LIVE · cybersecurity feed
Live wire
Metabase Zero-Day Exploited in the Wild, Exposing Admin Access and Sensitive DataCritical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise DataCVE-2026-8037 · CISA Adds Progress LoadMaster Command Injection Flaw to KEV CatalogSensitive Info Goes Into ‘No Reply’ Emails Constantly. This Guy Sees It AllAtlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to AttackersNew CSS Attacks Can Break Webmail Defenses to Steal Passwords and TokensCVE-2023-38646 · Metabase Zero-Day Exploited in Wild Allows Admin Access Without AuthenticationCVE-2026-18577 · N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and PersistCVE-2026-8037 · Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit AttemptsLiving off the coding agent: Two tales of tunnels and LaunchAgents

identity management

vishinghigh

UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data

A sophisticated cybercrime group known as UNC6671 is employing vishing attacks, targeting employees' personal phones to steal SaaS data. The attackers impersonate IT support, tricking victims into fraudulent login portals that capture credentials and multi-factor authentication tokens. This allows them to gain access to cloud environments and applications like Microsoft 365 and Okta, deploying scripts for data exfiltration.