Metabase CVSS 10 SQL Injection Zero-Day Hits Admin Access

The Metabase CVSS 10 SQL injection zero-day gives attackers admin access and every connected database credential. Framework and Tally already hit.

The Metabase CVSS 10 SQL injection zero-day lets an unauthenticated attacker turn a self-hosted analytics dashboard into a master key for every database it touches. Active exploitation began August 3, 2026, and two named victims — Framework and Tally — have already confirmed customer data theft. If your organization runs Metabase for internal reporting, this…

Read More

Top 5 Cybersecurity News Stories July 24, 2026

Cybersecurity News Stories July 24, 2026 — DIESEC editorial header showing five cybersecurity threat icons: OT control panel, firewall UI, server key, workflow dashboard, helpdesk document

The five stories in this week’s Cybersecurity News Stories July 24, 2026 share a structural feature that distinguishes them from the opportunistic exploitation patterns that dominate most news cycles: in each case, the component that was compromised, configured, or exposed was not the primary IT system the organisation considers its attack surface. It was the…

Read More

EY Third-Party Data Breach: 15 Days Inside Helpdesk

EY third-party data breach

EY third-party data breach: attackers spent 15 days inside a support-ticketing platform used by Ernst & Young’s tax practice, walking out with client tax filings, Social Security numbers and financial account data before anyone noticed — the firm’s third vendor-side security failure in under three years. What Happened This EY third-party data breach ran from…

Read More

June 2026 Cybersecurity Roundup: Supply Chain Breaches, Data Extortion, and Critical CVEs

June 2026 Cybersecurity Roundup

This June 2026 Cybersecurity Roundup lands in a month when the FIFA World Cup kickoff dominated the conversation, with most attention on cyber threats and fraud tied to the tournament. Away from the headlines, though, June’s most consequential incidents ran through SaaS supply chains, ransomware-driven data extortion, and identity compromise. Here’s a roundup of the…

Read More