Security news.
Today's cybersecurity landscape highlights a surge in active exploitation of critical vulnerabilities, including zero-days in Metabase and Progress LoadMaster, underscoring the urgency for immediate patching. AI systems are also under increased scrutiny with new research detailing 'Ghostjacking' and passkey bypass attacks, alongside a reported pause in OpenAI's Astra development due to advanced cyber capabilities.
Metabase Patches Zero-Day Vulnerability
A critical flaw allowing unauthenticated, remote administrative access to Metabase instances has been patched after being actively exploited in the wild.
Critical Progress LoadMaster Flaw Actively Exploited
CISA has warned that a critical Progress Kemp LoadMaster command injection vulnerability (CVE-2026-8037) is being actively exploited, urging immediate patching.
New Passkey Attacks Bypass Phishing-Resistant MFA
Researchers have demonstrated new methods to defeat passkey protections, either by recovering synced private keys or bypassing phishing-resistant multi-factor authentication.
‘Ghostjacking’ Attack Uses Poisoned Logs to Turn AI Agents Bad
A novel attack vector, "Ghostjacking," exploits AI agents by planting malicious instructions within system logs or alerts, causing the AI to execute attacker-controlled commands.
Valve Notifies Steam Hardware Customers of Data Breach
Valve is informing European Steam hardware customers that their data was stolen after its shipping partner, CEVA Logistics, suffered a hack.
New Jersey, Alabama Join States Targeted in Water Cyberattacks
Hackers linked to Iran have expanded their targeting of industrial control systems (ICS) at water facilities to include at least a dozen US states, including New Jersey and Alabama.
TrueConf Server Flaws Exploited to Deliver PhantomCore
The "Head Mare" threat actor is actively exploiting vulnerabilities in unpatched TrueConf servers to replace client installers with the PhantomCore backdoor, targeting Russian companies.
Corporate Data Stolen in Levi Strauss Cyberattack
Levi Strauss & Co. disclosed a cyberattack where a threat actor used social engineering to access three employee computers and exfiltrate corporate data.