hacker-news · Crawled Sep 7, 2026

⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More

4 IoCs 1 CVEs
Read original article ↗

AI Summary

Multiple active threats were reported this week, including a Chrome zero-day under active exploitation (CVE-2026-85046), which allows remote code execution via a crafted HTML page. MikroTik RouterOS devices are being targeted using an exploit chain called MikroTrick, combining CVE-2026-67276 and CVE-2026-86060 to achieve unauthenticated remote code execution. Unpatched Magento and Adobe Commerce stores are being compromised via a zero-day named StyleSmuggler, leading to backdoor installation. A supply chain attack on Coder's infrastructure delivered malicious Terraform modules that steal credentials. Additionally, the RevStealer information stealer is spreading via fake game cheats and a counterfeit Claude desktop app, using blockchain-based dead drops for resilience.

AI-extracted · verify before operational use

Extracted Entities 1 found

Indicators of Compromise 4 extracted

Type Value Detail
IP 82[.]192[.]72[.]4 Details →
IP 103[.]102[.]31[.]18 Details →
IP 99[.]84[.]67[.]186 Details →
Domain coder-infra[.]com Details →

MITRE ATT&CK TTPs 9 techniques