Weekly review

ThreatNoir Weekend Brief — August 8

2026-08-08Afternoon7 articles
Audio
Listen to the episode

Afternoon Review in IT Security — August 8, 2026

The threat landscape continues to intensify as critical vulnerabilities across enterprise software platforms are actively exploited in the wild. Today's security briefing reveals a concerning pattern of zero-day attacks, supply chain compromises, and novel attack vectors targeting widely-deployed business applications and infrastructure management tools.

Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication

Metabase has issued a critical warning regarding a maximum-severity security flaw affecting its business intelligence and data visualization software. The vulnerability, which carries a perfect CVSS score of 10.0 and currently lacks a CVE identifier, permits unauthenticated remote attackers to inject arbitrary SQL into the Metabase application database. This exploitation enables attackers to gain administrative access without requiring valid credentials, and the flaw is already being actively exploited in the wild. Source: The Hacker News

N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist

N-able has released a second round of hotfixes for its N-central Remote Monitoring and Management platform in response to ongoing exploitation of recently disclosed security vulnerabilities. The company confirmed that threat actors have successfully reached managed systems and established persistence mechanisms while evolving their attack techniques. The vulnerabilities tracked as CVE-2026-18556 and CVE-2026-18577 remain active threats, with indicators of compromise including multiple IP addresses associated with attacker infrastructure. Source: The Hacker News

Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts

The U.S. Cybersecurity and Infrastructure Security Agency added a critical-severity vulnerability in Progress Kemp LoadMaster to its Known Exploited Vulnerabilities catalog following active exploitation in the wild. CVE-2026-8037, rated 9.6 on the CVSS scale, is a command injection flaw that could allow arbitrary code execution. The addition to CISA's KEV catalog came after reports documented 792 exploitation attempts, underscoring the widespread targeting of this load balancing appliance. Source: The Hacker News

Critical One-Click Vulnerability in Atlassian's Rovo AI Exposed Enterprise Data

Varonis researchers identified a critical one-click vulnerability in Atlassian's Rovo AI assistant that could have been exploited through a method termed RovoBlast to steal sensitive data from Confluence, Jira, and SharePoint environments. The vulnerability represents a significant risk to enterprises relying on these widely-deployed collaboration platforms, as the attack requires minimal user interaction to compromise enterprise data. Source: SecurityWeek

Sensitive Info Goes Into 'No Reply' Emails Constantly. This Guy Sees It All

Security researchers purchased inexpensive domains including noreply.net, noreply.us, donotreply.com, and deleteduser.com, then configured email listening services on these addresses. The experiment revealed that hundreds of companies are routinely sending corporate secrets and sensitive information to these domains, which were previously abandoned or misconfigured. This widespread misuse of generic "no reply" email addresses demonstrates a critical gap in organizational email configuration practices and data handling procedures. Source: Wired

New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens

PortSwigger researchers have discovered novel CSS-based attack techniques capable of breaking through webmail security defenses across multiple major platforms including Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail. These attacks exploit the ability of email content to escape message boundaries and interfere with webmail interface elements, enabling attackers to capture passwords, steal authentication tokens, hijack third-party accounts, manipulate trusted UI actions, and compromise AI tools that process email content. Source: The Hacker News

Flock's Plans for Rideshare Dashcams and Coaching Police, Revealed

Recent reporting has exposed plans by Flock Safety to expand its surveillance capabilities through rideshare dashcams and police coaching programs. The briefing also covers additional security developments including a judicial ruling that cell tower dumps are unconstitutional, the expansion of water utility breaches to a dozen states, a phishing attack targeting a missile parts supplier, and the sentencing of a ransomware operator to 16 years in prison. Source: Wired

The convergence of zero-day exploits, supply chain vulnerabilities, and novel attack vectors underscores the need for organizations to maintain vigilant patching schedules, review email configurations, and implement defense-in-depth strategies across their infrastructure and cloud applications.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).

N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist
CVE2
  • Zero-day vulnerability in N-central server allowing authentication bypass and account takeover.
  • Related vulnerability, also actively exploited, with similar impact.
IP Address10
  • 68.235.46.214
    Indicator of Compromise (IoC) shared by N-able.
  • 68.235.46.235
    Indicator of Compromise (IoC) shared by N-able.
  • 92.118.112.181
    Indicator of Compromise (IoC) shared by N-able.
  • 87.249.138.34
    Indicator of Compromise (IoC) shared by N-able.
  • 173.249.252.176
    Indicator of Compromise (IoC) shared by N-able.
  • 173.249.252.200
    Indicator of Compromise (IoC) shared by N-able.
  • 185.156.46.150
    Indicator of Compromise (IoC) shared by N-able.
  • 23.234.94.43
    Indicator of Compromise (IoC) shared by N-able.
  • 37.153.90.88
    Indicator of Compromise (IoC) shared by N-able.
  • 37.19.210.32
    Indicator of Compromise (IoC) shared by N-able.
Sensitive Info Goes Into ‘No Reply’ Emails Constantly. This Guy Sees It All
Domain4
  • donotreply.com
    Domain previously highlighted by Brian Krebs for similar data leakage.
  • noreply.net
    Domain purchased by researcher Cory Solovewicz to capture misdirected emails.
  • noreply.us
    Domain purchased by researcher Cory Solovewicz to capture misdirected emails.
  • deleteduser.com
    Domain purchased by researcher Mike Sheward to capture misdirected emails.