Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More
This week, attackers used a QR code workaround to bypass email image blocking, and a trusted software source delivered code that stole credentials. MikroTik RouterOS flaws were exploited, and Magento and Adobe Commerce were compromised with an unpatched zero-day.
Intelligence analysis by Qwen 2.5 (3B)

This week's cybersecurity roundup includes a Chrome 0-Day, router hijacks, and supply chain attacks targeting e-commerce platforms.
This week, some bad guys found ways to trick people into giving them their passwords and to take control of devices. They used sneaky QR codes and fake apps to do it. It's important to keep your devices and software up to date to protect against these tricks.
Analysis
N-able Patches Critical N-central Flaws
N-able released hotfixes for two severe N-central flaws, including CVE-2026-86206 and CVE-2026-86207, which could allow unauthorized parties to bypass authentication controls and gain full access to the platform. N-able acknowledged that attackers are likely leveraging CVE-2026-86206 or CVE-2026-86207, but noted that unpatched systems remain at risk.
Google Warns of Chrome 0-Day Under Attack
Google patched 12 vulnerabilities, including CVE-2026-85046, a type confusion bug in V8, Chrome's JavaScript and WebAssembly engine. The flaw has been exploited in the wild, but details about the attacks and who is behind them were not disclosed.
MikroTik RouterOS Flaws Exploited
CERT Polska warned of two zero-day flaws in MikroTik RouterOS that could allow attackers to bypass authentication and elevate privileges. The flaws have been fixed in versions 6.49.21, 7.23.4, and 7.24.2.
Unpatched Magento and Adobe Commerce 0-Day Exploited
E-commerce storefronts were compromised with an unpatched zero-day dubbed StyleSmuggler, which gave attackers remote code execution. The attacks began on September 4, 2026.
RevStealer Spreads via Game Cheats and Fake Claude Desktop App
Elastic and Morphisec disclosed details of RevStealer, a Windows information stealer that targets gaming platforms for additional monetization.
Key points
- N-able patched two severe flaws in N-central
- Google patched a type confusion bug in Chrome
- MikroTik RouterOS flaws were exploited
- E-commerce stores were compromised with an unpatched zero-day
- RevStealer spreads via game cheats and fake apps
With more people and companies keeping their software updated, fewer of these tricks will work.
Even with updates, some bad guys will still find new ways to trick people and devices.



