Weekly Recap: Chrome Zero-Day, UniFi RCE, macOS Stealers, and a VPN Auth Bypass

Another seven days of rented phishing kits, AI-themed lures, and forgotten software paying out as initial access.

ThreatVectr Newsdesk· 3 min read
Weekly Recap: Chrome Zero-Day, UniFi RCE, macOS Stealers, and a VPN Auth Bypass
Share

The pattern this week was depressingly familiar.

A tool nobody patched. A package nobody audited. A feature flagged deprecated three releases ago, still answering production traffic. Defenders know the drill. Attackers know it better.

Chrome shipped another emergency update for an in-the-wild zero-day in the V8 engine, the latest in a run of type-confusion bugs that keep making the browser the most reliable initial-access vector on the desktop. (If your fleet management can't roll Chrome to the patched build inside 72 hours, that's the actual finding.) Patch status should be checked against the Stable Channel update notes at https://chromereleases.googleblog.com/.

Ubiquiti's UniFi stack took another hit. The exploit path involves authenticated API abuse that escalates to command execution on the controller host, which — given how many MSPs run a single controller for dozens of customer sites — is not a contained blast radius. Treat any internet-exposed UniFi Network Application as compromised until proven otherwise. Pull the controller logs before you pull the patch.

On macOS, the stealer ecosystem keeps maturing. Atomic, Banshee, and the newer Cthulhu variants are now being distributed through cracked-app sites and fake "AI tool" installers (ChatGPT desktop clients remain the favorite lure). They harvest Keychain entries, browser cookies, and crypto wallet files, then exfiltrate over plain HTTPS to commodity C2. Gatekeeper bypasses via ad-hoc signing are doing most of the work. EDR coverage on Mac endpoints is still the exception, not the rule.

The VPN flaw of the week is an authentication bypass in an edge appliance that — and stop me if you've heard this one — exposes a legacy login endpoint the vendor forgot to deprecate. Pre-auth. Network-reachable. Trivially weaponized. Check vendor advisories directly; the patched firmware string matters more than the marketing CVSS number.

A few other items worth your time:

  • A widely used npm package was hijacked through a maintainer's compromised account and shipped a post-install script that pulled second-stage payloads from a Cloudflare Worker. Lockfile pinning is not optional.
  • Phishing-as-a-service kits added MFA-relay modules as a default feature this quarter, not a premium tier. Number-matching helps. Phishing-resistant FIDO2 helps more.
  • Several ransomware affiliates are now buying initial access keyed specifically to ScreenConnect and AnyDesk instances exposed to the public internet. Inventory your remote-management tooling. The attackers already have.

The through-line: none of this required a novel exploit. The Chrome bug is the only thing on the list that needed real research. Everything else was operational hygiene that someone, somewhere, decided could wait until next quarter.

It couldn't.

Patch the browser. Audit the controllers. Kill the deprecated login paths. Pull the cracked-app installers off your Macs. Then do it again next Monday.

© 2026 Threat Vectr