Daily cybersecurity briefing

Top 10 Cybersecurity Stories for August 8, 2026

Immediate priority must be given to patching the Metabase zero-day and Progress Kemp LoadMaster flaw, both of which are under active exploitation. The broader threat landscape is currently defined by critical RMM vulnerabilities and a surge in AI-driven supply chain and social engineering attacks.

Compiled by the Slugnet Editorial System. Published Aug 8, 2026, 8:03 AM EDT

Audio briefing

Listen to this edition

A spoken version of today’s prioritized cybersecurity briefing.

  1. 01
    The Hacker News

    Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication

    What happened

    A maximum-severity zero-day SQL injection vulnerability in Metabase allows unauthenticated remote attackers to gain administrative access. The flaw is currently being exploited in the wild to facilitate customer data theft.

    Why it ranks #1

    Confirmed active exploitation of a CVSS 10.0 zero-day providing full admin access represents the highest possible urgency tier.

    Who should care

    IT and platform operations, SOC and incident response teams

    What to do

    Apply available vendor patches immediately and audit database logs for unauthorized SQL injection attempts.

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  2. 02
    The Hacker News

    Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts

    What happened

    CISA has added a critical command injection vulnerability (CVE-2026-8037) in Progress Kemp LoadMaster to its Known Exploited Vulnerabilities catalog. The flaw carries a CVSS score of 9.6 and can be weaponized for arbitrary code execution.

    Why it ranks #2

    CISA KEV inclusion confirms active exploitation of a critical infrastructure component, placing it in the highest priority tier.

    Who should care

    IT and platform operations, SOC and incident response teams

    What to do

    Update Progress Kemp LoadMaster to the latest patched version as per CISA directives.

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  3. 03
    The Hacker News

    N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist

    What happened

    N-able has released Hotfix 2 for N-central to counter evolving techniques used by threat actors exploiting a recently disclosed security flaw. Attackers are actively using the vulnerability to reach and persist within managed systems.

    Why it ranks #3

    Active exploitation of RMM tools is high-risk due to the potential for downstream supply-chain impact on managed clients.

    Who should care

    IT and platform operations, SOC and incident response teams

    What to do

    Deploy N-central Hotfix 2 immediately and monitor managed systems for unauthorized persistence.

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  4. 04
    The Hacker News

    New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP

    What happened

    A high-severity pre-authentication reflected XSS flaw (CVE-2026-64638) in WordPress can be chained to achieve PHP code execution on the server. The vulnerability affects all versions of the CMS when a logged-in administrator interacts with an attacker-controlled page.

    Why it ranks #4

    While not confirmed as actively exploited in the wild, the broad scope (all WP versions) and potential for RCE make this a critical enterprise risk.

    Who should care

    Application security teams, IT and platform operations

    What to do

    Update WordPress installations to the latest version to remediate CVE-2026-64638.

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  5. 05
    The Hacker News

    18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers

    What happened

    A use-after-free vulnerability in the Linux SCTP networking code, existing since 2008, allows local users to gain root privileges and escape containers. Patches have been released for stable kernels 7.1.6, 6.18.42, 6.12.101, and 6.6.148.

    Why it ranks #5

    Container escape to host root is a high-impact vulnerability in widely used cloud/developer infrastructure.

    Who should care

    Cloud security teams, IT and platform operations

    What to do

    Update Linux kernels to the specified stable versions or disable SCTP if not required.

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  6. 06
    The Hacker News

    Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers

    What happened

    Atlassian's Rovo AI assistant can be manipulated via attacker-controlled instructions to exfiltrate Jira and Confluence data to external servers. Researchers found multiple routes for this attack, though only one is confirmed closed.

    Why it ranks #6

    This represents a critical vulnerability in an AI agent integrated into enterprise knowledge bases, directly impacting data confidentiality.

    Who should care

    Application security teams, CISOs and security leaders

    What to do

    Review Atlassian Rovo configurations and monitor for unusual outbound data transfers from the assistant.

    Impact
    high
    Urgency
    near-term
    Confidence
    medium
    Scope
    enterprise
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  7. 07
    The Hacker News

    New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens

    What happened

    New CSS-based attack techniques allow email content to escape message boundaries and interfere with webmail interfaces across major providers including Gmail and Outlook. These attacks can capture passwords, leak tokens, and manipulate AI tools that process email.

    Why it ranks #7

    This is a novel technique affecting nearly all enterprise webmail users with the potential for identity theft and account takeover.

    Who should care

    Identity and access teams, SOC and incident response teams

    Impact
    high
    Urgency
    near-term
    Confidence
    medium
    Scope
    enterprise
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  8. 08
    The Hacker News

    Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer

    What happened

    Nearly 800 malicious npm packages are delivering a cross-platform RAT and infostealer targeting Windows, Mac, and Linux. The campaign utilizes AI-generated typo-squatting names to deceive developers.

    Why it ranks #8

    A large-scale supply chain attack targeting developer environments is a material threat to enterprise software integrity.

    Who should care

    Application security teams, SOC and incident response teams

    What to do

    Audit npm dependencies for typo-squatted packages and implement strict dependency pinning.

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  9. 09
    The Hacker News

    UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data

    What happened

    The threat actor UNC6671 is conducting vishing attacks against financial and professional services employees, posing as IT help desk staff. The goal is to steal SaaS data by convincing targets to facilitate urgent security migrations.

    Why it ranks #9

    Targeted social engineering campaigns against high-value sectors represent a material threat actor operation.

    Who should care

    CISOs and security leaders, SOC and incident response teams

    What to do

    Conduct employee awareness training specifically regarding vishing and verify IT requests through official channels.

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  10. 10
    BleepingComputer

    North Carolina Ports confirms cyberattack disrupting operations

    What happened

    The North Carolina Ports Authority confirmed a cyberattack that disrupted IT systems and slowed operations across multiple ports. The incident has caused operational delays at the Port of Wilmington, Port of Morehead City, and Charlotte Inland Port.

    Why it ranks #10

    A material breach causing physical operational disruption to critical infrastructure is a high-impact event.

    Who should care

    CISOs and security leaders, SOC and incident response teams

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email