ThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Stories

Executive Summary

The article highlights a week of security incidents, noting 200 Android vulnerabilities, a browser‑built phishing scheme, and 119,000 scam shops. It also covers 23 additional stories, including over‑privileged extensions, a trusted service used in phishing, a lingering old bug, and an exposed system that remained vulnerable. The common theme is that many flaws were allowed to persist due to overlooked access paths and insufficient oversight.


Intelligence Metadata - Source Publisher: The Hacker News - Published Date: 2026-09-10T17:47:38+00:00 - Category: threat-intel

Original Description: A lot of this week’s security news has the same awkward answer to one question: “Why was that allowed to work?” An extension asks for access and takes too much. A trusted service becomes part of a phishing chain. An old bug still gets results. An exposed system stays exposed. A package looks useful right up until it isn’t. Different stories, same basic problem: the path in was often already

"Imagination is not a talent of some men but is the health of every man."

— Ralph Waldo Emerson
Source: The Hacker News