ThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Stories

ThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Stories
This week’s security stories all point to the same failure: ordinary tools, trusted services, and exposed systems were allowed to do too much. From malicious browser extensions and npm packages to AI-driven intrusions, phishing relays, and ransomware chains, attackers kept exploiting weak handoffs already in place. #AxiomTrade #Padre #AnthropicClaudeCode #AlibabaQwen #DeepSeek #SecFlow #Trezor #Brevo #EtherRAT #TukTuk #TheGentlemen #BigBear2.0 #Evilginx2

Keypoints

  • Malicious Chrome and Firefox extensions stole session tokens and wallet data from Axiom Trade and Padre users.
  • AI tools like Claude Code, Qwen, and DeepSeek were used to automate intrusions against government and financial targets.
  • Trezor warned users after Brevo was breached and attackers launched phishing for wallet backup information.
  • Threat actors abused Google services, blob URLs, and QR codes to hide phishing and bypass security filters.
  • Attackers used malicious npm packages, fake shops, EtherHiding, and MFA-bypassing PhaaS to compromise victims at scale.

Read More: https://thehackernews.com/2026/09/threatsday-200-android-flaws-browser.html