<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[ThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Stories]]></title><description><![CDATA[<p dir="auto">This week's security roundup keeps circling back to one uncomfortable question: how did any of this get through? An extension asks for more access than it needs and gets it. A trusted service quietly becomes a link in a phishing chain. An old bug still delivers results. An exposed system stays exposed. A package looks legitimate right up until it isn't.</p>
<p dir="auto">The common thread across these stories is that the way in rarely required anything sophisticated. <strong>200 Android flaws</strong> headline the week's collection, alongside phishing campaigns assembled entirely inside the browser and a sprawling network of <strong>119,000 scam shops</strong>. The roundup also bundles in <strong>23 additional stories</strong> covering the broader threat landscape.</p>
<p dir="auto">A few patterns worth noting from the collection:</p>
<ul>
<li>Extensions and packages that appear useful until they turn malicious</li>
<li>Trusted services being abused as part of phishing infrastructure</li>
<li>Long-patched vulnerabilities that remain effective because systems were never updated</li>
<li>Exposed systems that simply stay exposed</li>
</ul>
<p dir="auto">The recurring lesson is that exposure often persists not because attackers are clever, but because basic hygiene gets skipped.</p>
<p dir="auto">Source: <a href="https://thehackernews.com/2026/09/threatsday-200-android-flaws-browser.html" target="_blank" rel="noopener noreferrer nofollow ugc">The Hacker News</a></p>
<p dir="auto">Which of these exposure patterns does your organization struggle with most, and how are you addressing it?</p>
]]></description><link>https://xploitlk.com/topic/293/threatsday-200-android-flaws-browser-built-phishing-119k-scam-shops-23-more-stories</link><generator>RSS for Node</generator><lastBuildDate>Sat, 12 Sep 2026 05:34:06 GMT</lastBuildDate><atom:link href="https://xploitlk.com/topic/293.rss" rel="self" type="application/rss+xml"/><pubDate>Fri, 11 Sep 2026 04:30:20 GMT</pubDate><ttl>60</ttl></channel></rss>