Robinhood account creation flaw abused to send phishing emails

2026-04-28T01:23:28Z4a7866b8b33aa96445177adf7bb6ec6dba4d0a30a4c1d4f35d49bc8588e2a0c4
browser-extensioncredential-theftdata-breachdeepfake-voiceexfiltrationglassworminfostealermalwareopenvsxphishingpypiransomware/extortionremote-access-backdoorsms-spoofingsocial-engineeringsupply-chaintelecom-impersonationtelemetry-outageunc6692

What happened

Multiple high-impact security stories: a Robinhood account-creation flaw was abused to inject phishing content into legitimate emails; supply-chain attacks resurfaced with GlassWorm using 73 malicious OpenVSX "sleeper" extensions and a PyPI package (elementary-data) pushed an infostealer to ~1.1M monthly users; major breaches and data exposures include ADT (5.5M affected), Medtronic (claiming ~9M records), and an Itron internal IT breach. Additional threats: UNC6692 deploying new “Snow” malware via Microsoft Teams, a rise in deepfake voice fraud, an SMS‑blaster operation disrupted in Toronto,及

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
4a7866b8b33aa96445177adf7bb6ec6dba4d0a30a4c1d4f35d49bc8588e2a0c4
Enrichment time
2026-04-28T01:23:28Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Robinhood account creation flaw abused to send phishing emails · Baitaphish