Security news.
Today's security landscape is marked by critical vulnerabilities and the persistent threat of active exploitation. Multiple zero-day flaws are being actively leveraged in the wild, underscoring the urgency for organizations to apply patches and enhance their defensive strategies, particularly around AI-powered systems and common enterprise software.
Metabase Zero-Day Actively Exploited for Admin Access
A maximum-severity SQL injection vulnerability (CVSS: 10.0) in Metabase business intelligence software is being exploited in the wild, allowing unauthenticated attackers to gain admin access and steal customer data.
Critical Flaw in Atlassian Rovo AI Exposed Enterprise Data
Varonis researchers uncovered a critical one-click vulnerability, dubbed "RovoBlast," in Atlassian's Rovo AI that could have allowed attackers to steal sensitive data from Confluence, Jira, and SharePoint.
N-able Releases Hotfix 2 for N-central Exploitation
N-able has issued a second round of hotfixes for its N-central RMM product as threat actors continue to evolve exploitation techniques against a recently disclosed security flaw (CVE-2026-18556).
Progress Kemp LoadMaster Flaw Added to CISA KEV Catalog
A critical command injection vulnerability, CVE-2026-8037 (CVSS: 9.6), in Progress Kemp LoadMaster has been added to CISA's KEV catalog following reports of active exploitation, with 792 exploit attempts observed.
New CSS Attacks Bypass Webmail Defenses to Steal Credentials
Research demonstrates novel CSS-based attacks that can break email message boundaries in Outlook, Gmail, and other webmail clients to steal passwords, tokens, and manipulate UI actions.
Unlimited Technology Systems Breach Impacts 3.8 Million
Healthcare software provider Unlimited Technology Systems reported a data breach from October 2025, affecting over 3.8 million individuals with stolen personal, medical, and health insurance information.
Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer
A campaign involving almost 800 malicious packages has been published to the npm registry, using typo-squatting names to deliver a potent RAT and infostealer targeting Windows, Mac, and Linux systems.
ClickFix Attacks Deploy macOS Stealer to Drain Crypto Wallets
ClickFix-style attacks are actively delivering a Go-based macOS malware that can steal cryptocurrency, browser-stored passwords, Apple iCloud Keychain data, and cached credentials.