{"id":398662,"date":"2026-08-02T04:07:03","date_gmt":"2026-08-02T04:07:03","guid":{"rendered":"https:\/\/malwaretips.com\/blogs\/?p=398662"},"modified":"2026-08-02T04:07:03","modified_gmt":"2026-08-02T04:07:03","slug":"new-device-signed-in-email-scam-fake-security-alert-steals-your-password","status":"publish","type":"post","link":"https:\/\/malwaretips.com\/blogs\/new-device-signed-in-email-scam-fake-security-alert-steals-your-password\/","title":{"rendered":"New Device Signed In Email Scam: Fake Security Alert Steals Your Password"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\"><strong>An email warns that a new device just signed in to your account. The red REPORT ACTIVITIES button feels like the fastest way to stop an intruder, but it opens a fake login built to steal your password.<\/strong><\/p><div id=\"mwtad1750307327\" class=\"gas_fallback-ad_309684--placement_360520\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3957935887\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">This is a confirmed phishing campaign, not a genuine security alert. Check account activity through the provider&#8217;s official app or website, never through the email button.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" width=\"1536\" height=\"1024\" src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/new-device-signed-in-email-scam.png\" alt=\"Fake new-device sign-in email leading to a counterfeit email login page\" class=\"wp-image-398654\" title=\"\" srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/new-device-signed-in-email-scam.png 1536w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/new-device-signed-in-email-scam-300x200.png 300w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/new-device-signed-in-email-scam-1024x683.png 1024w\" sizes=\"(max-width: 1536px) 100vw, 1536px\" \/><figcaption class=\"wp-element-caption\">The fake alert turns fear about an unfamiliar sign-in into a request for the victim&#8217;s email password.<\/figcaption><\/figure>\n\n\n\n<div id=\"mwtad1185113002\" class=\"gas_fallback-ad_309746-ad_309691-placement_360521\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"4456629336\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2 class=\"wp-block-heading\">Overview<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The New Device Signed In To Your Account email scam impersonates an email provider&#8217;s security system. One version arrives with the subject <strong>\u201cSign in from a new device\u201d<\/strong> and claims that an unfamiliar computer has accessed the recipient&#8217;s mailbox.<\/p><div id=\"mwtad1342070385\" class=\"gas_fallback-ad_381396-ad_309691-placement_360566\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"1471373341\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">The message says no action is needed if the sign-in was recognized. If it was not, the recipient is told to click <strong>REPORT ACTIVITIES<\/strong>. That wording mimics a legitimate security workflow while pushing the victim toward the attacker&#8217;s link.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The button leads to a phishing page hosted at <strong>usc1.contabostorage[.]com<\/strong>, an unrelated cloud-storage address. The page places a counterfeit login form over an imitation email homepage and requests an email address and password.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The form was labeled <strong>\u201cgmail Portal,\u201d<\/strong> indicating that Gmail users were among the targets. Similar kits can adapt their appearance after reading the submitted email address, showing different branding for different providers.<\/p><div id=\"mwtad2874448841\" class=\"gas_fallback-ad_309686-ad_309691-placement_360569\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"6935453015\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">Credentials entered on the page are collected by the scammers. A compromised mailbox can expose private conversations, password-reset links, cloud files, invoices and contacts. It can also become the launch point for phishing messages that appear to come from a trusted person.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Reading the alert does not compromise the account. Opening the linked page also does not automatically hand over a password. The damage begins when credentials or one-time codes are submitted, a login approval is accepted or an unexpected download is run.<\/p>\n\n\n\n<div id=\"mwtad48186133\" class=\"gas_fallback-ad_309747-ad_309691-placement_360587\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"9589536513\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2 class=\"wp-block-heading\">How the Fake New-Device Alert Works<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">Step 1: The email creates an account emergency<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The recipient is told that a device has signed in for the first time. Because genuine providers send similar warnings, the claim can feel immediately believable.<\/p><div id=\"mwtad1723200524\" class=\"gas_fallback-ad_381401-ad_309691-placement_360573\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"5315249587\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n\n\n\n<h3 class=\"wp-block-heading\">Step 2: The message offers one urgent response<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">A large REPORT ACTIVITIES button appears to be the only way to protect the account. Fear reduces the chance that the recipient will inspect the sender or link.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Step 3: The button leaves the real provider<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Instead of opening the provider&#8217;s security page, the link goes to third-party cloud storage. Hosting infrastructure can be legitimate while the user-created content on it is malicious.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Step 4: A fake sign-in form copies the provider<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The phishing kit imitates an email portal and requests credentials. The page design can change to match the address entered, but the browser domain remains unrelated.<\/p><div id=\"mwtad4135626307\" class=\"gas_fallback-ad_381404-ad_309691-placement_381406\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"8735619847\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n\n\n\n<h3 class=\"wp-block-heading\">Step 5: The attackers test the stolen credentials<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Scammers may sign in immediately, trigger multi-factor prompts or ask the victim for a one-time code. Reused passwords can also be tested against other services.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Step 6: The mailbox is turned into a fraud tool<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Attackers can create forwarding rules, reset accounts and message contacts. Business inboxes are especially valuable because they contain invoices and trusted supplier conversations.<\/p>\n\n\n\n<div id=\"mwtad4148620442\" class=\"gas_fallback-ad_309748-ad_309691-placement_360588\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3906789406\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2 class=\"wp-block-heading\">Warning Signs in the Email<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>An unexpected security alert<\/strong> with no matching notification in the official account.<\/li>\n\n\n<li><strong>A vague sender identity<\/strong> that does not use the provider&#8217;s real domain.<\/li>\n\n\n<li><strong>A panic-driven button<\/strong> labeled REPORT ACTIVITIES instead of a clear account-security link.<\/li>\n\n\n<li><strong>A cloud-storage destination<\/strong> unrelated to the email provider.<\/li>\n\n\n<li><strong>A generic login form<\/strong> requesting credentials outside the provider&#8217;s normal site.<\/li>\n\n\n<li><strong>Awkward labels<\/strong> such as \u201cgmail Portal\u201d or inconsistent capitalization.<\/li>\n\n\n<li><strong>A request for a one-time code<\/strong> after the supposed security report begins.<\/li>\n<\/ul>\n\n\n\n<div id=\"mwtad3598479723\" class=\"gas_fallback-ad_318930-ad_309691-placement_360589\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3818335085\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2 class=\"wp-block-heading\">How to Check Whether a Sign-In Is Real<\/h2>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Open the email provider&#8217;s official app directly.<\/li>\n\n\n<li>Type the provider&#8217;s website address into a new browser tab.<\/li>\n\n\n<li>Review recent devices and security activity inside account settings.<\/li>\n\n\n<li>Sign out unfamiliar sessions from the official security page.<\/li>\n\n\n<li>Change the password only after reaching the account independently.<\/li>\n\n\n<li>Do not reply to the warning or use links and phone numbers inside it.<\/li>\n<\/ol>\n\n\n\n<div id=\"mwtad3453949607\" class=\"gas_fallback-ad_381388-ad_309691-placement_381390\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3191649120\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2 class=\"wp-block-heading\">What to Do After Receiving the Fake Alert<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">If you only read the email<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Report it as phishing and delete it. Reading the message does not expose your password.<\/p><div id=\"mwtad199231779\" class=\"gas_fallback-ad_360582-ad_309691-placement_360581\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"9971336976\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n\n\n\n<h3 class=\"wp-block-heading\">If you opened the page but entered nothing<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Close the tab and check the browser&#8217;s download list. Delete unexpected downloads without opening them. Your password usually does not need changing solely because the page loaded.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">If you entered your password<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Secure the mailbox from a clean device immediately. Attackers can create hidden access even if no suspicious sent messages are visible.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Change the password.<\/strong> Use a unique password never used on another site.<\/li>\n\n\n<li><strong>Revoke active sessions.<\/strong> Sign out all devices and remove unfamiliar entries.<\/li>\n\n\n<li><strong>Enable strong multi-factor authentication.<\/strong> Prefer an authenticator app or security key.<\/li>\n\n\n<li><strong>Check recovery information.<\/strong> Remove unknown phone numbers and secondary emails.<\/li>\n\n\n<li><strong>Delete unauthorized forwarding rules and filters.<\/strong> Inspect every rule, not only the inbox.<\/li>\n\n\n<li><strong>Revoke app passwords and connected applications.<\/strong> Remove services you do not recognize.<\/li>\n\n\n<li><strong>Review sent, deleted and archived messages.<\/strong> Warn contacts if the account sent phishing.<\/li>\n\n\n<li><strong>Reset reused passwords.<\/strong> Start with banking, shopping, cloud and social accounts.<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">If you approved a sign-in or shared a one-time code<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Revoke the new session immediately and reset both the password and multi-factor settings. A valid code or approval can let the attacker establish a trusted session even after the visible password is changed.<\/p><div id=\"mwtad397772151\" class=\"gas_fallback-ad_360567-ad_309691-placement_360771\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"6224621518\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n\n\n\n<h3 class=\"wp-block-heading\">If the mailbox belongs to a business<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Notify IT or the email administrator. They should review sign-in logs, OAuth grants, mailbox delegates, transport rules and messages sent from the account. Finance teams should inspect recent payment conversations for tampering.<\/p>\n\n\n\n<div id=\"mwtad2804779799\" class=\"gas_fallback-ad_381392-ad_309691-placement_381395\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"2944237110\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2 class=\"wp-block-heading\">Frequently Asked Questions<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">Was a new device actually signed in?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The email itself does not prove that. Check the provider&#8217;s official security dashboard directly. The campaign described here invents the alert to steal credentials.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Is contabostorage.com my email provider?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">No. It is cloud-storage infrastructure, not the genuine login domain for Gmail or another major mailbox provider. Scammers can abuse third-party hosting to publish phishing pages.<\/p><div id=\"mwtad729407991\" class=\"gas_fallback-ad_360571-ad_309691-placement_360772\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"5867729999\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n\n\n\n<h3 class=\"wp-block-heading\">Can the page steal my password without me typing it?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The observed phishing form needs credentials to be submitted. The page may still track visits or attempt downloads, so close it and do not interact.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Why do I receive genuine-looking security alerts?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Phishing kits copy the visual language and wording of real providers. The sender domain, destination address and independent account activity are more reliable than the page design.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">The Bottom Line<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The New Device Signed In email is a fake security alert designed to cause a real account takeover.<\/strong> Ignore its REPORT ACTIVITIES button, open the provider independently and secure the mailbox immediately if you entered a password or approved a login.<\/p><div id=\"mwtad2163887544\" class=\"gas_fallback-ad_360576-ad_309691-placement_360773\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"6594472392\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>A fake New Device Signed In email sends recipients to a counterfeit login page hosted on cloud storage. Learn how the phishing alert works and what to do.<\/p>\n","protected":false},"author":50,"featured_media":398654,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"ai_generated_summary":"","footnotes":""},"categories":[2839,2842],"tags":[],"class_list":["post-398662","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-scam-emails","category-impersonation-scams","masonry-post","generate-columns","tablet-grid-50","mobile-grid-100","grid-parent","grid-50","resize-featured-image"],"_links":{"self":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/398662","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/users\/50"}],"replies":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/comments?post=398662"}],"version-history":[{"count":3,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/398662\/revisions"}],"predecessor-version":[{"id":398672,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/398662\/revisions\/398672"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media\/398654"}],"wp:attachment":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media?parent=398662"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/categories?post=398662"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/tags?post=398662"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}