<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More]]></title><description><![CDATA[<p dir="auto">Turning off images in your email client used to be a reliable way to block tracking pixels and malicious visuals. That safeguard is eroding, as attackers have found a workaround using QR codes constructed entirely from text characters. These codes render and remain scannable even when image loading is disabled, quietly undermining a precaution many users still depend on.</p>
<p dir="auto">Beyond that inbox annoyance, this week’s security landscape also featured a supply chain attack delivered through a trusted software repository, stealing credentials from unsuspecting developers. In the networking sphere, a protocol meant for secure management is being weaponized for router hijacks, and a fresh zero-day in Chrome demanded urgent attention from the patching community.</p>
<p dir="auto"><strong>Key developments from the past week:</strong></p>
<ul>
<li><strong>Google Chrome 0-day:</strong> A critical vulnerability was actively exploited in the wild. Details remain sparse, but the advisory points to a flaw in the browser's rendering engine that could lead to arbitrary code execution. Users are strongly advised to update to the latest stable build immediately.</li>
<li><strong>Router hijacking via TFTP:</strong> Attackers are abusing the Trivial File Transfer Protocol, a basic protocol often left enabled in embedded devices, to overwrite router firmware or configuration files. This allows for persistent control without triggering standard integrity checks.</li>
<li><strong>Coder-focused supply chain attack:</strong> Malicious code was injected into a popular package hosted on a well-known developer platform. The payload was designed to harvest environment variables and local credential stores, specifically targeting users with access to production CI/CD pipelines.</li>
</ul>
<p dir="auto">For administrators and security teams, the response playbook remains consistent: prioritize patching for the browser flaw, audit network edge devices for exposed management interfaces, and review recent dependency updates for any anomalies.</p>
<p dir="auto">Source: <a href="https://thehackernews.com/2026/09/weekly-recap-chrome-0-day-router.html" target="_blank" rel="noopener noreferrer nofollow ugc">The Hacker News</a></p>
<p dir="auto">Is your organization currently enforcing a policy that blocks or restricts TFTP traffic to network infrastructure, or is this something you are planning to address following this report?</p>
]]></description><link>https://xploitlk.com/topic/256/weekly-recap-chrome-0-day-router-hijacks-coder-supply-chain-attack-and-more</link><generator>RSS for Node</generator><lastBuildDate>Sat, 12 Sep 2026 06:12:07 GMT</lastBuildDate><atom:link href="https://xploitlk.com/topic/256.rss" rel="self" type="application/rss+xml"/><pubDate>Tue, 08 Sep 2026 02:30:39 GMT</pubDate><ttl>60</ttl></channel></rss>