200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Stories

200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Stories

Ravie LakshmananSep 10, 2026Hacking News / Cybersecurity News

A lot of this week’s security news has the same awkward answer to one question: “Why was that allowed to work?”

An extension asks for access and takes too much. A trusted service becomes part of a phishing chain. An old bug still gets results. An exposed system stays exposed. A package looks useful right up until it isn’t. Different stories, same basic problem: the path in was often already there.

Nothing here needed magic. Mostly access, trust, weak edges, and someone willing to keep poking. That’s the week.

The threats change every week. Subscribe, and we’ll alert you when each new ThreatsDay Bulletin is out.

The lesson this week is smaller than “patch faster.” Stop giving ordinary things unlimited trust. Extensions, packages, redirects, sessions, AI tools, exposed services — most of the trouble begins when something familiar is allowed to do too much.

Security still breaks at the boring handoffs: what gets access, what stays exposed, what gets inherited, and what nobody checks twice. Attackers do not need every door open. One lazy hinge is enough. That is probably the part worth remembering after the headlines disappear.

Source link

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply

Your email address will not be published. Required fields are marked *