A week in security (March 2 – March 8)
2026-03-09T08:52:00Z•30bcdb400859991cbf95c84dad878d0ce193ce329a057120b189bc41c240b26f
AndroidChromeCleanMyMacFileZillaGeminiOAuth-abuseOpenClawQualcommSHub StealerTeramindWindowsbrowser-RATcrypto-wallet-backdoordevice-managementfake-installersmacOSmalwarepatchesphishingsupply-chainvulnerability
What happened
Malwarebytes Labs published a weekly security roundup (Mar 2–8, 2026) and multiple threat-intel reports covering widespread malicious campaigns and recently patched vulnerabilities. Key findings include: a fake Google Meet update that enrolls Windows machines into an attacker-controlled device management system; fake installers (OpenClaw, FileZilla, CleanMyMac) distributing malware and backdooring macOS crypto wallets with SHub Stealer; phishing campaigns and OAuth abuse that redirect legitimate login flows to phishing or malware; a browser RAT disguised as a Google security check that harvest
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- malwarebytes_labs
- Record identifier
- 30bcdb400859991cbf95c84dad878d0ce193ce329a057120b189bc41c240b26f
- Enrichment time
- 2026-03-09T08:52:00Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.