Archives September 2026

Google’s new search redirects make links harder to check before you click

Google is changing how some links in its search results work.

Instead of linking directly to the destination, Google has started routing some search result links through opaque google.com/goto?url=... redirects. The url parameter does not show a readable version of the destination but uses a custom, Google-specific encoding.

Google confirmed the rollout to Search Engine Roundtable:

“We have a long history of deploying technical measures against evolving forms of abuse, and we regularly take steps to protect our services and users.”

Google has not said precisely what abuse the change is intended to prevent. However, the most likely reason is that the redirects are designed to make bulk extraction of destination URLs from Google search results more difficult and costly. Automated tools must now ask Google to resolve each result separately.

Since the rollout has apparently not reached my neck of the woods yet, I had to grab an image from another source.

New URL structure
Image courtesy of seroundtable.com

Some Reddit users find the change ironic: Google built its search business by automatically collecting information from other websites, but is now making it harder for others to collect information from Google.

Other users have complained about the collateral damage to legitimate tools. Rank tracking, SEO auditing, research, archival, accessibility, and alternate-index services may all face the same rate limits and costs as abusive scrapers.

Search results data provider Autom reports that the final destination is viewable only through the redirect response’s Location header. This means bulk collectors must make an additional request for every result.

Security

The first thing that popped into my one-track mind was the security downside. We often tell users to hover over a link before clicking it so they can check where it leads. That advice is less useful when hovering reveals an encoded Google redirect rather than the destination website.

Google still displays the claimed destination above each search result, but users can no longer use the link preview as an independent check.

So, Google, where does this leave our advice? We already tell people not to click Sponsored search results. Should we now tell them to avoid goto?url links too? Or will you give users an easy way to check where a link leads before they click it?



Crypto customers targeted by scammers after email marketing provider breach

An attacker breached an email marketing platform and launched targeted attacks against the newsletter subscribers of some of its customers, especially those working in cryptocurrency and adjacent fields.

The incident was a supply-chain phishing campaign carried out through Brevo, an email marketing provider used by several cryptocurrency companies and other firms.

Brevo initially said an attacker had gained access to 120 customer accounts, some of which were used to send phishing emails to the customers’ contact lists.

Brevo tweet

Brevo later said 138 customer accounts had been accessed in its postmortem:

“On September 10th at 6:30 AM UTC we identified a security issue where an attacker exploited a flaw in the way Brevo handles SAML SSO to gain access to 138 Brevo accounts. 6 of those accounts were used to send phishing emails to the contacts stored there, and for 43 accounts they exported the contacts. 93 accounts have no meaningful activity.”

According to reports, popular cryptocurrency companies Trezor, CoinTracking, and BitBox confirmed that phishing emails were sent to customers subscribed to their newsletters. Trezor warned its roughly 347,000 newsletter subscribers that a security incident at a third-party provider had resulted in a massive phishing campaign.

Trezor makes hardware wallets that store cryptocurrency private keys offline. Its customers received a phishing email titled “Critical Security Alert: STM32 Entropy Bug Identified.”

The subtitle read: “Urgent update regarding hardware microcontroller vulnerability.”

The email said:

“Dear customer,

We have some difficult news to share. Unfortunately, our engineering team has identified a critical hardware-level vulnerability in the STM32 microcontrollers used in a range of Trezor devices.

Currently we believe the majority of defective devices were initialized prior to 2023, however some newer devices also may be vulnerable. The bug is a hardware factory defect present in an estimated 1 in 4 devices.

The vulnerability results in:

  • Insufficient randomness in recovery phrase generation
  • Exposure of seeds to brute-force cracking
  • Seeds with as little as 40 bits of entropy”

That phishing email also contained a link that prompted recipients to download an app and enter their wallet backup.

CoinTracking said the attackers sent its customers an email titled “Data Breach Notice: Please refresh API Keys as soon as possible,” which also contained a malicious link. 

Because the emails came from legitimate company domains and looked convincing, some recipients may have fallen for them. The exact number is not currently known.

How to stay safe

It can be difficult to recognize a phishing email when it comes from a legitimate company domain and looks convincing. But there are a few things to keep in mind:

  • If a company emails you about an urgent security problem, check its official website or app for confirmation.
  • Do not install apps through links in unsolicited emails, no matter how urgent the message claims to be.
  • Never enter your recovery phrase anywhere other than on your physical device.
  • Reputable companies will not ask for recovery phrases, API keys, or login details by email.
  • Use Malwarebytes Scam Guard to check whether a message might be a scam and get guidance on what to do next.
  • Keep an eye out for further information about other Brevo customers that have been affected. The attackers exported contacts from 43 accounts, which could be used in future targeted phishing attacks.

Trezor advises moving your funds to a new wallet if you entered your wallet backup in any form. If you followed a link in a similar email from another provider, contact that company directly for advice.


Something feel off? Check it before you click.  

Malwarebytes Scam Guard helps you analyze suspicious links, texts, and screenshots instantly.  

Available with Malwarebytes Premium Security for all your devices, and in the Malwarebytes app for iOS and Android.  

Try it free ?