Attackers reportedly exploited a critical Metabase zero-day (CVSS 10) to gain admin access and steal sensitive data, including cases where victims included Metabase Cloud customers. Security researchers say the flaw was used before defenders even knew it existed, underscoring how quickly “unknown” cloud vulnerabilities can become real incidents. Organizations using Metabase should confirm they are on fixed versions and validate that external access paths are tightly controlled.
Source: Security Affairs
Progress LoadMaster Vulnerability Added to CISA’s KEV Catalog (CVE-2026-8037)
The U.S. CISA added a Progress LoadMaster flaw to its Known Exploited Vulnerabilities (KEV) catalog, increasing pressure for rapid remediation. Tracked as CVE-2026-8037 with a CVSS score of 9.6, the issue is described as an OS Command Injection leading to Remote Code Execution. If you run LoadMaster in your environment, treat this as urgent and verify mitigations or upgrades immediately.
Source: Security Affairs
CSS “Webmail” Attacks Weaponize Email Content to Steal Credentials and Hijack Sessions
PortSwigger researchers demonstrated that CSS embedded in emails can interfere with webmail interfaces and enable credential theft, session hijacking, and token leakage. The research spans major providers (including Outlook, Gmail, Fastmail, Proton Mail, Yahoo, and AOL) and highlights an emerging pattern: attackers are increasingly targeting how UI rendering happens, not just vulnerabilities in backend services. Security teams should review email security controls, user protections, and reduce exposure to risky email-driven actions—especially where AI assistants process inbox content.
Source: Security Affairs
Atlassian Rovo “AI Data Exfiltration” Risk—Jira/Confluence Data Can Be Prompted Out
Researchers reported that Atlassian Rovo can be manipulated with attacker-controlled instructions to collect Jira and Confluence data that the logged-in user can access. In practice, this can enable exfiltration to outside systems if the assistant’s data-handling behavior is induced to follow malicious “collection then send” logic. Teams should monitor AI assistant usage patterns, apply the least-privilege principle to what users can access, and watch for vendor guidance or patches.
Source: The Hacker News
Healthcare Data Breach: Unlimited Technology Systems Exposes Records of 3.8 Million Patients
Unlimited Technology Systems disclosed a breach after attackers gained access to a commercial data center between October 5–10, 2025. The incident reportedly exposed personal, medical, and insurance data for 3.8 million people—an impact profile that typically leads to both privacy harm and downstream fraud. Incident response should focus on evidence preservation, credential reset cycles where relevant, and verification of whether third-party data processors were impacted.
Source: Security Affairs
AI Agents in the Spotlight: ShadowAI-Watch Highlights How Agent Activity Can Exceed What Users See
Imperva’s ShadowAI-Watch argues that AI agents can quietly do far more than chat output suggests—reading files, executing commands, spawning subprocesses, accessing credentials, and calling external tools. As organizations adopt agents inside terminals and IDE workflows, the risk shifts from “prompt-only” behavior to broader, system-level actions with security implications. Adopt stronger controls like sandboxing, command allowlists, secret-scoping, and comprehensive auditing of agent operations.
Source: Imperva
You May Also Be Interested In...
Atlassian Rovo: One-Click Vulnerability Exposed Enterprise Data
AI-Powered BEC Scams Stealing Billions: How It Works and How to Defend
Apple Fixes a Mac Screen Sharing Security Issue—What You Need to Know