A week in security (August 31 – September 6)

2026-09-07T08:51:46Z2e999d46f8d7d5a91475bc0d057ab3002eb201a54c77aff29cb8ca3c8ef044a8
Android malwareChrome vulnerabilitiesClaudeClickFixIoT securityShinyHuntersStreamRatTerminalFixbanking trojancrypto scamcryptocurrency theftdark webdata breachhealthcareidentity data theftinfostealermalvertisingmalwarepassword-reset attackphishingremote code executionresidential proxiessession cookie theftsocial mediastreaming devices

What happened

Malwarebytes Labs coverage for August 31–September 6, 2026 highlights active cyber threats including StreamRat Android banking malware distributed through social-media advertising, Chrome remote-code-execution vulnerabilities, ClickFix-style TerminalFix campaigns, infostealer theft of Claude session cookies, cryptocurrency wallet-draining scams, residential proxy abuse through streaming devices, password-reset phishing, major data-breach claims, and evolving tech-support scams. The collection also includes privacy, AI-security, and defensive guidance topics.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
malwarebytes_labs
Record identifier
2e999d46f8d7d5a91475bc0d057ab3002eb201a54c77aff29cb8ca3c8ef044a8
Enrichment time
2026-09-07T08:51:46Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.