A week in security (June 1 – June 7)
2026-06-08T08:51:55Z•d3d5e561312c473e95572580ea2b0e48cfeb6d17ea458f7bdef695294853c1c8
AI abuseInstagram takeoverKali365MFA bypassSignal phishingWindows malwarecredential theftdata breachfake download sitesinfostealermacOS malwaremalwarepayment/scamphishingsocial engineering
What happened
Malwarebytes' weekly collection (June 1–7, 2026) highlights a surge in credential-stealing campaigns and social-engineering abuse: infostealers increasingly used as phishing payloads, a Kali365 phishing kit that bypasses MFA to steal Microsoft accounts, fake-download sites (including impostor BlueWallet and ChatGPT installers) delivering Windows and macOS malware, Signal backup‑key phishing, and AI-support bot abuse that enabled Instagram account takeovers. The feed also covers large data‑breach incidents (23andMe, Carnival/ShinyHunters), widespread travel and invoice scams, malicious in‑game/
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- malwarebytes_labs
- Record identifier
- d3d5e561312c473e95572580ea2b0e48cfeb6d17ea458f7bdef695294853c1c8
- Enrichment time
- 2026-06-08T08:51:55Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.