news.mlab.sh
Back to the feed
threat-intel

ThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Stories

HighCVSS 8.0
Summary

This week’s security news is dominated by a massive wave of Android vulnerabilities (200 total), a complex phishing campaign targeting Singpass accounts, and a growing number of exposed Plex servers. Beyond that, a Chinese-speaking operator is leveraging AI tools to automate cyber intrusions in multiple countries, while a network of fake e-commerce shops (DoppelCart) uses over 119,000 domains to steal payment card details. The overall theme is a concerning increase in access and exploitation – whether through malicious extensions, compromised email services, or sophisticated AI-powered attacks.

A lot of this week’s security news has the same awkward answer to one question: “Why was that allowed to work?”

First, Google released patches for 200 vulnerabilities as part of the September 2026 Android security updates. Most concerning is CVE-2026-28662, a critical Wi-Fi-related memory corruption flaw that could allow remote code execution without user interaction. The rapid release cycle is a response to the increasing volume of vulnerabilities discovered through LLM-assisted vulnerability discovery.

Meanwhile, a Chinese-speaking operator has been observed using Anthropic Claude Code, Alibaba Qwen, and DeepSeek to automate intrusions against government and financial systems in Afghanistan, Thailand, Taiwan, and the U.S. Some of the targets included Taiwan's Kuomintang Party History Archives, Indonesia's Ministry of Foreign Affairs, government and education systems in mainland China, and industrial hosts in Da Nang, Vietnam. The attacker is said to have used SecFlow, an AI orchestration framework, to convert “campaign objectives into tasks for specialized AI agents” and supply them with tools, target information, shared storage, and network routes, using a dedicated GLUTTON capability to deploy web shells and the SecBox backdoor framework. The campaign began in July 2026.

Another significant issue involves a network of fake e-commerce shops (DoppelCart) using over 119,000 domains to steal payment card details. The sites mimic legitimate businesses by copying product catalogs, descriptions, branding, and images, sometimes even loading assets directly from the real company's servers. “Each copies a real brand's photos and page text, then undercuts its prices,” Netby said. “Each also republishes the brand's own support address, so the people who get charged complain to the brand, not the shop.”

Beyond these attacks, a Chinese-speaking operator has been observed using AI tools to automate intrusions against government and financial systems in Afghanistan, Thailand, Taiwan, and the U.S. Some of the targets included Taiwan's Kuomintang Party History Archives, Indonesia's Ministry of Foreign Affairs, government and education systems in mainland China, and industrial hosts in Da Nang, Vietnam. The attacker is said to have used SecFlow, an AI orchestration framework, to convert “campaign objectives into tasks for specialized AI agents” and supply them with tools, target information, shared storage, and network routes, using a dedicated GLUTTON capability to deploy web shells and the SecBox backdoor framework. The campaign began in July 2026.

Singpass scheme tied to 170 victims: Singapore police officials have arrested two male Chinese Malaysians, aged 25 and 47, for their alleged involvement in a coordinated scheme that compromised the Singpass accounts of Singapore citizens and work permit holders. The two men were employees of a mobile phone shop located in Singapore. They allegedly exploited opportunities arising from their work to access customers' Singpass accounts. In one such occasion, when a customer was purchasing a new SIM card, one of the men allegedly offered to help update the mobile number linked to the customer's Singpass account, before using this opportunity to create a LiquidPay account without the customer's knowledge. Investigations have uncovered over 170 Singapore citizens and foreign workers whose Singpass accounts were linked to the same activity. The fraudulent Singpass accounts were then used to register for more than 160 additional LiquidPay accounts.

Email breach fuels wallet phishing: Cryptocurrency hardware wallet maker Trezor has warned customers to be on the lookout for phishing attacks after its third-party email provider Brevo was breached. The incident impacted 120 Brevo accounts, including Trezor's. “Please be aware that the email named ‘Critical Security Alert: STM32 Entropy Vulnerability’ is not coming from us, and it’s a phishing attempt,” it said. Do not click on any link. The incident affected our opt-in newsletter database, roughly 347,000 email addresses. These addresses might be potentially used for other phishing attacks in the future. The Brevo account has been suspended to prevent the threat actors from abusing it to send phishing emails. The phishing email sent from the account contained a malicious link that instructed users to download an app that asked them to enter their wallet backup.

33K+ Plex servers remain exposed: Data from the Shadowserver Foundation shows that there are over 33,800 exposed Plex servers susceptible to recently disclosed vulnerabilities, down from a high of 37,467 on September 5, 2026. Nearly 20,000 instances are located in North America.

EtherRAT chain ends in ransomware: An attack campaign that installs EtherRAT via a malicious MSI installer masquerading as a Sysinternals tool has been found to deliver an AI-generated malware framework called TukTuk and GoTo Resolve. Using the access provided by the remote access software, the threat actor is said to have successfully exfiltrated data to a cloud service and deployed The Gentleman ransomware. “TukTuk can use Arweave as a dead-drop resolver,” the DFIR Report said. “In this mode, the implant queries the Arweave blockchain for a specific Drive-Id, then retrieves an encrypted configuration blob. That blob contains the credential pool for all supported C2 transports. After execution of TukTuk, the threat actor began hands-on-keyboard activity, Kerberoasting operations, and credential discovery targeting administrative accounts. Next, the threat actor leveraged compromised service account credentials to deploy GoTo Resolve remote management tooling laterally across multiple systems, including servers and domain controllers. The Gentleman ransomware was deployed after the initial EtherRAT installation.”

CISA refreshes insider threat guidance: The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has released an updated version of its Insider Threat Mitigation Guide to highlight the “growing impact insider threats have on critical infrastructure, the dynamic and evolving operational landscape, and provide new use cases.”

Read the full article at The Hacker News