LIVE · cybersecurity feed
Live wire
Metabase Zero-Day Exploited in the Wild, Exposing Admin Access and Sensitive DataCritical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise DataCVE-2026-8037 · CISA Adds Progress LoadMaster Command Injection Flaw to KEV CatalogSensitive Info Goes Into ‘No Reply’ Emails Constantly. This Guy Sees It AllAtlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to AttackersNew CSS Attacks Can Break Webmail Defenses to Steal Passwords and TokensCVE-2023-38646 · Metabase Zero-Day Exploited in Wild Allows Admin Access Without AuthenticationCVE-2026-18577 · N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and PersistCVE-2026-8037 · Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit AttemptsLiving off the coding agent: Two tales of tunnels and LaunchAgents
scamsmedium

Congress Questions Executive Branch, Allies on Anti-Scam Coordination

US Senators questioned Trump administration officials regarding the coordination between federal agencies and international allies in combating scams. Lawmakers raised concerns about the lack of a central authority overseeing the numerous federal agencies involved and whether current efforts are sufficient to address transnational scam operations. Discussions also touched upon the potential need for a multinational coordination mechanism similar to those used for drug trafficking.

zeroday.news ·

A recent Senate Foreign Relations Committee hearing explored the complexities of combating international scam operations, with senators from both parties questioning Trump administration officials on the coordination of efforts among federal agencies and foreign allies. Witnesses acknowledged ongoing work to improve these efforts, which currently involve at least 13 federal agencies.

Lawmakers and administration officials alike noted that cracking down on scam operations in one location often leads to their relocation elsewhere, highlighting the transnational nature of the problem. Senator Pete Ricketts, R-Neb., drew a parallel to the 1990s Joint Interagency Task Force South, which targeted drug trafficking. He inquired whether the current threat, which combines cybercrime, human trafficking, money laundering, and cryptocurrency, warrants a similar multinational coordination mechanism.

Senator Jeanne Shaheen, D-N.H., emphasized the need for unified federal leadership, paraphrasing a former federal official who stated there is no single individual heading the interagency effort. She advocated for treating the issue with the urgency of combat and assigning a clear leader. Shaheen is a co-sponsor of the bipartisan Scam Compound Accountability and Mobilization (SCAM) Act, which aims to consolidate federal initiatives.

David Bedard, Deputy Assistant Secretary at the State Department’s Bureau of International Narcotics and Law Enforcement Affairs, informed Senator Shaheen that President Donald Trump considers scammers a national security priority. He explained that a presidential executive order is intended to address coordination, with an action plan currently undergoing interagency review to resolve potential conflicts. Bedard stated that a task force established by the executive order, which includes an international component, is expected to resolve these issues.

Bedard also mentioned that the administration shares intelligence with foreign allies, and Interpol maintains productive channels, including setting up its own task force. However, concerns exist about other countries potentially duplicating these actions.

Michael DeSombre, Assistant Secretary at the Bureau of East Asian and Pacific Affairs, and Bedard reported progress on the international front. DeSombre noted that President Trump has discussed the issue with Chinese President Xi Jinping, and China has leveraged its influence in Asia due to its own citizens becoming scam victims. Progress has been more significant in countries with stronger U.S. relations, such as Cambodia, compared to those with less close ties, like Burma and Laos. In Cambodia, a key strategy has been to prioritize the pursuit of scam center bosses.

scamscybercrimeinternational cooperationgovernment coordination
ShareXLinkedInWhatsAppFacebook

More News

view all →
breach

Hackers breach TrueConf to trojanize client installers with backdoors

The Head Mare hacktivist group has been exploiting vulnerabilities in unpatched TrueConf video conferencing servers to replace client installers with malicious versions that deliver backdoors. [...]

cybersecurity

China Launches Cybersecurity Review of Palo Alto Networks Products

China's Cyberspace Administration has initiated a cybersecurity review of Palo Alto Networks' products sold within the country, citing national security concerns. The review, based on national security and cybersecurity laws, lacks specific details regarding the reasons or potential impact. Palo Alto Networks has stated that its operations and product delivery in the region remain unaffected for now.

ai

Devs to Anthropic, OpenAI, Cursor, and friends: Make security and privacy the default

Researchers scour social media to measure developer concerns about AI coding tools

vulnerabilityhigh

Metabase Zero-Day Exploited in the Wild, Exposing Admin Access and Sensitive Data

Attackers exploited a CVSS 10 Metabase zero-day to gain admin access and steal sensitive data. Framework confirmed it was among the victims. Metabase just confirmed something no analytics vendor wants to write: attackers found and used an unpatched, maximum-severity flaw against Metabase Cloud before anyone on the defense side knew it existed. The company’s own […]

breachcritical

Critical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise Data

The RovoBlast attack method identified by Varonis researchers could have been exploited to steal Confluence, Jira and SharePoint data. The post Critical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise Data appeared first on SecurityWeek.

CVE-2026-8037critical

CISA Adds Progress LoadMaster Command Injection Flaw to KEV Catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in Progress LoadMaster products to its Known Exploited Vulnerabilities catalog. This OS command injection flaw, tracked as CVE-2026-8037, allows unauthenticated attackers to execute arbitrary commands remotely. Exploitation attempts were observed as early as June 29, 2026, shortly after a proof-of-concept exploit became available.