Feed aggregator
“Adult TikTok” searches lead to scams
Search for certain combinations of “TikTok” and adult content, and sooner or later you’ll land on a page promising exactly what you searched for: an endless feed of explicit clips, no signup required, just tap and watch.
There isn’t one.
On the other side of that click is an ad funnel dressed up as exclusive content.
These pages aren’t connected to TikTok itself. They simply exploit the platform’s name to attract search traffic. TikTok’s huge user base, and the number of people searching for adult content associated with the platform, make it an attractive lure both for advertisers and scammers.
What you need to know right awayNothing on these pages is genuine content pulled from TikTok. Their entire business model is get you to click, sign up, or install something.
The operators don’t need to host any videos to make money. The promise of exclusive content is enough to generate clicks, signups, and downloads.
Although you’re probably not going to lose your life savings here, you could well end up on a spam list, installing an unwanted app, or paying for an “age verification” that doesn’t verify anything.
A pitch built around your searchThese pages are designed to match exactly what you searched for. Many are built to rank for popular search terms in Google and other search engines, rather than relying on visitors coming from TikTok itself. They often acknowledge the frustrating hunt for working links before presenting themselves as the solution.
Below that, you’ll usually find a deliberately blurred video thumbnail, reassuring labels like “18+ only” and “HD clips,” and one or two buttons inviting you to Start watching or Sign up for free.
Mirroring the visitor’s own search behavior back at them is a common tactic in this category of ad-lure page. It’s designed to make the offer feel more relevant rather than generic.
What happens after you click varies from site to site, but you rarely get the content you were promised. Instead, you’re likely to be redirected through advertising networks, asked to hand over an email address or payment card for “age verification,” or prompted to install an app from outside the official app stores.
Each click or redirect can earn the site operator money through advertising or affiliate commissions, even if you never sign up or download anything.
Every step of the journey has value: A click can generate advertising revenue, a signup can earn an affiliate commission, and an email address can be sold or added to marketing lists. A payment card entered for “age verification” can lead to recurring subscription charges. Whether you ever see a video is irrelevant because the site has already achieved its goal.
Legitimate websites don’t normally need your payment card to prove you’re over 18. Fake “age verification” pages often use the process to collect card details, sign people up for recurring subscriptions, or both.
There’s no content, but there is a funnelThe blurred thumbnail is the entire “product.” It’s designed to look like a legitimate preview, suggesting there’s something just behind the next click, even though there usually isn’t. The site makes money from the clicks, signups, and downloads, not from any videos.
Depending on the page, the operator makes money in several ways:
- Affiliate commissions. You click through to a dating site, adult subscription, VPN, app, or other offer. If you sign up, the site owner gets paid.
- Advertising revenue. Every redirect, pop-up, or ad impression earns money.
- Lead generation. Your email address is collected and sold or used for spam and phishing.
- Subscription traps. “Age verification” asks for a payment card, then quietly enrolls you in a recurring subscription.
- Potential malware. Some pages push unwanted software or even malware outside official app stores.
Adult content lures carry a built-in advantage most scams don’t have: embarrassment. People are less likely to mention it to a friend, ask for a second opinion, or report it, which means fewer eyes catch the scam before it spreads further.
What to do- Close the tab. There isn’t any exclusive TikTok content waiting behind Start watching.
- Don’t enter your email address, payment card, or date of birth to verify access. It isn’t verifying anything, it’s collecting data.
- Don’t install anything you were prompted to download from a page like this.
- If you’ve already entered information, treat it as exposed. Watch for follow-up spam or phishing emails, and change any passwords you may have reused.
Adult-content lures are one of the oldest tricks in malvertising. Using TikTok’s name just makes them feel more relevant to today’s searches.
Something feel off? Check it before you click.Malwarebytes Scam Guard helps you analyze suspicious links, texts, and screenshots instantly.
Available with Malwarebytes Premium Security for all your devices, and in the Malwarebytes app for iOS and Android.
The AI Act kicks into action, forces companies to be clear about AI chatbots
The European Union (EU) has started enforcing key parts of the AI Act, with immediate, visible consequences for chatbots, deepfakes and other consumer‑facing Artificial Intelligence (AI) systems.
From August 2, what you’ll likely notice are more “this is AI” labels, clearer rules for powerful foundation models, and new ways for users and researchers to complain when systems go off the rails.
The AI Act moved from theory to practice for three big areas:
- General‑purpose AI (GPAI) models: The new AI Office in Brussels, together with national regulators, can now enforce rules on providers of general‑purpose AI models (think large language models and other foundation models behind many tools).
- Transparency obligations: Transparency rules kick in for interactive systems and AI‑generated content: chatbots must say they are bots, and synthetic audio, images, video and text need to be marked as AI‑generated or manipulated.
- Banned AI uses: A set of “unacceptable risk” AI uses is now formally prohibited, with enforcement shared between the AI Office, national authorities and the European Data Protection Supervisor for EU institutions.
Note that content that was generated and published before August 2, doesn’t need to be retro‑labelled, but anything published on or after that date falls under the rules, even if it was generated earlier.
From a security perspective, the AI Act’s transparency push is less about banning AI and more about taking away its best camouflage: pretending to be human.
Non‑compliance with transparency obligations can attract fines up to 15 million Euros (17.3 million USD) or 3% of worldwide annual turnover, whichever is higher, which should be significant enough to get large providers’ attention.
To make enforcement more than a paper tiger, the AI Office has launched tools aimed at people who see problems from the inside or as users:
- Complaint tool: Individuals and organizations can report alleged infringements of the AI Act by providers or deployers of AI systems supervised by the AI Office.
- Whistleblower tool: People professionally connected to AI providers or deployers get an anonymous channel to flag potential violations that could endanger fundamental rights, health or public trust.
- Downstream complaints channel: Firms building on top of GPAI models can report suspected breaches by the underlying model providers.
This creates a formal path for reporting systemic issues: think unsafe model behavior, ignored red‑team findings, or deployments that quietly cross legal lines around manipulation or discrimination.
Bans on “nudifiers” and abusive contentThe AI Office has introduced explicit prohibitions on AI systems that generate non‑consensual sexually explicit or intimate content (including “nudifier” apps) and child sexual abuse material.
For victims of these abuses, that’s more than a symbolic move. It gives regulators and law enforcement a clear legal basis to go after both providers and deployers of such systems in the EU, rather than trying to squeeze them into older, less specific laws.
These rules will apply from December 2, 2026, with companies given time to bring their systems into compliance or pull them from the EU market.
Regrettably, this will not stop abuse completely. Attackers will still use unlabeled tools and infrastructure outside the EU. But it raises the bar for legitimate services and makes it harder for mainstream platforms to ignore the risks of deceptive AI‑driven features.
The AI Act won’t make AI safe overnight, but it shifts the default from “anything goes” to “you must play by some basic rules if you operate in the EU.” For users, that’s a step toward AI systems you can at least recognize and question, instead of having invisible technology quietly shape our online experience.
Scammers don’t need to hack you. They just need you to click once.
Malwarebytes Identity Theft Protection catches suspicious activity before it becomes a problem.
Microsoft CEO Touts His Own DIY AI Project To Wall Street and His 20 Million Followers
Apple files fresh legal complaint over secret Home Office order to require it to provide access to encrypted iCloud data stored by UK customers
Californians can tell data brokers to DROP their information
California has launched the Delete Request and Opt‑out Platform (DROP), a state‑run portal that lets residents send deletion and opt‑out requests to all registered data brokers in one place.
DROP was created under California’s Delete Act, which forces data brokers to register with the California Privacy Protection Agency (CPPA) or face fines. Currently over 600 data brokers are in the registry.
Data brokers collect and sell extensive personal information, including financial details, online behaviors, and location data. This data is often gathered without explicit consent, raising concerns about privacy and transparency.
DROP is a state service that sends a standardized deletion/opt‑out request to all data brokers registered with the California Privacy Protection Agency. Starting August 1, 2026, registered data brokers in California are required to access DROP and have 90 days to delete a person’s records after a request.
How to use DROPYou’ll need to provide at least one reachable email address and/or mobile phone to verify your identity and track the request. Be ready to provide basic personal data (name, address, contact details) that brokers are likely to have and that DROP uses to match your records.
- Go to the DROP portal.
- Use the “Get Started” button on the homepage.
- Accept the terms and conditions presented by the platform by using the “I accept” button.
- You’ll need to verify that you are a California resident: you can either input your personal information manually, or authenticate via Login.gov, which allows identity verification through a federal login. If you receive the message “Unable to verify” your status as a California resident, click the link on screen to “Request a review of your eligibility.”
- After residency verification, create a deletion request:
- Provide your email address and/or phone number to verify contact details.
- Fill in basic information (name, address, etc.) so brokers can locate your records.
- Submit your request through DROP and you’ll receive a DROP ID that lets you track the status of your request online. Store that number somewhere.
Now, it’s up to the data brokers. They now have 90 days to delete your records and comply with opt‑out obligations. If you run into a problem there is a dedicated help site.
For non-CaliforniansSome other states—like Oregon, Texas, and Vermont—also require data broker registration, though only California currently offers a centralized platform like DROP. If you live in such a state, check your attorney general’s website or privacy office for a “data broker registry” or opt‑out guidance, and follow their listed processes to submit requests directly to each broker.
Even without DROP, US residents can still reduce data broker collection and sale of their data, but it requires more manual work. Where no centralized government tool exists, you can identify brokers by searching for “data broker opt‑out” and review lists from privacy advocacy groups.
For each broker you’ll have to submit individual requests:
- Use their web forms, email addresses, or postal addresses to request:
- Deletion of your data, and
- Opt‑out from sale or sharing of your data.
You’ll need to provide enough information to match your record (e.g., name, address, email, phone) but avoid oversharing additional sensitive data.
It’s advisable to maintain a spreadsheet with dates, brokers, and confirmations. Most privacy laws specify response deadlines, often 30–45 days, though this varies by state.
Sounds like a lot of work? Malwarebytes Personal Data Remover can help.
How to reduce future data broker collectionThis is probably the only field where “security by obscurity” works.
Use multiple email addresses where you reserve one for financial/critical accounts and use aliases or disposable emails for newsletters, shopping, and registrations, making it harder for brokers to build a unified profile.
A VPN encrypts your traffic and hides your IP address, reducing the ability of websites and analytics firms to link activity to a stable, location‑based identifier.
For non‑critical services, avoid providing full legal names, exact home addresses, or phone numbers if they’re not strictly necessary. This is especially true for rewards and loyalty programs.
Your name, address, and phone number may already be for sale.
Data brokers collect and sell your personal details to anyone willing to pay. Malwarebytes Personal Data Remover finds them and gets your information removed, then keeps watch so it stays that way.
Show HN: Fetchcheck – send a signed crawler to any site and see if it gets in
If you were ever curious whether a site allows signed crawlers, you can use this tool. This tool respects the website's robots.txt directive.
You will be surprised how many sites allow all robots, but then block crawlers
Comments URL: https://news.ycombinator.com/item?id=49161193
Points: 1
# Comments: 0
Awesome-FDE-Roadmap
Article URL: https://github.com/pierpaolo28/Awesome-FDE-Roadmap
Comments URL: https://news.ycombinator.com/item?id=49161191
Points: 1
# Comments: 0
How does your agent harness call you
Article URL: https://twitter.com/soztetik/status/2084378696312369236
Comments URL: https://news.ycombinator.com/item?id=49161184
Points: 1
# Comments: 0
I Don't Write Code Anymore. I Have It Written
Article URL: https://aydogan.dev/blog/i-dont-write-code-anymore/
Comments URL: https://news.ycombinator.com/item?id=49161140
Points: 1
# Comments: 0
What different types of typographic scales exist?
Article URL: https://cieden.com/book/sub-atomic/typography/different-type-scale-types
Comments URL: https://news.ycombinator.com/item?id=49161115
Points: 1
# Comments: 0
The Screen Act Threatens Privacy Far Beyond Adult Websites
Article URL: https://www.techdirt.com/2026/08/03/the-screen-act-threatens-privacy-far-beyond-adult-websites/
Comments URL: https://news.ycombinator.com/item?id=49161094
Points: 1
# Comments: 0
The Last Bug on Earth
Article URL: https://www.minid.net/2026/8/3/the-last-bug-on-earth
Comments URL: https://news.ycombinator.com/item?id=49161086
Points: 1
# Comments: 0
Data Integration Without an Ontology
Article URL: https://productnow.ai/blogs/ai-native-data-integration-without-an-ontology
Comments URL: https://news.ycombinator.com/item?id=49161062
Points: 1
# Comments: 0
Retiring the DALL·E GPT
Article URL: https://help.openai.com/en/articles/6825453-chatgpt-release-notes#retiring-the-dalle-gpt
Comments URL: https://news.ycombinator.com/item?id=49161061
Points: 1
# Comments: 0
Forward Deployed Executives: The Next Billion-Dollar AI Unblock
Article URL: https://www.rickmanelius.com/p/forward-deployed-executives-the-next
Comments URL: https://news.ycombinator.com/item?id=49161059
Points: 1
# Comments: 0
DeepSeek-V4-Flash 2.98x faster on 4x B200, lossless
Article URL: https://twitter.com/Akashi203/status/2084373935454400964
Comments URL: https://news.ycombinator.com/item?id=49161056
Points: 2
# Comments: 0
Minimax H3
Article URL: https://huggingface.co/MiniMaxAI/MiniMax-H3
Comments URL: https://news.ycombinator.com/item?id=49161053
Points: 1
# Comments: 0
Token budget circuit breaker – cut multi-agent retry waste ~98%
Article URL: https://github.com/mrblakessinger-rgb/paradox-engine-eots
Comments URL: https://news.ycombinator.com/item?id=49161048
Points: 1
# Comments: 0
No New Name Has Replaced "UX"
Article URL: https://www.nngroup.com/articles/no-new-name-ux/
Comments URL: https://news.ycombinator.com/item?id=49161036
Points: 2
# Comments: 0
