CyberNews: 09/08/2026 Edition

Published by Dunateo on 2026-08-09

Today’s roundup

  • CISA Urges Utilities to Remove Internet-Exposed PLCs After Minnesota Attacks
  • Metabase Zero-Day Exploited in the Wild, Exposing Admin Access and Sensitive Data
  • INC Ransomware is Calling Victims – Pressure Tactics Post SonicWall Zero-Day Exploit
  • Hackers breach TrueConf to trojanize client installers with backdoors
  • Researchers Discover Hidden Backdoor in 20 Router Models Allowing Remote Root Access
  • WordPress XSS2Shell Flaw Turns Simple Login Bug Into Full Server Takeover
  • CVE-2026-58048: cPanel Bug Enables Full Database Administrator Access
  • OVSwrap: 13-Year-Old Linux Kernel Flaw Lets Local Users Become Root
  • Unlimited Technology Systems Data Breach Exposes Data of 3.8 Million Healthcare Patients
  • SharePoint Flaws Used to Hack Switzerland’s Federal IT Agency
  • Summary

    The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent advisory to utility companies, recommending the removal of internet-exposed Programmable Logic Controllers (PLCs) following recent cyberattacks in Minnesota that targeted industrial control systems. This highlights critical vulnerabilities in operational technology environments.


    A zero-day vulnerability in Metabase, an open-source business intelligence platform, is actively being exploited. Attackers are leveraging this flaw to gain administrative access, leading to the exposure of sensitive data. Immediate patching is strongly advised for affected installations.


    INC Ransomware group is reportedly employing new and aggressive pressure tactics, including direct phone calls to victims, following successful exploitation of a zero-day vulnerability in SonicWall products. This indicates a concerning evolution in ransomware operational strategies and post-compromise victim engagement.


    The Head Mare hacktivist group has breached TrueConf video conferencing servers, exploiting unpatched vulnerabilities to distribute trojanized client installers containing backdoors. This supply chain attack poses a significant risk to users of TrueConf services.


    Security researchers have uncovered hidden backdoors providing remote root access in 20 different router models. This discovery raises serious supply chain integrity concerns and impacts the foundational security of numerous networking devices used by consumers and businesses.


    A critical XSS2Shell vulnerability (CVE-2026-64638) in WordPress can be leveraged from a simple login bug to achieve a full server takeover. This flaw represents a severe remote code execution risk for a vast number of WordPress installations globally.


    A significant cPanel vulnerability, identified as CVE-2026-58048, allows unauthorized individuals to gain full database administrator access. This critical flaw poses a considerable threat to web hosting providers and websites utilizing cPanel for management.


    A 13-year-old privilege escalation vulnerability, dubbed OVSwrap, has been found within the Linux kernel. This flaw enables local users to escalate their privileges to root, affecting a wide array of Linux-based systems and requiring prompt remediation.


    Unlimited Technology Systems, a provider of healthcare technology, has confirmed a data breach affecting 3.8 million healthcare patients. The incident resulted in the exposure of sensitive personal health information, underscoring ongoing cybersecurity challenges in the healthcare sector.


    Switzerland's Federal Office for Information Technology (FOITT) was targeted by a cyberattack that exploited vulnerabilities in SharePoint. This incident highlights persistent threats against government IT infrastructure and the ongoing need for robust defense mechanisms.

    Want to dig deeper?

    Vulnerabilities

    CVE-2026-58048 High
    CVE-2026-64638 High