CyberNews: 08/08/2026 Edition
Today’s roundup
Summary
A critical Metabase SQL injection zero-day (CVSS 10.0) is actively exploited, granting unauthenticated admin access and data theft. Self-hosted instances on versions 0.58 through 0.63.5 are vulnerable; Framework confirmed a breach. Immediate updates are crucial, and a log signature helps detect compromise.
WordPress faces an "XSS2Shell" vulnerability chain allowing unauthenticated RCE and full server takeover. The exploit on the login page uses DOM clobbering to gain admin application passwords and execute arbitrary PHP. Updates to WordPress 7.0.3, or backported fixes to 4.7, are urgently recommended.
CISA added critical Progress Kemp LoadMaster flaw, CVE-2026-8037 (CVSS 9.6) command injection, to its KEV catalog due to active exploitation. Unauthenticated attackers can execute arbitrary commands on LoadMaster appliances. Federal agencies must remediate by August 10, 2026.
A new supply chain campaign features nearly 800 malicious npm packages using "AI slop squatted" names. They deliver cross-platform RATs and infostealers targeting Windows, macOS, and Linux, posing a significant threat to developers.
Atlassian's Rovo AI assistant can be tricked by attacker-controlled instructions to exfiltrate sensitive Jira and Confluence data to external servers. This data theft vulnerability was independently found by two security firms, with one exploitation route patched.
N-able released "Hotfix 2" for its N-central RMM platform due to persistent and evolving attacks exploiting CVE-2026-18577. This aims to expand protections against attackers gaining administrative access to servers and compromising managed customer systems.
IEH Corporation, a U.S. military device manufacturer, disclosed a cyber incident to the SEC. The attack, discovered on Tuesday, led to immediate containment efforts, highlighting ongoing cybersecurity risks within the defense industrial base.
"ClickFix-style" attacks deploy Go-based macOS malware stealing cryptocurrency, browser passwords, iCloud Keychain, and cached credentials. The infection chain profiles the system and delivers a CPU-architecture-compatible payload for extensive data exfiltration.
The National Rural Water Association and cybersecurity experts launched a "Water Watch Center" to help U.S. water utilities bolster defenses. This responds to escalating cyber threats and recent attacks on critical infrastructure in multiple states.
Gen's H1 2026 Threat Report details two active attack chains: one uses compromised business inboxes and browser manipulation for banking malware, the other employs clipboard hijacking for cryptocurrency payment redirection. These highlight evolving financial cybercrime tactics.
Want to dig deeper?
Vulnerabilities
| CVE-2026-8037 | Critical |
| CVE-2026-18577 | Critical |