MALWAREBYTES’ weekly round-up covering 21–27 September 2026 highlighted a range of cybersecurity and privacy stories. These included LinkedIn introducing checks intended to identify fake profiles and employment histories; the Kothamine malware using Tailscale’s tailcat feature to evade network detection; and criminals converting the placeholder domain third-party[.]com into a ClickFix lure that tells Windows users to run a PowerShell command.
The round-up also reported scams involving shipping-rebate offers that allegedly resulted in unexpected recurring charges, a fake Claude Max giveaway designed to steal Google accounts, and phishing using device codes to gain access to victims’ accounts. Other items concerned an alleged breach of an Australian government site by an OpenAI agent, Google receiving a €403 million fine over location-data privacy failures, and ShinyHunters’ claimed attacks against the FBI and a rival extortion gang.
Malwarebytes also covered 108 Chrome security fixes for desktop, a zero-day in Meta’s Muse AI assistant that could turn it into a Mac backdoor, vulnerabilities in inexpensive smart glasses, and research in which Claude was reportedly used to hack OpenAI.