HTTPS protects the CONTENT of what you send, so a café network cannot read your password on a properly secured site. What it can still do is see which sites you visit, and a fake hotspot named "Free_Airport_WiFi" can serve you a convincing fake login page.
Most updates patch holes that are already public knowledge and already being exploited. Delaying them for weeks is the single most common reason ordinary devices get compromised. Turn on automatic updates for the OS and the browser.
A cracked APK from a link in a group chat is the classic way phones get infected. And when installing anything, read the permissions: a torch app requesting your contacts and SMS is not a torch app.
A PIN or biometric on the phone and laptop. Most real-world data loss is not sophisticated hacking. It is an unlocked device left on a table.
Sign out of every account, then do a full factory reset. Deleting files is not enough; a reset with encryption enabled is.