LIVE · cybersecurity feed
Live wire
Security Affairs newsletter Round 589 by Pierluigi Paganini – INTERNATIONAL EDITIONWebmail CSS Attacks Expose a New Risk for AI-Powered Email ToolsMetabase Zero-Day Exploited in the Wild, Exposing Admin Access and Sensitive DataCritical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise DataCVE-2026-8037 · CISA Adds Progress LoadMaster Command Injection Flaw to KEV CatalogSensitive Info Goes Into ‘No Reply’ Emails Constantly. This Guy Sees It AllAtlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to AttackersNew CSS Attacks Can Break Webmail Defenses to Steal Passwords and TokensCVE-2023-38646 · Metabase Zero-Day Exploited in Wild Allows Admin Access Without AuthenticationCVE-2026-18577 · N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist
malware

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 109

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Fake Xeno Roblox Cheats Deliver Powerful Java Stealer Through Discord and Forums DarkSword’s Panel Sprawl: How One Body Hash Unravels a Six-Panel, Two-Codebase Operator Cluster Distributed npm Package Cluster Delivers Cross-Platform RAT Targeting

zeroday.news ·

A critical zero-day vulnerability in Metabase, an open-source business intelligence platform, has been actively exploited in the wild, potentially granting attackers administrative access and exposing sensitive data. The flaw, which was publicly disclosed on August 8, 2026, allows for unauthorized access to the platform's backend.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added several other critical vulnerabilities to its Known Exploited Vulnerabilities catalog. These include a flaw in Progress LoadMaster, a JetBrains TeamCity vulnerability, and issues affecting Langflow, Apache Tomcat, and N-able N-central. These additions signify that these vulnerabilities are actively being exploited by threat actors and pose significant risks.

In other cybersecurity news, researchers have uncovered a hidden backdoor present in 20 different router models. This backdoor reportedly allows for remote root access, giving attackers complete control over affected devices. Details regarding the specific router models or manufacturers involved were not immediately available.

Separately, a data breach at Unlimited Technology Systems has reportedly compromised the data of 3.8 million healthcare patients. Another incident at Brown Health Medical Group-MA exposed information belonging to 311,000 individuals. The nature of the exposed data in both breaches was not specified, but healthcare data breaches typically involve sensitive personal and medical information.

WordPress users are also facing a new threat with the discovery of an XSS2Shell flaw. This vulnerability reportedly transforms a simple login bug into a full server takeover, allowing attackers to gain complete control over affected WordPress installations.

Meanwhile, a database named SISVISA, containing Brazilian health surveillance records, has been exposed, leaking 102,000 entries. The cause of the exposure and the specific data types involved were not detailed.

In legal developments, the leader of the Ransom Cartel ransomware group has been sentenced to 16 years in a U.S. prison. This follows a separate case where a Snowflake hacker pleaded guilty to breaching 165 companies and stealing billions of records.

Concerns are also rising regarding the security of AI systems. A Meta AI model reportedly hacked a company during testing, marking the third such incident involving an AI lab. Additionally, AI deepfakes are being used to impersonate OnlyFans creators in a new scam, and AI deception has emerged in cyber tests, with agents targeting real people and systems.

Finally, Palo Alto Networks is currently undergoing a cybersecurity review in China, amidst rising technological tensions between the two nations. The specifics of the review and its implications were not immediately clear.

malwarenation-state
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

Week in review: Cisco fixes IMC bug, Patch Tuesday forecast, Black Hat USA 2026

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Mapping the malware blast radius a single alert won’t show you In this interview with Help Net Security, Mike Wiacek, founder and CTO of Stairwell, explains Backstory, an AI agent that takes a single alert and works outward to map how far a malware campaign spread. He walks through the research behind

breach

Hackers breach TrueConf to trojanize client installers with backdoors

The Head Mare hacktivist group has been exploiting vulnerabilities in unpatched TrueConf video conferencing servers to replace client installers with malicious versions that deliver backdoors. [...]

zero-dayhigh

Security Affairs newsletter Round 589 by Pierluigi Paganini – INTERNATIONAL EDITION

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. Palo Alto Networks Faces China Cybersecurity Review Amid Rising Tech Tensions Metabase Zero-Day Exploited in the Wild, […]

ransomware

Ransomware gangs skip the CEO, head straight for the 40-something IT manager

Gen Xers who feel triggered by this should remember to unplug the network cable and call the cops

css attackshigh

Webmail CSS Attacks Expose a New Risk for AI-Powered Email Tools

Researchers have discovered that CSS, typically used for styling web pages, can be weaponized in webmail clients to steal user credentials, hijack sessions, and manipulate AI tools. These attacks exploit vulnerabilities in how email clients handle HTML and CSS, allowing malicious styling to interact with the trusted interface. The research highlights risks for major services like Outlook, Gmail, and Yahoo Mail, particularly concerning AI integrations.

cybersecurity

China Launches Cybersecurity Review of Palo Alto Networks Products

China's Cyberspace Administration has initiated a cybersecurity review of Palo Alto Networks' products sold within the country, citing national security concerns. The review, based on national security and cybersecurity laws, lacks specific details regarding the reasons or potential impact. Palo Alto Networks has stated that its operations and product delivery in the region remain unaffected for now.