A week in security (March 2 – March 8)

2026-03-09T08:52:00Z30bcdb400859991cbf95c84dad878d0ce193ce329a057120b189bc41c240b26f
AndroidChromeCleanMyMacFileZillaGeminiOAuth-abuseOpenClawQualcommSHub StealerTeramindWindowsbrowser-RATcrypto-wallet-backdoordevice-managementfake-installersmacOSmalwarepatchesphishingsupply-chainvulnerability

What happened

Malwarebytes Labs published a weekly security roundup (Mar 2–8, 2026) and multiple threat-intel reports covering widespread malicious campaigns and recently patched vulnerabilities. Key findings include: a fake Google Meet update that enrolls Windows machines into an attacker-controlled device management system; fake installers (OpenClaw, FileZilla, CleanMyMac) distributing malware and backdooring macOS crypto wallets with SHub Stealer; phishing campaigns and OAuth abuse that redirect legitimate login flows to phishing or malware; a browser RAT disguised as a Google security check that harvest

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
malwarebytes_labs
Record identifier
30bcdb400859991cbf95c84dad878d0ce193ce329a057120b189bc41c240b26f
Enrichment time
2026-03-09T08:52:00Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.