LIVE · cybersecurity feed
Live wire
breach

Week in review: Salesforce and ServiceNow portals exposed for 17 months, exploited Metabase 0-day

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: GitHub Dependabot malware alerts now cover eight ecosystems GitHub has flagged npm malware since March 2026. Anyone pulling in a bad PyPI, Maven, RubyGems, NuGet, Go, crates.io, or PHP Composer package has had no such warning, because GitHub’s malware detection only ever watched one ecosystem. That ch

zeroday.news ·

A zero-day vulnerability in the Metabase business intelligence service has been exploited to access customer data from Framework, a San Francisco-based laptop manufacturer. The breach exposed names, email addresses, phone numbers, physical addresses, and login IP addresses of affected Framework customers. Payment information and order records were not compromised.

Separately, researchers at Reco have identified a global campaign, dubbed "City-Forum," that has been extracting records from Salesforce and ServiceNow portals for 17 months. The campaign utilizes a domain registered in 2002 that now resolves to a generic rented server from a German hosting provider. The method of data extraction relies on the portals functioning as designed, rather than exploiting a flaw.

In other cybersecurity news, N-able has released a second security hotfix for its N-central monitoring and management (RMM) solution to address ongoing exploitation of CVE-2026-18577. This solution is widely used by managed service providers (MSPs).

Microsoft's August 2026 Patch Tuesday included fixes for over 400 vulnerabilities. Among these was CVE-2026-68820, which has been actively exploited as a zero-day. Three other vulnerabilities were publicly disclosed prior to the patch release.

Cisco has confirmed that a high-severity vulnerability, CVE-2026-20349, is being actively exploited to temporarily disrupt the operation of its firewalls. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added this flaw to its Known Exploited Vulnerabilities catalog, requiring remediation by U.S. civilian federal agencies by August 14, 2026.

In the realm of supply chain security, Valve, the video game publisher, is notifying European customers of a data breach at CEVA Logistics, its Steam hardware shipping partner. The breach involved the exposure of names, addresses, and order data.

CERT Polska reported that a cyberattack on a Polish combined heat and power (CHP) plant on December 29 represented the first observed instance of attackers gaining access to an operational technology (OT) network through a private APN. This dedicated mobile network is typically set up by a Distribution System Operator (DSO) with a mobile carrier.

Research from Dragos indicates that ransomware groups can disrupt industrial production by targeting IT systems that support industrial environments, even without direct access to industrial control systems (ICS). In the second quarter of 2026, Dragos identified 1,140 ransomware incidents affecting industrial organizations, a 12% increase from 1,020 in the first quarter.

Finally, GitHub's Dependabot malware alerts have expanded their coverage from solely npm data to include eight ecosystems: PyPI, Maven, RubyGems, NuGet, Go, crates.io, and PHP Composer. Dependabot operates across more than 30 million repositories and over 34 package ecosystems.

breachmalware
ShareXLinkedInWhatsAppFacebook

More News

view all →
ransomware

Philips and GE investigating Clop ransomware data theft claims

Tech giants General Electric (GE) and Philips have also confirmed they're investigating claims that the Clop ransomware gang breached their systems and stole data. [...]

breach

Africa’s Cybersecurity Challenge Is Bigger Than Access to Technology

Gopan Sivasankaran is Rapid7's Regional Director, Middle East & Africa. Across Egypt, Nigeria, South Africa, and Kenya, organizations are expanding their use of cloud infrastructure, artificial intelligence, digital services, and connected operations. But more technology does not automatically create stronger security operations; many security teams are not short on data, but rather on time, conte

security

Hacking Public Wi-Fi DNS to Steal Credentials

Criminals are hacking into public Wi-Fi devices—at hotels, conference centers, and so on—around the world and changing their DNS settings. The goal is to redirect users to fake login pages and steal their credentials.

security

Fake TikTok rewards promise cash you’ll never get

TikTok-branded rewards pages offer cash for simple tasks and daily check-ins. But getting your hands on the money is another story.

vulnerability

Recent macOS Screen Sharing Vulnerability Exploited in Attacks

Threat actors gained root access to the vulnerable systems and deployed a Monero miner. The post Recent macOS Screen Sharing Vulnerability Exploited in Attacks appeared first on SecurityWeek.

CVE-2026-58231critical

Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure

The vulnerability tracked as CVE-2026-58231 can be exploited to execute arbitrary code and compromise internal components. The post Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure appeared first on SecurityWeek.