
Coverage: Last 72 hours
Today’s Highlights
Active exploitation, AI-driven risk, and platform-wide flaws are pressuring defenders to tighten controls on both SaaS and open-source environments. Review hotfix status, supply chain exposure, and sensitive data accessible via modern AI assistants. Themes this cycle include persistent zero-day and supply chain exploitation targeting Metabase, N-central, npm, and WordPress, new data leakage risk exposed through AI-driven SaaS integrations, and critical vulnerabilities surfacing in core infrastructure and identity systems. Social engineering and interface-busting CSS attacks remain sharp reminders that security boundaries are constantly being tested by adversaries.
Table of Contents
- Critical Flaws Discovered in Belgian eID Software Used by 2 Million People
- Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers
- N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist
- Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer
- UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data
- New WordPress Pre-Auth XSS Could Lead to PHP Code Execution – Patch ASAP
- Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication
- Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts
Top Stories
Critical Flaws Discovered in Belgian eID Software Used by 2 Million People
Source: SecurityWeek | Risk: Critical | Impacted: Belgian banks, Government agencies using eID, Identity and fraud teams
Summary: The vulnerabilities affected software used by eight of Belgium’s ten largest banks and over 60 government agencies. The post Critical Flaws Discovered in Belgian eID Software Used by 2 Million People appeared first on SecurityWeek.
Why it matters: Widespread flaws in trusted identity software used by banks and government agencies increase the exposure of sensitive personal and financial data to fraud or impersonation.
Practitioner Perspective
Digital identity platforms are a lucrative, high-impact target; when so many banks and public sector entities depend on a single software stack, systemic risk amplifies. Any exploit against Belgian eID could enable widespread account takeover, fraudulent transactions, or data leakage. Financial organizations and public service operators should coordinate with Belgian NCSC or relevant authorities to get prioritized patch guidance, even before formal CVEs or advisories. Treat all requests for access via eID as high risk until remediation is complete and identity chain-of-custody is restored.
Recommended Actions
- Coordinate directly with eID software vendors and Belgian NCSC for patches and official remediation steps.
- Increase authentication scrutiny and transaction verification on accounts accessed via the affected eID platform.
Emerging Signals
Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers
Source: The Hacker News | Risk: High | Impacted: Atlassian Rovo users, Jira and Confluence admins, Data protection teams
Summary: Attacker-controlled instructions can make Atlassian’s Rovo assistant collect Jira or Confluence data that a signed-in user can access, then send it to an outside server. Two security firms found that behavior independently, by different routes. Only one of those routes is confirmed closed. PromptArmor, an AI security firm, hid the instructions in content Rovo reads. It said an uploaded file
Why it matters: AI assistants able to exfiltrate privileged SaaS data without robust intent validation create new lateral movement opportunities and data loss channels within enterprise environments.
Practitioner Perspective
Any organization with Atlassian Rovo deployed should assume insider-attacker prompt or file-based abuse is plausible, especially for users with broad Jira or Confluence access. AI-driven SaaS integrations can blur data boundaries and make privilege abuse easier, this extends beyond Atlassian to other collaborative platforms with AI plugins. Waiting for vendor patches is not sufficient: defenders must independently audit AI workflow controls and access logs. Key takeaway: Assume every AI/LLM assistant is a novel exfiltration channel until proven otherwise.
Recommended Actions
- Hunt for atypical export and file access patterns in Rovo and related Atlassian logs, especially after AI assistant usage spikes.
- Manually review Rovo prompt and content ingestion controls, do not trust default vendor settings to block prompt-injection.
N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist
Source: The Hacker News | Risk: High | Impacted: N-able N-central managed service providers, IT support orgs using N-central, Downstream customer networks
Summary: N-able has released a fresh round of hotfixes for N‑central as part of its investigation into ongoing exploitation of a recently disclosed security flaw in the Remote Monitoring and Management (RMM) product. “We are proactively expanding protections in response to ongoing monitoring of threat actors as they evolve their attack techniques,” the company said. “This is not a duplicate of
Why it matters: Ongoing exploitation of N-able N-central exposes managed services environments to attacker persistence and possible privilege escalation across customer networks.
Practitioner Perspective
RMM platforms like N-able N-central are prime targets for supply-chain and post-exploitation activity, especially as attackers adapt their methods during hotfix cycles. If attackers reach managed endpoints and persist despite initial fixes, assume they may leverage the management plane to spread laterally or conduct business email compromise. This incident underscores why continuous monitoring of vendor platforms and their update cadence is business-critical for MSPs and their downstream clients.
Recommended Actions
- Deploy the latest N-central hotfixes, including Hotfix 2, across all managed instances.
- Run targeted incident response to detect persisting threats or anomalous changes on systems managed by N-central.
Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer
Source: The Hacker News | Risk: High | Impacted: Frontend and backend DevOps teams, CI/CD environments using npm, Desktop engineering groups
Summary: A cluster of nearly 800 malicious packages has been published to the npm registry as part of a new campaign designed to deliver cross-platform malware targeting Windows, Mac, and Linux systems. “These packages appear to use AI slop squatted, or randomly generated typo-squatting package names, but all of them deliver a powerful RAT and infostealer payload,” OpenSourceMalware researcher Paul
Why it matters: Developers and CI pipelines are at increased risk from widely distributed, typo-squatted npm packages delivering cross-platform infostealer and RAT malware.
Practitioner Perspective
Mass-malware in npm typifies the ongoing risk of open-source package supply chains. Automated and AI-driven package publishing makes it easy for attackers to slip payloads into developer dependency trees, especially if code review or allow-listing is lacking. Impact extends from compromised build pipelines to lateral movement into production environments. If you have not recently reaudited your npm import history and lockfiles, now is the time, malicious package names will cause lasting technical debt if left unresolved.
Recommended Actions
- Scan all active npm projects and package-lock.json files for any of the nearly 800 identified typo-squatted or malicious packages.
- Purge and reimage developer endpoints that show evidence of unauthorized npm package execution.
UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data
Source: The Hacker News | Risk: High | Impacted: Financial services staff, Professional services firms, SaaS admin teams
Summary: A recent wave of cyber attacks targeting financial services, private equity, and professional services has been attributed to a data extortion group known as UNC6671. “UNC6671 continues to rely on voice phishing (vishing) to target enterprise employees, posing as IT help desk staff facilitating mandatory, urgent security migrations. Significantly, the threat actor often contacts employees via
Why it matters: Attackers bypass traditional enterprise controls by socially engineering staff on personal devices, resulting in elevated risk of SaaS data breach and credential compromise.
Practitioner Perspective
UNC6671’s vishing approach highlights the weakness in depending solely on corporate phishing controls and endpoint telemetry. High-value business units like financial or professional services can be targeted directly via personal apps or phones, compromising both identity and sensitive SaaS data. Incident response needs to include staff retraining and review of SaaS admin activity, not merely blocking inbound emails. The greatest risk now is the blurred boundary between personal and enterprise identity for privileged users.
Recommended Actions
- Review SaaS provider admin logs for evidence of credential misuse or unscheduled access provisioning tied to end-user support requests.
- Strengthen verification and callback procedures for all IT helpdesk-initiated access resets or migrations, no exceptions for personal phones.
New WordPress Pre-Auth XSS Could Lead to PHP Code Execution – Patch ASAP
Source: The Hacker News | Risk: Critical | Impacted: Public WordPress sites, Web administrators, Third-party WordPress plugin/theme maintainers
Summary: WordPress has fixed a pre-authentication reflected cross-site scripting (XSS) flaw in its login screen that affects every version of the content management system. pwn.ai demonstrated how the flaw can be chained into PHP code execution on the server when a logged-in administrator interacts with an attacker-controlled page. Tracked as CVE-2026-64638 (CVSS score: 8.9), the high-severity
Why it matters: Any WordPress site left unpatched can be instantly taken over by chaining reflected XSS into remote code execution when an admin is lured to an attacker-controlled page.
Practitioner Perspective
With CVE-2026-64638 covering the login page of all WordPress versions, the internet-facing attack surface for this XSS is enormous. Publicly available exploit code and active demonstrations mean that mass exploitation is likely in progress. Privileged admins are the main targets for drive-by compromise, and once one is breached, arbitrary PHP execution is trivial. You cannot treat this as a normal WordPress patch: coordinate with site owners and admins to validate no backdoored themes or plugins were left behind.
Recommended Actions
- Patch all WordPress instances for CVE-2026-64638 with the vendor’s latest update.
- Force a credentials and session reset for all WordPress admins across impacted sites.
Exploits & CVEs
Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication
Source: The Hacker News | Risk: Critical | Impacted: Self-hosted Metabase instances, Data analytics teams, Cloud infrastructure linked to Metabase
Summary: Metabase has warned that a maximum-severity security flaw impacting its business intelligence and data visualization software package has been exploited in the wild as a zero-day. The vulnerability (CVSS score: 10.0), which does not carry a CVE identifier, allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, enabling them to gain
Why it matters: Metabase instances that remain unpatched are likely already compromised, with attackers able to extract or alter sensitive databases using unauthenticated SQL injection.
Practitioner Perspective
If you have public-facing or partner-exposed Metabase, immediate incident response is advised: with a CVSS 10.0 flaw exploited as a zero-day, assume persistence. Attackers gaining admin-access via SQL injection can implant backdoors, access business analytics, or pivot into connected data sources. Any exposed BI tool is a high-value target due to its privileged data reach. If patching is not complete, take Metabase offline now and review all changed credentials and audit logs since first public disclosure.
Recommended Actions
- Apply the latest Metabase security updates and patches for unauthenticated SQL injection immediately, even without a CVE number.
- Rotate all Metabase admin accounts and repository credentials; check for suspicious new accounts or database modifications.
Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts
Source: The Hacker News | Risk: Critical | Impacted: Enterprises using Progress Kemp LoadMaster, Network appliance admins, IT infrastructure teams
Summary: The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a critical-severity security flaw impacting Progress Kemp LoadMaster to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the wild. The vulnerability, tracked as CVE-2026-8037 (CVSS score: 9.6), is a command injection flaw that could be weaponized to achieve arbitrary
Why it matters: Enterprise load balancers exposed to the internet are actively targeted for arbitrary command execution, putting internal services, session keys, and network trust boundaries at risk.
Practitioner Perspective
The CVE-2026-8037 flaw in Progress Kemp LoadMaster opens a direct line for attackers to move from external perimeter to privileged access inside corporate networks. The high exploitation volume indicates automated scanning and rapid weaponization. Many organizations underestimate the privileged role of network appliances and delay patching due to HA/DR constraints, but every day unpatched LoadMasters are online multiplies breach likelihood. Prioritize these systems for patch-and-test, not just after-hours.
Recommended Actions
- Patch Progress Kemp LoadMaster systems for CVE-2026-8037 immediately, status is now CISA KEV due to confirmed exploitation.
- Hunt for indicators of arbitrary command execution or unusual network flows sourcing from LoadMaster appliances.
Defensive Actions
- Coordinate directly with eID software vendors and Belgian NCSC for patches and remediation steps if using Belgian eID software.
- Increase authentication and transaction validation for accounts accessed via Belgian eID until patching is complete.
- Hunt for atypical export and file access patterns in Rovo and review Atlassian logs after AI assistant spikes.
- Manually audit Rovo prompt ingestion controls and do not trust default vendor protections against prompt-injection.
- Deploy the latest N-central hotfixes across all managed instances and check for signs of adversary persistence.
- Scan all active npm projects for signs of typo-squatted or malicious packages published in this campaign.
- Purge and reimage developer endpoints where unauthorized npm package execution is detected.
- Review SaaS provider admin logs for unusual credential or access provisioning, especially after user support requests.
- Patch all WordPress deployments for CVE-2026-64638 and require admin session resets.
- Apply Metabase security updates for unauth SQLi and rotate all admin credentials.
- Patch Progress Kemp LoadMaster for CVE-2026-8037 immediately and audit appliances for command execution artifacts.
What We’re Watching
- Large-scale supply chain attacks are targeting open-source and managed platforms, amplifying both dependency and update risk.
- Increasing sophistication in prompt-based AI attacks and the use of personal communication channels for phishing.
- Rapid escalation from proof-of-concept to in-the-wild exploitation for zero-days affecting business-critical SaaS and infrastructure.
- The need to audit not only traditional software security but also AI-augmented workflows that can bypass long-standing controls.
Categories: Cybersecurity Blog, Cybersecurity News
Leave a Reply