⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More
- ID
- 22129
- Status
- summarized
- Published
- 07 Sep 2026, 10:36 PM
- Fetched
- 08 Sep 2026, 1:06 AM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/weekly-recap-chrome-0-day-router.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 6.0
- Created
- 08 Sep 2026, 1:13 AM
- Tags
- Audience
- developersvibe_coderssaas_founders
What happened
A weekly security recap covering an actively exploited Chrome 0-day, a supply chain attack where a trusted software source delivered credential-stealing code, and N-able patching two critical N-central authentication bypass flaws (CVE-2026-86206, CVE-2026-86207) plus a CVSS 10.0 pre-auth RCE (CVE-2026-86218). Huntress reported signs that attackers are already leveraging the N-central flaws against a fully patched production environment, despite N-able saying no confirmed exploitation.
Why it matters
If you use N-central in your IT stack, apply the hotfixes immediately—Huntress found compromise evidence even on patched systems, meaning the patch may be insufficient or there's an unknown exploit path. For developers, the supply chain attack on a trusted code source means you should verify integrity of dependencies rather than assuming trusted sources are safe. Update Chrome now given the active 0-day.
Discussion angle
The N-able situation is the most interesting: a vendor says 'no confirmed exploitation' while Huntress says they investigated a compromised fully-patched production environment on September 4—discuss how to handle the gap between vendor assurance and third-party incident findings when deciding whether to trust a patch.