Week in Cybersecurity: Chrome 0-Days, Router Botnets, AWS Breach & Rogue AI

TL;DR Summary
This weekly security digest highlights Google Chrome’s two actively exploited 0-days (CVE-2026-3909/3910) patched by Google, plus widespread router botnets like SocksEscort and KadNap leveraging firmware abuse; it also details UNC6426’s AWS breach via an nx npm supply-chain compromise and GitHub‑to‑AWS trust abuse. The roundup covers new threats such as the Roundish Roundcube toolkit, AI-agent collaboration risks, phishing targeting AWS credentials, a AppsFlyer SDK supply-chain incident, and ransomware like GIBCRYPTO, along with notable security news (Meta ending Instagram E2EE) and new defense tools like Dev Machine Guard and Trajan.
- ⚡ Weekly Recap: Chrome 0-Days, Router Botnets, AWS Breach, Rogue AI Agents & More The Hacker News
- [updated] Google patches two Chrome zero-days under active attack Malwarebytes
- Google Fixes Two Chrome Zero-Days Exploited in the Wild Affecting Skia and V8 The Hacker News
- Google Zero-Day Alert For 3.5 Billion Chrome Users—Attacks Underway Forbes
- Google rushes Chrome update fixing two zero-days already under attack theregister.com
Reading Insights
Total Reads
1
Unique Readers
2
Time Saved
18 min
vs 19 min read
Condensed
98%
3,764 → 88 words
Want the full story? Read the original article
Read on The Hacker News