Malwarebytes Labs – The Security Blog From Malwarebytes | Malwarebytes Labs Data breaches FBI agents’ blood tests and doctors’ notes surface after breach September 28, 2026 – A “shellfish and banana allergy” is among the details in medical records hackers showed reporters. They claim to hold records on thousands of FBI staff. Threat Intel Kothamine malware uses Tailscale’s tailcat to evade network detection Threat Intel That shipping rebate offer may come with a monthly charge News LinkedIn adds new checks for fake profiles and work histories News Criminals turn placeholder domain into ClickFix trap Podcast Listen to the latest in cybersecurity and privacy. VIEW EPISODES AI Find out the newest developments in AI. READ MORE Data breaches Keep on top of the latest data breach news. READ MORE Threat Intel Stay up to date with our latest research. READ MORE OpenAI pauses work on top AI models after agent slips past internet controls Pieter Arntz September 28, 2026 0 Comments An OpenAI agent bypassed internet restrictions and kept running after an alert. It's another case of AI misalignment no one can afford to ignore. FBI agents’ blood tests and doctors’ notes surface after breach Pieter Arntz September 28, 2026 0 Comments A “shellfish and banana allergy” is among the details in medical records hackers showed reporters. They claim to hold records on thousands of FBI staff. A week in security (September 21 – September 27) Malwarebytes Labs September 28, 2026 0 Comments A list of topics we covered in the week of September 21 to September 27 of 2026 LinkedIn adds new checks for fake profiles and work histories Pieter Arntz September 25, 2026 0 Comments The platform is adding new checks as AI makes profiles easier to forge. But scammers can still invent a company to recruit for. Kothamine malware uses Tailscale’s tailcat to evade network detection Gabriele Orini September 25, 2026 0 Comments Kothamine uses a legitimate Tailscale tool to receive attackers’ commands through an encrypted connection with no malicious domain to block. Criminals turn placeholder domain into ClickFix trap Pieter Arntz September 25, 2026 0 Comments A domain used in software examples—third-party[.]com—now serves up a fake verification page that tells Windows users to run a PowerShell command. That shipping rebate offer may come with a monthly charge Pieter Arntz September 25, 2026 0 Comments Customers say they signed up for shipping rebates, then found recurring charges they didn’t expect. OpenAI agent breached Australian government site, took months to report it Pieter Arntz September 24, 2026 0 Comments The agent was looking for public spending data. It found a way into non-public files instead. What do we need to change to stop this from happening? New Browser Guard features add protection before and after you click Malwarebytes Labs September 24, 2026 0 Comments Spot dangerous sites before you click—and check for scams once you’re there. 1 2 3 … 655 Next Contributors Threat Center Podcast Glossary Scams