ThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Stories

2 hours ago 3

A lot of this week’s security news has the same awkward answer to one question: “Why was that allowed to work?”

An extension asks for access and takes too much. A trusted service becomes part of a phishing chain. An old bug still gets results. An exposed system stays exposed. A package looks useful right up until it isn’t. Different stories, same basic problem: the path in was often already there.

Nothing here needed magic. Mostly access, trust, weak edges, and someone willing to keep poking. That’s the week.

  1. Malicious extensions steal crypto data

    A set of four malicious Google Chrome and Mozilla Firefox extensions has been found to target Axiom Trade and Padre users to steal session tokens and wallet data. The extensions are J7Tracker (Chrome), VREO (Chrome and Firefox), and Orbit Tracker (Firefox). While the first three contain the same Axiom and Padre collection module, the fourth implements a different collector but targets the same data, while retaining some artifacts from J7Tracker. "The module is byte-identical across all three analyzed extensions. It automatically retrieves authenticated user information, wallet-related bundle data, Firebase access tokens, and application state, then sends the information to threat actor-controlled Vercel deployments," Socket said. The same Chrome publisher has been traced back to two earlier extensions, GhostApe and GhostApe Color, impersonating the MockApe trading add-on.

  2. AI agents automate cyber intrusions

    A Chinese-speaking operator has been observed using Anthropic Claude Code, Alibaba Qwen, and DeepSeek to automate intrusions against government and financial systems in Afghanistan, Thailand, Taiwan, and the U.S. Some of the targets included Taiwan's Kuomintang Party History Archives, Indonesia's Ministry of Foreign Affairs, government and education systems in mainland China, and industrial hosts in Da Nang, Vietnam. The attacker is said to have used SecFlow, an AI orchestration framework, to convert "campaign objectives into tasks for specialized AI agents" and supply them with tools, target information, shared storage, and network routes, Hunt.io said, adding the tool "split reconnaissance, exploitation, collection, and reporting among specialist workers." Some of the vulnerabilities exploited by the threat actor are Shellshock, Spring4Shell, Ghostcat, Shiro deserialization, Log4Shell, Grafana and Nexus path traversals, and a Nacos authentication bypass. The exploitation is followed by the deployment of web shells, which are generated through a dedicated GLUTTON capability, and used to facilitate follow-on actions, like reconnaissance, privilege escalation, credential theft, and custom implant deployment. One such backdoor is SecBox, a Go-based remote-access and network-pivot framework. Details of the campaign first came to light in July 2026.

  3. Shadow AI exposes sensitive data

    The U.K.'s National Cyber Security Center (NCSC) has warned that employees using unapproved AI tools can expose sensitive corporate data and create security risks that organizations may struggle to detect and manage. "Providing shadow AI access to company or customer data likely increases the risk of data breaches, intellectual property loss and failure to meet regulatory requirements," NCSC said. "Employees who transfer sensitive or proprietary information to consumer AI services will likely reduce the organization's visibility and control over that information. AI agents are complex pieces of software that can have critical security vulnerabilities. If an attacker successfully exploits a vulnerability, they can gain access to the same data, services, and privileges that the agent has legitimate access to."

  4. Fake M&A deals drive wire fraud

    Attackers are masquerading as executives and tricking targets in legal teams into moving conversations to WhatsApp and personal email with an aim to initiate international wire transfers using forged acquisition documents as part of a merger and acquisition scam. "The attackers presented the acquisition as a tightly controlled transaction coordinated by a reputable adviser, with only a small group involved and an announcement approaching fast," Gen Digital said. "The organizations and professions varied. The targets included senior people in private equity, industrial finance, sales, mining and energy. For each of them, an acquisition or strategic investment narrative would have been credible enough to justify initial engagement. Despite the different branding, the documents followed substantially the same sequence of sections and reused the same legal language. They all imposed confidentiality, directed communications towards WhatsApp and personal email, and introduced a short period between the NDA date and the supposed public announcement."

  5. Windows adds privacy-preserving age checks

    Microsoft is adding new age-awareness APIs called the Windows Age API to Windows 11 that will allow apps to determine whether a user is a child, teenager, or adult without exposing their exact date of birth. "Apps receive only the age-related signal needed for the experience and not sensitive personal data such as full date of birth," Microsoft said. "By making age awareness available as a platform capability, Windows helps developers build safeguards into experiences from the start rather than placing the burden on children and families to manage protections app by app."

  6. 119K domains power fake shops

    A massive operation dubbed DoppelCart is using more than 119,000 domains to run a network of fake e-commerce shops that steal payment card details. The sites mimic legitimate businesses by copying product catalogs, descriptions, branding, and images, sometimes even loading assets directly from the real company's servers. In all, the shops mimic 44,182 different brands, with a median of two clones for each. "Each copies a real brand's photos and page text, then undercuts its prices," Netby said. "Each also republishes the brand's own support address, so the people who get charged complain to the brand, not the shop."

  7. Chrome accelerates security releases

    Google has officially shifted to a two-week cadence for major Chrome milestones, with weekly security updates, in response to a shifting cybersecurity landscape in the AI era. The shift is driven by LLM-assisted vulnerability discovery approaches, which have increased the volume of patches and updates across the software ecosystem. "While this dramatic change in software security brought about by LLMs might be startling, an increase in bugs found and fixed is not a sign of failure," Google said. "Every bug found and fixed is one less foothold for an attacker. But discovering and fixing a bug is only half the battle — we must also ship the fix and apply the update for users faster than adversaries can exploit the bug." The idea, therefore, is to shrink the window between pushing a fix in a public codebase and getting that fix to end users before it can be exploited. A shorter release cycle would reduce the patch gap – the time frame between when a security vulnerability is known and when it gets addressed. Google moved to a four-week release cycle for Chrome in 2021, down from six weeks. Similar moves have been adopted by other browser makers like Microsoft, Mozilla, and Brave.

  8. 200 Android flaws patched

    Google has released patches for 200 vulnerabilities as part of the September 2026 Android security updates. This includes a number of critical and high-severity vulnerabilities, including those that could allow attackers to remotely execute code without user interaction. One of the flaws worth highlighting is CVE-2026-28662, a critical Wi-Fi-related bug that could potentially allow an attacker to achieve remote code execution. "Most concerning from this list is CVE-2026-28662 because it's a Wi-Fi-related memory corruption flaw," Adam Boynton, enterprise strategy manager at Jamf, said. "If left unpatched, it could enable attackers to execute code remotely, without any additional privileges or user interaction, potentially allowing privilege escalation. This vulnerability will only continue to pose a risk if devices are left unpatched. It's crucial that organizations issue the updates across their device fleet as soon as possible."

  9. Singpass scheme tied to 170 victims

    Singapore police officials have arrested two male Chinese Malaysians, aged 25 and 47, for their alleged involvement in a coordinated scheme that compromised the Singpass accounts of Singapore citizens and work permit holders. "Investigations revealed that the two men were employees of a mobile phone shop located in Singapore," authorities said. "They allegedly exploited opportunities arising from their work to access customers' Singpass accounts. In one such occasion, when a customer was purchasing a new SIM card, one of the men allegedly offered to help update the mobile number linked to the customer's Singpass account, before using this opportunity to create a LiquidPay account without the customer's knowledge." Investigations have uncovered over 170 Singapore citizens and foreign workers whose Singpass accounts were linked to the same activity. The fraudulent Singpass accounts were then used to register for more than 160 additional LiquidPay accounts.

  10. Email breach fuels wallet phishing

    Cryptocurrency hardware wallet maker Trezor has warned customers to be on the lookout for phishing attacks after its third-party email provider Brevo was breached. The incident impacted 120 Brevo accounts, including Trezor's. "Please be aware that the email named 'Critical Security Alert: STM32 Entropy Vulnerability' is not coming from us, and it's a phishing attempt," it said. Do not click on any link. The incident affected our opt-in newsletter database, roughly 347,000 email addresses. These addresses might be potentially used for other phishing attacks in the future." The Brevo account has been suspended to prevent the threat actors from abusing it to send phishing emails. The phishing email sent from the account contained a malicious link that instructed users to download an app that asked them to enter their wallet backup. The domain has since been taken down.

  11. EtherRAT chain ends in ransomware

    An attack campaign that installs EtherRAT via a malicious MSI installer masquerading as a Sysinternals tool has been found to deliver an AI-generated malware framework called TukTuk and GoTo Resolve. Using the access provided by the remote access software, the threat actor is said to have successfully exfiltrated data to a cloud service and deployed The Gentlemen ransomware. "TukTuk can use Arweave as a dead-drop resolver," the DFIR Report said. "In this mode, the implant queries the Arweave blockchain for a specific Drive-Id, then retrieves an encrypted configuration blob. That blob contains the credential pool for all supported C2 transports. After execution of TukTuk, the threat actor began hands-on-keyboard activity, Kerberoasting operations, and credential discovery targeting administrative accounts. Next, the threat actor leveraged compromised service account credentials to deploy GoTo Resolve remote management tooling laterally across multiple systems, including servers and domain controllers."

  12. CISA refreshes insider threat guidance

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has released an updated version of its Insider Threat Mitigation Guide to highlight the "growing impact insider threats have on critical infrastructure, the dynamic and evolving operational landscape, and provide new use cases to help organizations address new challenges." Some of the key updates relate to emerging workplace trends such as increased hybrid and remote work, the use of AI for manipulation and deception, access control, and visitor screening.

  13. AI abuse leads to 15-year sentence

    James Strahler II, 37, of Columbus, has been sentenced in the U.S. to 15 years in prison for using both real and AI-generated sexually explicit images and intimidating victims with threats of violence. "Strahler had installed more than 24 AI platforms and more than 100 AI web-based models on his phone," the Justice Department said. "The defendant used telephone calls, voicemails, text messages and web postings to engage in a campaign of harassment against his victims. From December 2024 until June 2025, Strahler sent harassing messages to at least six adult female victims. These messages included nude images of the victims, both real and AI-generated. Strahler also posted online AI-generated obscenities he created of children." The defendant is said to have created more than 700 images of both real victims and animated persons and posted them to a website dedicated to child sexual abuse. He was arrested in June 2025.

  14. Bank takeover suspect extradited

    Sergei Anatolyevich Filimonov, 36, a Russian national and web developer, has been extradited to the U.S. in connection with a transnational cyber-fraud conspiracy responsible for large-scale bank account takeover attacks. "Filimonov and his co-conspirators executed a sophisticated scheme involving spoofed domains that mimicked the websites of federally insured financial institutions," the Justice Department said. "The conspirators purchased sponsored search-engine links to divert unsuspecting banking customers to fraudulent login pages, where victims entered their credentials. The conspirators used the stolen credentials to access bank accounts, review account balances, and initiate unauthorized wire transfers to steal bank account funds." Filimonov is also accused of developing and maintaining online infrastructure supporting the operation, including interactive databases storing more than 5,000 stolen login credentials and software designed to harvest and transmit sensitive authentication data. One of the backend domains linked to the scheme was seized by U.S. authorities in December 2025. Filimonov has pleaded not guilty to the charges.

  15. $245M crypto theft ringleader pleads guilty

    Malone Lam (aka Anne Hathaway, $$$, and King Greavy), 22, a citizen of Singapore and recent resident of Miami, has pleaded guilty in the U.S. for their role as a "ringleader of an international cybercrime conspiracy" that used social engineering to steal and launder cryptocurrency valued at more than $245 million. "The criminal enterprise began no later than October 2023 and continued through at least May 2025," the Justice Department said. "The scheme developed through connections made on online gaming platforms and was comprised of individuals based in California, Connecticut, New York, Florida, and abroad. The RICO conspiracy used social engineering and occasional home break-ins to obtain information that allowed the conspirators to drain their victims' cryptocurrency wallets." Lam is accused of organizing the enterprise, identifying target victims, and coordinating with different co-conspirators. The stolen assets were used to purchase nightclub services, luxury handbags, high-end watches and clothing, rental homes, private jet rentals, a team of private security guards, and a fleet of exotic cars.

  16. Teams to obscure external QR codes

    Microsoft said it will provide additional protection for QR codes shared by external users in team messages. "Images containing QR codes from external senders will be obscured by default and require users to reveal them before viewing or scanning," the company said. "This helps reduce the risk of phishing and fraud by encouraging more deliberate interaction with QR code content." The feature is expected to start rolling out next month.

  17. Google services abused as phishing relay

    A newly discovered phishing campaign has been observed routing "victims through a deliberate chain of legitimate Google services before landing them on credential harvesters or deploying remote access tools," according to KnowBe4 Threat Lab. What's unusual about the attack is that it abuses six distinct Google properties (Meet, Search, DoubleClick, Programmable Search Engine, Image Search, and Tag Manager) across a multi-hop redirection path to bypass email security filters. "The page pulls live company logos from Clearbit, real-time website screenshots from a third-party screenshot API, and uses Google's public DNS to validate the victim's corporate email domain," it added. Recent phishing campaigns have also increasingly exploited .vu, Vanuatu's country-code top-level domain, for setting up malicious infrastructure. KnowBe4 said it recorded a 159% increase in phishing sites, 1,660 unique domains, and over 28,000 malicious emails from April through July 2026. "Security vendors have historically seen almost no .vu traffic, so there is no TLD-level risk signal built into most threat feeds," the company said. Another "iCloud Sign-In Alert" phishing attack has been found to detect the operating system and serve a remote access tool for Windows users and a credential harvesting page for Apple users. "Everyone else gets walked through a fake Microsoft login while a human operator watches the credentials arrive in Telegram in real time," KnowBe4 said.

  18. Smart TV privacy claims spark scrutiny

    LG is drawing criticism over claims from YouTube channel Gamers Nexus that its smart TVs gather extensive information about users and their surroundings to fuel its advertising business. The channel crew said it observed the TV capturing IP addresses, location data, and the names, signal strengths, and channel numbers of nearby Wi-Fi networks. The consumer hardware also enumerated devices on the local network that were not paired with it, including smartphones, watches, routers, thermostats, air purifiers, server baseboard management controllers, and PCs. The move has been described as "an egregious invasion of privacy." In a statement shared with The Register, the company said the allegations are not true. "LG TVs process voice data only when the voice button on the remote control is pressed and held, or when a wake word such as 'Hi LG' is recognized after the user has activated the Far-Field voice recognition feature," the company said. Other than these instances, the TVs do not collect or record ambient conversations. If the wake word is not recognized, no voice data is transmitted to the server; wake word detection is processed locally on the device and immediately deleted. Additionally, to provide smart TV functionalities, LG TVs feature the ability to scan for and connect to nearby devices on the same network. This is a standard function commonly available on smart TVs and smart home devices."

  19. Malicious npm packages compromise wallets

    A set of 13 malicious wallet packages have been discovered on the npm registry. According to InstallSafe, their names reference wallets, signing, analytics, Solana, Base, or mobile components. "Any computer that has this package installed or running should be considered fully compromised," GitHub warns in an advisory. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.

  20. Blob URLs hide phishing pages

    Barracuda has disclosed details of a DocuSign-themed attack campaign that replaces the traditional phishing site with a phishing page generated inside the victim’s browser using blob URLs. "Victims are routed through legitimate Microsoft services, making the attack appear trustworthy and reducing common warning signs," the cybersecurity company said. "Because the page exists only within that browser session, there is no persistent phishing URL for security tools to retrieve, analyze, or blocklist in advance. Because the visible navigation remains within trusted Microsoft services, users and automated scanners may be less likely to identify the activity as malicious."

  21. 5,400 hacked sites fuel EtherHiding

    More than 5,400 compromised websites have been used for carrying out EtherHiding attacks. "The compromised websites have little in common beyond being small businesses (clinics, plumbers, e-commerce shops) with no shared industry, region, or owner," Netskope said. "These compromised sites include either an inline script or a spoofed package that calls the BSC testnet and downloads a ClickFix overlay as the next step of the attack, which instructs visitors to run a command on their PC." Another variant of the attack has been found to open a covert WebRTC data channel for command-and-control (C2) instead of serving the ClickFix overlay and use it to receive and execute arbitrary JavaScript code.

  22. Executive SSNs flood dark web markets

    Rapid7 said it has identified 476 instances of compromised Social Security numbers (SSNs) across 395 unique corporate personnel since early 2026. "Over 73% of these exposures directly targeted top-level leadership, with C-suite executives comprising 44.6% of affected profiles and Presidents making up another 28.6%," it said. "Unsurprisingly, given the geographical nature of SSNs, 95.6% of these leaks stemmed from U.S.-headquartered organizations, concentrated heavily in high-value sectors like Financials (over 25%) and Industrials (17%)." Marketplaces like Xilo, Bankom, and PeopleFinder together account for 81.5% of all executive SSN leaks present in its dataset, led by Xilo at 40.8%, Bankom at 21.8%, and PeopleFinder at 18.9%.

  23. MCP tools expose high-impact attack paths

    An analysis of 33,563 published MCP server builds containing 475,865 tools has found that 2 in 5 server builds include a tool that can access sensitive data or take consequential action and 1 in 13 server builds contain a code or command-execution primitive. "When an MCP host makes a tool available to a model, the tool’s description can enter the model's context," Island said. "After the tool is called, its returned text can enter that context too. The model may interpret either as guidance, not just documentation. An attacker may not need a malicious binary. A paragraph of natural language can be enough." This makes the "instruction supply chain" a critical attack surface, allowing bad actors to embed covert instructions in tool descriptions and prompts that a model may read and trigger unintended actions without requiring malicious executable code. "Security teams need a control plane that governs a tool from discovery to execution: inspect its code and instructions, constrain its capabilities, verify configuration changes, and evaluate each action in runtime context," Island said. "Approval cannot be a one-time package score; it must account for the tool version, the agent and user invoking it, the destination, the data in scope, and the action being attempted."

  24. MFA-bypassing PhaaS hits 40+ countries

    Hundreds of organizations across more than 40 countries have been targeted by BigBear 2.0, a rebranded Evilginx2-based Microsoft 365 phishing-as-a-service (PhaaS) operation. The stolen records are tied to 461 organizations. CloudSEK, which was able to gain admin access to the threat actor panel, said the operation has "exfiltrated 5,137 credential records — including 474 complete MFA-bypassed authentications, 1,032 plaintext passwords, and 4,148 session cookies — affecting 3,331 unique victim IPs across 40+ countries." The multi-user PhaaS panel has been leased to at least five affiliate operators so far. "The core technique employed is adversary-in-the-middle (AitM) phishing," CloudSEK said. "Unlike classical phishing that only captures passwords, Evilginx2's reverse proxy relays the entire session."

  25. FBI unveils first cyber strategy

    The U.S. Federal Bureau of Investigation (FBI) has outlined its first-ever cyber strategy, stating it "will detect shifts in adversary intent and capability, disrupt their ability to profit or operate safely, expose their tradecraft and enablers, bring offenders to justice with domestic and international partners, and provide the evidence and intelligence that underpin sanctions, diplomatic action, and partner law enforcement actions." The agency also aims to attribute malicious cyber activity with confidence, support victims following intrusions, share actionable intelligence, and partner with U.S. allies and the private sector to increase impact. Furthermore, the agency said it will "adopt agentic AI in ways that securely scale defense and disruption, and will implement AI-enabled tools to detect, divert, and deceive threat actors where operationally appropriate."

The lesson this week is smaller than “patch faster.” Stop giving ordinary things unlimited trust. Extensions, packages, redirects, sessions, AI tools, exposed services — most of the trouble begins when something familiar is allowed to do too much.

Security still breaks at the boring handoffs: what gets access, what stays exposed, what gets inherited, and what nobody checks twice. Attackers do not need every door open. One lazy hinge is enough. That is probably the part worth remembering after the headlines disappear.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Read Entire Article