Daily cybersecurity intelligence digest from CyberNetSec.io - August 10, 2026
π 12 threat intelligence reports covering vulnerabilities, exploits, threat actors, and security advisories.
1. Metabase Zero-Day Flaw Exploited to Steal Data
A critical, unauthenticated SQL injection vulnerability in the Metabase analytics platform, rated CVSS 10.0, is being actively exploited in the wild. Tracked as GHSA-vwf4-m7j8-wcjf, the flaw allows attackers to gain full administrator access. The exploit has already led to data breaches at companies like Framework and Tally, where attackers exfiltrated sensitive customer information. Metabase has released patches and urges all users of self-hosted instances to update immediately.
2. Cyberattack on Suisun City Disrupts 911 Services
Suisun City, California, has declared a local state of emergency following a significant cyberattack that infected its IT systems with 'malicious software.' The incident, which began on August 7, severely disrupted public safety operations, including 911 routing and police and fire dispatch, forcing a complete network shutdown and a federal investigation.
3. China-Linked Group Hits N-able RMM with New Ransomware
The China-linked threat actor Storm-1175 is exploiting a critical authentication bypass vulnerability (CVE-2026-18577) in N-able's N-central RMM software. The attacks, which began on August 2, use the flaw as a launchpad for a new custom ransomware strain called 'StormEncryptor,' posing a significant supply-chain risk to managed service providers (MSPs) and their clients. CISA has added the flaw to its KEV catalog.
4. Suspected Iranian Cyber Campaign Hits US Water Utilities
A widespread cyber campaign, suspected to be linked to Iran, has targeted the operational technology of water and wastewater facilities in at least 12 U.S. states. The attacks have disrupted operations by targeting programmable logic controllers (PLCs), forcing some utilities into manual mode and prompting federal warnings and new legislative proposals to regulate cybersecurity in the water sector.
5. Head Mare Group Breaches TrueConf to Deploy Backdoors
The hacktivist group 'Head Mare' is exploiting a chain of vulnerabilities in unpatched TrueConf video conferencing servers to conduct supply-chain attacks. By compromising the servers, the attackers replace legitimate client installers with malicious versions that deliver the PhantomCore RAT and another backdoor, targeting a range of organizations in Russia.
6. ENISA Scales Up Role as CVE Root Authority in EU
The European Union Agency for Cybersecurity (ENISA) is significantly expanding its role as a Root in the Common Vulnerabilities and Exposures (CVE) Program. It has onboarded new CVE Numbering Authorities (CNAs), including the NATO Communications and Information Agency (NCIA) and AI security firm AISLE, bringing its total managed CNAs to 20 and strengthening the EU's position in global vulnerability management.
7. Qilin Ransomware Lists Chemical Firm as Victim
The Qilin ransomware group has listed Chun Tai Sing Chemical Industry, a Hong Kong-based company, as a victim on its data leak site. The group, known for its double-extortion tactics, claims to have stolen internal data, including customer information, after the company reportedly refused to pay a ransom. The breach has not been officially confirmed by the chemical manufacturer.
8. Phishing Breach at Defense Firm IEH Corp Exposes M365 Data
U.S. defense and aerospace manufacturer IEH Corporation disclosed that a targeted phishing attack led to the compromise of an employee's Microsoft 365 account. The breach, discovered on August 4, 2026, exposed sensitive files, including engineering documents and potentially export-controlled technical information, highlighting supply chain risks within the defense industrial base.
9. California Announces AI Cyber Defense Program
California Governor Gavin Newsom has announced a first-in-the-nation AI Cyber Defense Program to protect the state's assets and critical infrastructure. The initiative, part of the updated Cal-Secure 2.0 strategy, will leverage artificial intelligence for advanced vulnerability detection, network hardening, and accelerated incident response in the face of increasingly sophisticated AI-enabled threats.
10. Dutch Cybersecurity Act (NIS2) Enters Force August 15
The Netherlands has transposed the EU's NIS2 directive into national law. The new Dutch Cybersecurity Act (Cyberbeveiligingswet, or Cbw) is set to take effect on August 15, 2026, with no grace period. The law imposes significant new obligationsβincluding a duty of care, stringent 24-hour incident reporting, and mandatory registrationβon an estimated 8,000 organizations across 18 sectors.
11. WordPress Patches Critical XSS2Shell Flaw (CVE-2026-64638)
WordPress has released security update 7.0.3 to patch a high-severity vulnerability nicknamed 'XSS2Shell' and tracked as CVE-2026-64638. The flaw, rated CVSS 8.9, is an unauthenticated cross-site scripting (XSS) bug on the login page that can be chained with another step to achieve remote code execution on vulnerable sites. All WordPress versions from 6.4 through 7.0.2 are affected, and administrators are urged to update immediately.
12. Unlimited Technology Systems Breach Hits 3.8M Patients
Unlimited Technology Systems, an Ohio-based healthcare financial technology provider, has disclosed a massive data breach impacting 3,803,750 individuals. The incident, which occurred in October 2025, was detected on October 19, 2025, and involved an unauthorized party gaining access to a commercial data center. The breach exposed a vast amount of patient PII, sensitive medical data, and health insurance information.
π Subscribe to daily updates at CyberNetSec.io
All reports include detailed analysis, IOCs, mitigation strategies, and references.
Top comments (0)