⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More
Multiple zero-day vulnerabilities exploited in Chrome and MikroTik RouterOS, alongside a supply chain attack.
Summary
This week's recap highlights critical security developments including a zero-day vulnerability in Google Chrome (CVE-2026-85046) that is actively being exploited, allowing for arbitrary code execution. MikroTik RouterOS is also facing active exploitation of two zero-day flaws (part of the MikroTrick chain) that can lead to full device control. Additionally, a supply chain attack has been reported where a trusted software source delivered malicious code, and attackers found a workaround for email image blocking using QR codes.
Full text
⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More Ravie LakshmananSep 07, 2026Cybersecurity / Hacking Turning off email images should at least stop the pictures. This week, attackers had a workaround: a scannable QR code built out of text. It still appears, even with images blocked. A small detail, but an annoying one if that was a precaution you were counting on. Elsewhere, a trusted software source delivered code that stole credentials, and a protocol designed for secure network management gave outsiders useful clues before login. Add active attacks on browsers, routers, and online stores, and there’s plenty to check—even for teams that have kept up with the patches. Read the full recap for the week’s major developments, plus more research, attacks, and security news beyond what we covered last week. ⚡ Threat of the Week N-able Patches Critical N-central Flaws — N-able has released hotfixes to address two severe N-central flaws (CVE-2026-86206 and CVE-2026-86207) that could allow an unauthorized party to bypass authentication controls and gain full access to the platform. Also patched is a maximum-severity security flaw (CVE-2026-86218, CVSS score: 10.0) that could allow for pre-authenticated remote code execution on the N-central server. "At this time, we have no confirmation that these vulnerabilities have been exploited in production environments, but unpatched systems remain at risk," N-able said. However, Huntress said it observed signs that attackers are likely leveraging CVE-2026-86206 or/and CVE-2026-86207, after it launched an investigation on September 4 following the compromise of a customer's fully patched N-central production environment. "However, due to limited historical logging available directly on the appliance, we cannot definitively confirm which specific exploit the threat actor used to achieve their compromise, nor can we rule out the use of alternative vulnerabilities," it said. AI Spend Out of Control? There's a Path Forward Imagine you’ve received a water bill for 500,000,000 gallons. Now, you have to account for every teaspoon of that water. IT leaders face a similar task when managing AI budgets, and it’s not as simple as token caps or model limits. Learn how your team can optimize your company's AI spend. Learn More ➝ 🔔 Top News Google Warns of Chrome 0-Day Under Attack — Google released security updates to patch 12 vulnerabilities, including one that has come under active exploitation in the wild. The high-severity vulnerability, tracked as CVE-2026-85046 (CVSS score: 8.8), has been described as a type confusion bug in V8, Chrome's JavaScript and WebAssembly engine. "Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page," according to a description of the flaw in CVE.org. Security researcher Salvatore Gulizia (aka Serotav) has been credited with discovering and reporting the flaw on August 4, 2026. As is usual in these cases, Google acknowledged that an "exploit for CVE-2026-85046 exists in the wild," but did not reveal any details about the nature of the attacks or who is behind them. With the latest development, Google has addressed a total of six actively exploited Chrome zero-days since the start of the year. MikroTik RouterOS Flaws Exploited — The CERT Polska Team warned that bad actors are actively exploiting two zero-day flaws in MikroTik RouterOS that could be combined to take full control of the device without authentication if the device supports remote access using the SSH protocol. The exploit chain has been codenamed MikroTrick. A total of fix flaws (CVE-2026-67276, CVE-2026-67277, CVE-2026-67278, CVE-2026-67279, CVE-2026-67281, and CVE-2026-86060) have been identified. The MikroTrick chain involves CVE-2026-67276 and CVE-2026-86060 (CVSS scores: 9.2), which can allow an attacker to bypass authentication and elevate their privileges. The issues have been fixed in versions 6.49.21 (Long-term), 7.23.4 (Long-term), and 7.24.2 (Stable). "The successful attacks observed so far, including the creation of the 'ops' account, originated from the IP address 82.192.72.4 and have been occurring since at least 2 September," CERT Polska said. "In addition, the IP address 103.102.31.18 was used in attempts to exploit the described chain." Unpatched Magento and Adobe Commerce 0-Day Exploited to Backdoor Online Stores — E-commerce storefronts are being compromised to inject a backdoor by exploiting an unpatched Magento and Adobe Commerce zero-day dubbed StyleSmuggler, which gives unauthenticated attackers remote code execution. The attacks commenced on September 4, 2026. "StyleSmuggler injects malicious code into Magento's template system," Sansec said. "By using the styles properties, it can evade existing safeguards. It works in two stages: (1) Inject (poison) PHP code, for example by generating a failure report, and (2) Let Magento execute the poisoned code via a failed payment email." The backdoor is a Rust program that connects to the "99.84.67[.]186" C2 server and waits for further instructions. There are currently no indications that the backdoor has been weaponized. There are two different variants named fc-cache and chronyd. A separate attack cluster has been found to leverage the same weakness to drop a PHP web shell into the product image cache. RevStealer Spreads via Game Cheats and Fake Claude Desktop App — Elastic and Morphisec disclosed details of RevStealer (aka REF2859), a Windows information stealer that comes with an embedded sandbox scoring system and Polygon blockchain-based dead drop for resilience, a technique also called EtherHiding. "Beyond credential theft, REVSTEALER targets gaming platforms for additional monetization; the developer clearly understands that victim accounts on these platforms hold real monetary value in resale markets," Elastic said. The malware is distributed via social engineering attacks, using YouTube videos claiming to advertise hacks for the Albion Online game or rogue GitHub repositories for Anthropic's Claude Opus 5 Free Desktop project. Once installed, the stealer can receive additional executable content through C2 tasks, including additional executable content through (for wallet-file and browser-extension theft, phishing overlays, password-aware input capture, and payload delivery), WinUpdate (for cryptocurrency-address replacement and mnemonic-shaped clipboard theft), SoftManager (for reverse SOCKS5 proxy and backconnect access over an encrypted WebSocket protocol), and LockAppHost (for XMRig deployment, competitor suspension, and persistence). OpenAI Agents Keep Going Rogue — OpenAI is once again in hot water after a swarm of agents self-identifying as from the AI startup hijacked a German website as early as May and used it as a bulletin board for other AI agents. The agent swarm is said to have taken over the obscure German-language wiki in May and June to make around 18,000 posts, relying on it to coordinate on evaluations and swap methods to evade OpenAI’s own controls. The revelations come days after OpenAI published its own detailed account of July's Hugging Face breach in which another swarm of OpenAI agents worked together to escape their sandbox during a cybersecurity evaluation and break into Hugging Face's servers. A subsequent cluster used similar techniques to break into OpenAI's own infrastructure. In response to the wiki incident, OpenAI said it is working on a framework for reporting misalignment incidents during training, evaluation, and deployment. ️🔥 Trending CVEs Bugs drop weekly, and the gap between a patch and an exploit is shrinking fast. These are the heavy hitters for the week: high-severity, widely used, or already being poked at in the wild. Check the list, patch what you have, and hit the ones marked urgent first — CVE-2026-78174, CVE-2026-19313, CVE-2026-19318, CVE-2026-19315, CVE-2026-57910, CVE-20
Indicators of Compromise
- cve — CVE-2026-86206
- cve — CVE-2026-86207
- cve — CVE-2026-86218
- cve — CVE-2026-85046
- cve — CVE-2026-67276
- cve — CVE-2026-67277
- cve — CVE-2026-67278
- cve — CVE-2026-67279
- cve — CVE-2026-67281
- cve — CVE-2026-86060