This week’s security stories all point to the same failure: ordinary tools, trusted services, and exposed systems were allowed to do too much. From malicious browser extensions and npm packages to AI-driven intrusions, phishing relays, and ransomware chains, attackers kept exploiting weak handoffs already in place. #AxiomTrade #Padre #AnthropicClaudeCode #AlibabaQwen #DeepSeek #SecFlow #Trezor #Brevo #EtherRAT #TukTuk #TheGentlemen #BigBear2.0 #Evilginx2
Keypoints
- Malicious Chrome and Firefox extensions stole session tokens and wallet data from Axiom Trade and Padre users.
- AI tools like Claude Code, Qwen, and DeepSeek were used to automate intrusions against government and financial targets.
- Trezor warned users after Brevo was breached and attackers launched phishing for wallet backup information.
- Threat actors abused Google services, blob URLs, and QR codes to hide phishing and bypass security filters.
- Attackers used malicious npm packages, fake shops, EtherHiding, and MFA-bypassing PhaaS to compromise victims at scale.
Read More: https://thehackernews.com/2026/09/threatsday-200-android-flaws-browser.html