Robinhood account creation flaw abused to send phishing emails
2026-04-28T01:23:28Z•4a7866b8b33aa96445177adf7bb6ec6dba4d0a30a4c1d4f35d49bc8588e2a0c4
browser-extensioncredential-theftdata-breachdeepfake-voiceexfiltrationglassworminfostealermalwareopenvsxphishingpypiransomware/extortionremote-access-backdoorsms-spoofingsocial-engineeringsupply-chaintelecom-impersonationtelemetry-outageunc6692
What happened
Multiple high-impact security stories: a Robinhood account-creation flaw was abused to inject phishing content into legitimate emails; supply-chain attacks resurfaced with GlassWorm using 73 malicious OpenVSX "sleeper" extensions and a PyPI package (elementary-data) pushed an infostealer to ~1.1M monthly users; major breaches and data exposures include ADT (5.5M affected), Medtronic (claiming ~9M records), and an Itron internal IT breach. Additional threats: UNC6692 deploying new “Snow” malware via Microsoft Teams, a rise in deepfake voice fraud, an SMS‑blaster operation disrupted in Toronto,及
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 4a7866b8b33aa96445177adf7bb6ec6dba4d0a30a4c1d4f35d49bc8588e2a0c4
- Enrichment time
- 2026-04-28T01:23:28Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.