⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More
TacitSoft analysis
Operators tracking Chrome, router, and software supply-chain risk can use this recap as a source-attributed overview of the reported events.
This edition tracks network and management-platform attacks, Microsoft cloud phishing, Perl ecosystem vulnerabilities, and research on AI-agent and prompt-injection risk.
Ranked operator signal
Each item links to its publisher and includes one independently written TacitSoft sentence based on structured facts.
TacitSoft analysis
Operators tracking Chrome, router, and software supply-chain risk can use this recap as a source-attributed overview of the reported events.
TacitSoft analysis
Cloud security programs are the subject of a source-attributed critique of checklist-only evaluation and its operational limits.
TacitSoft analysis
Telerik UI operators should assess exposure to chained padding-oracle behavior that can enable unauthenticated remote code execution and has a public exploit.
TacitSoft analysis
Operators of AI agents using skills should consider how neutral-looking prompts could steer hallucinations inside those workflows.
TacitSoft analysis
MikroTik RouterOS operators should investigate newly reported flaws associated with active router hijacking.
TacitSoft analysis
Language-model defenders can evaluate semantic overlays as a research approach to mitigating prompt injection beyond token-level annotations and steering vectors.
TacitSoft analysis
Security teams evaluating AI-enabled social engineering can use this study of personalized pretexts in LLM-generated spear phishing.
TacitSoft analysis
N-central operators should prioritize the available patch because the maximum-severity flaw is associated with ongoing attacks.
TacitSoft analysis
Microsoft 365 defenders should examine identity controls after reported BigBear phishing activity bypassed MFA across 258 organizations.
TacitSoft analysis
ScreenConnect operators should investigate rogue client activity that may deliver a four-stage VBScript chain to newly connected hosts.
TacitSoft analysis
Perl HTTP/2 services using Protocol::HTTP2 before 1.14 should be assessed for CVE-2026-16028 memory-exhaustion risk when closed streams remain in the connection table.
TacitSoft analysis
Net::IP::LPM operators should assess versions before 1.12 for CVE-2026-86287 because malformed prefix lengths may be accepted during Perl network-prefix processing.
Choose daily, weekly, monthly, or any combination.