Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers

08/08/2026 0 Comments 0 tags

Attacker-controlled instructions can make Atlassian’s Rovo assistant collect Jira or Confluence data that a signed-in user can access, then send it to an outside server. Two security firms found that

Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication

08/08/2026 0 Comments 0 tags

Metabase has warned that a maximum-severity security flaw impacting its business intelligence and data visualization software package has been exploited in the wild as a zero-day. The vulnerability (CVSS score:

N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist

08/08/2026 0 Comments 0 tags

N-able has released a fresh round of hotfixes for N‑central as part of its investigation into ongoing exploitation of a recently disclosed security flaw in the Remote Monitoring and Management

Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts

08/08/2026 0 Comments 0 tags

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a critical-severity security flaw impacting Progress Kemp LoadMaster to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation

Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer

07/08/2026 0 Comments 0 tags

A cluster of nearly 800 malicious packages has been published to the npm registry as part of a new campaign designed to deliver cross-platform malware targeting Windows, Mac, and Linux

ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets

07/08/2026 0 Comments 0 tags

ClickFix-style attacks are being used to deliver a Go-based malware capable of stealing cryptocurrency assets, as well as browser-stored passwords, Apple iCloud Keychain data, and cached credentials. The macOS-focused infection

UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data

07/08/2026 0 Comments 0 tags

A recent wave of cyber attacks targeting financial services, private equity, and professional services is attributed to a data extortion group known as UNC6671. “UNC6671 continues to rely on voice

New WordPress Pre-Auth XSS Could Lead to PHP Code Execution – Patch ASAP

07/08/2026 0 Comments 0 tags

WordPress has fixed a pre-authentication reflected cross-site scripting (XSS) flaw in its login screen that affects every version of the content management system. Under additional conditions, the bug can be

Growing Up The Hard Way

07/08/2026 0 Comments 0 tags

Open Source had a great childhood. For two decades it got to be a kid. It ran around barefoot, gave everything away, trusted strangers, and never once thought about who

18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers

07/08/2026 0 Comments 0 tags

A use-after-free bug in Linux’s SCTP networking code can be turned into full root on a host, and Tencent researchers say they used it to escape a container and reach