Top 5 Cybersecurity News Stories August 14, 2026

Cybersecurity News Stories August 14, 2026 featured image showing five connected attack vectors — Windows kernel rootkit, OT network lateral movement, ERP platform RCE, analytics credential exposure, and MSP management plane bypass — unified by an amber threat thread in a dark enterprise security environment`

This week’s Cybersecurity News Stories August 14, 2026 arrives during a week when defenders discovered something uncomfortable: the tools and infrastructure they depend on to manage, monitor, and protect their environments were themselves the target. A nation-state rootkit disabled Windows security callbacks at the kernel level. A heating plant lost control of its steam turbine…

Read More

Metabase CVSS 10 SQL Injection Zero-Day Hits Admin Access

The Metabase CVSS 10 SQL injection zero-day gives attackers admin access and every connected database credential. Framework and Tally already hit.

The Metabase CVSS 10 SQL injection zero-day lets an unauthenticated attacker turn a self-hosted analytics dashboard into a master key for every database it touches. Active exploitation began August 3, 2026, and two named victims — Framework and Tally — have already confirmed customer data theft. If your organization runs Metabase for internal reporting, this…

Read More