Chrome Zero-Days, Android Banking Trojan, and VeloCloud Exploit

Chrome Zero-Days, Android Banking Trojan, and VeloCloud Exploit

•

Episode description

Chrome Zero-Days, Android Banking Trojan, and VeloCloud Exploit

Five Chrome V8 vulnerabilities are under active exploitation by Chinese threat actors right now. A single malicious page visit can compromise an unpatched device without user interaction beyond the click. Meanwhile, the RemControl Android banking trojan is targeting UK financial institutions through fake app downloads, stealing credentials via Accessibility Service abuse. Arista has patched an actively exploited VeloCloud Orchestrator zero-day affecting SD-WAN infrastructure, and Microsoft’s September updates have broken Always On VPN for some Windows 11 systems. Mauven walks through the exploitation chains, the real exposure for UK SMBs, and the concrete actions required before close of business today. This is not theoretical risk. These are operational threats requiring immediate patch management, staff briefings, and infrastructure verification.

Chapters

  • Intro Chrome is being actively exploited by a Chinese threat actor. Unpatched browsers can be compromised through a single page visit with no user action beyond the click.
  • Chrome V8: Multiple Zero-Days Under Active Exploitation Five CVEs published against Chromium’s V8 engine are confirmed under active exploitation. Chinese threat actor UTA0565 is using fake domains and phishing emails to silently exploit browsers and escalate to full device compromise. UK SMBs with unmanaged or inconsistently patched Chrome installations face immediate risk. Update Chrome across all devices today and verify browser restarts.
  • CTA Follow the show and share with colleagues who need daily threat intelligence.
  • RemControl: Android Banking Trojan Targeting Western European Banks RemControl is an Android banking trojan distributed via fake TVTap IPTV download pages in paid search ads. It abuses Accessibility Service permissions to inject phishing overlays on legitimate banking apps and stream device screens in real time. UK banks are in scope. Staff personal devices used for work represent soft perimeter risk. Brief staff to only install apps from official stores and decline Accessibility Service requests from non-essential apps.
  • Arista VeloCloud Orchestrator: Actively Exploited Zero-Day Arista has patched an actively exploited zero-day in VeloCloud Orchestrator on-premises deployments. VCO manages SD-WAN infrastructure. Most UK SMBs will encounter this through managed service providers. Ask your IT provider if VCO is in your environment and confirm the patch has been applied today.
  • September Windows Updates and Always On VPN Microsoft’s September security updates break Always On VPN on some Windows 11 systems. Remote staff losing VPN connectivity should not work around it by bypassing the VPN. Wait for Microsoft’s fix or apply their documented workaround. Do not remove the control.
  • The Pattern Worth Noting Today’s threats exploit the browser, the phone, and the network connection. The defences are patch management, staff awareness, and infrastructure visibility. ClickFix campaigns continue to succeed through bulletproof hosting and social engineering that asks users to paste commands into Windows Run dialogs. The threat surface is everyday infrastructure. The controls are unglamorous and effective.
  • Outro Update Chrome today, brief staff on APK risks this week, and verify VeloCloud patching if applicable. Three actions within reach before close of business.

Links

No chapters are available for this episode.