Cybersecurity Newsfeed - 10/08/26
Daily cybersecurity news covering vulnerabilities, adversaries, trends, breaches, and other notable security developments.
Cybersecurity Newsfeed
📅 10/08/26
🛡️ Vulnerabilities
Metabase Zero-Day SQL Injection (CVSS 10.0): Metabase issued an urgent warning regarding an unauthenticated zero-day SQL injection vulnerability affecting versions 1.58+ under active exploitation. Attackers can grant themselves admin access, alter configurations, and steal stored credentials. Administrators are advised to apply patches immediately or temporarily block the
/api/session/reset_passwordendpoint. More infoAtlassian Rovo AI Prompt Injection & Data Exfiltration: Security researchers demonstrated that Atlassian’s Rovo AI assistant can be tricked into leaking sensitive Jira and Confluence data. Exploiting indirect prompt injections via uploaded files or parameter flaws (“RovoBlast”) allows attackers to append internal data to external URLs. Atlassian patched the RovoBlast link flaw on July 8. More info More info Progress Kemp LoadMaster Command Injection (CVE-2026-8037): CISA added CVE-2026-8037 (CVSS 9.6) to its KEV catalog following almost 800 global exploitation attempts. The bug stems from unsanitized input in escape_quotes(), allowing unauthenticated attackers to execute arbitrary system commands. Federal agencies must patch by August 10, 2026. More infoMore info N-able N-central Authentication Bypass (CVE-2026-18577): N-able released Hotfix 2 for N-central following active exploitation of CVE-2026-18577 (CVSS 8.2), caused by an incomplete fix for CVE-2026-18556. Attackers are exploiting the flaw to gain administrative access, use Take Control capabilities, and deploy persistent Cloudflare Tunnels. More info
WordPress “XSS2Shell” Remote Code Execution Chain: Researchers disclosed an RCE chain in WordPress that escalates a login page formatting flaw via DOM clobbering and
wp_kses_postbypasses. Unauthenticated attackers can manipulate admin sessions to generate REST API Application Passwords and upload malicious plugins. The flaw was resolved in version 7.0.3. More infoCritical Flaws in AI Coding Harnesses (Gemini CLI & Claude Code): Researchers identified severe vulnerabilities in AI coding tools, including OS command injection via
.envfiles in Google’s Gemini CLI (CVE-2026-12537) and API key exfiltration in Anthropic’s Claude Code (CVE-2026-54316). Patches have been issued by both vendors. More info“NatJack” Attacks Hijack Active TCP Sessions: A newly disclosed vulnerability class exploits state-tracking logic in Windows NAT (CVE-2026-56181) and Linux Netfilter conntrack (CVE-2026-63913). Attackers can hijack active TCP connections, spoof DNS responses, and exhaust NAT tables across adjacent workloads. More info
- Novel CSS Attacks Bypass Webmail Isolation: Black Hat USA 2026 research revealed CSS sanitization bypasses affecting major providers like Outlook, Gmail, Yahoo, Proton Mail, and Fastmail. Attackers can spoof login interfaces, exfiltrate OAuth tokens, and perform prompt injections against connected AI tools. More info
🎯 Adversaries
UNC6671 Vishing Campaigns Target Major Financial Firms: Threat group UNC6671 impersonated IT support in phone calls to target over 200 high-profile firms, including Blackstone, Apollo, and KKR. Using AitM phishing portals, they captured credentials and live MFA tokens to steal Microsoft 365 and Okta data, demanding millions in ransom under brands like Redact and Pink. More info More info Head Mare Trojanizes TrueConf Server Installers: Hacktivist group Head Mare exploited unauthenticated flaws (KLCERT-26-057 and KLCERT-26-058) in unpatched TrueConf conferencing servers to distribute PhantomCore and PhantomGraph backdoors. Users downloading updates from compromised servers inadvertently infected their systems. More info
TeamPCP Deploys “Kamikaze” Wiper in Infrastructure Attacks: Oligo Security linked threat actor TeamPCP to software supply chain attacks (Operation PCPcat and ShadowRay 2.0). The group poisoned open-source libraries via GitHub Actions and introduced “kube.py,” containing a “Kamikaze” wiper aimed at destroying Kubernetes nodes. More info
ClickFix Social Engineering Pushes macOS Infostealer: A Go-based macOS infostealer is being distributed via ClickFix prompts that trick users into running Terminal commands. Operating under a fake
trustdprocess name, the malware harvests Keychain data and includes dynamic cryptocurrency draining routines. More info- Google Ads Malvertising Spreads Crypto Info-Stealers: An active malvertising campaign uses malicious Google Ads and fake crypto exchange/wallet sites to deliver trojanized installers. The dropped malware harvests browser credentials, private keys, and session cookies from victims. More info
📈 Trends
ChainDrop npm Worm Infects Over 400 Packages: Unit 42 analyzed “ChainDrop,” a self-propagating npm worm triggered via preinstall hooks. It exfiltrates cloud credentials and GitHub OIDC tokens while maintaining persistence across VS Code and Claude Code configurations. More info
Dual Attack Chains Deploy GepyS Malware and Crypto Hijackers: Gen Threat Labs highlighted two H1 2026 attack vectors: one using compromised corporate emails to deliver GepyS banking malware, and another leveraging Rust-based clipboard hijackers that resolve C2 endpoints through Binance Smart Chain smart contracts via EtherHiding. More info
💥 Breaches & Leaks
Framework, Tally, and LexisNexis Breach via Metabase Zero-Day: Laptop maker Framework, form platform Tally, and LexisNexis confirmed data breaches resulting from the exploitation of the critical Metabase SQL injection zero-day (CVSS 10.0). Stolen data includes names, email addresses, billing addresses, and hashed passwords. More info
Levi Strauss & Co. Discloses Social Engineering Data Theft: In an SEC filing, Levi Strauss & Co. reported that attackers social-engineered three employees to gain unauthorized access to corporate systems and exfiltrate data. Containment was executed quickly, preventing customer data impact or operational downtime. More info
South Korean Military Medical System Targeted: South Korean authorities investigated an intrusion targeting network infrastructure within the military medical command. Unauthorized access attempts were detected and contained before military personnel healthcare data could be exfiltrated. More info
📚 Others
- ShieldFont Web Font Blocks AI Scraping: Developers launched ShieldFont, a security-oriented web font designed to defeat automated AI web scrapers. By displaying clean text to users while placing decoy content inside raw HTML, it corrupts automated model training datasets. More info
