Sam's News — security — 2026-08-08¶
TL;DR¶
- Metabase zero-day SQL injection exploited in wild for data theft
- Atlassian Rovo AI assistant can be tricked into exfiltrating enterprise data
- New Mexico judge orders Meta to pay $567M for youth mental health crisis
- Nearly 800 malicious npm packages deliver cross-platform malware
- Critical Kemp LoadMaster vulnerability added to CISA KEV following active exploitation
- N-able confirms attackers reached customer networks via N-central flaw
Security¶
Metabase zero-day SQL injection exploited in wild for data theft¶
A maximum-severity, unpatched SQL injection flaw in Metabase was exploited in the wild to steal customer data, hitting companies including Framework and Tally before a patch was released.
- CVSS 10.0 flaw affects Metabase versions 1.58 and above; no CVE assigned yet
- Allowed unauthenticated attackers to gain admin access via SQL injection
- Framework breach (Aug 3) exposed names, emails, IPs, addresses, phone numbers—no payment data taken
- Tally breach exposed customer emails and password hashes
- Fixed versions: x.58.24, x.59.21, x.60.17, x.61.11, x.62.9, x.63.5
- Metabase blocked attack endpoints, patched Aug 7, and notified law enforcement
Sources: The Hacker News Research, BleepingComputer Research, The Cryptonomist RSS
Atlassian Rovo AI assistant can be tricked into exfiltrating enterprise data¶
Researchers independently discovered that Atlassian's Rovo assistant can be manipulated via attacker-controlled instructions to steal Jira and Confluence data accessible to signed-in users.
Sources: SecurityWeek RSS, The Hacker News RSS
Nearly 800 malicious npm packages deliver cross-platform malware¶
A cluster of nearly 800 malicious npm packages deployed RAT and infostealer malware targeting Windows, Mac, and Linux systems using typosquatting tactics.
Sources: The Hacker News RSS
Critical Kemp LoadMaster vulnerability added to CISA KEV following active exploitation¶
A critical-severity Progress Kemp LoadMaster vulnerability was added to CISA's Known Exploited Vulnerabilities catalog after 792 reported exploit attempts.
Sources: The Hacker News RSS
N-able confirms attackers reached customer networks via N-central flaw¶
N-able disclosed that threat actors exploited a recently disclosed security flaw in its N-central RMM product to gain access to managed customer systems.
Sources: The Hacker News RSS
CSS attacks can break webmail defenses to steal passwords and tokens¶
New CSS-based attack techniques can escape email message boundaries and interfere with webmail interfaces across Outlook, Gmail, Fastmail, and other providers to capture credentials.
Sources: The Hacker News RSS
ClickFix malware campaign delivers macOS stealer targeting crypto wallets¶
ClickFix-style attacks are delivering Go-based malware for macOS that steals cryptocurrency, passwords, iCloud Keychain data, and cached credentials.
Sources: The Hacker News RSS
UNC6671 vishing attacks target employees for SaaS data theft¶
Data extortion group UNC6671 targeted financial services and professional services firms with voice phishing attacks impersonating IT help desk staff.
Sources: The Hacker News RSS
Levi Strauss confirms corporate data theft via employee social engineering¶
Levi's disclosed that hackers stole corporate data by conducting social engineering attacks against three employees to access their machines.
Sources: BleepingComputer RSS
Tech¶
New Mexico judge orders Meta to pay $567M for youth mental health crisis¶
A New Mexico judge ordered Meta to fund a $567 million program to address youth mental health harms linked to social media use.
Sources: Ars Technica RSS, The Record RSS