New research demos also show CSS/HTML attack paths across Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail that can leak tokens, hijack UI actions, or lead to account takeover.
Metabase has warned that a maximum-severity security flaw impacting its business intelligence and data visualization software package has been exploited in the wild as a zero-day.
The vulnerability (CVSS score: 10.0), which does not carry a CVE identifier, allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, enabling them to gain administrator access to the instance.
The vulnerability (CVSS score: 10.0), which does not carry a CVE identifier, allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, enabling them to gain administrator access to the instance.
Attackers are exploiting a LoadMaster flaw for command execution.
CVE-2026-8037 lets unauthenticated attackers run arbitrary commands on affected appliances. KEVIntel logged 792 exploitation attempts from 65 IPs in 41 days.
CVE-2026-8037 lets unauthenticated attackers run arbitrary commands on affected appliances. KEVIntel logged 792 exploitation attempts from 65 IPs in 41 days.
Nearly 800 malicious npm packages are delivering a cross-platform RAT and infostealer.
The campaign targets Windows, macOS, and Linux, with WEL1DROPPER fetching platform-specific payloads and falling back to DNS TXT records when HTTPS fails.
The campaign targets Windows, macOS, and Linux, with WEL1DROPPER fetching platform-specific payloads and falling back to DNS TXT records when HTTPS fails.
A newly discovered WordPress pre-auth XSS affects every version.
XSS2Shell (CVE-2026-64638) can run attacker-controlled JS in a site's origin without a login. With a logged-in Administrator, one click, and required deployment conditions, it can be chained to PHP code execution.
XSS2Shell (CVE-2026-64638) can run attacker-controlled JS in a site's origin without a login. With a logged-in Administrator, one click, and required deployment conditions, it can be chained to PHP code execution.
Three new Cisco SD-WAN flaws just scored 9.9.
Cisco also patched a 9.8 IOS XE command injection bug. A separate IMC flaw with public PoC could let a low-privilege attacker gain root on a controller that can influence BIOS and Secure Boot.
Cisco also patched a 9.8 IOS XE command injection bug. A separate IMC flaw with public PoC could let a low-privilege attacker gain root on a controller that can influence BIOS and Secure Boot.
ZBT Firmware Backdoor Dubbed ENDLESSDOORS
Researchers say the hidden backdoor enables remote command execution with full root privileges on affected routers.
Researchers say the hidden backdoor enables remote command execution with full root privileges on affected routers.
Ukraine Receives €1.5 Billion Cyber Defense Support
An 18-nation coalition has provided funding, equipment, cloud services, and cyber-defense assistance to Ukraine.
An 18-nation coalition has provided funding, equipment, cloud services, and cyber-defense assistance to Ukraine.
EU Approves 348-Satellite IRIS² Network
Europe’s planned satellite constellation will provide secure communications for government, defense, and emergency services.
Europe’s planned satellite constellation will provide secure communications for government, defense, and emergency services.
TONTOU Attack Bypasses Spectre Defenses
Researchers demonstrated a technique that can circumvent some Spectre v2 protections on AMD and Intel processors.
Researchers demonstrated a technique that can circumvent some Spectre v2 protections on AMD and Intel processors.
IBM Gives AI Security Tools to Universities
IBM and Red Hat will provide free vulnerability-analysis services to U.S. universities and nonprofit organizations.
IBM and Red Hat will provide free vulnerability-analysis services to U.S. universities and nonprofit organizations.
Newcastle University confirms data breach after ExfilSquad claims 440k records.
Nikita Bier is stepping down as X’s head of product after roughly a year in the role, but will remain as an adviser. The move comes amid continued leadership changes at the platform—watching closely for who takes over product.
Levi Strauss discloses data breach after social engineering attack on employees.
UK Naval Drones Found Transmitting Data Signals to China
A routine cyber audit by the UK Ministry of Defense revealed that cameras on Kraken Technology naval drones were transmitting signals to an internet address in China
A routine cyber audit by the UK Ministry of Defense revealed that cameras on Kraken Technology naval drones were transmitting signals to an internet address in China
Anthropic now invisibly marks Claude-generated content worldwide, following new EU AI Act transparency rules effective August 2026.
Supported Claude models embed machine-readable watermarks directly into text, which can survive copy-pasting.
Generated images/files can carry signed C2PA provenance metadata.
Supported Claude models embed machine-readable watermarks directly into text, which can survive copy-pasting.
Generated images/files can carry signed C2PA provenance metadata.
ICYMI: One click from a logged-in WordPress admin can trigger a chain from pre-auth XSS to PHP code execution.
CVE-2026-64638 affects all WordPress versions, and the login-page XSS itself requires no authentication.
CVE-2026-64638 affects all WordPress versions, and the login-page XSS itself requires no authentication.
Mozilla revoked the Firefox and Thunderbird Linux signing key after an unencrypted copy was accidentally committed to a private repo.
No unauthorized access was found, but older downloads can stop verifying and some Firefox RPM updates may fail.
No unauthorized access was found, but older downloads can stop verifying and some Firefox RPM updates may fail.
A malicious SIM can take over the modem from inside the device.
Researchers found 9 of 26 tested phones and cellular modules accept RUN AT commands from the SIM, including 6 of the 8 modules. On one commercial EV charger, they chained the interface to code execution.
Researchers found 9 of 26 tested phones and cellular modules accept RUN AT commands from the SIM, including 6 of the 8 modules. On one commercial EV charger, they chained the interface to code execution.