{"id":426198,"date":"2026-10-10T13:38:53","date_gmt":"2026-10-10T13:38:53","guid":{"rendered":"https:\/\/malwaretips.com\/blogs\/?p=426198"},"modified":"2026-10-10T13:38:53","modified_gmt":"2026-10-10T13:38:53","slug":"cmd-tax-update-text-financas-phishing-scam","status":"publish","type":"post","link":"https:\/\/malwaretips.com\/blogs\/cmd-tax-update-text-financas-phishing-scam\/","title":{"rendered":"CMD Tax Update Text Scam: Fake Finan\u00e7as Deadlines Steal Your Private Data"},"content":{"rendered":"<p>A text marked CMD says your tax details need updating before a deadline. It appears beside familiar authentication messages, making the request unusually easy to trust.<\/p><div id=\"mwtad3090404066\" class=\"gas_fallback-ad_309684--placement_406659\" style=\"margin-top: 50px;margin-right: 10px;margin-bottom: 50px;margin-left: 10px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3957935887\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>Before opening that link, look at the task it wants you to complete. The CMD tax update text scam depends on one surprisingly convincing detail.<\/p>\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"1536\" height=\"1024\" src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/10\/cmd-tax-update-text-financas-phishing-scam-illustration.png\" alt=\"Illustration of a fake CMD tax-data update text with a fictional website address\" class=\"wp-image-426199\" title=\"\" srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/10\/cmd-tax-update-text-financas-phishing-scam-illustration.png 1536w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/10\/cmd-tax-update-text-financas-phishing-scam-illustration-300x200.png 300w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/10\/cmd-tax-update-text-financas-phishing-scam-illustration-1024x683.png 1024w\" sizes=\"auto, (max-width: 1536px) 100vw, 1536px\" \/><\/figure>\n<div id=\"mwtad3099025068\" class=\"gas_fallback-ad_309746-ad_309685-placement_406660\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"4456629336\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Overview<\/h2>\n<h3>The CMD label is being used to disguise tax phishing<\/h3>\n<p>These tax-update texts are a confirmed impersonation scam. Criminals borrow the name of Portugal&#8217;s Chave M\u00f3vel Digital to send people toward counterfeit government-looking websites.<\/p><div id=\"mwtad3062450345\" class=\"gas_fallback-ad_381396-ad_309685-placement_406667\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"1471373341\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>Neither CMD nor Portugal&#8217;s tax authority is running the deception. The fraud is the message and the website pretending to speak for them.<\/p>\n<p>The <a href=\"https:\/\/www.gov.pt\/noticias\/tentativa-de-fraude-por-sms-em-nome-da-autoridade-tributaria-e-da-chave-movel-digital-cmd\" target=\"_blank\" rel=\"noopener\">official September 24, 2026 warning<\/a> identifies short update deadlines and addresses designed to resemble tax-administration services.<\/p>\n<p>Depending on the page, the requested information can include personal details, banking information, or access codes. The official warning does not establish every field in every version.<\/p><div id=\"mwtad487395700\" class=\"gas_fallback-ad_309686-ad_309685-placement_406668\" style=\"margin-top: 50px;margin-right: 10px;margin-bottom: 50px;margin-left: 10px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"6935453015\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>The illustration above uses a fictional address to show the message&#8217;s basic shape. It is not an original victim&#8217;s text or a working phishing link.<\/p>\n<h3>A familiar conversation can contain an unfamiliar sender<\/h3>\n<p>The particularly misleading feature is placement. A fraudulent message using CMD as its sender can appear in the same conversation as genuine authentication codes.<\/p>\n<p>Seeing older legitimate messages above it can make the new request feel checked already. Your phone&#8217;s grouping does not authenticate the person who sent that request.<\/p><div id=\"mwtad1320689110\" class=\"gas_fallback-ad_381401-ad_309685-placement_406669\" style=\"margin-top: 50px;margin-right: 10px;margin-bottom: 50px;margin-left: 10px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"5315249587\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>This distinction matters because you may normally treat that conversation as a trusted place. The attacker benefits from trust established by someone else.<\/p>\n<p>There is no need to assume the government service was breached. A familiar sender label alone does not establish that anyone accessed your CMD account.<\/p>\n<div id=\"mwtad2894682194\" class=\"gas_fallback-ad_381404-ad_309685-placement_406670\" style=\"margin-top: 50px;margin-right: 10px;margin-bottom: 50px;margin-left: 10px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"8735619847\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><p>Judge the new message by its destination and demand. An existing conversation does not give a new website permission to collect private information.<\/p>\n<h3>The safest check happens outside the message<\/h3>\n<p>Use a route you choose yourself to inspect your tax situation. The suspicious SMS should not decide where you sign in or which information you disclose.<\/p>\n<ul>\n<li>A deadline in a text is a claim to verify, not an instruction to obey immediately.<\/li>\n<li>Words such as gov or Autoridade Tribut\u00e1ria inside an address do not make it an official government domain.<\/li>\n<li>CMD codes, passwords, and Citizen Card PINs are sensitive credentials, even when a form describes them as routine verification.<\/li>\n<li>A convincing logo cannot tell you who controls the page receiving your information.<\/li>\n<li>If banking details were entered, contact the bank promptly rather than waiting for the supposed update to finish.<\/li>\n<\/ul>\n<div id=\"mwtad2472361089\" class=\"gas_fallback-ad_309747-ad_309685-placement_406661\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"9589536513\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Why a Tax Deadline Creates Such Effective Pressure<\/h2>\n<p>The message does not need an extravagant promise. It presents a dull administrative task, exactly the kind of thing people often complete quickly and move past.<\/p>\n<p>Tax matters also bring uncertainty. You may wonder whether an address, phone number, or document has become outdated without realizing it.<\/p>\n<p>A short deadline turns that uncertainty into a problem that seems easier to solve than investigate. Opening the link appears to be the efficient choice.<\/p>\n<p>That is the useful pause: you do not yet know that a task exists. You only know that an unsolicited message says it does.<\/p>\n<p>There is a difference between checking your tax account and complying with a text. Checking begins with your own access route and the actual account information.<\/p>\n<p>Compliance begins with the sender&#8217;s link, then accepts whatever explanation the resulting page supplies. The scam tries to make those two activities feel interchangeable.<\/p>\n<p>Even someone expecting a tax notification can receive an unrelated fake. Timing can make a message plausible without proving that it belongs to their case.<\/p>\n<p>The same goes for a message addressed to a taxpayer. That broad description fits many recipients and should not be mistaken for evidence of personal knowledge.<\/p>\n<div id=\"mwtad2707568893\" class=\"gas_fallback-ad_309748-ad_309685-placement_406662\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3906789406\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>How the CMD Tax Update Text Scam Works<\/h2>\n<h3>Step 1: The SMS creates an unfinished administrative task<\/h3>\n<p>The opening request tells you to update personal information. In the reported September samples, dates make the request appear to have an approaching or recently missed deadline.<\/p>\n<p>The text provides a direct link, so the reader does not have to search for the relevant office. Convenience becomes part of the persuasion.<\/p>\n<p>At this stage, no authentic account record has confirmed the requirement. The entire reason for acting comes from the same message offering the shortcut.<\/p>\n<p>Do not try to settle that uncertainty by replying. A response stays inside the communication route whose identity is already in doubt.<\/p>\n<h3>Step 2: The name CMD supplies borrowed credibility<\/h3>\n<p>CMD is associated with digital identification, so its name can make a tax-related instruction appear connected to an official authentication process.<\/p>\n<p>A recipient who has previously used the service may recognize the conversation instantly. Recognition happens before the website address receives much attention.<\/p>\n<p>The safest response is to treat each new demand separately. Old genuine codes say nothing about whether a later message is entitled to request more information.<\/p>\n<p>Do not forward a screenshot containing those old codes to friends or public forums. You can describe the suspicious request without exposing unrelated authentication history.<\/p>\n<h3>Step 3: The address imitates the tax authority<\/h3>\n<p>The official warning lists autoridadetributariagov[.]com and portal-autoridade-tributariagovpt[.]online\/at\/ as deceptive destinations. These are campaign indicators, shown here in a non-clickable form.<\/p>\n<p>They contain familiar institution words, but that wording is part of the address chosen by the operator. It is not a government endorsement.<\/p>\n<p>A longer address can be especially distracting on a small screen. The recognizable beginning receives attention while the domain ending is overlooked.<\/p>\n<p>You do not need to become a domain investigator to avoid this route. Open the official service independently and look for the alleged requirement there.<\/p>\n<h3>Step 4: The supposed update becomes a disclosure<\/h3>\n<p>A copied page can frame each field as necessary to complete your record. That explanation does not establish why the recipient needs the information.<\/p>\n<p>Stop when an unexpected process begins asking for account credentials, codes, or banking details. More fields do not make the original claim more trustworthy.<\/p>\n<p>Submitting some information can create a feeling that you should finish. Resist that pull. Additional disclosures can expand the problem without resolving the first one.<\/p>\n<p>A final confirmation screen, success message, or error cannot reliably tell you whether information was retained. Explain what you entered when seeking help.<\/p>\n<h3>Step 5: The exposed information determines the next risk<\/h3>\n<p>A phone number creates different concerns from a banking password. An authentication code creates different concerns from an address. Your response should follow the actual disclosure.<\/p>\n<p>Personal details may make later contacts sound more convincing. Treat an unexpected caller quoting those details as another contact to verify, not automatic support.<\/p>\n<p>If you disclosed credentials, do not wait for visible misuse before protecting the affected service. Ask its real support team what controls require attention.<\/p>\n<p>None of this proves that every recipient loses money or has their identity stolen. It explains why the information request itself deserves immediate action.<\/p>\n<div id=\"mwtad294719209\" class=\"gas_fallback-ad_318930-ad_309685-placement_406663\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3818335085\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>How to Check the Tax Request Without Feeding the Scam<\/h2>\n<p>Close the message route and type the official Portal das Finan\u00e7as address yourself. Use an established bookmark if you already know it points to the right site.<\/p>\n<p>Read the actual notices in your account. Compare the subject, requested action, and any case details with the SMS without entering information into its linked page.<\/p>\n<p>If there is a real tax issue, address it through that official session. A real issue does not validate the separate instructions sent by an impostor.<\/p>\n<p>If you cannot find the alleged requirement, contact the authority using contact details obtained independently. Avoid numbers or support buttons supplied only by the suspicious message.<\/p>\n<p>Checking the address means reading the domain, not merely finding a familiar word. An official name in a page heading can be typed by anyone.<\/p>\n<p>Encrypted connections are also a separate matter. A secure connection to the wrong operator still delivers your information to the wrong operator.<\/p>\n<p>Do not enter a false password to experiment with the form. Testing keeps you on an untrusted page and gives no useful guarantee about its behavior.<\/p>\n<p>Similarly, a page that no longer loads does not authenticate the earlier message. Websites can disappear after sending many recipients through them.<\/p>\n<h2>What to Do if You Have Fallen Victim to This Scam<\/h2>\n<ol>\n<li>\n<p><strong>Write down exactly what you disclosed.<\/strong> Separate personal details, passwords, card information, CMD codes, Citizen Card PINs, and any approvals you made.<\/p>\n<p>Record the approximate time and the address shown. An accurate account of the interaction helps support staff choose the right protection steps.<\/p>\n<\/li>\n<li>\n<p><strong>Protect financial access first when it was exposed.<\/strong> Reach your bank through its normal app, a trusted number, or another established channel.<\/p>\n<p>Explain whether you entered card details, banking credentials, or approved an action. Ask about blocking affected access, reviewing transactions, and handling suspicious payments.<\/p>\n<p>If money moved, give the amount, time, and payment route. Ask what can still be stopped or investigated without expecting a guaranteed reversal.<\/p>\n<\/li>\n<li>\n<p><strong>Change exposed passwords through the genuine service.<\/strong> Leave the phishing page before doing this. A replacement password should never be entered into the same untrusted form.<\/p>\n<p>Check other accounts only if they use the exposed password. Prioritize email when it shares that password because it may control account recovery elsewhere.<\/p>\n<\/li>\n<li>\n<p><strong>Get specific help for CMD or Citizen Card exposure.<\/strong> Tell the official support team whether a PIN, code, or approval was involved.<\/p>\n<p>The <a href=\"https:\/\/www.autenticacao.gov.pt\/perguntas-frequentes\" target=\"_blank\" rel=\"noopener\">official authentication help page<\/a> provides Citizen Contact Centre details. Use the current published contacts to discuss the appropriate account response.<\/p>\n<p>Do not assume changing an unrelated website password protects a disclosed authentication code. Different services require different controls.<\/p>\n<\/li>\n<li>\n<p><strong>Keep a useful copy of the suspicious message.<\/strong> Save the new text, sender label, link, and any relevant transaction confirmation before removing it.<\/p>\n<p>Keep private copies of sensitive records. If sharing evidence publicly, conceal personal details and genuine codes from older messages in the conversation.<\/p>\n<\/li>\n<li>\n<p><strong>Report the impersonation using official routes.<\/strong> Portugal&#8217;s <a href=\"https:\/\/www.gov.pt\/informacoes-e-ajuda\/burlas-e-sms-fraudulentas-em-nome-de-chave-movel-digital-gov-pt-ou-autenticacao-gov\" target=\"_blank\" rel=\"noopener\">government fraud guidance<\/a> lists police and other complaint channels.<\/p>\n<p>Explain the deceptive request and your response. A report is more useful when it identifies the actual link and exposure rather than only saying CMD contacted you.<\/p>\n<\/li>\n<li>\n<p><strong>Check the device if the interaction went beyond viewing.<\/strong> If you installed software or noticed unexpected behavior, investigate that separately from account protection.<\/p>\n<p>Malwarebytes can assist with a device scan when needed. AdGuard can reduce exposure to some unwanted advertising and known malicious destinations, but cannot undo disclosed credentials.<\/p>\n<\/li>\n<li>\n<p><strong>Reject follow-up offers to recover the account through another link.<\/strong> Continue with the support channels you opened yourself, particularly if someone demands a code or payment.<\/p>\n<p>A person knowing your earlier interaction is not automatically an investigator. Ask the genuine institution to verify the contact through its own records.<\/p>\n<\/li>\n<\/ol>\n<h2>If You Clicked but Did Not Enter Anything<\/h2>\n<p>Close the page and do not return to finish an update. Review whether the browser downloaded a file, requested notification permission, or prompted an installation.<\/p>\n<p>Opening a page is not the same as surrendering an account password. Avoid treating every click as proof that your bank or digital identity was taken over.<\/p>\n<p>If you did type information, include it in your exposure note even when you stopped before the final button. Some pages may handle input before completion.<\/p>\n<p>If you are unsure what happened, say so to support. Uncertainty is useful information; guessing that everything was safe can hide an action that needs attention.<\/p>\n<p>You can also warn relatives about the exact request. Explain that a familiar CMD conversation may contain a fraudulent tax-update text, rather than forwarding its active link.<\/p>\n<p>For someone less comfortable with online tax services, help them reach the official account. Do not ask them to read authentication codes aloud while following unsolicited instructions.<\/p>\n<h2>Frequently Asked Questions<\/h2>\n<h3>Is Chave M\u00f3vel Digital itself a scam?<\/h3>\n<p>No. CMD is a real Portuguese authentication service. This article concerns criminals impersonating that service and the tax authority through false texts and websites.<\/p>\n<h3>Can the fake text appear beside real CMD codes?<\/h3>\n<p>Yes. The official warning specifically describes that possibility. A familiar conversation layout does not authenticate the new message or the address it contains.<\/p>\n<h3>Does a deadline mean my tax account is in trouble?<\/h3>\n<p>The text alone does not establish that. Inspect your tax account through the official portal or contact the authority independently before acting on the claim.<\/p>\n<h3>Is an address containing gov automatically official?<\/h3>\n<p>No. Read the complete domain and use the genuine Portuguese government route. Words inside a lookalike address are not proof of the operator&#8217;s identity.<\/p>\n<h3>What should I do after giving a CMD code?<\/h3>\n<p>Stop following the message and contact official authentication support promptly. Explain the code and any related approvals; involve your bank if financial access was also exposed.<\/p>\n<h3>Can deleting the text remove the information I submitted?<\/h3>\n<p>No. Removing the message stops it remaining in your inbox, but does not retrieve data already disclosed. Protect the affected service and keep necessary evidence first.<\/p>\n<h2>The Bottom Line<\/h2>\n<p>The CMD tax update text scam uses a familiar identity label to make a false administrative task feel routine. Your phone&#8217;s message grouping is its strongest disguise.<\/p>\n<p>Check the requirement through the real tax portal. If you already supplied information, protect the specific accounts or credentials involved and report the impersonation.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A text marked CMD says your tax details need updating before a deadline. It appears beside familiar authentication messages, making the request unusually easy to trust. Before opening that link, look at the task it &#8230; <\/p>\n<p class=\"read-more-container\"><a title=\"CMD Tax Update Text Scam: Fake Finan\u00e7as Deadlines Steal Your Private Data\" class=\"read-more button\" href=\"https:\/\/malwaretips.com\/blogs\/cmd-tax-update-text-financas-phishing-scam\/#more-426198\" aria-label=\"Read more about CMD Tax Update Text Scam: Fake Finan\u00e7as Deadlines Steal Your Private Data\">Read more<\/a><\/p>\n","protected":false},"author":51,"featured_media":426199,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[49],"tags":[],"class_list":["post-426198","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-scam-reports","masonry-post","generate-columns","tablet-grid-50","mobile-grid-100","grid-parent","grid-50","resize-featured-image"],"_links":{"self":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/426198","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/users\/51"}],"replies":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/comments?post=426198"}],"version-history":[{"count":1,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/426198\/revisions"}],"predecessor-version":[{"id":426200,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/426198\/revisions\/426200"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media\/426199"}],"wp:attachment":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media?parent=426198"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/categories?post=426198"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/tags?post=426198"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}