The security defect allows unauthenticated, remote attackers to gain administrative access to Metabase instances.
The post Metabase Patches Vulnerability Exploited as Zero-Day appeared first on SecurityWeek.
The security defect allows unauthenticated, remote attackers to gain administrative access to Metabase instances.
The post Metabase Patches Vulnerability Exploited as Zero-Day appeared first on SecurityWeek.
CERT.PL said this appears to be the first instance of a private APN being used as an attack vector.
The post Novel Private APN Pivot Let Hackers Sabotage Second Polish Energy Facility appeared first on SecurityWeek.
The critical-severity flaw allows unauthenticated, remote attackers to execute arbitrary commands.
The post CISA Urges Immediate Patching of Exploited Progress LoadMaster Vulnerability appeared first on SecurityWeek.
Using social engineering, a threat actor accessed the computers of three employees and exfiltrated data from them.
The post Corporate Data Stolen in Levi Strauss Cyberattack appeared first on SecurityWeek.
The vulnerabilities affected software used by eight of Belgium’s ten largest banks and over 60 government agencies.
The post Critical Flaws Discovered in Belgian eID Software Used by 2 Million People appeared first on SecurityWeek.
The RovoBlast attack method identified by Varonis researchers could have been exploited to steal Confluence, Jira and SharePoint data.
The post Critical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise Data appeared first on SecurityWeek.
Noteworthy stories that might have slipped under the radar: ban on Chinese data center tech, QuickFox VPN supply chain attack, IEH Corporation mailbox breached via phishing.
The post In Other News: AI Slop Limits Apple Bounties, North Carolina Port Attacks, Hackers Target Wall Street appeared first on SecurityWeek.
Initially calling itself BlackFile, the group has expanded operations to the Redact, Pink, Helix, and Falcon brands.
The post Vishing Extortion Group UNC6671 Rebrands After Making Millions appeared first on SecurityWeek.
NMFTA research shows a Bendix EC80 brake controller safety recall also patched remote code execution and DoS vulnerabilities.
The post Truck Brake Controller’s Safety Recall Doubled as Hidden Security Fix appeared first on SecurityWeek.
Companies are showcasing their products and services this week at the 2026 edition of the Black Hat conference in Las Vegas.
The post Black Hat USA 2026 – Summary of Vendor Announcements (Part 4) appeared first on SecurityWeek.