Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication
Metabase Zero-Day Exploitation Shows Why Analytics Platforms Must Be Treated as Privileged Data InfrastructureThe active exploitation of a zero-day vulnerability affecting Metabase demonstrates how business intelligence…
Aug 09, 2026
Hackers breach TrueConf to trojanize client installers with backdoors
Nearly 800 Malicious npm Packages Show How Software Dependencies Are Becoming Malware Delivery InfrastructureThe discovery of hundreds of malicious packages in the npm ecosystem demonstrates how software supply-chain at…
Aug 09, 2026
Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer
Nearly 800 Malicious npm Packages Show How Software Dependencies Are Becoming Malware Delivery InfrastructureThe discovery of hundreds of malicious packages in the npm ecosystem demonstrates how software supply-chain at…
Aug 08, 2026
CISA Adds One Known Exploited Vulnerability to Catalog
CISA Adds Actively Exploited Progress LoadMaster RCE to KEV CatalogCISA’s addition of CVE-2026-8037 to its Known Exploited Vulnerabilities Catalog should trigger immediate action from organizations operating Progress Ke…
Aug 08, 2026
Unlimited Technology Systems breach impacts 3.8 million people
Unlimited Technology Systems Breach Exposing 3.8 Million Patients Highlights the Growing Risk of Healthcare Data ConcentrationThe data breach affecting Unlimited Technology Systems demonstrates the enormous security con…
Aug 08, 2026
Metabase SQLi zero-day exploited in customer data-theft attacks
Metabase Zero-Day Attacks Show How Analytics Platforms Can Become Gateways to Sensitive Business DataThe disclosure of active attacks exploiting a previously unknown SQL injection vulnerability in Metabase demonstrates …
Aug 08, 2026
18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers
18-Year-Old SCTPhantom Linux Flaw Shows How an Obscure Networking Feature Can Become a Root and Container-Escape VulnerabilityThe disclosure of CVE-2026-64564, named SCTPhantom by Tencent Zhuque Lab, demonstrates how vu…
Aug 07, 2026
New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP
New WordPress Pre-Authentication XSS Shows How a Browser-Side Bug Can Escalate into Server CompromiseThe disclosure of CVE-2026-64638 highlights how a vulnerability that initially appears to be a browser-side cross-site…
Aug 07, 2026
North Carolina Ports confirms cyberattack disrupting operations
North Carolina Ports Cyberattack Shows How IT Disruption Can Quickly Become a Supply-Chain ProblemThe cyberattack affecting North Carolina Ports demonstrates how disruption of ordinary information technology systems can…
Aug 07, 2026
Levi Strauss & Co. says hackers stole corporate data in cyberattack
Levi Strauss Cyberattack Shows How Three Compromised Employees Can Become a Corporate Data BreachThe cybersecurity incident disclosed by Levi Strauss & Co. demonstrates how social engineering can allow attackers to bypa…
Aug 07, 2026
ClickFix attack pushes macOS infostealer for crypto theft attacks
ClickFix macOS Infostealer Shows How Social Engineering Is Evolving into Direct Cryptocurrency TheftA newly analysed ClickFix campaign targeting macOS users demonstrates how attackers are combining social engineering, c…
Aug 07, 2026
Cisco Patches 12 SD-WAN and IOS XE Flaws, Including Three 9.8 CVSS Score Bugs
Cisco’s SD-WAN and IOS XE Security Update Highlights the Risks Concentrated in Network InfrastructureCisco’s release of patches for 12 vulnerabilities affecting Catalyst SD-WAN and IOS XE Software highlights the serious…
Aug 07, 2026