Week in Security: Chrome, MikroTik, and LG Flaws Highlighted in Early September
A busy week in cybersecurity saw actively exploited Chrome and Windows vulnerabilities, critical MikroTik router flaws, and potential eavesdropping risks in LG TVs.

The first week of September 2026 proved to be a significant period for cybersecurity news, with multiple critical vulnerabilities disclosed across various platforms and devices. Malwarebytes Labs reported on a range of threats, underscoring the persistent and evolving nature of cyber risks.
One of the most pressing issues highlighted was the active exploitation of zero-day vulnerabilities in Google Chrome and Microsoft Windows. These flaws were reportedly leveraged by the BlueMoon exploit kit, a tool known for its ability to compromise user systems by exploiting unpatched browser and operating system weaknesses. Users were urged to update Chrome immediately to mitigate the risk of infection.
In parallel, critical security flaws were identified in MikroTik routers, which could allow attackers to gain complete control of these devices without requiring any authentication. Given the widespread use of MikroTik routers in both home and business networks, these vulnerabilities posed a significant threat to network security and data integrity.
Further complicating the security landscape, vulnerabilities were discovered in LG televisions that could potentially allow attackers to eavesdrop on users, even when the TV was in standby mode. This raised concerns about privacy and the security of smart home devices.
The week also saw a notable data breach affecting an email marketing provider, which specifically targeted cryptocurrency customers. This incident highlighted the risks associated with third-party data handling and the specific threats faced by individuals involved in the cryptocurrency space.
Beyond specific product vulnerabilities, the broader threat of online fraud was emphasized by the discovery of over 100,000 fake e-commerce stores designed to steal credit card details. This indicates a large-scale, coordinated effort by cybercriminals to defraud consumers.
Microsoft addressed a record number of vulnerabilities, including two zero-days that were already being exploited in the wild. This underscores the ongoing challenges faced by major software vendors in keeping pace with sophisticated threat actors.
Other notable security events included a settlement by Grindr over a lawsuit concerning the sharing of HIV status data, and a discussion on the potential impact of AI on social media algorithms. The week's events collectively paint a picture of a complex and dynamic threat environment requiring constant vigilance from users and organizations alike.