Metabase has released security updates after confirming active exploitation of a zero day vulnerability that allows attackers to gain administrator access without authentication.
Research presented at Black Hat USA 2026 demonstrates CSS based attack techniques affecting major webmail services, highlighting risks involving passwords, authentication tokens, and AI connected email workflows.
Cybersecurity experts warn that fragmented identity verification systems are weakening fraud detection by losing critical telemetry needed to stop digital injection attacks and synthetic identity fraud.
Salesforce warns of large scale scanning attempts targeting misconfigured Experience Cloud sites using a modified AuraInspector tool capable of extracting sensitive data from public endpoints.
Researchers have uncovered nearly 3,000 publicly exposed Google Cloud API keys that gained unintended access to Gemini endpoints after API enablement, raising concerns over data exposure and unexpected billing charges.
IBM discloses critical CVE-2025-13915 vulnerability in API Connect allowing potential remote authentication bypass. Users are advised to apply interim fixes immediately.
Trust Wallet reveals Shai-Hulud supply chain attack compromised Chrome extension, stealing $8.5 million in crypto assets from 2,520 wallets. Users urged to update to version 2.69.