ISC Stormcast For Monday, August 10th, 2026 https://isc.sans.edu/podcastdetail/10044, (Mon, Aug 10th)

A Critical Vulnerability Hits Unpatched Systems, Exposing Them to Remote Attacks A newly discovered vulnerability in a widely used internet protocol is putting millions of unpatched systems at risk of remote exploitation. The flaw, located in the Internet Group Management Protocol (IGMP), allows attackers to execute arbitrary code on affected devices, giving them full control … Read more

Hackers breach TrueConf to trojanize client installers with backdoors

A devastating cyberattack has been uncovered, with hackers breaching video conferencing servers from TrueConf, a tool widely used in Russia. The Head Mare hacktivist group has taken advantage of vulnerabilities in unpatched TrueConf servers to deliver backdoors and compromise sensitive information. This attack highlights the importance of patching software and staying vigilant against cyber threats. … Read more

Critical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise Data

A Critical Vulnerability in Atlassian’s Rovo AI Assistant Exposes Enterprise Data to Attackers A team of researchers at Varonis Threat Labs has uncovered a severe vulnerability in Rovo, the enterprise AI assistant developed by Atlassian. The flaw, dubbed RovoBlast, allows attackers to inject malicious instructions into a user’s live AI session with just one click … Read more

Hackers breach TrueConf to trojanize client installers with backdoors

A critical vulnerability in TrueConf video conferencing servers has been exploited by hackers to deliver backdoors and compromise sensitive data. The Head Mare hacktivist group is behind the attacks, which have targeted organizations in various sectors, including enterprise and government entities in Russia. The attackers took advantage of unpatched vulnerabilities in TrueConf Server versions 5.3.x … Read more

Critical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise Data

A Critical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise Data At the DEF CON 34 conference, cybersecurity researchers from Varonis Threat Labs revealed a devastating one-click vulnerability in Rovo, an enterprise AI assistant developed by Atlassian. Dubbed “RovoBlast,” this flaw allowed attackers to inject malicious instructions directly into a user’s live AI session with … Read more

New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens

CyberNews.work has learned that a new class of attacks is targeting webmail defenses, allowing hackers to break through and steal sensitive credentials. The CSS-based attacks exploit vulnerabilities in how websites handle JavaScript code, giving malicious actors a way into otherwise secure systems. This breach can lead to the theft of not only passwords but also … Read more

Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers

A Critical Vulnerability in Atlassian’s Rovo Affects Thousands of Organizations, Exposing Sensitive Data Atlassian, a leading provider of collaboration software, has disclosed a critical vulnerability in its Rovo product that allows attackers to trick it into sending sensitive data from Jira and Confluence instances to unauthorized parties. The issue affects thousands of organizations worldwide that … Read more

Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts

A Critical Vulnerability in Progress Kemp LoadMaster Puts Government and Enterprise Networks at Risk A recently discovered flaw in Progress Kemp LoadMaster, a web application delivery controller used by numerous government agencies and enterprises, has exposed sensitive data and opened doors to potential cyber attacks. According to reports, the vulnerability has already been exploited over … Read more

N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist

A Critical Vulnerability in N-central Has Been Exploited by Attackers, Putting Thousands of Managed Systems at Risk N-able has released a hotfix for its N-central platform after reports emerged that attackers have successfully exploited a critical vulnerability to gain unauthorized access to thousands of managed systems. The vulnerability, which affects various versions of the platform, … Read more

Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication

A Critical Zero-Day Vulnerability in Metabase Exposes Admin Access Without Authentication, Leaving Many Organizations Vulnerable A newly discovered zero-day vulnerability in the popular data analytics platform Metabase has been exploited in the wild, allowing attackers to gain administrative access without requiring any authentication credentials. This critical flaw affects numerous organizations worldwide that rely on Metabase … Read more