FR
live
section

Security

Metabase Zero-Day CVSS 10.0 Grants Full Admin Access Without Authentication

On August 8, 2026, Metabase disclosed a maximum-severity SQL injection flaw (CVSS 10.0) that was already being exploited in the wild. The vulnerability lets unauthenticated attackers gain administrator privileges and drain every connected database. Self-hosted Metabase admins must patch, revoke sessions, and rotate all secrets immediately.

DOUBLECUP turns your browser cache into an arsenal — Russian loader‑as‑a‑service uses steganography to deliver CountLoader and a brand‑new RAT

On August 3, 2026, SOCRadar documented DOUBLECUP, a Russian loader-as-a-service active since June 2026 that hides malicious code in browser‑cached PNG images. The ClickFix chain delivers CountLoader to Windows and macOS alongside a previously undocumented DeviceManager RAT steered by smart contracts.

The Cyber Resilience Act Takes Effect — Every Software Dependency Must Be Documented, Signed, and Traceable Within 36 Months

EU Regulation 2024/2847, the Cyber Resilience Act, enters phased application starting in 2026. It requires every software vendor selling in the EU to produce a complete SBOM, fix known vulnerabilities within five business days, and notify critical incidents to ENISA within 24 hours. Here's what your organization must do before the first binding deadline.

A silent AI worm spreads through Copilot for Word — and Microsoft can’t patch it

On July 28, 2026, researcher Håkon Måløy published the first public demonstration of a document-borne AI worm capable of silently altering financial reports and self-propagating through Microsoft Copilot for Word. After 144 days of coordinated disclosure and two attempted fixes — including a model upgrade to GPT-5.6 — the vulnerability class remains exploitable.

API attacks became the number one data breach vector in 2026

99% of organizations experienced an API security incident in 2025. APIs now account for 43% of actively exploited vulnerabilities in CISA’s KEV catalog. Your API gateway is your new firewall — and you probably haven’t configured it.

June 2026 Was the Month Cybersecurity Broke Its Own Scale

Microsoft shipped its largest-ever Patch Tuesday, 24 billion stolen credentials surfaced on an exposed Elasticsearch cluster, and ransomware gangs claimed 721 new victims. Three records, one month — and none of them are a coincidence.

May 2026’s data breaches didn’t make headlines — and that’s the real problem

Mediaworks lost 8.5 TB of internal data to a ransomware group. Instructure paid ShinyHunters to keep 3.65 TB of Canvas data off the dark web. Across two weeks in May 2026, a cascade of breaches hit education, manufacturing, media, and retail — and barely anyone noticed. When breaches become background noise, the threat isn’t technical anymore. It’s apathy.

Ransomware Surges 48% in May 2026 as Global Attacks Decline

Check Point Research records 698 ransomware attacks worldwide in May 2026, a 48% year-over-year jump, even as overall attack volumes drop 7%. Fewer attacks, more impact — threat actors are getting better at doing more with less.

BreachForums Hacked — 325,000 Cybercriminal Accounts Exposed

On January 10, 2026, the BreachForums cybercrime bazaar suffered its own data breach: 324,000 user accounts with IP addresses, display names, and the forum’s official PGP key were published online. The leak is a goldmine for law enforcement and an operational catastrophe for members whose anonymity collapsed overnight.

AI-assisted cyberattacks now breach systems in 72 minutes

Attackers are deploying AI agents to automate reconnaissance, phishing, and exfiltration, compressing the breach-to-theft window to 72 minutes in the fastest observed cases. SOC teams that still rely solely on human-first triage are structurally unable to keep up.

Type at least two characters.

navigate open esc dismiss