Weekly review

ThreatNoir Morning Brief — August 10

2026-08-10Morning4 articles
Audio
Listen to the episode

Morning Review in IT Security — August 10, 2026

The cybersecurity landscape continues to face mounting pressure as multiple critical vulnerabilities are being actively exploited in the wild. From compromised video conferencing platforms to zero-day flaws in business intelligence tools, organizations face an expanding attack surface that demands immediate attention and patching efforts.

Hackers Breach TrueConf to Trojanize Client Installers with Backdoors

The Head Mare hacktivist group has been actively exploiting vulnerabilities in unpatched TrueConf video conferencing servers to compromise client installers with malicious backdoors. By targeting unpatched systems, the threat actors have been able to replace legitimate client installers with trojanized versions that deliver backdoor payloads to unsuspecting users. The campaign has identified malware variants including PhantomCore and PhantomGraph as part of the attack infrastructure. Source: Hackers breach TrueConf to trojanize client installers with backdoors

Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication

A maximum-severity zero-day vulnerability in Metabase business intelligence and data visualization software has been confirmed as actively exploited in the wild. The flaw, which carries a perfect CVSS score of 10.0 and currently lacks a CVE identifier, permits unauthenticated remote attackers to inject arbitrary SQL commands into the Metabase application database. This capability grants attackers the ability to gain administrative access without any form of authentication, posing an immediate and critical risk to affected deployments. Source: Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication

N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist

N-able has released additional hotfixes for its N-central Remote Monitoring and Management platform as the company continues investigating active exploitation of recently disclosed security flaws. The company confirmed that threat actors have successfully reached managed systems and established persistence across multiple customer environments. N-able stated it is proactively expanding protections in response to ongoing monitoring of threat actors as they evolve their attack techniques, indicating that the threat landscape remains fluid and adaptive. The vulnerabilities tracked as CVE-2026-18556 and CVE-2026-18577 have been linked to multiple attacker infrastructure IP addresses. Source: N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist

Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts

The U.S. Cybersecurity and Infrastructure Security Agency added a critical-severity vulnerability affecting Progress Kemp LoadMaster to its Known Exploited Vulnerabilities catalog following confirmation of active exploitation in the wild. CVE-2026-8037, which carries a CVSS score of 9.6, is a command injection flaw that could allow attackers to achieve arbitrary code execution. The vulnerability has been reported exploited at least 792 times before the federal mandate was issued, demonstrating the widespread nature of active attacks against unpatched LoadMaster instances. Source: Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts

Organizations must prioritize immediate patching of all identified vulnerabilities and conduct thorough audits of their infrastructure to detect any signs of compromise. The convergence of multiple actively exploited flaws across critical business systems underscores the urgent need for comprehensive vulnerability management and incident response capabilities.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).

Hackers breach TrueConf to trojanize client installers with backdoors
Malware2
  • PhantomCore
    Backdoor deployed by Head Mare via trojanized TrueConf client installers.
  • PhantomGraph
    Backdoor deployed by Head Mare using DLL files and OneDrive for command and control.
IP Address1
  • 4307
    TCP port used by Head Mare to connect to TrueConf servers without authentication.
N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist
CVE2
  • Zero-day vulnerability in N-central server allowing authentication bypass and account takeover.
  • Related vulnerability, also actively exploited, with similar impact.
IP Address10
  • 37.19.210.32
    Indicator of Compromise (IoC) shared by N-able.
  • 68.235.46.214
    Indicator of Compromise (IoC) shared by N-able.
  • 87.249.138.34
    Indicator of Compromise (IoC) shared by N-able.
  • 92.118.112.181
    Indicator of Compromise (IoC) shared by N-able.
  • 68.235.46.235
    Indicator of Compromise (IoC) shared by N-able.
  • 173.249.252.176
    Indicator of Compromise (IoC) shared by N-able.
  • 173.249.252.200
    Indicator of Compromise (IoC) shared by N-able.
  • 185.156.46.150
    Indicator of Compromise (IoC) shared by N-able.
  • 23.234.94.43
    Indicator of Compromise (IoC) shared by N-able.
  • 37.153.90.88
    Indicator of Compromise (IoC) shared by N-able.