A week in security (September 21 – September 27)
Cybersecurity Classified by Officially
Last week on Malwarebytes Labs:
- LinkedIn adds new checks for fake profiles and work histories
- Kothamine malware uses Tailscale’s tailcat to evade network detection
- Criminals turn placeholder domain into ClickFix trap
- That shipping rebate offer may come with a monthly charge
- OpenAI agent breached Australian government site, took months to report it
- New Browser Guard features add protection before and after you click
- Update Chrome: 108 security fixes for desktop, new release for Android
- Google’s location data privacy failures draw a €403 million fine
- How device code phishing gives scammers access to your account
- Fake Claude Max giveaway hides a Google account phishing trap
- ShinyHunters claims FBI breach was revenge for “false” report
- Some cheap smart glasses are a security disaster
- Meta’s Muse AI assistant has a zero-day that can turn it into a Mac backdoor
- Researchers used Claude to hack OpenAI
- The AI plot to scan and destroy books (Lock and Code S07E19)
- The fake sites using a cheap toolkit to sell $2,000 AI subscriptions
- Gemini’s breach of real companies exposes an AI guardrail problem
- ShinyHunters hacks rival extortion gang and takes over its dark web site
Stay safe!
From reporting threats to removing them.
This is an extract. The publication continues at the source.
Read the original at the source: https://www.malwarebytes.com/blog/news/2026/09/a-week-in-security-september-21-september-27
Officially imported this from Malwarebytes’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.
Provenance
- Organization
- Malwarebytes — imported from official source
- Official source
- https://www.malwarebytes.com/blog/feed/index.xml RSS
- Imported
- September 28, 2026 08:00
- Versions
- 1 recorded
- Identity
https://www.malwarebytes.com/blog/news/2026/09/a-week-in-security-september-21-septembe...