A week in security (September 14 – September 20)

2026-09-21T08:51:45Z•85290b7163d5811f20121c1e105b088e4532844e38e8a1b657787a76c56f608a
AI-assisted scamsAndroid malwareBlueMoonChrome vulnerabilitiesGigabudGoogle PixelRatHatWindows vulnerabilitiesaccount hijackingactively exploited vulnerabilitybanking trojancredential theftcryptocurrency scamsdata breachdeepfakesexploit kitfinancial fraudinformation stealerphishingsmishing

What happened

Malwarebytes Labs’ September 14–20, 2026 coverage highlights active cyber threats including Android banking malware, phishing and smishing campaigns, account hijacking, data breaches, exploit-kit activity, actively exploited mobile vulnerabilities, information stealers, cryptocurrency scams, and AI-assisted fraud. Notable items include RatHat stealing banking credentials and PINs, Gigabud hiding cloned banking apps, BlueMoon exploiting patched Chrome and Windows flaws, and a Google Pixel modem vulnerability used in targeted attacks.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
malwarebytes_labs
Record identifier
85290b7163d5811f20121c1e105b088e4532844e38e8a1b657787a76c56f608a
Enrichment time
2026-09-21T08:51:45Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · A week in security (September 14 – September 20) · Baitaphish