Posts Tagged ‘data breach’
Metabase CVSS 10 SQL Injection Zero-Day Hits Admin Access
The Metabase CVSS 10 SQL injection zero-day lets an unauthenticated attacker turn a self-hosted analytics dashboard into a master key for every database it touches. Active exploitation began August 3, 2026, and two named victims — Framework and Tally — have already confirmed customer data theft. If your organization runs Metabase for internal reporting, this…
Read MoreJuly 2026 Cybersecurity Roundup: A Rogue AI Agent, Ransomware Disruption, and Critical CVEs
This July 2026 Cybersecurity Roundup lands in a month when the peak of northern-hemisphere summer brought no letup in cyber incidents — if anything, July produced some of the year’s most unusual attacks so far. Here’s a roundup of the month’s key incidents and newly disclosed vulnerabilities, along with our take on what they mean.…
Read MoreTop 5 Cybersecurity News Stories July 24, 2026
The five stories in this week’s Cybersecurity News Stories July 24, 2026 share a structural feature that distinguishes them from the opportunistic exploitation patterns that dominate most news cycles: in each case, the component that was compromised, configured, or exposed was not the primary IT system the organisation considers its attack surface. It was the…
Read MoreEY Third-Party Data Breach: 15 Days Inside Helpdesk
EY third-party data breach: attackers spent 15 days inside a support-ticketing platform used by Ernst & Young’s tax practice, walking out with client tax filings, Social Security numbers and financial account data before anyone noticed — the firm’s third vendor-side security failure in under three years. What Happened This EY third-party data breach ran from…
Read MoreJune 2026 Cybersecurity Roundup: Supply Chain Breaches, Data Extortion, and Critical CVEs
This June 2026 Cybersecurity Roundup lands in a month when the FIFA World Cup kickoff dominated the conversation, with most attention on cyber threats and fraud tied to the tournament. Away from the headlines, though, June’s most consequential incidents ran through SaaS supply chains, ransomware-driven data extortion, and identity compromise. Here’s a roundup of the…
Read More
