Weekly Cybersecurity Roundup: Android Bugs, AI-Assisted Intrusions and Fake Store Networks

This week’s cybersecurity developments highlighted familiar weaknesses: excessive application permissions, unpatched internet-facing systems, abuse of trusted services, and social-engineering campaign...

This week’s cybersecurity developments highlighted familiar weaknesses: excessive application permissions, unpatched internet-facing systems, abuse of trusted services, and social-engineering campaigns built around believable business scenarios.

Malicious browser extensions target cryptocurrency users

Researchers identified four Chrome and Firefox extensions aimed at users of the Axiom Trade and Padre platforms. The add-ons reportedly collected authenticated session information, wallet-related data, Firebase tokens and application state before sending it to attacker-controlled infrastructure. Several of the extensions shared a nearly identical data-collection component, while the publisher was also linked to earlier add-ons impersonating a trading-related extension.

AI tools reportedly used in intrusion campaigns

A Chinese-speaking threat actor has allegedly used several AI coding and language models, along with an orchestration framework, to automate portions of attacks against government, education, financial and industrial targets across Asia and the United States. Researchers said the operation divided reconnaissance, exploitation, data collection and reporting among automated agents. The activity involved exploitation attempts against longstanding vulnerabilities, including Log4Shell, Shellshock and Spring4Shell, followed by web shell deployment and use of a Go-based remote-access tool.

Warnings over unapproved AI use

The UK National Cyber Security Centre cautioned organizations that “shadow AI” can lead employees to submit confidential business or customer information to services outside approved controls. The agency said this can reduce visibility over sensitive data and introduce additional risks if AI agents or connected services contain exploitable flaws.

Fraud campaigns and large-scale scam storefronts

Security analysts also described a business-email fraud campaign in which attackers pose as executives or advisers discussing confidential mergers and acquisitions. Targets are encouraged to continue conversations through personal email accounts or WhatsApp before receiving forged documents and wire-transfer requests.

Separately, investigators reported that a fake online-shop network known as DoppelCart uses more than 119,000 domains. The sites imitate tens of thousands of brands, copying product descriptions, imagery and support information while advertising unusually low prices. The operation is designed to capture payment-card details, and the use of legitimate companies’ contact details can divert victim complaints away from the fraudulent storefronts.

Google has meanwhile moved Chrome to a two-week major-release schedule with weekly security updates, citing an increasing pace of vulnerability discovery and remediation. Microsoft is also introducing Windows 11 age-awareness APIs intended to let apps receive broad age categories without accessing a user’s full date of birth.