An OpenAI agent bypassed internet restrictions and kept running after an alert. It’s another case of AI misalignment no one can afford to ignore.
Category: Malwarebytes
FBI agents’ blood tests and doctors’ notes surface after breach
A “shellfish and banana allergy” is among the details in medical records hackers showed reporters. They claim to hold records on thousands of FBI staff.
A week in security (September 21 – September 27)
A list of topics we covered in the week of September 21 to September 27 of 2026
Kothamine malware uses Tailscale’s tailcat to evade network detection
Kothamine uses a legitimate Tailscale tool to receive attackers’ commands through an encrypted connection with no malicious domain to block.
LinkedIn adds new checks for fake profiles and work histories
The platform is adding new checks as AI makes profiles easier to forge. But scammers can still invent a company to recruit for.
Criminals turn placeholder domain into ClickFix trap
A domain used in software examples—third-party[.]com—now serves up a fake verification page that tells Windows users to run a PowerShell command.
That shipping rebate offer may come with a monthly charge
Customers say they signed up for shipping rebates, then found recurring charges they didn’t expect.
Meta’s Muse AI assistant has a zero-day that can turn it into a Mac backdoor
A simple terminal command can hijack Muse and use its extensive permissions to spy on Mac users and control their connected accounts.
Researchers used Claude to hack OpenAI
Claude helped researchers break into OpenAI in under 72 hours, and exposed how quickly AI is lowering the bar for sophisticated hacking.
OpenAI agent breached Australian government site, took months to report it
The agent was looking for public spending data. It found a way into non-public files instead. What do we need to change to stop this from happening?
OpenAI agent breached Medicare statistics site, then took months to report it
The agent was looking for public spending data. It found a way into non-public files instead. What do we need to change to stop this from happening?
New Browser Guard features add protection before and after you click
Spot dangerous sites before you click—and check for scams once you’re there.
Update Chrome: 108 security fixes for desktop, new release for Android
Google has released Chrome 154 for desktop and begun rolling out Chrome 155 for Android. Here’s what to check on your device.
Google’s location data privacy failures draw a €403 million fine
Turning off Location History did not necessarily stop Google from recording where users went. Ireland’s privacy regulator has now fined the company €403…
ShinyHunters hacks rival extortion gang and takes over its dark web site
Hackers hacked the hackers as a feud between two cybercrime groups escalated, leaving ShinyHunters with the upper hand over rival Clop.
How device code phishing gives scammers access to your account
A scammer asks you to enter a code to open a file or join a meeting. Approving it could sign them in to your account instead.
A week in security (September 14 – September 20)
A list of topics we covered in the week of September 14 to September 20 of 2026
Fake Claude Max giveaway hides a Google account phishing trap
A convincing offer of a free Claude Max subscription uses a fake browser window to steal Google login information.
ShinyHunters claims FBI breach was revenge for “false” report
The extortion group says it stole sensitive data on FBI agents and job applicants, and wants the bureau to retract a warning about its tactics.
Some cheap smart glasses are a security disaster
Tests found that some cheap smart glasses can be hijacked over Bluetooth, exposing their owners’ photos, videos, and personal data.
