Cybersecurity Newsfeed - 11/08/26
Daily cybersecurity news covering vulnerabilities, adversaries, trends, breaches, and other notable security developments.
Cybersecurity Newsfeed
📅 11/08/26
🛡️ Vulnerabilities
BDThemes WordPress Plugin Supply Chain Attack & Poisoned API: BDThemes plugins suffered a supply chain compromise via a poisoned update API, resulting in malicious code injections across multiple WordPress plugins. Attackers leveraged the compromised mechanism to create unauthorized rogue administrator accounts for persistence and data exfiltration. Site owners are urged to audit user accounts and update to patched versions immediately. More info More info Metabase SQL Injection Zero-Day Exploited in Wild: Metabase installations are facing widespread attacks due to an unauthenticated zero-day SQL injection vulnerability. The flaw allows remote attackers to execute arbitrary database queries, leading to potential data theft and total system takeover. Organizations should update Metabase immediately and restrict administrative access to internal networks. More info
CISA Warns of SonicWall SMA1000 Flaws: CISA added critical vulnerabilities in SonicWall SMA1000 series appliances to its KEV catalog following active exploitation by ransomware gangs. The flaws allow unauthenticated code execution and authentication bypass, requiring immediate patching and network access restrictions. More info
Critical N-Able N-Central Vulnerability (CVE-2026-18577): N-able issued an urgent hotfix for N-Central addressing a high-severity flaw that allows remote attackers to gain unauthorized access or escalate privileges. MSPs are advised to apply the patch immediately and audit logs for potential client network compromises. More info
CISA Issues Alert on Progress LoadMaster Flaw: A critical flaw in Progress LoadMaster load balancers is under active exploitation, enabling remote unauthenticated code execution. Administrators must apply patches immediately and isolate management interfaces from the public internet. More info
- Coruna and Darksword iOS Exploits Proliferate: Sophisticated Coruna and Darksword iOS exploit chains targeting Apple mobile devices are spreading globally. Used for covert surveillance and data exfiltration, these high-end mobile exploits bypass standard security controls, highlighting the need for strict device management and rapid OS updates. More info
🎯 Adversaries
Head Mare Group Exploits TrueConf Software: Threat actor group “Head Mare” is actively targeting TrueConf communication hubs by exploiting architectural flaws to achieve remote code execution and maintain persistent access. Administrators should patch servers immediately and restrict access to trusted IP ranges. More info
Hackers Pivot from IT to OT via Private APN in Poland: Threat actors crossed into operational technology (OT) infrastructure in Poland by exploiting a private Access Point Name (APN) mobile entry point. By bypassing perimeter defenses, attackers moved laterally into industrial control environments, underscoring critical risks in IT/OT convergence. More info
New StormEncryptor Ransomware Emerges: Operatives tied to a former Medusa ransomware affiliate have deployed StormEncryptor, a new ransomware variant utilizing advanced encryption techniques to lock enterprise networks. Defense teams are urged to monitor for Medusa-linked TTPs and enforce strict MFA. More info
DeadLock Ransomware Leverages Rust and Decentralized Recovery: Microsoft published analysis on DeadLock, a novel Rust-based ransomware strain using memory safety features and obfuscation alongside a decentralized recovery infrastructure to ensure persistence despite command server disruption. More info
📈 Trends
Python Integrates Post-Quantum Cryptography Library: Python has officially integrated a dedicated post-quantum encryption library into its standard ecosystem, enabling developers to build quantum-resistant primitives into modern software and counter “harvest now, decrypt later” threats. More info
Microsoft Edge Dropping Legacy Extension Support: Edge is ending support for older extension standards as part of its Manifest V3 transition. While strengthening browser security, the move may break popular legacy privacy and security extensions. More info
Faking Digital Data Trails to Manipulate Prices: Analysis highlights how threat actors weaponize false digital data trails to trick automated tracking and commerce algorithms, manipulating dynamic pricing models for economic advantage. More info
GitHub Misconfiguration Allows AI Benchmark Manipulation: A misconfiguration in repository settings allowed unauthorized users to manipulate data powering the Kimi K3 cybersecurity benchmark, raising concerns about the security of automated testing pipelines. More info
💥 Breaches & Leaks
Valve Notifies Steam Hardware Customers of Breach: Valve has begun notifying Steam hardware customers after discovering anomalous activity that exposed contact information. Payment details were reportedly uncompromised. More info
LexisNexis Shuts Down Services After Suspicious Activity: LexisNexis suspended specific data services as a precautionary measure following the detection of unauthorized server activity while an investigation takes place. More info
