Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
AhnLab ASEC discovered a phishing campaign where emails disguised as transaction receipts impersonate US company employees, tricking recipients into opening malicious attachments by asking them to confirm fund deposits.
The article describes how the Head Mare hacktivist group breaches TrueConf video conferencing servers by exploiting unpatched vulnerabilities. They replace client installers with malicious versions that deliver backdoors to users.
Two independent security firms discovered that Atlassian's Rovo assistant can be tricked via prompt injection to send Jira or Confluence data to attackers. PromptArmor hid instructions in an uploaded file, while Varonis used a URL parameter; only Varonis's flaw has been fixed.
New research presented at Black Hat USA 2026 demonstrates CSS attacks that allow email content to break out of its message boundary and compromise webmail interfaces. These attacks can capture passwords, steal tokens, and manipulate AI tools across providers like Outlook and Gmail.
Metabase disclosed a maximum-severity zero-day vulnerability that allows unauthenticated remote attackers to inject SQL and gain administrator access to instances. The flaw has been exploited in the wild, leading to credential theft and data exfiltration.
N-able issued a second hotfix for N-central after attackers exploited an authentication bypass vulnerability (CVE-2026-18577) to gain administrative access and connect to managed systems. The attackers registered a Cloudflare Tunnel service for persistence.