Hackers are increasingly using online ads for malicious purposes. Often, it’s happening through routine Google searches.
These schemes are dubbed malvertising, and cyber criminals are striking more often and with increased sophistication. In fall 2023, cybersecurity software firm Malwarebytes tracked a 42% increase month-over-month in malvertising incidents in the U.S. All types of brands are being targeted, whether it’s for phishing purposes or for actual malware, said Jérôme Segura, senior director of research at Malwarebytes. “What I’m seeing is just the tip of the iceberg,” he said.
Many of these rogue ads appear as sponsored content during a search engine query on a desktop or mobile device. But malicious code can also be hidden in ads that appear on mainstream websites consumers routinely visit. Some of these ads will only ensnare consumers who click on them, but in some cases, people can be vulnerable in a more passive way — sometimes just by visiting an infected site, said Erich Kron, security awareness advocate for KnowBe4, a security awareness and training company.
Corporate employees can also be targets of malvertising, Segura said. He cited a few actual examples that were recently uncovered involving big companies. Lowe’s staff members were targeted via a Google ad for an employee portal claiming to be associated with the retailer. Clicking on the link, “myloveslife.net,” which contains a misspelling of the company’s name, took users to a phishing page with Lowe’s logo. This had the potential to confuse employees since many don’t know offhand the URL for their internal website. “You see the brand, even the official logo of that brand, and for you it’s enough to think it’s real,” Segura said.
Segura also cited an ad meant to impersonate Salesforce-owned communication tool Slack. Initially, by clicking on the ad, he was redirected to a price page on Slack’s official website. But suspecting bad actors were at play, Segura dug deeper and uncovered an impersonation ploy, which involved trying to convince unsuspecting users to download something purporting to be the Slack app.
It’s not Google’s fault, but don’t trust it
Malvertising is not new, but cybercriminals are getting smarter and the ads are often so realistic that it’s easy to be duped. The problem is exacerbated by the fact that so many people use and trust Google as a search engine, where many of the malicious ads can be found. It’s not a problem with Google, per se; malicious ads can also show up in queries using other search engines like Microsoft’s Bing. It’s just that Google is such a widely used search engine and people trust it and let their guard down. “You see something appearing on a Google search, you kind of assume it is something valid,” said Stuart Madnick, professor of information technology at MIT Sloan School of Management.
Consumers can also fall prey to malicious ads on trusted websites they visit regularly. Many of these ads are legitimate, but some bad ones can slip through the cracks. “It’s like the post office. Does the mailman check every letter you get to make sure it’s really from Publishers Clearing House?” Madnick said.
Be very careful about where and when you click
Consumers can take steps to protect themselves against malvertising attempts. For instance, they should avoid clicking on sponsored links that come up during an internet search. Often, the first ad below the sponsored one will be the product they are looking for, and since it isn’t sponsored, there’s less chance of being sidelined by malicious code or a phishing attempt.
If you do click on a sponsored link, check the URL at the top of the web page to make sure it’s really where you meant to be before taking any other actions. For example, if you’re trying to visit Gap.com, make sure you’re not really on Gaps.com. Consumers who find themselves on a suspicious site should close the window immediately, said Avinash Collis, assistant professor at Carnegie Mellon University’s Heinz College. In most cases, this will avoid further trouble, he said.
Consumers also need to be careful about clicking ads they see on trusted websites, Kron said. They may, for instance, see ads for products that are much lower in cost than elsewhere. But Kron recommends not clicking and instead visiting the trusted website of the product seller. Most of the time, consumers will be able to search on the provider’s site if a special deal exists, or the deal will be highlighted on the main page of the trusted website, he said.
Also avoid calling a telephone number listed in a sponsored ad because it could be a fake telephone number. If you call it, cyber thieves could gain access to your computer or your personal information, depending on the scheme, said Chris Pierson, CEO of BlackCloak, a cybersecurity and privacy platform that provides digital executive protection for corporate executives.
Consumers should make sure they are calling a number from official product documentation they have in their possession, Pierson said. Alternatively, consumers could visit the company’s home page for this information. “Doing a [web] search could return results that are not sponsored by the company and telephone numbers that are associated with cybercriminals. All it takes to get an ad out there is money and, of course, cybercriminals that are stealing money, have the ability to pay for that bait,” Pierson said.
Avoid ‘drive-by-downloads’
Consumers should also make sure the operating system and internet browsers are up-to-date on their computer and mobile phone.
So-called drive-by-downloads, which can impact people who merely visit a website infected with malicious codes, generally rely on a vulnerability in the user’s browser. This is not as much of a threat for people who keep their browsers and browser extensions up-to-date, Kron said.
Consumers could also consider installing anti-malware software on their computer and phone. Another option is to avoid ads by installing an ad blocker extension such as uBlock Origin, a free and open-source browser extension for content filtering, including ad blocking. Some consumers may also opt to install a privacy browser such as Aloha, Brave, DuckDuckGo or Ghostery on their personal devices. Many privacy browsers have embedded ad blockers; consumers may still see sponsored ads, but they will see fewer of them, which minimizes the chances of malvertising.
Consumers who come across suspicious ads should report them to the applicable search engine for investigation and removal if deemed malicious, Collis said. This can help protect other people from being ensnared.
Proper safety precautions are especially important since there are millions of ads on the internet and cyber thieves are relentless. “You should assume that this could happen to you no matter how careful you are,” Madnick said.
U.S. Treasury Secretary Scott Bessent and U.S. Trade Representative Jamieson Greer hold a press conference, following a meeting with Chinese Vice Premier He Lifeng, on the day of U.S.-China talks on trade, economic and national security issues, in Madrid, Spain, September 15, 2025.
Louiza Vradi | Reuters
Treasury Secretary Scott Bessent said Tuesday that President Donald Trump was willing to let TikTok go dark, and it was “what turned the tide” in the deal framework with China.
“President Trump made it clear that he would have been willing to let Tiktok go dark, that we were not going to give up national security in favor of the deal,” Bessent told CNBC’s “Squawk Box.”
TikTok parent company ByteDance is still looking at a Sept. 17 deadline to divest the app’s U.S. operations or potentially be shut down in the country.
The Trump administration hasn’t yet formally extended the deadline, though U.S. Trade Representative Jamieson Greer said Monday that more time may be needed for the deal to be finalized and signed.
Bessent said Tuesday that the commercial terms of the deal between ByteDance and the new investors had been done “in essence” since March or April.
After Trump’s massive tariff announcement on April 2, the Chinese put the deal on hold, he said.
Trump and Chinese President Xi Jinping are expected to speak Friday to finalize the deal.
“We were able to reach a series of agreements, mostly for things we will not be doing in the future that have no effect on our national security,” Bessent said Tuesday.
Read more CNBC tech news
This is breaking news. Please refresh for updates.
Meta CEO Mark Zuckerberg tries on Orion AR glasses at the Meta Connect annual event at the company’s headquarters in Menlo Park, California, U.S., September 25, 2024. REUTERS/Manuel Orbegozo
Manuel Orbegozo | Reuters
Meta spent billions of dollars unsuccessfully trying to make virtual reality catch on with consumers. As it shifts its metaverse bet toward smart glasses, investors will be watching to see how the public responds.
The social media company is set to unveil its most advanced smart glasses yet on Wednesday at its Connect annual event. The glasses, internally codenamed Hypernova, feature a small display that can be controlled via hand gestures through a wristband that utilizes neural technology, CNBC reported in August.
A promotional video of the device reportedly appeared on Meta’s YouTube page on Monday but was later removed.
The device, expected to cost $800, builds upon Meta’s partnership with EssilorLuxottica, which spawned the AI-powered Ray-Ban Meta smart glasses in 2023 and the Oakley Meta HSTN smart glasses unveiled in June. Those glasses contain cameras, speakers and microphones, allowing users to command the Meta AI voice assistant to take a photo, shoot video or play music.
Wall Street has been concerned about the spending by Reality Labs, the company’s division in charge of developing consumer hardware products like the Ray-Ban Meta glasses and the Quest VR headsets. Meta revealed in July that its Reality Labs division recorded an operating loss of $4.53 billion during the second quarter, and has totaled nearly $70 billion in losses since late 2020.
Investors understand that Meta’s Reality Labs spending won’t significantly pay off for years, but they also “want to see progress” that indicates they will “see potential returns on investment,” said Justin Post, a Bank of America Securities internet research analyst. For now, smart glasses seem like a more sound investment than VR headsets, which are still niche and could take years to blossom, he said.
“I’ve definitely seen the company’s focus shift from VR headsets to glasses,” Post said. “At this point, the glasses are going to be much more impactful and more mass market.”
Meta declined to comment.
In Hypernova, Meta is selling smart glasses with a display to consumers for the first time. Though that display is expected to be small and limited in what it shows to users, the release of Hypernova represents a middle ground between the Ray-Ban Meta glasses and the experimental Orion augmented reality glasses that Meta showed off during last year’s Connect event.
Meta’s Orion AR glasses are displayed during a viewing in Menlo Park, California, U.S., Sept. 26, 2024.
Manuel Orbegozo | Reuters
The Orion AR glasses, working in tandem with a wireless computing “puck,” can project 3D visuals onto the physical world that people can interact with using a wristband. But while the Orion AR glasses can produce dazzling visuals, it’s still experimental and costly to make, said Anshel Sag, a principal analyst at Moor Insights & Strategy.
“Delivering something like Orion at scale will take time, which is why they are still a prototype,” Sag said. “I think a single display is a move in the right direction and would help build an ecosystem of apps.”
Connect presents Meta with an opportunity to build off the unexpected success of the Ray-Ban Meta glasses, said Leo Gebbie, a CCS Insight analyst and director. EssilorLuxottica said in July, during the company’s most recent earnings report, that Ray-Ban Meta smart glasses sales more than tripled year over year.
“It really feels like a chance to break through with a really new product category,” Gebbie said.
Analysts will also be watching for any signs that Meta’s recent artificial intelligence-related strategy shifts, which kicked off in June when the company invested $14.3 billion into Scale AI, can help its hardware efforts. The glasses could be the right hardware form factor for AI features, Post said.
“If they get the integration right with devices, it really could be a better portal for AI than even phones,” he said.
But although Meta has the money and technical talent to build its smart glasses, it needs to cultivate an ecosystem of developers who will build compelling apps and software that captivate consumers, Sag said.
The risk for Meta is that consumers ultimately reject the Hypernova and potentially the broader market of smart glasses with displays, Gebbie said. At $800, the glasses are expected to cost more than twice as much as the Ray-Ban Meta glasses, which start at $299. Already, Meta is setting low internal expectations for sales of the Hypernova glasses, CNBC reported in August, but the company will want the unveiling to at least generate some buzz.
Meta’s ambition is for smart glasses to become the next major personal computing platform. For now, Apple and Google remain on top with the iOS and the Android mobile operating systems, respectively.
Apple declined to comment. Google didn’t respond to a request for comment.
It’s unclear if Meta’s glasses will ever usurp the smartphone’s standing with consumers, but there’s enough of a threat that both Apple and Google are working on their own competitive products. Apple is reportedly working on its own glasses project, and Google in May announced a $150 million partnership with Warby Parker to build smart glasses
“The fact that everyone is now developing glasses suggests that Meta’s Reality Labs concept was well conceived, and they’re out in front at this point on glasses,” said Post. “The question for the competition is, can they leverage their mobile operating systems to get people to buy their glasses?”
Tesla CEO Elon Musk attends the Saudi-U.S. Investment Forum, in Riyadh, Saudi Arabia, May 13, 2025.
Hamad I Mohammed | Reuters
Tesla’s shares have finally turned positive for the year.
After a dismal first quarter, which was the worst for the stock in any period since 2022, and a brutal start to April, following President Donald Trump’s announcement of sweeping new tariffs, Wall Street has again rallied around the electric vehicle maker.
The stock rose 3.6% on Monday to $410.26, topping its closing price of 2024 by over $6. It’s up 85% since bottoming for the year at $221.86 on April 4. A new filing revealed that CEO Elon Musk purchased about $1 billion worth of shares in the company through his family foundation.
It’s the second straight year Tesla has bounced back after a down first quarter. Last year, the shares fell 29% in the first three months before ending up 63% for 2024.
In recent weeks, analysts have praised the EV maker’s proposed pay plan for Musk, which could amount to a $1 trillion windfall for the world’s richest person over the next decade. The company has also gotten a boost from its new MegaBlocks battery energy storage systems that Tesla ships preassembled to businesses looking to lower their power costs or make greater use of electricity from renewable resources.
Even with the rebound, Tesla is the second-worst performer this year among tech’s megacaps, ahead of only Apple, which is down about 5% in 2025. Tesla is still in the midst of a multi-quarter sales slump due to an aging lineup of EVs and increased competition from lower-cost competitors in China, namely BYD.
Tesla has seen a consumer backlash, in part because of Musk’s political activities, including spending nearly $300 million to propel President Trump back to the White House and his work with the Trump administration to slash the federal workforce.
Tesla leadership has been working to shift investors’ attention to other topics such as robotaxis and humanoid robots.
However, the company has yet to deliver vehicles that are safe to use without a human onboard and ready to take control if needed. And while Musk is touting Tesla’s Optimus robots, which he says will be able to do everything from factory work to babysitting, a product is still a long way from hitting the market.