Metabase SQLi Zero-Day Flaw Grants Attackers Admin Access and Steals Database Credentials
August 7, 2026 A critical SQL injection vulnerability in Metabase is under active zero-day exploitation, allowing unauthenticated attackers to seize administrator control of instances and steal connected database credentials. The flaw has already…
CISA KEV Alert: IBM Langflow CVE Enables Unauthenticated RCE on AI Workflow Platform
August 8, 2026 The U.S. Cybersecurity and Infrastructure Security Agency has added CVE-2026-9198 to its Known Exploited Vulnerabilities catalog. This critical flaw in IBM Langflow OSS allows unauthenticated attackers to execute remote code with superuser…
NatJack NAT Attack Hijacks TCP Sessions and Spoofs DNS
August 6, 2026 Security researcher Malcolm Stagg has disclosed a new attack class called NatJack that manipulates network address translation connection state to hijack active TCP sessions, spoof DNS responses, and disclose victim IP addresses and mapped…
N-able CVE: Active Exploitation of N-central Auth Bypass Threatens MSPs and Downstream Clients
August 4, 2026 N-able has confirmed active exploitation of an authentication bypass vulnerability in its N-central remote monitoring and management platform. The flaw, tracked as CVE-2026-18577, allows threat actors to seize administrative control of…
Iranian APT Actors Exploit Internet-Exposed PLCs in U.S. Critical Infrastructure
August 3, 2026 Iranian-affiliated threat actors are actively exploiting internet-exposed programmable logic controllers (PLCs) across U.S. critical infrastructure sectors, including government facilities, water systems, and energy plants. A joint…
CISA KEV Alert for Active Zero-Day Exploitation of Cisco FMC
July 30, 2026 CISA has added a newly disclosed Cisco Secure Firewall Management Center zero-day to its Known Exploited Vulnerabilities catalog after confirming active exploitation in the wild. The vulnerability, tracked as CVE-2026-20316, allows…
Critical Rails Active Storage Flaw Exposes Server Secrets
July 29, 2026 A critical vulnerability in Ruby on Rails Active Storage could let unauthenticated attackers read arbitrary files from application servers using crafted image uploads. Tracked as CVE-2026-66066 with a CVSS score of 9.5, the flaw exposes…
Server BMCs Leak Password Hashes via 20-Year-Old IPMI Flaw
July 28, 2026 More than 24,000 internet-exposed servers are leaking authentication password hashes through a 20-year-old vulnerability in their Baseboard Management Controller interfaces. Researchers at cybersecurity firm Lava discovered that…
Critical Pre-Auth RCE Flaw Enables Remote Code Execution
July 28, 2026 A critical pre-authentication remote code execution vulnerability in vBulletin forum software allows unauthenticated attackers to execute arbitrary PHP code on affected servers. The flaw, tracked as CVE-2026-61511, impacts versions 5.7.5…
Dysphoria IoT Botnet Hijacks Devices Worldwide
July 28, 2026 A rapidly evolving IoT botnet named Dysphoria has infected an estimated 200,000 devices worldwide. Consequently, defenders must understand its blockchain-based command-and-control architecture and aggressive DDoS capabilities. The botnet…