Saturday, August 8, 2026 | Jonathan Brown
Attackers used an unpatched Metabase flaw to reach corporate analytics warehouses
Metabase disclosed an actively exploited, unauthenticated SQL injection flaw on August 6. The issue has no CVE identifier yet, but Metabase tracks it as GHSA-vwf4-m7j8-wcjf. The vendor’s advisory says an internet-reachable attacker can exploit the flaw without an account or user interaction, and Metabase has confirmed exploitation.
The affected ranges are x.58.0 through x.58.22, x.59.0 through x.59.19, x.60.0 through x.60.16, x.61.0 through x.61.9, x.62.0 through x.62.7, and x.63.0 through x.63.2. Fixed releases are x.58.24, x.59.21, x.60.17, x.61.11, x.62.9, and x.63.5. If an immediate upgrade is impossible, Metabase says to block the /api/session/reset_password endpoint.
The operational concern extends beyond the analytics application. Metabase instances commonly retain database credentials, API keys, administrator accounts, and the ability to query production warehouses. Metabase directs affected customers to invalidate sessions, review API keys and administrator accounts, rotate credentials for every connected database, and inspect warehouse query history. Its published hunting pattern is a POST to /api/session/reset_password returning HTTP 400, followed by a GET to /api/user/current returning HTTP 200.
Watch for: A CVE assignment, a wider victim disclosure, or evidence that the attackers established persistence beyond stolen sessions and API keys.
Sources: Metabase, “GHSA-vwf4-m7j8-wcjf,” August 6, 2026; The Hacker News, “Metabase Zero-Day Exploited in the Wild,” August 8, 2026.
CISA says a Kemp load-balancer flaw is exploited while the vendor bulletin says it is not
CISA added CVE-2026-8037 in Progress Kemp LoadMaster to the Known Exploited Vulnerabilities Catalog on August 7, setting an August 10 remediation deadline for federal civilian agencies. CISA describes an unauthenticated attacker executing arbitrary commands through unsanitized input in multiple command endpoints.
Progress’s bulletin, however, still states that it has no reports of exploitation. The disagreement is material. Defenders should report both positions accurately: CISA’s KEV listing treats exploitation as confirmed, while the vendor bulletin has not been updated to reflect that determination.
The flaw affects LoadMaster GA version 7.2.63.1 and earlier, and LTSF version 7.2.54.17 and earlier. Fixed releases are 7.2.63.2 for GA and 7.2.54.18 for LTSF. Zero Day Initiative describes a pre-authentication path to root-level code execution and assigns CVSS 9.8; public technical research has been available since June. Load balancers frequently sit at the application edge, terminate TLS, and retain certificates or administrative reachability, so compromise warrants review of appliance configuration, logs, certificates, and stored credentials as well as patching.
Watch for: Clarification from Progress on the KEV designation and evidence identifying the operators or scale of active exploitation.
Sources: CISA, “Known Exploited Vulnerabilities Catalog,” August 7, 2026; Progress Software, “LoadMaster Critical Security Bulletin June 2026,” June 2026; Zero Day Initiative, “ZDI-26-342,” 2026.
A calendar invitation can run script in SOGo webmail, and CERT/CC says it is being used
CERT/CC published an advisory on August 6 for CVE-2026-8496 in Alinto SOGo webmail and says active exploitation has been confirmed through VirusTotal sightings. The flaw is a cross-site scripting issue in malformed ICS calendar invitations.
An attacker can embed a malicious SVG payload in an invitation’s DESCRIPTION field. When a recipient opens the calendar view, the payload can execute in the user’s webmail session. CERT/CC identifies SOGo 5.12.7 as affected and SOGo 5.12.8 as the fixed release. The advisory does not provide a CVSS score, name the exploiting actor, or establish whether the activity is targeted or broad.
Webmail script execution can enable session theft, mail collection, or manipulation of mailbox settings. SOGo administrators should update immediately, inspect calendar invitations for unexpected SVG or script content, and review webmail logs for session reuse, unusual mail forwarding, or newly created rules. The vendor’s public response status is listed as unknown in the CERT/CC notice.
Watch for: A vendor advisory, a fuller affected-version range, or incident reporting that identifies the actor and target set.
Sources: CERT Coordination Center, “VU#487613: Alinto SOGo XSS via Malformed ICS Invitations,” August 6, 2026; Alinto, “SOGo v5.12.8 Released,” 2026.
Today is the federal deadline for the exploited TeamCity build-server flaw
August 8 is the remediation deadline that CISA set for federal civilian agencies for CVE-2026-63077 in JetBrains TeamCity. The KEV entry describes unauthenticated remote code execution through TeamCity’s agent polling protocol.
JetBrains says all TeamCity On-Premises versions are affected. The company fixed the flaw in TeamCity 2025.11.7 and 2026.1.3, and offers a security patch plugin for versions from 2017.1 onward when a full upgrade cannot happen immediately. TeamCity Cloud was remediated by the vendor.
The risk is not limited to code execution on a build server. TeamCity can hold source-repository access, package-registry credentials, cloud keys, signing material, deployment tokens, and build definitions. CISA’s KEV listing means exploitation is confirmed, while JetBrains has not publicly identified the actor or scale. Organisations that had a reachable unpatched server should patch or apply the plugin, remove direct internet access, rotate accessible secrets where compromise cannot be excluded, and revalidate recent builds and releases.
Watch for: Public technical evidence showing how the flaw has been exploited and whether any build artifacts or deployment environments were altered.
Sources: CISA, “Known Exploited Vulnerabilities Catalog,” August 5, 2026; JetBrains, “CVE-2026-63077,” July 27, 2026.
A cyberattack disrupted North Carolina port operations, but contingency plans restored gate activity
North Carolina Ports confirmed a cyberattack affecting the Port of Wilmington, the Port of Morehead City, and the Charlotte Inland Port. The organization detected the attack on August 4, activated its contingency plan, and began recovery on August 5 after a systems-wide information-technology outage.
An August 7 update said normal gate schedules and vessel activity had resumed, although some delays were expected. No actor has claimed responsibility, and authorities have not disclosed the initial access path, whether ransomware was involved, or whether data was taken.
This is primarily an availability and logistics event. Wilmington handles roughly 5,000 container gate moves per week, while Wilmington and Morehead City together handle millions of short tons of cargo annually. The useful resilience lesson is the recovery outcome: degraded procedures kept cargo moving while systems were restored. Ports and peer transport operators should validate segmentation between terminal operating systems and enterprise networks, maintain tested manual gate and yard procedures, and preserve evidence before rebuilding affected infrastructure.
Watch for: Attribution, a disclosure of the disrupted systems, or evidence that the incident affected partner, shipping, or rail networks.
Sources: BleepingComputer, “North Carolina Ports Confirms Cyberattack Disrupting Operations,” August 7, 2026.
Water-sector investigations point to a cellular-router exposure problem, not one universal PLC flaw
Forescout’s August 5 analysis adds important context to the water and wastewater incidents reported across at least 12 states. A Shodan query found 4,407 devices exposing EtherNet/IP on port 44818, including 2,844 in the United States. MicroLogix 1400 controllers represented half of the visible population.
The most revealing finding is connectivity. More than half of the exposed devices were on large mobile-carrier networks, and more than 70 percent of the United States subset used those networks. Forescout identified 22 exposed hosts in cities affected by the campaign; 19 were on the same mobile-carrier network. The research does not establish that those hosts belong to the affected utilities or that a specific CVE was used.
That distinction matters. Forescout says the observed impacts, including changed controller addresses and passwords, could have occurred without exploiting a product vulnerability. The immediate defensive priority is therefore exposure reduction: remove controllers and human-machine interfaces from public reachability, move cellular gateways onto private carrier access or a protected VPN path, disable public gateway administration, replace shared remote-access credentials, and preserve controller and gateway logs before resetting equipment.
Watch for: A federal advisory identifying a common access path, confirmed campaign infrastructure, or a shared affected device set.
Sources: Forescout Research, “OT Security Analysis: Exposed Devices Attacked in US Water Systems,” August 5, 2026; FBI and Environmental Protection Agency, water and wastewater utility advisory, July 2026.
A timing flaw in a Linux Spectre defense affects AMD Zen systems running untrusted local code
AMD published its Safe RET Interrupt Vulnerability bulletin on August 6, describing a weakness in the Linux implementation of the Safe RET mitigation for speculative return stack overflow. CVE-2026-68480 tracks the Linux kernel fix, which makes the mitigation more robust against interrupt injection.
AMD says an attacker who can already execute code on an affected system could time an interrupt to disrupt Safe RET and potentially disclose information. The company lists Zen 1 through Zen 4 processors as affected, while noting that the technique was demonstrated on Zen 1 and Zen 2 and only suggested, not demonstrated, on Zen 3 and Zen 4.
This is a local information-disclosure risk, not a remote takeover. The highest priority is shared compute: multi-tenant hosts, build runners, container hosts, and systems that execute untrusted code. Apply distribution kernel updates as they become available, verify the mitigation state after patching, keep platform firmware current, and assess whether any high-risk host also had plausible untrusted local execution. AMD does not assign a CVE or a severity score in its own bulletin.
Watch for: Distribution-specific fixed kernel versions, proof of practical exploitation on Zen 3 or Zen 4, or evidence of use outside research conditions.
Sources: AMD, “Safe RET Interrupt Vulnerability, AMD-SB-7061,” August 6, 2026; CVE Program, “CVE-2026-68480,” August 2026; BleepingComputer, “New TONTOU CPU Attack Bypasses Spectre v2 Fixes,” August 2026.
An old SCTP kernel flaw escaped a container to reach host root in research testing
Tencent Zhuque Lab published research on August 6 for CVE-2026-64564, a use-after-free flaw in Linux SCTP Dynamic Address Reconfiguration. The defect dates to code introduced in 2007 and can enable a local privilege escalation.
The researchers validated a container escape to host root under a default seccomp profile without CAP_NET_ADMIN or CAP_SYS_ADMIN. They reported success in six of eight attempts. Their results included recent Debian, Ubuntu, Rocky Linux, Red Hat Enterprise Linux, and OpenCloudOS configurations, but kernel version strings alone do not establish exposure because vendor backports vary.
The fix is present in Linux stable releases 6.6.148, 6.12.101, 6.18.42, and 7.1.6, as well as mainline 7.2-rc5. No public exploit code or active exploitation has been reported. Shared Kubernetes nodes, multi-tenant hosts, and servers where the SCTP module is loadable deserve priority. Where patching must wait and SCTP is not required, administrators can prevent the module from loading after confirming that no application depends on it.
Watch for: Distribution advisories that map the defect to shipped kernels, or public exploit code that changes the urgency for exposed container platforms.
Sources: Tencent Zhuque Lab, “SCTPhantom: CVE-2026-64564,” August 6, 2026; oss-security, “CVE-2026-64564 Linux Kernel SCTP Use After Free,” August 6, 2026.
A missing authorization check turned an AI agent platform into a possible remote code-execution service
Oasis Security has disclosed CVE-2026-41679 in Paperclip, an AI management platform used to operate autonomous agents. SecurityWeek reports that a missing authorization check let an unauthenticated remote attacker reach a state where commands could execute with the Paperclip server process’s permissions.
The reported issue affects network-accessible Paperclip instances using the default authenticated-mode configuration. The flaw received CVSS 10. Paperclip corrected authorization checks in the affected import flows and tightened company scoping, but public reporting does not establish a fixed version number, a vendor advisory location, or active exploitation.
Agent-management systems are emerging privileged control planes. They can hold execution adapters, source access, local credentials, cloud secrets, and reachability into internal services. Organisations using Paperclip should update to the vendor’s corrected release, remove it from public reachability, disable open self-registration, inventory secrets available to agent processes, and constrain host-level execution to approved operations.
Watch for: A Paperclip advisory with exact fixed releases, confirmation of the disclosure timeline, or evidence that the flaw was abused before remediation.
Sources: SecurityWeek, “Critical Paperclip Flaw Allowed Admin Access, Code Execution,” August 6, 2026.
Rovo research shows how a connected assistant can export data that a user is already allowed to see
Two research teams have shown that attacker-controlled instructions can cause Atlassian Rovo to collect accessible Jira or Confluence data and send it outward. One technique, called RovoBlast by Varonis, used an attacker-controlled prompt in a URL. Varonis says Atlassian applied and validated a server-side fix on July 8.
A separate PromptArmor disclosure describes instructions hidden in content that Rovo reads, including an uploaded file. At publication on August 5, PromptArmor said the chain still worked. It could cause Rovo to search Jira and Confluence, append results to an attacker-controlled URL, and open that URL. Neither report shows a conventional permission bypass or evidence of use against a real organisation.
The governance issue is nonetheless immediate. Connected assistants can move data across services without the user explicitly choosing to export it. Rovo is enabled by default on Standard, Premium, and Enterprise plans. Administrators should narrow Rovo access by application and user group, disconnect unused connectors, keep highly sensitive content out of assistant scope, disable browsing and multi-step automation that is not needed, and review assistant activity for unexpected outbound fetches.
Watch for: Atlassian confirmation that the content-borne route has been fixed and guidance on monitoring assistant-generated outbound requests.
Sources: The Hacker News, “Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers,” August 8, 2026; Varonis Threat Labs, “RovoBlast,” updated August 7, 2026.
Jonathan Brown is a cybersecurity researcher and investigative journalist at bordercybergroup.com.
If you would like to support our work — useful, well-researched, ad-free cybersecurity intelligence — subscribe, comment, or buy us a coffee! Thanks.
Member discussion: