← Latest brief

Security news.

·Morning Brief

Today's cybersecurity landscape is marked by multiple critical vulnerabilities and active exploitation, alongside significant developments in AI-driven attacks. Several zero-day flaws are being actively exploited in the wild, underscoring the urgency for immediate patching and vigilance.

THNZERO-DAY
Aug 8READ

Metabase Zero-Day Exploited in Wild

A maximum-severity SQL injection vulnerability (CVSS: 10.0) in Metabase business intelligence software is being actively exploited to gain unauthenticated admin access and steal customer data.

THNKEV
Aug 8READ

Progress Kemp LoadMaster Flaw Added to CISA KEV

CISA has added a critical command injection vulnerability (CVE-2026-8037, CVSS: 9.6) in Progress Kemp LoadMaster to its Known Exploited Vulnerabilities catalog following widespread exploitation attempts.

BLEEPINGBREACH
Aug 8READ

TrueConf Breached, Client Installers Trojanized

Hackers exploited vulnerabilities in unpatched TrueConf video conferencing servers to replace legitimate client installers with malicious versions containing backdoors.

SECURITYWEEKAI
Aug 8READ

Critical Vulnerability in Atlassian Rovo AI

A critical "RovoBlast" attack method in Atlassian's Rovo AI could have allowed attackers to steal sensitive data from Confluence, Jira, and SharePoint with a single click.

THN
Aug 8READ

New CSS Attacks Target Webmail Defenses

Research demonstrates novel CSS-based attacks that can bypass webmail defenses across platforms like Outlook and Gmail, potentially stealing passwords, tokens, and manipulating AI tools.

THNEXPLOIT
Aug 8READ

N-able Releases N-central Hotfix for Active Exploitation

N-able has issued N-central Hotfix 2 to address ongoing exploitation of a recently disclosed security flaw, as threat actors evolve their attack techniques to reach managed systems.

BLEEPINGBREACH
Aug 7READ

Unlimited Technology Systems Data Breach

Healthcare software company Unlimited Technology Systems reported a data breach from October 2025, affecting over 3.8 million individuals and exposing personal and health information.

THNSUPPLY CHAIN
Aug 7READ

Hundreds of Malicious npm Packages Deliver RAT and Infostealer

Nearly 800 malicious packages were found in the npm registry, deploying a cross-platform RAT and infostealer targeting Windows, macOS, and Linux systems through typo-squatted names.

Generated twice daily from public security RSS feeds. Informational only.