⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More
AI Summary
Multiple active threats were reported this week, including a Chrome zero-day under active exploitation (CVE-2026-85046), which allows remote code execution via a crafted HTML page. MikroTik RouterOS devices are being targeted using an exploit chain called MikroTrick, combining CVE-2026-67276 and CVE-2026-86060 to achieve unauthenticated remote code execution. Unpatched Magento and Adobe Commerce stores are being compromised via a zero-day named StyleSmuggler, leading to backdoor installation. A supply chain attack on Coder's infrastructure delivered malicious Terraform modules that steal credentials. Additionally, the RevStealer information stealer is spreading via fake game cheats and a counterfeit Claude desktop app, using blockchain-based dead drops for resilience.
AI-extracted · verify before operational use