THREATSDAY’S current bulletin aggregates a broad spectrum of security incidents and research highlights from the week, underscoring a common thread: the path of least resistance is often a familiar, trusted vector. The piece flags multiple notable cases, from Android and browser exploits to supply-chain and social-engineering campaigns, emphasising that attackers frequently exploit ordinary operations—extensions, sessions, exposed services, and misconfigurations—rather than requiring spectacular zero-days.
Among the concrete items, Google released Android security updates patching 200 flaws, including CVE-2026-28662, a critical Wi‑Fi‑related memory corruption flaw that could allow remote code execution without user interaction. The report also notes a sprawling DoppelCart network using over 119,000 domains to host fake shops, plus more than 33,800 exposed Plex servers with recently disclosed flaws.
Other highlighted threads include AI-enabled intrusion campaigns, phishing techniques abusing legitimate Google properties, and a rise in PhaaS-style MFA-bypass campaigns. Additional themes cover exposed routers (MikroTik SSH without authentication), Windows age-awareness APIs, and a notable NIL of “boring handoffs” where access, exposure, and trust decisions create attack surfaces.
The piece repeatedly stresses that practical defence hinges on tightening access, reducing exposure, and auditing handoffs, since attackers need only a single vulnerable hinge to compromise a system.