Google’s New Search Redirects Make It Harder to Check Where Links Lead Before Clicking
Malwarebytes reports Google's new encoded google.com/goto?url= redirects break hover-preview link checking, weakening a common phishing defense.
Google now routes some search results through opaque google.com/goto?url= redirects using custom encoding, so browser link previews no longer reveal the true destination, only the claimed label above the result. Malwarebytes found the final destination is visible only in the redirect response's Location header, complicating hover-based safety checks as well as scraping, archiving, and audit tools. The change arrives amid malvertising, search-result poisoning, and fake installer campaigns like the recent Node.js infostealer lure. Google says it deploys measures against evolving abuse but did not explain the change.
Tech support scams look different now. Here’s what to watch for
Malwarebytes warns tech support scammers now abuse sponsored search results, fake listings, calendar invites, and Apple Pay notifications, and shares red flags for impersonation scams.
Malwarebytes describes how tech support scams have expanded beyond browser locks and fake virus warnings to sponsored search results, hijacked on-site searches, fake platform listings, renewal scams, fake calendar invites, and Apple Pay notifications. Scammers impersonate trusted security companies including Malwarebytes, seeking payment, personal information, or remote access to victims' computers. Malwarebytes notes it does not outsource support, never makes unsolicited calls, and works with the FTC and the Global Anti-Scam Alliance to combat these scams.