Metabase has released security updates after confirming active exploitation of a zero day vulnerability that allows attackers to gain administrator access without authentication.
Research presented at Black Hat USA 2026 demonstrates CSS based attack techniques affecting major webmail services, highlighting risks involving passwords, authentication tokens, and AI connected email workflows.
Operation Endgame has disrupted the Amadey and StealC malware ecosystem, resulting in the takedown of 326 servers, 142 domains, recovery of 27 million stolen credentials, and restriction of more than $47 million in criminal cryptocurrency assets.
DragonForce ransomware operators have been linked to a new Go based remote access trojan called Backdoor.Turn that hides command and control communications through Microsoft Teams relay infrastructure, enabling long term stealthy access to victim networks.
Google, in collaboration with industry partners, has disrupted the infrastructure of UNC2814, a suspected China-linked cyber espionage group using GRIDTIDE malware to target 53 organizations across 42 countries, supporting affected organizations and cutting off malicious access.