The record
Written from the 1 report below. Nothing here is unsourced.
- This week's ThreatsDay bulletin covers more than two dozen cybersecurity stories, including malicious browser extensions, AI-automated intrusions, data breaches, and software vulnerabilities.
- Four malicious Chrome and Firefox extensions were found stealing session tokens and wallet data from Axiom Trade and Padre users, with the same publisher linked to two earlier fake trading add-ons.
- A Chinese-speaking operator used AI tools including Anthropic Claude Code, Alibaba Qwen, and DeepSeek to automate intrusions against government and financial systems in Afghanistan, Thailand, Taiwan, and the U.S.
- The U.K.'s NCSC warned that employees using unapproved AI tools can expose sensitive corporate data and increase the risk of breaches and intellectual property loss.
- A scam operation called DoppelCart is running more than 119,000 fake e-commerce domains mimicking 44,182 brands to steal payment card details, showing how readily available access and trust are being exploited by attackers.
What to watch next
- Whether Google and Mozilla remove the malicious extensions J7Tracker, VREO, and Orbit Tracker from their stores.
- Further details on the SecFlow AI orchestration framework and the campaign it enabled, first reported in July 2026.
- Expansion or takedown of the DoppelCart network of 119,000 fake e-commerce domains.
Coverage1
1 report
English national1
All filed from India
Named Afghanistan · Thailand · Taiwan · United States · China · Indonesia · Vietnam · United Kingdom · Singapore · Brevo · Trezor · Alibaba · Anthropic · DeepSeek · Gen Digital · Google · Microsoft · Mozilla · National Cyber Security Center · Netby · Shadowserver Foundation
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
