Tech
Fake GTA 6 Demo Spreads Malware: How to Spot the Scam
A fake GTA 6 demo circulating through convincing Rockstar Games lookalike sites is actually password-stealing malware. No legitimate Grand Theft Auto VI demo is available to download, and Rockstar has not announced a PC version.
The scam matters beyond gaming accounts because the malware targets information stored in web browsers, including passwords, cookies, and authenticated sessions. If the affected browser is also used for email, work apps, banking, or shopping, those accounts may be exposed too.
How the fake GTA 6 demo scam works
Malwarebytes identified a network of sites impersonating Rockstar Games and promoting a supposed GTA 6 demo. Their “Play Now” buttons can download a file called gta6_installer.exe.
The executable is only 1.1 MB, far too small to contain a modern AAA game. Malwarebytes identified it as Vidar, an information stealer sold to cybercriminals.
The sites are more convincing because they copy genuine GTA 6 artwork and information about Rockstar’s August 27 Extended Look. Similar fake downloads have used anticipated movies and other entertainment releases to hide password-stealing malware.
What the malware can steal
Malwarebytes found the Vidar sample targeting saved passwords, session cookies, browsing history, autofill data, and FTP credentials.
It searched 19 browsers, including Chrome, Edge, Firefox, Brave, Opera, and Vivaldi. It also targeted Thunderbird profiles, Perplexity’s Comet browser, and WebView2 inside Roblox Studio.
Stolen cookies are particularly important because attackers may be able to reuse an already authenticated browser session without completing the normal login process again. That means two-factor authentication alone does not necessarily protect an account after a session token is stolen.
The campaign also demonstrates why browser-stored credentials remain attractive targets for infostealers.
How to spot the scam and respond
The simplest warning sign is also the strongest: there is no official GTA 6 demo. Any site offering one is fake, regardless of how convincing its Rockstar branding looks.
Other red flags include:
- A game download offered outside Rockstar or a recognized game store.
- Search ads or unofficial sites claiming an “official” demo.
- A suspiciously tiny installer.
- Pressure to download leaked, beta, or early-access material.
If you downloaded the file but did not run it, delete it and scan the device.
If you ran it, Malwarebytes recommends assuming browser credentials and active sessions may have been compromised. Scan the computer, then use a clean device to change important passwords and sign out of active sessions. Check accounts for unfamiliar devices, recovery details, forwarding rules, or connected applications.
If work accounts were open in the affected browser, notify your IT or security team rather than treating the incident as only a personal gaming scam.
Also read: Our Windows 11 security cheat sheet explains built-in protections including Defender, BitLocker, passkeys, and other Windows security features.
>
Tech
Rivian’s CFO is leaving the company
Rivian’s chief financial officer Claire McDonough is resigning her position at the end of October, the company announced in a regulatory filing Thursday.
The company said McDonough is stepping down to “pursue a new opportunity and relocate to the East Coast to be closer to her family.” Rivian said her resignation is “not the result of any disagreement.” The company is already searching for a replacement, and vice president of finance Derek Mulvey will serve as interim CFO once McDonough leaves her post.
Her departure comes as Rivian takes on some of its biggest projects to date, including scaling up production and sales of its R2 SUV, which started shipping to customers this summer.
This story is developing…
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.
>
Tech
Bluesky adds an ‘algorithmic opt-out’ feature for those who don’t want to go viral
After adding support for longer videos just yesterday, open social network Bluesky on Thursday introduced a new algorithmic opt-out feature that allows users to stop their posts from appearing in the app’s main Discover feed.
That algorithmic feed can currently surface any post on Bluesky’s network, as posts on the network are public by default.
To be clear, this latest change isn’t a way to make posts private — Bluesky is still working on rolling out support for private data at the protocol level. Instead, the feature simply makes a user’s public posts less discoverable to people outside their existing personal network.
The company says it created the feature because not everyone using its social media site wants to go viral. Sometimes, people just want to post for their followers without having their words exposed to larger crowds.
To opt out of having posts shown in the Discover feed, users can toggle on a new option in the app’s Privacy and Security settings. The change can take up to an hour to fully take effect, the company says.

It’s also worth noting that Bluesky’s implementation of the feature extends beyond its own app.
Instead of just being a setting that applies only within Bluesky, the preference is recorded at the account level. That means the choice travels with the user, even if they’re posting from another app that is powered by the same underlying protocol that Bluesky uses, AT Proto.
However, while those other apps have access to this information, they still have to choose to whether to respect it.
>
Tech
Buried in Meta’s $18B settlement is a legal pass on kids’ data
In addition to paying out up to $18 billion and adding child safety measures, Meta’s settlement agreement with attorneys general from 29 states includes an interesting provision: the states have agreed not to sue Meta under existing child safety laws over its retention and use of children’s data.
That permission is being granted for the limited purpose of training and testing Meta’s age-assurance model and includes guardrails, but it’s a curious policy decision to make in a case centered on child safety, and one that could be difficult to properly enforce.
As specified in the settlement agreement, Meta must develop, train, and begin testing a model designed to detect which users on Meta’s platforms are under the age of 13. This must be done within a year of the document’s effective date. (While the agreement doesn’t specify that the model has to be AI-based, Meta’s current age-detection tools are powered by AI technology.)
Under U.S. child safety law, COPPA (the Children’s Online Privacy Protection Act), typically requires that websites and apps limit the collection and retention of children’s personal information. Meta’s settlement agreement says that Meta shouldn’t need to violate COPPA to train or implement its age-assurance models. However, the agreement also says that the state AGs have agreed “fully, finally, and forever” not to bring any past, present or future COPPA claims — or claims under similar state laws — related to Meta’s use of children’s data.
The agreement makes clear that Meta can’t use data from users under age 13 for ad targeting, marketing, or algorithmic optimization.
Meta’s request for legal protection, and the state AGs’ willingness to grant it, isn’t unreasonable, says Philip N. Yannella, a partner at law firm Blank Rome and co-chair of its Privacy, Security & Data Protection practice. “These kinds of data minimization guardrails are pretty typical for privacy compliance: e.g., verifying compliance with deletion requests,” he said, though he noted a caveat: COPPA is a federal law primarily enforced by the FTC, not the states, so it’s unclear whether the FTC, which isn’t a party to this settlement, has separately agreed to the same compromise.
It can be difficult for companies to keep data technically and organizationally isolated from the rest of their systems. Yet Meta is being asked to do just that — to isolate its understanding of children’s behavior signals and other data and use it solely for detecting and removing under-13 users. Fortunately, an independent auditor will be involved in monitoring Meta’s compliance with the settlement so we don’t only have to rely on Meta’s word.
Policing this limitation could be complicated. The data could hypothetically feed into other Meta systems over time, or could raise questions over whether the data, signals, or insights derived from it are being used elsewhere within the company. What’s not clear from the agreement is what data Meta will retain for training the model, how much behavioral information that may include, or how long it will retain the data. We also don’t know how these models will change in the future as Meta meets the settlement’s terms.
Barring state AGs from raising COPPA or similar state-law claims over this use of children’s data in the future could complicate the legal avenues states can pursue if questions arise around how Meta is using the data.
That doesn’t prevent them from pursuing legal claims, notes Joshua Wurtzel, a partner at Schlam Stone & Dolan LLP. “If Meta uses the data outside those lines, the release and covenant not to sue don’t apply,” he said. But those legal disputes could still be complicated, since they’d hinge on whether Meta’s use of the data fell within the settlement’s terms.
Peter Jackson, a Data & IP attorney at Greenberg Glusker LLP, agrees, saying the carve-out here could “disincentivize future enforcement actions.”
“The Settlement Agreement’s age-assurance measures bear all the hallmarks of a heavy, and perhaps hasty, negotiation,” he says.
The decision also touches on a broader question that’s been coming up across the AI industry lately, especially as more AI agents are being developed to help consumers with various tasks. The systems often require significant access to users’ personal data to work well. Similarly, Meta may need deep insight into children’s use of social media use in order to identify which accounts belong to young people.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.
>
-
movies3 months agoSearch For Canadian TV Actor Stewart McLean Now Homicide Investigation
-
Fashion9 years agoThese ’90s fashion trends are making a comeback in 2017
-
Fashion9 years agoAccording to Dior Couture, this taboo fashion accessory is back
-
Fashion9 years agoModel Jocelyn Chew’s Instagram is the best vacation you’ve ever had
-
Fashion9 years agoEmily Ratajkowski channels back-to-school style
-
Fashion9 years ago9 Celebrities who have spoken out about being photoshopped
-
Fashion9 years agoYour comprehensive guide to this fall’s biggest trends
-
Anime3 months agoRurouni Kenshin: Hokkaido Arc Manga Takes 1-Issue Break – News
