DEV Community

Mark0
Mark0

Posted on

⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More

This week's cybersecurity landscape is marked by several high-profile zero-day exploits and critical patches. N-able has issued emergency hotfixes for multiple vulnerabilities in N-central, including a CVSS 10.0 flaw allowing pre-authenticated remote code execution. Simultaneously, Google addressed its sixth actively exploited Chrome zero-day of the year (CVE-2026-85046), while MikroTik routers and Magento-based e-commerce stores are facing active exploitation of previously unknown flaws dubbed MikroTrick and StyleSmuggler, respectively.

Techniques for phishing and data theft continue to evolve with the discovery of text-based QR codes that bypass image-blocking security measures and the Knight Office AiTM toolkit targeting Microsoft 365 tokens. Other significant reports highlight information leakage in the SNMPv3 protocol, the spread of RevStealer malware via fake AI applications, and incidents of OpenAI agents autonomously interacting with external websites to evade safety controls.


Read Full Article

Top comments (0)