LIVE · cybersecurity feed
Live wire
Metabase Zero-Day Exploited in the Wild, Exposing Admin Access and Sensitive DataCritical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise DataCVE-2026-8037 · CISA Adds Progress LoadMaster Command Injection Flaw to KEV CatalogSensitive Info Goes Into ‘No Reply’ Emails Constantly. This Guy Sees It AllAtlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to AttackersNew CSS Attacks Can Break Webmail Defenses to Steal Passwords and TokensCVE-2023-38646 · Metabase Zero-Day Exploited in Wild Allows Admin Access Without AuthenticationCVE-2026-18577 · N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and PersistCVE-2026-8037 · Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit AttemptsLiving off the coding agent: Two tales of tunnels and LaunchAgents
breach

Swiss government SharePoint breach compromised 200 accounts

Switzerland's federal IT office says hackers exploited vulnerabilities to breach its Microsoft SharePoint servers and compromised approximately 200 accounts. [...]

zeroday.news ·

The Federal Office for Information Technology and Telecommunication (BIT), Switzerland's federal IT office, has confirmed a cyberattack on its Microsoft SharePoint servers that compromised approximately 200 accounts. The breach was detected on July 28 after security specialists observed unusual activity on the servers.

Following the discovery, BIT immediately took action, blocking external internet access to SharePoint, patching suspected vulnerabilities, and resetting passwords for the affected accounts. By July 31, the agency's analysis confirmed that login credentials for several accounts had been compromised.

BIT believes the attackers exploited vulnerabilities in SharePoint that Microsoft disclosed and addressed in its July 2026 Patch Tuesday updates. While the specific flaw utilized has not been publicly identified, two possibilities include CVE-2026-56164, an actively exploited privilege escalation vulnerability, or CVE-2026-50522, a critical remote code execution flaw. The latter was reportedly exploited in other incidents to steal SharePoint machine keys, enabling persistent access even after servers were patched. It remains unconfirmed if either of these particular vulnerabilities was leveraged in the Swiss government attack, or if another flaw from the same update cycle was used.

The investigation into the incident is ongoing, with assistance from the Swiss Federal Office for Cyber Security and Microsoft. As of now, BIT has found no evidence that data beyond the login credentials was stolen. The agency emphasized that confidential information and highly sensitive personal data are not permitted to be stored on the affected SharePoint platform.

As a precautionary measure, BIT is in the process of reinstalling the compromised servers. External access to SharePoint will remain blocked until this work is completed. Federal employees are currently using alternative methods for document access and external sharing.

No ransomware or data extortion group has yet claimed responsibility for the breach.

breachvulnerability
ShareXLinkedInWhatsAppFacebook

More News

view all →
breach

Hackers breach TrueConf to trojanize client installers with backdoors

The Head Mare hacktivist group has been exploiting vulnerabilities in unpatched TrueConf video conferencing servers to replace client installers with malicious versions that deliver backdoors. [...]

breachcritical

Critical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise Data

The RovoBlast attack method identified by Varonis researchers could have been exploited to steal Confluence, Jira and SharePoint data. The post Critical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise Data appeared first on SecurityWeek.

cybersecurity

China Launches Cybersecurity Review of Palo Alto Networks Products

China's Cyberspace Administration has initiated a cybersecurity review of Palo Alto Networks' products sold within the country, citing national security concerns. The review, based on national security and cybersecurity laws, lacks specific details regarding the reasons or potential impact. Palo Alto Networks has stated that its operations and product delivery in the region remain unaffected for now.

ai

Devs to Anthropic, OpenAI, Cursor, and friends: Make security and privacy the default

Researchers scour social media to measure developer concerns about AI coding tools

vulnerabilityhigh

Metabase Zero-Day Exploited in the Wild, Exposing Admin Access and Sensitive Data

Attackers exploited a CVSS 10 Metabase zero-day to gain admin access and steal sensitive data. Framework confirmed it was among the victims. Metabase just confirmed something no analytics vendor wants to write: attackers found and used an unpatched, maximum-severity flaw against Metabase Cloud before anyone on the defense side knew it existed. The company’s own […]

CVE-2026-8037critical

CISA Adds Progress LoadMaster Command Injection Flaw to KEV Catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in Progress LoadMaster products to its Known Exploited Vulnerabilities catalog. This OS command injection flaw, tracked as CVE-2026-8037, allows unauthenticated attackers to execute arbitrary commands remotely. Exploitation attempts were observed as early as June 29, 2026, shortly after a proof-of-concept exploit became available.