ThreatsDay Roundup: 200 Android Flaws, AI-Driven Attacks, and E-commerce Scams Highlighted
A comprehensive ThreatsDay report details a wide array of cyber threats, including numerous Android vulnerabilities, sophisticated AI-powered intrusions, and a massive network of fake e-commerce shops.

This week's security landscape is marked by a recurring theme: the exploitation of basic, often preventable, security oversights. A new ThreatsDay report, compiled by The Hacker News, underscores this by detailing a broad spectrum of cyber threats, from hundreds of Android flaws to advanced AI-driven attacks and a vast operation involving fake online stores.
The report highlights the persistent issue of excessive permissions granted to browser extensions, with four malicious extensions identified targeting cryptocurrency users. These extensions, including J7Tracker, VREO, and Orbit Tracker for Google Chrome and Mozilla Firefox, were found to steal session tokens and wallet data by exfiltrating information to attacker-controlled servers. This tactic leverages the trust users place in browser add-ons, turning them into tools for financial theft.
Further complicating the threat environment, sophisticated threat actors are leveraging artificial intelligence to automate cyber intrusions. Chinese-speaking operators have been observed using AI models like Anthropic Claude Code and Alibaba Qwen to target government and financial systems across Afghanistan, Thailand, Taiwan, and the United States. These actors employ an AI orchestration framework called SecFlow, which delegates tasks like reconnaissance, exploitation, and data collection to specialized AI agents, enabling rapid and widespread attacks against known vulnerabilities such as Shellshock, Spring4Shell, and Log4Shell.
The proliferation of AI also introduces new risks through "shadow AI" usage within organizations. The UK's National Cyber Security Centre (NCSC) has warned that employees using unapproved AI tools can inadvertently expose sensitive corporate data, leading to potential data breaches, intellectual property loss, and regulatory non-compliance. The inherent security vulnerabilities within AI agents themselves pose a significant risk, potentially granting attackers access to the same data and privileges as the legitimate AI service.
Beyond technical exploits, the report also sheds light on large-scale e-commerce fraud. A massive operation dubbed DoppelCart has been uncovered, utilizing over 119,000 domains to host fake online shops. These sites meticulously mimic legitimate businesses, stealing payment card details from unsuspecting shoppers. This operation exemplifies how attackers exploit the convenience of online shopping for widespread financial gain.
In a different vein, attackers are also employing social engineering tactics through fake merger and acquisition (M&A) deals. By impersonating executives and using forged acquisition documents, threat actors trick legal teams into communicating via less secure channels like WhatsApp and personal email, ultimately aiming to initiate fraudulent international wire transfers.
On the defensive front, Microsoft is introducing new age-awareness APIs for Windows 11, allowing applications to infer user age groups without collecting precise birth dates, thereby enhancing child privacy. However, the sheer volume and diversity of threats detailed in the ThreatsDay report, from malicious extensions and AI-driven attacks to elaborate phishing schemes and fake e-commerce operations, underscore the ongoing challenges in maintaining robust cybersecurity defenses.