The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical command injection vulnerability in Progress LoadMaster, tracked as…
Tag: Vulnerability
Metabase Zero-Day Allows Unauthenticated Admin Access
Metabase has released security patches addressing a critical vulnerability that was exploited as a zero-day, allowing unauthenticated remote attackers to…
Cyber vulnerability sweep picks up Royal Navy drones sending data to China
No, no nasties to see here, guv…
N-able ships second N-central hotfix as attackers keep exploiting CVE-2026-18577
To help customers fend off ongoing attacks, N-able released a second security hotfix for N‑central, its monitoring and management (RMM) solution popular…
Metabase Patches Vulnerability Exploited as Zero-Day
The security defect allows unauthenticated, remote attackers to gain administrative access to Metabase instances.
Framework loses customer data in Metabase zero-day attack
Repairable hardware is little comfort when personal details escape
Atlassian Rovo AI Vulnerability Lets Attackers Steal Enterprise Data With a Single Click
RovoBlast is a recently disclosed vulnerability affecting Atlassian’s Rovo AI assistant that allows attackers to expose sensitive enterprise data through…
CISA Urges Immediate Patching of Exploited Progress LoadMaster Vulnerability
The critical-severity flaw allows unauthenticated, remote attackers to execute arbitrary commands.
Metabase 0-Day Vulnerability Exploited in the Wild to Gain Admin Access
Metabase, the widely used open-source business intelligence and data visualization platform, has confirmed that a critical zero-day vulnerability tracked…
SQL Injection Used in Zero-Day Metabase Customer Data Theft Hacks
To exploit customer instances in data theft hacks, a critical Metabase SQL injection flaw was abused in zero day attacks. The vulnerability impacted Tally…
Critical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise Data
The RovoBlast attack method identified by Varonis researchers could have been exploited to steal Confluence, Jira and SharePoint data.
Metabase Zero-Day Exploited in the Wild, Exposing Admin Access and Sensitive Data
Attackers exploited a CVSS 10 Metabase zero-day to gain admin access and steal sensitive data. Framework confirmed it was among the victims. Metabase just…
18-Year-Old Linux Kernel SCTP Vulnerability Lets Attackers Gain Root and Escape Containers
SCTPhantom, tracked as CVE-2026-64564, is a high-severity Linux kernel use-after-free vulnerability in the Stream Control Transmission Protocol (SCTP)…
Critical macOS RCE Vulnerability Allows Attackers to Gain Root Access Without Password
Apple has shipped emergency macOS updates to close a critical vulnerability in Screen Sharing, tracked as CVE-2026-65400, which allows unauthenticated…
Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication
Metabase has warned that a maximum-severity security flaw impacting its business intelligence and data visualization software package has been exploited…
Wordfence Intelligence Weekly WordPress Vulnerability Report (July 27, 2026 to August 2, 2026)
Last week, there were disclosed in and that have been added to the Wordfence Intelligence Vulnerability Database, and there were that contributed to…
18-Year-Old Linux Kernel SCTP Vulnerability Lets Attackers Gain Full Root on Host
A newly disclosed Linux kernel vulnerability, dubbed SCTPhantom and tracked as CVE-2026-64564, allows attackers to escalate from unprivileged local access…
New ‘Zapscape’ Linux KVM Vulnerability Opens Path for Privileged Guest-to-Host Escape
A newly disclosed vulnerability in Linux’s Kernel-based Virtual Machine (KVM) could allow an attacker with kernel-level control inside a nested virtual…
CVE-2026-64561 Zapscape Lets KVM Guests Escape to Linux Host With Root Privileges
A Linux kernel vulnerability, tracked as CVE-2026-64561 and named Zapscape, could allow attackers to escape a KVM virtual machine and take control of its…
AI-Assisted HTTP Terminator Finds Novel HTTP Desync Techniques and Apache Zero-Day
PortSwigger says HTTP Terminator, an artificial intelligence (AI)-assisted research system built by James Kettle, generated and proved new HTTP…
