requests for upfront payment, unfamiliar platformsย |
| Merchandise Scamย | Counterfeit World Cup gear sold onlineย | Buyers receive low-quality or no product at allย | Unverified sellers, poor site quality, deals that seem too good to be trueย |
How AI is Making These Scams More Convincing
Unfortunately, with the continued improvement of AI, theseย scamsย are becoming more convincing.ย
AI tools allow scammers to create:ย
- More realistic websites and messagesย
- Personalized outreach that feels legitimateย
- Fake endorsements, images, or promotionsย
That means traditional advice like โlook for typosโ is no longer enough on its own.ย
Todayโsย scamsย often look polished, professional, and believable.ย


What โOfficialโ Actually Means (and Why It Matters)ย
For the World Cup, official ticket sales happenย through designated FIFA sales phases and platforms.ย
Buying outside those channels increases the risk of:ย
- Invalid or duplicate ticketsย
- Inflated pricing without guaranteesย
- No recourse if something goes wrongย
Even if a ticket looks legitimate, it may be:ย
- Sold to multiple buyersย
- Already voidedย
- Rejected at the gate
When in doubt,ย go directly to the officialย FIFA websiteย instead of clicking links from messages or ads.ย You can alsoย visit their comprehensive FAQ sectionย for all your ticket and event questions.ย
How to Stay Safe When Buying Tickets or Travelingย
Here are practical steps fans can take to reduce risk:ย
| Safety Checkย | What To Doย |
| Buy from official sourcesย | Use FIFAโs official ticket platform whenever possibleย |
| Avoid clicking links in messagesย | Navigate directly to official websites instead.ย McAfeeโs Safe Browing toolsย help prevent you from opening malicious links.ย |
| Be cautious with resale offersย | Verify platforms and avoid direct peer-to-peer paymentsย |
| Check QR codes before you scan themย | You can check for QR codeย scamsย on-demandย withย Scam Detectorย |
| Donโtย pay with untraceable methodsย | Avoid wire transfers, gift cards, or crypto-only paymentsย |
| Double-check URLsย | Look for misspellings or unusual domainsย |
| Use secure connectionsย | Avoid making purchases on publicย Wi-Fi, orย use aย VPNย like McAfeeโs.ย |
| Protect your accountsย | Use strong passwords and enable two-factor authentication. Consider aย password managerย like McAfeeโs.ย ย |
| Verify before you buyย | If something feels off, pause and check before sending moneyย |
What to Do If You Thinkย Youโveย Been Scammedย
If you think you may haveย purchasedย a fraudulent ticket, clicked a suspicious link, or shared information with a scammer, acting quickly can help limit the impact.ย
Immediate steps to takeย
Stop communication immediately
Do not sendย additionalย money or information, even if the sender claims you need to โcompleteโ a transaction.ย Itโsย alsoย a good ideaย to take screenshots of messages in case the scammer disappears.ย
Contact your bank or payment provider
Report the transaction as soon as possible. Many institutions can help reverse charges or flag fraudulent activity if caught early.ย
Secure your accounts
Change passwords for any accounts that may be affected, especially email, banking, and ticketing platforms.ย Ourย password managerย andย free password generatorย helpย create unique passwords every time.ย ย
Enable two-factor authentication (2FA)
Adding an extra layer of security can help prevent unauthorized access, even if your password was exposed.ย
Scan your device for threats
If you clicked a suspicious link or downloaded a file, run a security scan to check for malware or malicious software.ย Check out our free security scan.ย
Monitor for unusual activity
Keep an eye on financial accounts, email logins, and any services tied to your personal information.ย Our free WebAdvisorย helps protect you from malware and phishing attempts while you surf.ย

How McAfee Helps You Spot Scams in the Momentย
McAfee offers more than traditional antivirus, combining multiple layers of digital protection in one app to help you stay safer while searching, clicking, and buying online.ย
Scam Detectorย helps flag suspicious texts, emails, and videos automatically,ย so you can spot aย scamย before it hits you and your walletย
Safe Browsing toolsย help block risky websites, alert you to phishing attempts, and guide you away from malicious linksย
VPNย helps keep your connection private on public Wi-Fi, protecting your personal and payment informationย
Password Managerย helps create and store strong, unique passwords to reduce the risk of account takeoverย
Identity Monitoring and Alertsย notify youย if your personal information appears where itย shouldnโt, so you can quickly take steps to fix itย
Personalย info removalย helps find and remove your personal infoย from dataย broker sitesย and close out old forgotten accountsย
Device and Account Securityย helps protect the devices and accounts you use every dayย
Finalย Thoughtsย
The World Cupย isnโtย just another event,ย itโsย a moment when millions of people are making fast decisions involving real money, travel plans, and personal information.ย
What McAfeeโs research makes clear is that the biggest riskย isnโtย a lack of awareness. Most fans already knowย scamsย exist.ย The risk is what happens next.ย
When tickets are scarce, prices are high, and the pressure to act is real, even informed consumers may take chances they normallyย wouldnโt.ย Thatโsย where scammers succeed: not by tricking people whoย arenโtย paying attention, but by catching people in moments of urgency.ย
As demand continues to build toward the tournament, more fans will be searching, comparing, andย purchasingย online.ย ย
The takeaway is simple:ย Staying safeย isnโtย just about knowingย scamsย exist.ย Itโsย about slowing down, verifying before you buy, and using tools that help you make informed decisions in the moment.ย
*McAfee is not affiliated with or endorsed by FIFA.ย
The post Are Your World Cup Tickets Legit? 40% of Fans May Risk Unofficial Sellers appeared first on McAfee Blog.
-
/r/netsec - Information Security News & Discussion
- Stealing Passwords via HTML Injection Under a Strict CSP
Stealing Passwords via HTML Injection Under a Strict CSP
Palo Alto VPN bug graduates from advisory to active exploitation
-
Security โ Cisco Blog
- Cisco Secure Access and Microsoft Purview Integration for Simplified Data Protection
Cisco Secure Access and Microsoft Purview Integration for Simplified Data Protection
Cisco Secure Access and Island Browser Enable Zero Trust Everywhere
-
Security โ Cisco Blog
- Finding what lives between the alerts: Announcing Cisco Talos Threat Hunting
Finding what lives between the alerts: Announcing Cisco Talos Threat Hunting
-
Security โ Cisco Blog
- From Log Flood to Threat Signal: Cisco and Splunk Bring Context to Modern Defense
From Log Flood to Threat Signal: Cisco and Splunk Bring Context to Modern Defense
China-Aligned Groups Ramp Up Attacks: Dragon Weave Hits Czech Republic & Taiwan
The Security Growth Platform: Why MSPs Are Moving Beyond vCISO Tools
-
The Register - Security
- Password manager Dashlane suspends customer accounts amid brute-force attacks
Password manager Dashlane suspends customer accounts amid brute-force attacks
-
The Register - Security
- Putin sends submarines to survey Britain's subsea cables. UK deploys Royal Navy, mobilizes parliamentary draftsmen
Putin sends submarines to survey Britain's subsea cables. UK deploys Royal Navy, mobilizes parliamentary draftsmen
The Romance Scammer Who Made a Small Fortune Posing as a WWE Superstar
-
The Hacker News
- OpenAI Codex Authentication Tokens Stolen in codexui-android npm Supply Chain Attack
OpenAI Codex Authentication Tokens Stolen in codexui-android npm Supply Chain Attack
Websites Can Now Spy on You Through Your Hard Drive