Metabase has released security updates after confirming active exploitation of a zero day vulnerability that allows attackers to gain administrator access without authentication.
Research presented at Black Hat USA 2026 demonstrates CSS based attack techniques affecting major webmail services, highlighting risks involving passwords, authentication tokens, and AI connected email workflows.
Huntress reports active exploitation of a newly uncovered Gladinet CentreStack and Triofox vulnerability linked to hard coded cryptographic keys, enabling unauthorized access and remote code execution across affected systems.