
CISA Adds Metabase SQL Injection Zero-Day to KEV With Aug 14 Deadline
CISA adds CVE-2026-72898 Metabase SQL injection flaw to KEV, setting an August 14 patch deadline for federal agencies and urging

CISA adds CVE-2026-72898 Metabase SQL injection flaw to KEV, setting an August 14 patch deadline for federal agencies and urging

Varonis and PromptArmor disclosed prompt-injection flaws in Atlassian Rovo that can exfiltrate Jira, Confluence, and SharePoint data from enterprise tenants.

Yeeth Security flagged malicious Solidity Pro VS Code extensions that steal crypto wallets, API keys, and developer credentials, exfiltrating them

BIT’s SharePoint intrusion compromised credentials for about 200 Swiss federal accounts, likely via Microsoft flaws fixed in the July Patch

Unlimited Technology Systems disclosed an October 2025 data theft affecting 3.8 million people, exposing Social Security numbers, diagnoses, and ID

Huntress traced credential-theft alerts to attackers who compiled the khunt toolkit inside Oracle to reach SYSTEM-level code execution on a

Connor Riley Moucka pleaded guilty in Seattle federal court to intrusions into 165 Snowflake customers that exposed records of more

Brown Health Medical Group of Massachusetts disclosed a historic file-server breach exposing personal, medical, and financial data belonging to 311,760

The ChainDrop npm worm, a new Shai-Hulud variant, poisoned over 440 registry packages and uses stolen tokens to republish malware

A Google Firebase misconfiguration in the tl;dv AI meeting tool lets users query others’ meeting data and potentially join calls,
Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.