DEV Community

Mark0
Mark0

Posted on

⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More

This week's cybersecurity landscape was dominated by critical zero-day vulnerabilities affecting widely used infrastructure and enterprise software. N-able released urgent fixes for N-central flaws capable of pre-authenticated remote code execution, while Google addressed an actively exploited type confusion bug in its Chrome V8 engine. Additionally, MikroTik routers faced a new exploit chain dubbed "MikroTrick," and Magento e-commerce stores were targeted by a stealthy zero-day known as "StyleSmuggler" that injects malicious code through the template system.

Beyond software flaws, the report highlights sophisticated social engineering and reconnaissance techniques. Attackers are now using text-based QR codes to bypass image-blocking security measures and deploying adversary-in-the-middle (AiTM) phishing kits like "Knight Office" to hijack Microsoft 365 sessions. Significant developments also include the discovery of credential-harvesting modules in Coder’s infrastructure and research into indirect prompt injection attacks that can manipulate AI-driven email summarizers.


Read Full Article

Top comments (0)