Google Patches 200 Android Flaws in September Security Update

Google Patches 200 Android Flaws in September Security Update

Google's September 2026 Android update fixes 200 flaws, including a critical Wi-Fi bug that allows remote code execution; also phishing, fake shops, exposed ser…

Google has released the September 2026 Android security update, which patches 200 vulnerabilities, including a critical Wi-Fi-related flaw that could allow remote code execution without user interaction. The most concerning issue, according to Adam Boynton, enterprise strategy manager at Jamf, is CVE-2026-28662, a memory corruption bug in Wi-Fi handling. If left unpatched, an attacker could exploit it to run code remotely without extra privileges or the victim clicking anything, and possibly escalate privileges on the device. Boynton stressed that organizations should push the update to device fleets as soon as possible.

Google also announced a shift to a two-week cadence for major Chrome milestones, with weekly security updates. The company says this is a response to a changing cybersecurity landscape in the AI era, where large language model (LLM) assisted vulnerability discovery has increased the volume of patches. Google points out that finding and fixing more bugs is not a sign of failure; every bug fixed removes a foothold for attackers. The shorter release cycle is designed to reduce the patch gap, the time between a vulnerability becoming known and a fix reaching end users. Google moved Chrome to a four-week cycle in 2021, down from six weeks, and other browser makers such as Microsoft, Mozilla, and Brave have made similar moves.

A separate report from Socket describes four malicious browser extensions that steal cryptocurrency session tokens and wallet data from users of Axiom Trade and Padre. The extensions are J7Tracker for Chrome, VREO for Chrome and Firefox, and Orbit Tracker for Firefox. Socket says the data collection module is byte-identical across the first three, and it automatically retrieves authenticated user information, wallet-related bundle data, Firebase access tokens, and application state, then sends that information to attacker-controlled Vercel deployments. The fourth extension uses a different collector but targets the same data and retains artifacts from J7Tracker. The same Chrome publisher has been linked to two earlier extensions, GhostApe and GhostApe Color, which impersonated the MockApe trading add-on.

Cryptocurrency hardware wallet maker Trezor warned customers about phishing emails after its third-party email provider Brevo suffered a breach affecting 120 accounts, including Trezor's. The incident exposed Trezor's opt-in newsletter database, roughly 347,000 email addresses. Attackers sent a phishing email titled 'Critical Security Alert: STM32 Entropy Vulnerability' from the compromised account. The email contained a malicious link that told users to download an app and enter their wallet backup. Trezor has suspended the Brevo account to stop further abuse, and the malicious domain has since been taken down.

A large fake e-commerce operation called DoppelCart has used more than 119,000 domains to run a network of fraudulent shops that steal payment card details. According to Netby, the shops copy product catalogs, descriptions, branding, and images from real businesses, sometimes loading assets directly from the legitimate company's servers. In total, the fake shops imitate 44,182 different brands, with a median of two clones per brand. Each clone undercuts the real brand's prices and republishes the brand's own support address, so victims who are charged complain to the real company instead of the fraudsters.

Shadowserver Foundation data shows more than 33,800 exposed Plex servers remain vulnerable to recently disclosed flaws. That number is down from a high of 37,467 on September 5, 2026, but it still leaves a large attack surface. Nearly 20,000 of those instances are in North America. Plex is a media server application, and exposing it directly to the internet without patching can let attackers reach known vulnerabilities.

The DFIR Report details an attack chain that begins with a malicious MSI installer disguised as a Sysinternals tool. The installer drops EtherRAT, and the intrusion later delivers an AI-generated malware framework called TukTuk and the legitimate remote management tool GoTo Resolve. TukTuk can use the Arweave blockchain as a dead-drop resolver: the implant queries the blockchain for a specific Drive-Id, then retrieves an encrypted configuration blob containing credentials for its command and control channels. After gaining access, the attacker performed hands-on-keyboard activity, Kerberoasting, and credential discovery against administrative accounts, then used compromised service account credentials to deploy GoTo Resolve laterally across servers and domain controllers. The final stage was data exfiltration to a cloud service and deployment of The Gentlemen ransomware.

The U.K. National Cyber Security Centre (NCSC) has warned that employees using unapproved AI tools can expose sensitive corporate data and create risks that organizations may struggle to detect and manage. The NCSC says providing shadow AI access to company or customer data likely increases the risk of data breaches, intellectual property loss, and regulatory failure. AI agents are complex software and can have critical security vulnerabilities; if an attacker exploits one, they can gain the same data, services, and privileges the agent legitimately has.

Hunt.io reported on a Chinese-speaking operator using Anthropic Claude Code, Alibaba Qwen, and DeepSeek to automate intrusions against government and financial systems in Afghanistan, Thailand, Taiwan, and the United States. Targets included Taiwan's Kuomintang Party History Archives, Indonesia's Ministry of Foreign Affairs, government and education systems in mainland China, and industrial hosts in Da Nang, Vietnam. The attacker used SecFlow, an AI orchestration framework, to convert campaign objectives into tasks for specialized AI agents, splitting reconnaissance, exploitation, collection, and reporting among specialist workers. Exploited vulnerabilities included Shellshock, Spring4Shell, Ghostcat, Shiro deserialization, Log4Shell, Grafana and Nexus path traversals, and a Nacos authentication bypass. After exploitation, the attacker deployed web shells generated through a dedicated GLUTTON capability, then performed reconnaissance, privilege escalation, credential theft, and custom implant deployment. One backdoor, SecBox, is a Go-based remote-access and network-pivot framework. Details of the campaign first came to light in July 2026.

Gen Digital described a phantom deal fraud campaign in which attackers pose as executives and trick legal team targets into moving conversations to WhatsApp and personal email. The goal is to initiate international wire transfers using forged acquisition documents as part of a merger and acquisition scam. Targets included senior people in private equity, industrial finance, sales, mining, and energy. The documents followed substantially the same sequence of sections and reused the same legal language, imposed confidentiality, directed communication

How to Protect Yourself

  1. Update your phone and browser as soon as new versions are available to close known security holes.
  2. Remove browser extensions you do not recognize, especially any that ask for wallet or account data.
  3. Before buying online, check the web address carefully for lookalike shop names and avoid prices that seem too good to be true.
  4. If an email asks you to download an app or enter a wallet backup, ignore the link and go directly to the official website.
  5. Keep home media servers and routers updated, and do not expose them directly to the internet unless you must.
  6. Use a secure DNS service that can block known malicious websites by default.

Vulnerabilities & Fixes

  • CVE-2026-28662 A critical Wi-Fi-related memory corruption flaw in Android patched in the September 2026 security update, which could allow remote code execution without user interaction. View the fix & details →

Terms Explained

  • remote code execution When an attacker can run their own commands on a device or server without the owner's permission.
  • memory corruption A type of software bug where a program wrongly changes data in memory, often allowing attackers to take control.
  • session token A small piece of data that proves you are logged in, which attackers can steal to access your account.
  • patch gap The time between a security fix being created and users actually installing it.
  • web shell A small hidden script placed on a server that lets an attacker control it remotely through a web browser.
  • ransomware Malicious software that locks or steals data and demands payment to restore access.
  • CVE Common Vulnerabilities and Exposures, a public list that gives each known security flaw a unique number.

Related AEU services

  • AEU-I IT and security consulting