This week’s cybersecurity bulletin reveals sweeping threats—from advanced phishing campaigns to mass device vulnerabilities. At the heart of it: Google’s fix for 200 Android flaws, including a Wi-Fi bug that could allow remote code execution without user interaction. Here’s what to know.
Major Updates & Emerging Threats
Google’s September 2026 Android security update addresses 200 vulnerabilities, several of which are rated high or critical. Particularly concerning is CVE-2026-28662, a Wi-Fi related memory corruption issue. Left unpatched, this flaw could enable attackers to gain code execution privileges on devices with no user action required. Vendors and organizations are being urged to push updates across devices quickly.
A massive fake shop operation dubbed DoppelCart has been exposed, using over 119,000 domains to imitate 44,000+ brands in order to trick shoppers into providing payment card data. These sites clone real images, copy content directly from legitimate sites, and republish customers’ support contacts so that those charged blame the real brand rather than the fraudster.
On the phishing front, several dangerous tactics have surfaced:
- Malicious browser extensions across Chrome and Firefox are stealing wallet data, session tokens, and Firebase credentials via modules that are shared among multiple extensions.
- A global phishing campaign is abusing Google’s infrastructure—using Meet, Search, Image Search, Tag Manager, and other services as part of a chain of redirects to slip past email security filters and land victims on credential harvesting sites.
- Barracuda uncovered an attack that generates phishing pages directly in a victim’s browser session using blob URLs, rendering standard blocklists ineffective. The visual navigation remains within trusted Microsoft services, which hides malicious activity from both users and scanners.
Other Significant Stories
Shadow AI is now officially flagged by the U.K.’s National Cyber Security Center. The agency warns that employee-use of unapproved AI tools could unknowingly expose sensitive corporate data. The lack of visibility and the potential for exploitation of tool vulnerabilities are the biggest risks.
Another trend: large-scale social engineering. One case involves fake M&A offers sent to legal teams, using WhatsApp and personal email to arrange wire transfers through forged documents. Victims spanned private equity, industrial finance, sales, mining, and energy sectors.
Crypto security continues to be sticky. After an email provider’s breach exposed customer info, hardware wallet maker Trezor warns of wallet-themed phishing attempting to steal both credentials and backup data.
Lastly, exposed network servers still pose huge risks. Over 33,800 Plex instances remain vulnerable after recent disclosures, with nearly 20,000 located in North America alone. These servers could be exploited if not secured properly.
Across all these incidents, a recurring theme is clear: threat actors are abusing trust—of extensions, infrastructure, credentials—to gain access. What’s allowed in often becomes what attackers target.
What this means: The scale of these attacks shows that even well-known platforms and services are weak links when it comes to security. Organizations and individuals must stay on top of patching, limit permissions for browser extensions and third-party tools, and remain hyper-aware of social engineering tricks.