ThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Stories
Multiple threat actors leverage malicious extensions, AI agents, and unapproved AI tools to steal data and compromise
Summary
This week's security news highlights several threats including malicious browser extensions targeting cryptocurrency users, Chinese-speaking actors using AI to automate intrusions against government and financial systems, and a UK NCSC warning about the risks of employees using unapproved AI tools, which can expose sensitive data.
Full text
ThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Stories Ravie LakshmananSep 10, 2026Hacking News / Cybersecurity News A lot of this week’s security news has the same awkward answer to one question: “Why was that allowed to work?” An extension asks for access and takes too much. A trusted service becomes part of a phishing chain. An old bug still gets results. An exposed system stays exposed. A package looks useful right up until it isn’t. Different stories, same basic problem: the path in was often already there. Nothing here needed magic. Mostly access, trust, weak edges, and someone willing to keep poking. That’s the week. The threats change every week. Subscribe, and we’ll alert you when each new ThreatsDay Bulletin is out. Malicious extensions steal crypto data Cross-Browser Extension Campaign Leads to Crypto Session and Wallet Data Theft A set of four malicious Google Chrome and Mozilla Firefox extensions has been found to target Axiom Trade and Padre users to steal session tokens and wallet data. The extensions are J7Tracker (Chrome), VREO (Chrome and Firefox), and Orbit Tracker (Firefox). While the first three contain the same Axiom and Padre collection module, the fourth implements a different collector but targets the same data, while retaining some artifacts from J7Tracker. "The module is byte-identical across all three analyzed extensions. It automatically retrieves authenticated user information, wallet-related bundle data, Firebase access tokens, and application state, then sends the information to threat actor-controlled Vercel deployments," Socket said. The same Chrome publisher has been traced back to two earlier extensions, GhostApe and GhostApe Color, impersonating the MockApe trading add-on. AI agents automate cyber intrusions Chinese-Speaking Uses AI to Target Asia A Chinese-speaking operator has been observed using Anthropic Claude Code, Alibaba Qwen, and DeepSeek to automate intrusions against government and financial systems in Afghanistan, Thailand, Taiwan, and the U.S. Some of the targets included Taiwan's Kuomintang Party History Archives, Indonesia's Ministry of Foreign Affairs, government and education systems in mainland China, and industrial hosts in Da Nang, Vietnam. The attacker is said to have used SecFlow, an AI orchestration framework, to convert "campaign objectives into tasks for specialized AI agents" and supply them with tools, target information, shared storage, and network routes, Hunt.io said, adding the tool "split reconnaissance, exploitation, collection, and reporting among specialist workers." Some of the vulnerabilities exploited by the threat actor are Shellshock, Spring4Shell, Ghostcat, Shiro deserialization, Log4Shell, Grafana and Nexus path traversals, and a Nacos authentication bypass. The exploitation is followed by the deployment of web shells, which are generated through a dedicated GLUTTON capability, and used to facilitate follow-on actions, like reconnaissance, privilege escalation, credential theft, and custom implant deployment. One such backdoor is SecBox, a Go-based remote-access and network-pivot framework. Details of the campaign first came to light in July 2026. Shadow AI exposes sensitive data U.K. NCSC Warns of Shadow AI Risks The U.K.'s National Cyber Security Center (NCSC) has warned that employees using unapproved AI tools can expose sensitive corporate data and create security risks that organizations may struggle to detect and manage. "Providing shadow AI access to company or customer data likely increases the risk of data breaches, intellectual property loss and failure to meet regulatory requirements," NCSC said. "Employees who transfer sensitive or proprietary information to consumer AI services will likely reduce the organization's visibility and control over that information. AI agents are complex pieces of software that can have critical security vulnerabilities. If an attacker successfully exploits a vulnerability, they can gain access to the same data, services, and privileges that the agent has legitimate access to." Fake M&A deals drive wire fraud Phantom Deal Fraud Campaign Exposed Attackers are masquerading as executives and tricking targets in legal teams into moving conversations to WhatsApp and personal email with an aim to initiate international wire transfers using forged acquisition documents as part of a merger and acquisition scam. "The attackers presented the acquisition as a tightly controlled transaction coordinated by a reputable adviser, with only a small group involved and an announcement approaching fast," Gen Digital said. "The organizations and professions varied. The targets included senior people in private equity, industrial finance, sales, mining and energy. For each of them, an acquisition or strategic investment narrative would have been credible enough to justify initial engagement. Despite the different branding, the documents followed substantially the same sequence of sections and reused the same legal language. They all imposed confidentiality, directed communications towards WhatsApp and personal email, and introduced a short period between the NDA date and the supposed public announcement." Windows adds privacy-preserving age checks Microsoft Adds Age-Awareness APIs to Windows 11 Microsoft is adding new age-awareness APIs called the Windows Age API to Windows 11 that will allow apps to determine whether a user is a child, teenager, or adult without exposing their exact date of birth. "Apps receive only the age-related signal needed for the experience and not sensitive personal data such as full date of birth," Microsoft said. "By making age awareness available as a platform capability, Windows helps developers build safeguards into experiences from the start rather than placing the burden on children and families to manage protections app by app." 119K domains power fake shops DoppelCart Runs Sprawling Fake Shop Operation A massive operation dubbed DoppelCart is using more than 119,000 domains to run a network of fake e-commerce shops that steal payment card details. The sites mimic legitimate businesses by copying product catalogs, descriptions, branding, and images, sometimes even loading assets directly from the real company's servers. In all, the shops mimic 44,182 different brands, with a median of two clones for each. "Each copies a real brand's photos and page text, then undercuts its prices," Netby said. "Each also republishes the brand's own support address, so the people who get charged complain to the brand, not the shop." Chrome accelerates security releases Google Transitions to a 2-Week Release Cadence Google has officially shifted to a two-week cadence for major Chrome milestones, with weekly security updates, in response to a shifting cybersecurity landscape in the AI era. The shift is driven by LLM-assisted vulnerability discovery approaches, which have increased the volume of patches and updates across the software ecosystem. "While this dramatic change in software security brought about by LLMs might be startling, an increase in bugs found and fixed is not a sign of failure," Google said. "Every bug found and fixed is one less foothold for an attacker. But discovering and fixing a bug is only half the battle — we must also ship the fix and apply the update for users faster than adversaries can exploit the bug." The idea, therefore, is to shrink the window between pushing a fix in a public codebase and getting that fix to end users before it can be exploited. A shorter release cycle would reduce the patch gap – the time frame between when a security vulnerability is known and when it gets addressed. Google moved to a four-week release cycle for Chrome in 2021, down from six weeks. Similar moves have been adopted by other browser makers like Microsoft, Mozilla, and Brave. 200 Android flaws patched Google Fixes 200 Flaws in Android Google has released patches for 200 vulnerabilities as
Indicators of Compromise
- malware — J7Tracker
- malware — VREO
- malware — Orbit Tracker
- malware — GhostApe
- malware — GhostApe Color
- malware — SecBox