Cyber Briefing: 2026.03.02
Malicious Chrome extension update steals crypto, RAT spreads via fake gaming tools, major breaches exposed, Europol arrests suspects, fake ID creator pleads guilty.
👉 What's happening in cybersecurity today?
Welcome to Cyber Briefing, the newsletter that informs you about the latest cybersecurity advisories, alerts, incidents and news every weekday.
First time seeing this? Please Subscribe
🚨 Cyber Alerts
1. QuickLens Chrome Extension Steals Crypto
The QuickLens Chrome extension was recently pulled from the Web Store after a malicious update compromised roughly 7,000 users. Following an ownership change, version 5.8 introduced scripts designed to execute ClickFix attacks and steal cryptocurrency data by bypassing browser security headers.
2. Microsoft Warns RAT via Fake Gaming Utilities
Hackers are tricking gamers into downloading infected utilities through chat apps and browsers to secretly install a remote access trojan on their systems. This sophisticated campaign utilizes legitimate Windows tools and PowerShell scripts to bypass security software and maintain permanent access to compromised devices.
3. ClawJacked Flaw Exposes OpenClaw Users
A security flaw known as ClawJacked allowed malicious websites to hijack local OpenClaw AI agents to facilitate silent data extraction. Developers should update to version 2026.2.26 immediately to resolve this vulnerability and secure their local environments.
For more alerts click here!
💥 Cyber Incidents
4. Canadian Tire Breach Hits 38M Accounts
Canadian Tire recently experienced a significant security incident involving an unauthorized intrusion into its e-commerce database during October 2025. This breach exposed the personal information of over 38 million accounts across several brands, including SportChek, Mark’s, and Party City.
5. UH Cyber Hack Exposes 1.15M SSNs
The University of Hawaiʻi Cancer Center recently disclosed that a ransomware attack exposed the Social Security numbers of approximately 1.15 million individuals. In response, the university is providing one year of credit monitoring and identity theft insurance to those whose personal data was compromised during the breach.
6. Hackers Steal 15M French Medical Records
Following a major breach of bank account details, a massive medical data hack in France has exposed the sensitive information of millions of citizens, including high-profile politicians. The leak, which originated from software used by 1,500 medical practices, reportedly includes private doctors’ notes regarding patient sexuality and serious illnesses like AIDS.
For more incidents click here!
📢 Cyber News
7. Europol Nets 30 in “The Com” Crackdown
Europol’s Project Compass recently dismantled a portion of the cybercrime network known as The Com, resulting in 30 arrests and the identification of 62 victims. The international crackdown successfully removed four children from immediate danger while strengthening the collaborative defense against decentralized digital threats.
8. Hackers Target Iranian Apps, Sites After Strikes
Cybersecurity experts reported a series of digital strikes targeting Iran on Saturday that coincided with military actions by the United States and Israel. These operations disrupted internet connectivity and compromised various platforms, including government services and a popular religious application, to spread messages and hinder a coordinated response.
9. “OnlyFake” Creator Pleads Guilty
The United States Attorney for the Southern District of New York and the FBI have announced the guilty plea of Ukrainian national Yurii Nazarenko for operating OnlyFake, a website specializing in the creation of digital fake identification documents. This case marks one of the first major legal actions against a platform that manufactured over 10,000 fraudulent passports and licenses used to bypass security regulations and facilitate financial crimes.
For more news click here!
📈Cyber Stocks
Cybersecurity stocks on Monday, 2nd March 2026 saw continued volatility in tech markets with mixed performance across pure-play names, as rotation pressures and sector narratives around AI-driven tooling influenced near-term flows.
Palo Alto Networks Inc closed near ~162.69 dollars and was modestly mixed, as shares navigated recent earnings reactions and competitive AI tooling narratives.
CrowdStrike Holdings Inc finished around ~372.05 dollars and was softer, with sell-offs in high-growth endpoint and identity security names amid broader sector weakness.
Okta Inc closed near ~86.74 dollars and was modestly subdued, with identity and access management stocks tracking mixed tech flows.
Zscaler Inc ended near ~170.90 dollars and moved lower, reflecting profit-taking even after solid fundamentals and cloud security demand.
Fortinet Inc closed around ~84.26 dollars and was modestly down, with network security names trading softer in the session.
💡 Cyber Tip
🎮 Microsoft Warns of RAT via Fake Gaming Utilities
Attackers are spreading fake gaming tools like Xeno.exe and RobloxPlayerBeta.exe to trick users into installing a remote access trojan. The campaign abuses legitimate Windows utilities and PowerShell to evade detection, disable protections, and maintain long-term control of infected systems.
🛠️ What You Should Do
Download game utilities only from official developer websites
Avoid running executables shared through chat apps or forums
Monitor for unusual PowerShell activity or scheduled task creation
Review Microsoft Defender exclusions for unauthorized changes
Keep endpoint protection enabled and fully updated
⚠️ Why This Matters
Once a remote access trojan is installed, attackers can steal personal data, monitor activity, and deploy additional malware. Gaming communities are being used as an entry point into both personal and corporate systems.
📚 Cyber Book
The Fight for Privacy by Danielle Keats Citron
Copyright © 2026 CyberMaterial. All Rights Reserved.
Follow CyberMaterial on:
Substack, LinkedIn, Twitter, Reddit, Instagram, Facebook, YouTube, and Medium










