CyberNews: 08/08/2026 Edition

Published by Dunateo on 2026-08-08

Today’s roundup

  • Metabase Zero-Day Exploited in the Wild, Exposing Admin Access and Sensitive Data
  • WordPress XSS2Shell Flaw Turns Simple Login Bug Into Full Server Takeover
  • U.S. CISA adds a Progress LoadMaster flaw to its Known Exploited Vulnerabilities catalog
  • Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer
  • Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers
  • N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist
  • Military device manufacturer discloses cyber incident to SEC
  • ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets
  • Water utilities group partners with DEF CON offshoot for Water Watch Center
  • Real emails, hijacked payments: Two H1 2026 attack chains
  • Summary

    A critical Metabase SQL injection zero-day (CVSS 10.0) is actively exploited, granting unauthenticated admin access and data theft. Self-hosted instances on versions 0.58 through 0.63.5 are vulnerable; Framework confirmed a breach. Immediate updates are crucial, and a log signature helps detect compromise.

    WordPress faces an "XSS2Shell" vulnerability chain allowing unauthenticated RCE and full server takeover. The exploit on the login page uses DOM clobbering to gain admin application passwords and execute arbitrary PHP. Updates to WordPress 7.0.3, or backported fixes to 4.7, are urgently recommended.

    CISA added critical Progress Kemp LoadMaster flaw, CVE-2026-8037 (CVSS 9.6) command injection, to its KEV catalog due to active exploitation. Unauthenticated attackers can execute arbitrary commands on LoadMaster appliances. Federal agencies must remediate by August 10, 2026.

    A new supply chain campaign features nearly 800 malicious npm packages using "AI slop squatted" names. They deliver cross-platform RATs and infostealers targeting Windows, macOS, and Linux, posing a significant threat to developers.

    Atlassian's Rovo AI assistant can be tricked by attacker-controlled instructions to exfiltrate sensitive Jira and Confluence data to external servers. This data theft vulnerability was independently found by two security firms, with one exploitation route patched.

    N-able released "Hotfix 2" for its N-central RMM platform due to persistent and evolving attacks exploiting CVE-2026-18577. This aims to expand protections against attackers gaining administrative access to servers and compromising managed customer systems.

    IEH Corporation, a U.S. military device manufacturer, disclosed a cyber incident to the SEC. The attack, discovered on Tuesday, led to immediate containment efforts, highlighting ongoing cybersecurity risks within the defense industrial base.

    "ClickFix-style" attacks deploy Go-based macOS malware stealing cryptocurrency, browser passwords, iCloud Keychain, and cached credentials. The infection chain profiles the system and delivers a CPU-architecture-compatible payload for extensive data exfiltration.

    The National Rural Water Association and cybersecurity experts launched a "Water Watch Center" to help U.S. water utilities bolster defenses. This responds to escalating cyber threats and recent attacks on critical infrastructure in multiple states.

    Gen's H1 2026 Threat Report details two active attack chains: one uses compromised business inboxes and browser manipulation for banking malware, the other employs clipboard hijacking for cryptocurrency payment redirection. These highlight evolving financial cybercrime tactics.

    Want to dig deeper?

    Vulnerabilities

    CVE-2026-8037 Critical
    CVE-2026-18577 Critical