"Most concerning from this list is CVE-2026-28662 because it's a Wi-Fi-related memory corruption flaw," Adam Boynton, enterprise strategy manager at Jamf, said. That blunt warning sits alongside a week of attacks and misconfigurations that share a common theme: ordinary access and trusted services doing far more than they should.
CVE-2026-28662 and the September Android security sweep
Google's September 2026 Android security update patched 200 vulnerabilities, including critical and high-severity issues that could permit remote code execution without user interaction. The bulletin highlights CVE-2026-28662, a Wi‑Fi–related memory corruption flaw that Jamf's Adam Boynton called "most concerning" because it could enable remote code execution and privilege escalation if devices remain unpatched. The practical take-away in the advisory is simple and repeated across other incidents this week: these risks persist only when devices are left unpatched.
Malicious browser extensions target Axiom Trade and Padre users
Security researchers traced four malicious extensions—J7Tracker and VREO for Chrome, and VREO and Orbit Tracker for Firefox—that steal session tokens and wallet data for Axiom Trade and Padre users. Socket reported that "the module is byte-identical across all three analyzed extensions," automatically retrieving authenticated user information, wallet bundle data, Firebase access tokens and application state, then sending the data to threat-actor controlled Vercel deployments. The same Chrome publisher was linked to earlier impersonating extensions, GhostApe and GhostApe Color, which mimicked a MockApe trading add-on, illustrating how extension ecosystems can be repurposed to harvest credentials and keys.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleAI orchestration: SecFlow, GLUTTON, SecBox and hands-on follow-up
Hunt.io documented a Chinese‑speaking operator using multiple LLMs—Anthropic Claude Code, Alibaba Qwen and DeepSeek—tied together by an orchestration framework called SecFlow to automate intrusions across targets in Afghanistan, Thailand, Taiwan, the U.S., and elsewhere. SecFlow split reconnaissance, exploitation, collection and reporting among specialized AI agents and supplied them tools, target information, shared storage and network routes. The campaign exploited long-known vulnerabilities—Shellshock, Spring4Shell, Ghostcat, Shiro deserialization, Log4Shell, among others—then used a GLUTTON capability to generate web shells. From those footholds the actor deployed SecBox, a Go‑based remote access and pivoting framework, and performed follow-on activity including privilege escalation and credential theft. The DFIR Report also described a chain that delivered EtherRAT via a malicious MSI, then installed an AI-generated framework called TukTuk, exfiltrated data to a cloud service, and deployed The Gentlemen ransomware after lateral movement using GoTo Resolve.
DoppelCart: 119,000 domains cloning brands to steal cards
Netby exposed a sprawling operation named DoppelCart that powers more than 119,000 domains running fake e‑commerce shops. The networks mimic 44,182 different brands—typically two clones per brand—copying product catalogs, descriptions, images and in some cases loading assets directly from the real companies' servers. Each fake shop republishes the brand’s legitimate support address so victims complain to the brand, not the malicious operator, and undercuts real prices to bait purchases and collect card details at scale.
Multi-hop phishing: Google services, blob URLs and PhaaS
Phishing campaigns this week used two clever evasions. KnowBe4 Threat Lab observed campaigns routing victims through a deliberate chain of legitimate Google services—Meet, Search, DoubleClick, Programmable Search Engine, Image Search and Tag Manager—to land users on credential harvesters or deliver remote access tools, a technique that helps bypass email security filters. Barracuda described DocuSign-themed pages generated inside the victim’s browser using blob URLs, which leave no persistent phishing URL for blocklists to find because the page exists only in the browser session. CloudSEK reported that a rebranded Evilginx2-based PhaaS, BigBear 2.0, has exfiltrated 5,137 credential records—474 complete MFA‑bypassed authentications, 1,032 plaintext passwords and 4,148 session cookies—affecting 3,331 unique victim IPs across 40+ countries, underlining how session-centric phishing and multi-hop redirects let adversaries keep and reuse sessions rather than just passwords.
What this means for technologists, policymakers, and consumers
- Technologists and security teams: expect intrusion chains that begin with trusted artifacts—extensions, npm packages, blob URLs, third‑party services—and escalate through automated AI agents. Priorities from the reporting include rapid patch deployment (Android updates), tighter extension and package vetting, and controls that limit what third‑party or scripted components can access.
- Policymakers and regulators: incidents that misuse trusted platforms—email providers, cloud services, and browser ecosystems—highlight the regulatory challenge of defining and enforcing responsibility across service providers, extension marketplaces and orchestration frameworks. The NCSC warned that shadow AI use reduces visibility and increases data‑breach risk.
- Consumers and end users: cloned shops, phishing routed through legitimate services, and compromised email lists (Trezor’s Brevo incident affected about 347,000 addresses) all point to a simple user risk: credible‑looking content can be weaponized. Vigilance about links, QR codes, and unexpected install prompts remains necessary.
The week’s record is less about novel exploits than about familiar objects doing unfamiliar damage: extensions, packages, redirects, sessions and AI agents with too much trust. As the closing note in the bulletin put it, "Stop giving ordinary things unlimited trust." That observation—plain, precise and repeatable—may be the most actionable guidance of all.




