The Head Mare hacktivist group has been targeting unpatched TrueConf video conferencing servers, exploiting vulnerabilities to swap out legitimate client installers with malicious versions that contain backdoors. This means that unsuspecting users who download these compromised installers may unknowingly install malware that could allow attackers unauthorized access to their systems. TrueConf, which is used for video conferencing, is now facing scrutiny as users may be at risk of data breaches and privacy violations. Organizations using TrueConf need to ensure their servers are updated and secure to prevent these kinds of attacks, which are becoming increasingly common as hackers look for easy targets. It's crucial for users to be aware of the risks and to regularly update their software to protect against such vulnerabilities.
Latest Cybersecurity Threats
Real-time threat intelligence from trusted sources
Security Affairs
A serious security vulnerability has been discovered in Metabase Cloud, a popular analytics platform, allowing attackers to exploit a zero-day flaw rated at CVSS 10. This high-severity vulnerability has enabled unauthorized access to administrative features and the potential theft of sensitive data from affected users. Framework, a known user of Metabase, confirmed it was one of the victims of this breach. The flaw was unpatched and unknown to security teams at the time of exploitation, raising concerns about the effectiveness of current security measures in place. Companies using Metabase should take immediate action to assess their exposure and implement protective measures to safeguard their data.
Researchers from Varonis have discovered a serious vulnerability in Atlassian’s Rovo AI that allows attackers to exploit a one-click method known as the RovoBlast attack. This vulnerability could potentially enable unauthorized access to sensitive enterprise data stored in applications like Confluence, Jira, and SharePoint. Organizations using these tools should be particularly concerned, as the exposure of this data could lead to significant breaches and loss of confidential information. The discovery emphasizes the need for companies to regularly update their security protocols and patch vulnerabilities promptly to safeguard their data. As of now, the specific details about whether this vulnerability is being actively exploited are not confirmed.
Atlassian's Rovo assistant has a vulnerability that allows attackers to trick it into gathering sensitive data from Jira and Confluence, which it can then send to external servers. This issue was identified by two separate security firms, although only one method of exploitation has been confirmed as blocked. PromptArmor was able to embed malicious instructions in content that Rovo processes, leading to unauthorized data access. This incident poses a significant risk to organizations using these Atlassian products, as it could lead to the exposure of confidential project information and internal communications. Users of Jira and Confluence should be aware of this vulnerability and take steps to secure their data against potential exploitation.
Recent research has revealed new attack techniques that can exploit webmail services by allowing malicious content in emails to escape their intended boundaries. This vulnerability affects major platforms like Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail. Attackers can use these methods to capture user passwords, take control of third-party accounts, leak sensitive tokens, and manipulate user interface actions. This is particularly concerning as it could allow for unauthorized access to personal information and interactions with AI tools that read emails. The implications for user privacy and security are significant, as these attacks can bypass traditional defenses that many users rely on.
The Hacker News
Metabase has issued a warning about a serious security vulnerability in its data visualization software, which is currently being exploited by attackers. This zero-day flaw, rated with a CVSS score of 10.0, allows unauthorized individuals to execute arbitrary SQL commands in the Metabase application database without needing to log in. As a result, attackers can gain administrative access to sensitive data. Since this vulnerability does not have a CVE identifier, it adds another layer of urgency for users to secure their systems. Organizations using Metabase should take immediate action to protect their data, as the exploit is actively being used in the wild.
The Hacker News
N-able has issued a hotfix for its N-central Remote Monitoring and Management (RMM) software amid ongoing attacks exploiting a recently identified security flaw. The company is enhancing its protective measures as it observes evolving tactics from threat actors targeting managed systems. This update is part of their commitment to maintaining system integrity and safeguarding user data. Users of N-central should apply the latest hotfix to mitigate the risks associated with these active exploitation attempts. The situation underscores the importance of timely updates in the face of persistent cyber threats.
A serious SQL injection vulnerability in Metabase has been exploited in zero-day attacks, resulting in unauthorized access to customer data. This flaw has specifically affected companies like Framework and Tally, raising concerns about the security of user information stored in Metabase instances. Attackers have taken advantage of this weakness to steal sensitive data, which highlights the urgent need for affected organizations to address the vulnerability promptly. Users and companies relying on Metabase should be vigilant and ensure their systems are secure against potential breaches. The situation emphasizes the importance of maintaining robust security measures, especially when using widely-used data analysis tools.
BleepingComputer
Unlimited Technology Systems, a healthcare software provider, has reported a significant data breach that has affected over 3.8 million individuals. The breach, which took place in October 2025, has raised serious concerns about the security of personal information in the healthcare sector. While the company has not disclosed specific details about how the breach occurred, the scale of the incident suggests that sensitive data may be at risk. This situation highlights the growing vulnerability of healthcare organizations to cyberattacks, emphasizing the need for robust security measures to protect patient data. Affected individuals may face risks such as identity theft or fraud, making timely notification and support essential.
A vishing group identified as UNC6671 has shifted its focus to targeting mergers and acquisitions (M&A) firms with extortion schemes. This group, known for using voice phishing tactics, aims to exploit sensitive financial data and negotiations occurring in these high-stakes environments. Experts are advising firms to implement managed-device logins and closely monitor audit logs to combat the rising threat of phishing-led data theft. The implications of this shift are significant, as M&A firms often handle large sums of money and confidential information, making them prime targets for attackers seeking to leverage that data for financial gain.
SCM feed for Latest
Researchers have discovered a way to bypass the mitigations put in place for Spectre v2 vulnerabilities. This new attack exploits a timing gap known as the time-of-neutralization to time-of-use (TONTOU) window, which occurs between the isolation of the branch predictor and its actual use. This finding raises concerns for users of affected systems, as it shows that existing defenses can be circumvented, potentially allowing attackers to access sensitive data. Companies and developers must take this seriously to ensure their systems are secure against these types of exploits. Continued vigilance and updates to security measures will be essential to protect against these risks.
SCM feed for Latest
Zbtlink is facing scrutiny after claims from VulnCheck CTO Jacob Baines, who alleges that Zbtlink routers are designed to communicate with command and control servers, likening this feature to a 'phone-home trojan horse.' This allegation raises concerns about potential security vulnerabilities in Zbtlink products. The company has paused firmware downloads, which could indicate a response to these claims or an effort to address any underlying issues. Users of Zbtlink routers may need to be cautious about their device security and monitor for any unusual activity. The implications of these claims could be significant, as users’ personal data and privacy might be at risk if the allegations are proven true.
SCM feed for Latest
Walmart is facing a lawsuit in the U.S. District Court for the Northern District of Illinois over allegations that it secretly collects voiceprints from customers who call its stores. The lawsuit claims that Walmart records these calls and extracts vocal characteristics to create mathematical templates that can identify callers in the future. This raises significant privacy concerns, especially regarding how data is collected and used without explicit consent. If the allegations are proven true, it could lead to serious implications for Walmart's operations and customer trust, especially in a time when data privacy is a major concern for consumers. The case could set a precedent for how companies handle customer data in the future.
Recent research has shown that more than half of security patches generated by artificial intelligence are likely to fail in fully addressing vulnerabilities. In some cases, these AI-generated solutions may even create new vulnerabilities that attackers can exploit. This raises significant concerns for organizations relying on AI to automate their security measures, as they may inadvertently introduce more risks instead of mitigating them. Companies and security teams should be cautious and verify the effectiveness of AI-generated patches before implementation to prevent potential exploitation. The findings serve as a reminder that while AI can aid in cybersecurity, it should not be solely depended upon without thorough human oversight.
SCM feed for Latest
A new report from Chainalysis reveals a troubling trend where criminals are using physical violence, known as 'wrench attacks,' to steal cryptocurrency from victims. These attacks often involve assailants targeting individuals in their homes or public spaces, demanding access to digital wallets and private keys. This method of theft is particularly alarming because it combines traditional robbery tactics with the growing popularity of virtual currencies. Victims can suffer significant financial losses, and this shift in criminal strategy raises concerns about the safety of cryptocurrency holders. As the market for digital currencies expands, users need to be more vigilant about their physical security and take precautions to protect their assets.