Morning Review in IT Security — August 9, 2026
The cybersecurity landscape continues to face mounting pressure as multiple critical vulnerabilities are actively exploited in the wild. Today's threat landscape encompasses supply chain compromises, zero-day attacks against business intelligence platforms, and widespread exploitation of remote management infrastructure, underscoring the urgent need for rapid patching and defensive measures across enterprise environments.
Hackers Breach TrueConf to Trojanize Client Installers with Backdoors
The Head Mare hacktivist group has been exploiting vulnerabilities in unpatched TrueConf video conferencing servers to replace client installers with malicious versions. This supply chain attack vector delivers backdoors including PhantomCore and PhantomGraph malware to unsuspecting users who download compromised installation files. The threat actors are targeting organizations that have failed to apply security patches to their TrueConf infrastructure, creating a window of opportunity for persistent compromise. Source: Hackers breach TrueConf to trojanize client installers with backdoors
Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication
A maximum-severity zero-day vulnerability in Metabase business intelligence and data visualization software is being actively exploited in the wild. The flaw, which carries a CVSS score of 10.0 and lacks a CVE identifier, permits unauthenticated remote attackers to inject arbitrary SQL into the Metabase application database. This vulnerability enables attackers to gain administrative access without requiring valid credentials, representing a critical threat to organizations relying on Metabase for data analytics and reporting functions. Source: Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication
N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist
N-able has released additional hotfixes for N-central as part of its ongoing investigation into active exploitation of recently disclosed security flaws in the Remote Monitoring and Management product. The company reports that threat actors have successfully reached managed systems and established persistence across customer environments. N-able has identified multiple attack IP addresses and is proactively expanding protections in response to evolving threat actor techniques. The vulnerabilities tracked as CVE-2026-18556 and CVE-2026-18577 continue to present significant risk to organizations utilizing N-central for infrastructure management. Source: N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist
Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts
The U.S. Cybersecurity and Infrastructure Security Agency has added a critical-severity vulnerability in Progress Kemp LoadMaster to its Known Exploited Vulnerabilities catalog following confirmation of active exploitation in the wild. CVE-2026-8037, with a CVSS score of 9.6, is a command injection flaw that allows arbitrary code execution on affected load balancing appliances. Reports indicate at least 792 exploit attempts have been documented, with multiple threat actors leveraging this vulnerability against unpatched systems before the federal mandate for remediation. Source: Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts
Organizations face an accelerating threat environment where zero-day exploits and supply chain compromises demand immediate attention. Security teams must prioritize patching efforts for N-central, Metabase, and Progress Kemp LoadMaster while implementing enhanced monitoring for compromised TrueConf installations. The convergence of multiple active exploitation campaigns underscores the critical importance of vulnerability management and rapid incident response capabilities.