Threat Analysis: Chrome Zero-Days, ClickFix Campaigns, and a RemControl Android Trojan Targeting UK Banking
This is your Daily Threat Analysis for 23rd September 2026.
Three stories today. Two of them require action before the end of the working day. One is operational context that will matter if your staff are working remotely.
Chrome V8: Multiple Zero-Days Under Active Exploitation
Five CVEs were published today against Chromium’s V8 JavaScript engine: CVE-2026-87564 (type confusion), CVE-2026-87587 (use-after-free), CVE-2026-87612 (type confusion), CVE-2026-87489 (memory corruption), and CVE-2026-87536 (use-after-free). These are not theoretical. Volexity published research on 21st September documenting active exploitation of Chrome and Windows zero-days by a Chinese threat actor tracked as UTA0565.
The attack chain is worth understanding because it is operationally simple. UTA0565 registered fake domains impersonating legitimate organisations, including media outlets and think tanks, and used them as landing pages in targeted phishing emails. Victims who clicked were directed to pages that silently exploited unpatched Chrome vulnerabilities. From there, the actor chained to Windows privilege escalation to complete the compromise. The primary targets documented were Asian government entities, but the TTPs do not require a nation-state target list to be reused.
What the advisory does not say explicitly: the fake domain technique is indistinguishable from a legitimate site to a user who does not inspect the URL carefully. The social engineering is light because the browser exploit does the heavy lifting. If Chrome is unpatched, the user does not need to do anything beyond visiting the page.
For UK SMBs, the primary exposure is unmanaged or inconsistently patched browsers. If your devices rely on users to manually update Chrome, or if your managed update policy runs on a monthly cycle, you have a window right now.
What to do: Update Chrome across every managed device today. Check unmanaged devices, personal laptops used for remote work, BYOD phones accessing company email. If you use Microsoft Edge (also Chromium-based), the same urgency applies; verify updates are current.
RemControl: A New Android Banking Trojan Targeting Western European Financial Institutions
Group-IB published research today on RemControl, an Android banking trojan operating as Malware-as-a-Service since May 2026. It targets more than 30 financial institutions across Western Europe, the Middle East, and Canada.
The distribution mechanism is malvertising: fake TVTap IPTV download pages served through paid advertising. A user searching for a free streaming app clicks what looks like a legitimate download link, installs the APK, and grants Accessibility Service permissions, which the malware then abuses to inject phishing overlays on top of legitimate banking applications and to stream device footage to the attacker.
This is not a novel technique. Accessibility Service abuse has been the standard Android banking trojan playbook for several years. The NCSC has published guidance on mobile device security that addresses precisely this vector. The fact that a new MaaS platform is successfully running this campaign in 2026 tells you how consistently that guidance is being applied.
The relevance to UK SMBs is indirect but real. Your staff’s personal Android devices, if used to access company email, approve multi-factor authentication requests, or access cloud business applications, represent a soft perimeter. An employee whose banking credentials are stolen may also have company credentials stored in the same browser or credential manager. And a device streaming its screen to an attacker is streaming everything visible on that screen, including work applications.
What to do: Brief staff that apps should only be installed from official app stores (Google Play, Apple App Store). No APK downloads from links in emails, advertisements, or websites offering free streaming software. If your organisation has a BYOD policy, now is a reasonable time to remind staff of it in writing. If Accessibility Service permissions are requested by an app that has no legitimate need for them, a media player, a utility tool, that is a red flag.
Arista VeloCloud Orchestrator: Actively Exploited Zero-Day Patched Today
Arista Networks has released patches for an actively exploited zero-day affecting VeloCloud Orchestrator (VCO) on-premises deployments. Details on the specific vulnerability class are limited in the public advisory at time of writing, but active exploitation is confirmed.
VeloCloud is an SD-WAN platform. On-premises VCO deployments are the management layer for that infrastructure. If you or your managed service provider run VeloCloud Orchestrator on-prem, this is not a routine patch, it is an emergency fix for something being exploited in the wild right now.
Most UK SMBs will not be running VeloCloud Orchestrator directly, but some will have it managed on their behalf. The question to ask your IT provider or MSP is direct: do we have VeloCloud Orchestrator in our environment, and has the patch been applied?
What to do: If you run VCO on-prem, apply Arista’s patches immediately. If your infrastructure is managed, confirm with your provider that this has been actioned today.
Operational Note: September Windows Updates and Always On VPN
Microsoft has confirmed that the September 2026 security updates introduce a known issue breaking Always On VPN connections on some Windows 11 systems. This is not a security vulnerability, it is a patch quality issue, but it has operational security implications.
If remote staff report that their VPN has stopped working after recent Windows updates, the instinct in some organisations will be to tell them to connect without VPN, or to use a personal hotspot as a workaround. Both of those responses create genuine security exposure. The right answer is to wait for Microsoft’s fix or apply their documented workaround, not to bypass the control.
Microsoft is working on a resolution. In the meantime, if you are seeing VPN failures on Windows 11 machines after the September patch cycle, this is the likely cause.
The Pattern Worth Noting
Today’s three main items share a common thread: the attack surface is the everyday tools your staff use. The browser they have open all day. The app store habits on their personal phone. The remote access tool keeping them connected to the office. None of these requires a sophisticated attacker to exploit if the basics are not maintained.
The ClickFix bulletproof hosting research published today by Black Hills Information Security reinforces this. Over five months, four separate malicious campaigns ran through the same hosting provider, disposable domains, fake CAPTCHA pages, users instructed to paste commands into their own Windows Run dialogs. It is effective precisely because it asks the user to do something that looks mundane. The sophistication is in the persistence, not the technique.
If your IT provider tells you none of this applies to you because you are too small to be a target, ask them when they last verified that Chrome was up to date on every device in your environment. That answer will tell you more than any reassurance will.
If Threat Analysis is useful to you, follow the show wherever you listen so tomorrow’s briefing lands automatically, and pass it to someone who needs the heads-up.