Android patches and browser-based phishing define the latest threat wave

Google’s September 2026 Android security updates address 200 vulnerabilities, including CVE-2026-28662, a critical Wi-Fi memory-corruption flaw that could allow remote code execution without user interaction. The release arrived amid a broader set of incidents involving browser-mediated phishing, malicious extensions, exposed services and compromised software packages.
Google also moved Chrome to a two-week cadence for major milestones and weekly security updates. The company said the change responds to a growing volume of patches and updates associated with LLM-assisted vulnerability discovery, with the aim of reducing the interval between a public fix and its deployment to users.
Patch exposure remains a direct operational risk
CVE-2026-28662 stands out because it is Wi-Fi related and could potentially permit remote code execution without additional privileges or user interaction. Jamf enterprise strategy manager Adam Boynton said devices left unpatched would remain at risk and urged organisations to issue the update across their fleets as soon as possible.
Internet-facing systems show the same problem at a different layer. Shadowserver Foundation data identified more than 33,800 exposed Plex servers susceptible to recently disclosed flaws, down from 37,467 on September 5. Nearly 20,000 of those instances were in North America.
The patching pressure also extends to browsers. In a related update cycle, Chrome flaws and attacks on SonicWall, SaaS and DNS illustrates how browser vulnerabilities can intersect with attacks on SonicWall, SaaS environments and DNS infrastructure, while the current Chrome schedule change is designed to narrow the patch gap for users.
Trusted services are being turned into phishing infrastructure
KnowBe4 Threat Lab described a phishing campaign that led victims through six legitimate Google properties—Meet, Search, DoubleClick, Programmable Search Engine, Image Search and Tag Manager—before reaching credential harvesters or remote-access tools. The route was intended to bypass email security filters by making each stage appear to use familiar infrastructure.
Barracuda separately reported a DocuSign-themed campaign in which the phishing page is generated in the victim’s browser through blob URLs. Because the page exists only in that browser session, there is no persistent phishing URL for security tools to retrieve, analyse or blocklist in advance. The visible navigation can remain within trusted Microsoft services, reducing common warning signs for users and scanners.
The reporting also documented a 159% increase in phishing sites using the .vu top-level domain, alongside 1,660 unique domains and more than 28,000 malicious emails recorded from April through July 2026. Microsoft plans to obscure QR-code images from external senders in Teams by default, requiring recipients to reveal them before viewing or scanning.
Ordinary access paths need stronger checks
Four malicious Chrome and Firefox extensions targeting Axiom Trade and Padre users were found collecting session tokens, wallet-related data, Firebase access tokens and application state. Socket said the data was sent to attacker-controlled Vercel deployments. Separately, 13 malicious wallet-related packages were identified on npm, prompting a warning that a machine running an affected package should be treated as fully compromised.
For businesses, the immediate implication is to combine rapid Android and browser patching with inventory of exposed services, extension allow-listing, package controls and phishing defences that evaluate redirect chains and browser behaviour. Familiar platforms and legitimate-looking workflows should not be treated as sufficient evidence of trust.

