Security news.
Today's cybersecurity landscape is marked by widespread exploitation of critical vulnerabilities, including multiple zero-days, alongside sophisticated supply chain attacks. Several advisories highlight actively exploited flaws in widely used enterprise software, emphasizing the urgent need for patching and robust defense mechanisms.
Metabase Zero-Day Actively Exploited for Admin Access
A maximum-severity Metabase flaw (CVSS 10.0), lacking a CVE, is being exploited in the wild to allow unauthenticated remote attackers to inject SQL and gain administrative access, leading to customer data theft.
Hackers Breach TrueConf to Trojanize Client Installers
The Head Mare hacktivist group is exploiting unpatched TrueConf video conferencing servers to replace legitimate client installers with malicious versions containing backdoors.
Progress Kemp LoadMaster Flaw Added to CISA KEV
CISA has added a critical command injection vulnerability (CVE-2026-8037, CVSS 9.6) in Progress Kemp LoadMaster to its Known Exploited Vulnerabilities catalog after reports of active exploitation.
Critical Atlassian Rovo AI Vulnerability Exposed Enterprise Data
A "RovoBlast" attack method in Atlassian's Rovo AI could have allowed attackers to steal sensitive data from Confluence, Jira, and SharePoint with a single click.
N-able Issues New N-central Hotfix as Attackers Persist
N-able has released Hotfix 2 for N-central to address ongoing exploitation of a recently disclosed security flaw, with threat actors evolving their attack techniques to reach managed systems.
New CSS Attacks Can Bypass Webmail Defenses
Research demonstrates that malicious CSS within an email can escape its message boundary, interfering with webmail interfaces like Outlook and Gmail to steal passwords, tokens, and manipulate UI actions.
Unlimited Technology Systems Breach Impacts 3.8 Million
Healthcare software company Unlimited Technology Systems reported a data breach from October 2025, affecting over 3.8 million individuals and exposing personal, medical, and health insurance information.
Nearly 800 Malicious npm Packages Deliver Cross-Platform Malware
A new campaign involving nearly 800 malicious npm packages, often using AI-generated or typo-squatted names, is distributing a powerful cross-platform RAT and infostealer targeting Windows, Mac, and Linux systems.