daily cyber × ai intelligence

index

August 11, 2026

Metabase Zero-Day Blast Radius Widens to LexisNexis and Framework

66 of 70 sources 385 gathered 385 triaged 48 clustered 48 written

The still-CVE-less Metabase SQL injection zero-day keeps claiming victims, with LexisNexis pulling services offline and Framework confirming stolen customer data. On the offensive side, the Black Hat Kerberos flaws picked up Linux weaponization, and multiple research teams detailed fresh ways to hijack AI agents.

Vulnerabilities & Exploits

  • Metabase’s unauthenticated SQL injection zero-day is spreading downstream, and there’s still no CVE. The maximum-severity reset_password flaw grants remote administrator access to the analytics platform, and its blast radius now reaches hosted customers of Metabase itself (Dark Reading). LexisNexis took its Diligence, Metabase API, and Newsdesk services offline after suspicious server activity at a third-party vendor (BleepingComputer), and Framework confirmed customer data loss and rotated credentials (The Register). A loopback-only Docker lab comparing patched vs. vulnerable builds is public (earlier coverage). (discussion)
  • The two Black Hat Kerberos logic flaws are now weaponized against Linux and NetExec. A full write-up walks through exploiting ResetNightmare (CVE-2026-27912, a Change Password protocol flaw enabling any account’s password reset via UPN spoofing) and KerberLoss (CVE-2026-25177, service impersonation) from a Linux box to full domain takeover (cravaterouge), building directly on last week’s PoC drop (earlier coverage).
  • A researcher published two working macOS Screen Sharing exploits for CVE-2026-65400. The write-up details how any network attacker can reach a Mac with Screen Sharing enabled, following last week’s PoC release (calif.io, earlier coverage).
  • A zero-day iOS 26/27 sandbox escape, bad_query, went public after iOS 27 beta 5 quietly patched it. The PoC underpins the mond MobileGestalt editor and was released once the bug was killed (rooootdev).
  • Cisco warned of high-severity ClamAV DoS bugs with public PoC. Remote, unauthenticated attackers can crash the scanner (SecurityWeek).

New Tools & Releases

  • NoiseHound re-ranks BloodHound attack paths by expected detection cost, calibrated across audit/EDR/SIEM tiers to surface the quietest route to an objective — a purple-team-friendly take on path scoring (GitHub).
  • SgrmFault revives a COM-based code-injection chain in WerFaultSecure, abusing an APC-based process-tampering feature exposed by SgrmAgent.sys (lem0nSec).
  • ctxdebug is an MCP-powered reverse-engineering platform wiring WinDbg, IDA Pro, and x64dbg into a unified JSON-RPC interface with 160+ AI-accessible debugging and analysis tools (GitHub).
  • pyca/cryptography now ships post-quantum support (ML-KEM and ML-DSA), bringing PQC asymmetric schemes to Python for crypto agility (Trail of Bits). (discussion)

AI & Model Security

  • New “GhostJacking” research shows attackers manipulating AI agents through security alerts and blocked events. By feeding agents crafted alerts and denied-action signals, adversaries can hijack their behavior — exposing identity-governance gaps in how agents handle tool permissions (Dark Reading).
  • Atlassian Rovo can be hijacked by hidden text in a PDF, a second route separate from last week’s “RovoBlast.” PromptArmor showed instructions buried in an uploaded file silently exfiltrating Jira and Confluence data with no user confirmation and no trace (The Decoder); THN notes two firms found the behavior independently and only one route is confirmed closed (The Hacker News, earlier coverage).
  • North Korea’s Kimsuky is running LLMs offline on its own servers to industrialize operations. Genians documents AI-generated decoy documents, local/private LLM deployments, RAG over stolen files, and .NET/C# AI libraries being collected to build AI into malware — moving beyond public chatbots (The Hacker News, The Register).
  • OpenAI launched GPT-5.6-Cyber, a defender-focused model that answers up to 98.5% of security queries normally blocked. It reportedly already surfaced two previously unknown Chrome bugs; access requires identity verification (The Decoder).
  • Meta released Muse Glimmer, a 30B open-weight agent model under Apache 2.0. It’s tuned for local, always-on agent workflows and runs on consumer hardware in under 20 GB once quantized — Meta’s first cleanly OSI-licensed weights (Simon Willison, The Decoder). (discussion)

Threat Activity

  • FBI and South Korea warned that the Gunra RaaS gang is breaching critical infrastructure via firewall vulnerabilities. Gunra, which moved to a RaaS model in 2026, uses double extortion with a dedicated leak site against government and critical-infrastructure targets (The Record, CISA).
  • A former Medusa affiliate, tracked as Storm-1175, is deploying a new StormEncryptor strain, likely via the N-central flaw. Microsoft dates the campaign to early August; the actor is described as China-linked (BleepingComputer, The Hacker News). (discussion)
  • Microsoft dissected DeadLock, a Rust-based ransomware with decentralized recovery infrastructure. The financially motivated operation runs victim communications, negotiations, and leaks over decentralized infrastructure alongside double extortion (Microsoft).
  • Zscaler detailed Abyssos, a new modular C++ RAT in active development. It supports credential theft, file exfiltration, and VNC remote access, with multiple obfuscation passes to evade security products (Zscaler).
  • Poland disclosed a second heat-plant OT breach hidden for months, and CERT.PL calls the private-APN pivot a first. Attackers reached the OT network of a plant serving ~50,000 residents via a private Access Point Name — the same day 30+ renewable installations were hit (SecurityWeek, BleepingComputer, earlier coverage).
  • CERT-UA warns of Sandworm subcluster UAC-0145 running fake-job social engineering against Ukrainian sysadmins. Posing as an IT firm (e.g. “ATLAS Business Group”) on job boards, the actor studies a candidate’s résumé before making contact — attribution ties to APT44/Seashell Blizzard (CERT-UA).
  • Hunt.io profiled a Russian-speaking operator’s toolkit for compromising Ukrainian IP cameras, providing remote access and data theft against surveillance infrastructure (Hunt.io).
  • A member of “The Com” was jailed for two years for blackmail and sextortion of 117 girls aged 13–17. The UK’s NCA case against Justin Swaddle underscores the collective’s child-targeting activity (The Record, BleepingComputer).

Supply Chain

  • A malicious VS Code extension, “Solidity Pro,” steals crypto wallets, API keys, and credentials. Two variants (helper-beeps.solidity-pro, web3devtoolsx.solidity-pro) delivered a browser-wallet and credential stealer before being pulled from Open VSX (The Hacker News).

Breaches & Data Exposure

  • Valve is notifying European Steam hardware customers of a breach traced to shipping partner CEVA Logistics. The same cyberattack disrupted eight CEVA warehouses across Europe, hitting e-commerce fulfillment (BleepingComputer, FreightWaves). (discussion)
  • A threat actor is advertising 800,000+ TCS employee records allegedly pulled from the company’s Azure tenant using compromised credentials, including names, employee IDs, emails, job titles, and phone numbers (DailyDarkWeb).
  • Argentina’s National Identity Registry was allegedly leaked — 48 million citizen records, including home addresses (DarkWebInformer).
  • Newcastle University confirmed a configuration-related breach after ExfilSquad claimed 440,000 records, exposing contact details with no evidence yet of broader compromise (CyberInsider).

Policy & Regulation

  • All Claude models launched in the EU now carry machine-readable AI-content marking to meet EU AI Act obligations. Generated text gets embedded watermarks and files include digitally signed provenance metadata where supported (Check Point).
  • New Zealand sanctioned 33 Russian individuals and entities over cyberattacks and anti-Ukraine propaganda, including actors tied to the abduction of Ukrainian children (The Record).
  • CERT-DK warns that ransomware is hitting universities harder, flagging the higher-education sector as an intensifying target across the Nordics (CERT.dk).