Security news.
Today's cybersecurity landscape is marked by critical vulnerabilities and ongoing exploitation campaigns. Several zero-day flaws are being actively leveraged, while supply chain attacks continue to pose significant risks, notably involving trojanized software installers and malicious npm packages.
Metabase Zero-Day Exploited in Wild for Admin Access
A maximum-severity security flaw in Metabase business intelligence software (CVSS: 10.0) is being actively exploited as a zero-day, allowing unauthenticated remote attackers to inject arbitrary SQL and gain admin access.
Hackers Breach TrueConf to Trojanize Client Installers
The Head Mare hacktivist group is exploiting vulnerabilities in unpatched TrueConf video conferencing servers to replace legitimate client installers with malicious versions that deliver backdoors.
Critical One-Click Flaw in Atlassian Rovo AI Exposed Enterprise Data
A critical vulnerability, dubbed "RovoBlast" by researchers, in Atlassian's Rovo AI could have allowed attackers to steal sensitive data from Confluence, Jira, and SharePoint with a single click.
Progress Kemp LoadMaster Flaw Added to CISA KEV Catalog
A critical command injection vulnerability (CVE-2026-8037, CVSS: 9.6) in Progress Kemp LoadMaster has been added to CISA's KEV catalog due to active exploitation attempts, allowing arbitrary code execution.
N-able Issues Second N-central Hotfix Amid Active Exploitation
N-able has released further hotfixes for its N-central RMM product as threat actors continue to evolve their techniques to exploit a recently disclosed security flaw, impacting managed systems.
New CSS Attacks Bypass Webmail Defenses to Steal Credentials
Research demonstrates novel CSS-based attacks that can break webmail message boundaries in platforms like Outlook and Gmail, leading to password theft, token leakage, and account hijacking.
Unlimited Technology Systems Breach Impacts 3.8 Million People
Healthcare software provider Unlimited Technology Systems reported a data breach from October 2025, affecting over 3.8 million individuals and exposing personal information.
Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer
A campaign involving almost 800 malicious npm packages is delivering a powerful cross-platform Remote Access Trojan (RAT) and infostealer targeting Windows, Mac, and Linux systems.