Robinhood account creation flaw abused to send phishing emails

2026-04-28T07:23:28Z75511f09a37dbb4c291cda07216c913c7d13c4ef6755ae58fcd3e567eae1d5da
adtdata-breachdeepfake-voiceemail-phishingespionageextensionsextraditionglassworminfostealeritronmedtronicopenvsxoutlook-outagepackage-tamperingphishingpyPIsilk-typhoonsmishingsms-phishingsnow-malware','browser-extension','tunneler','backdoorsocial-media-fraudsoftware-supply-chainsupply-chain-compromiseunc6692voice-cloning

What happened

BleepingComputer roundup (27 Apr 2026) covering multiple high-impact incidents: a Robinhood account‑creation flaw was abused to inject phishing content into legitimate emails; GlassWorm resurfaced via 73 “sleeper” OpenVSX extensions that go malicious after updates; three arrested in Toronto for operating an “SMS blaster” (fake cell‑tower) used to send phishing texts; a suspected Silk Typhoon operator extradited to the U.S. for alleged cyberespionage; the FTC reports Americans lost over $2.1B to social‑media scams in 2025; a popular PyPI package (elementary-data) was backdoored to distribute an

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
75511f09a37dbb4c291cda07216c913c7d13c4ef6755ae58fcd3e567eae1d5da
Enrichment time
2026-04-28T07:23:28Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Robinhood account creation flaw abused to send phishing emails · Baitaphish