A week in security (February 23 – March 1)
2026-03-04T21:18:54Z•99560376a4e7fa778ca57af8d7e5512c1c7e51beb194a542cb6fda245cc0db52
ai-securityapi-keysbrowser-ratchild-safetyconduentcredential-theftdata-breachexposed-frontendfacebook-adsgoogle-geminimalwaremonitoring-softwareopenclawpassword-managerspassword-securitypayment-card-fraudpersonaphishingprivacyregulatoryscamsteramindthird-party-breachtyposquattingvalleyrat
What happened
Malwarebytes covered a broad set of consumer and enterprise risks (Feb 16–Mar 1, 2026), highlighting active phishing/scam campaigns, credential- and payment-card theft, exposed third-party systems, and privacy/regulatory issues. Notable items: public Google API keys can expose Gemini data; a fake Google security check becomes a browser RAT that harvests contacts/location; typosquatted and fake meeting pages install legitimate monitoring tools (Teramind) or ValleyRAT; Facebook ads distribute fake Windows 11 downloads that steal passwords and crypto wallets; a refund scam impersonating Avast exf
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- malwarebytes_labs
- Record identifier
- 99560376a4e7fa778ca57af8d7e5512c1c7e51beb194a542cb6fda245cc0db52
- Enrichment time
- 2026-03-04T21:18:54Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.