CHECKLEAKED.CC

Loading

Classic site

DAILY BRIEFING

Hackers breach TrueConf to trojanize client installers with backdoors

Today's security briefing covers an active Metabase zero-day, mandatory N-able hotfixes, backdoored TrueConf installers, webmail CSS exploits, and Atlassian Rovo prompt injection risks.

Critical infrastructure and enterprise software face heightened exposure as attackers actively exploit zero-day flaws and compromise distribution channels. System administrators and security personnel must prioritize immediate patching for business intelligence and monitoring tools that grant elevated privileges.

Beyond server-side exploits, client software integrity and AI-assisted workflows present expanding attack vectors. Organizations operating self-hosted platforms or using integrated assistants need to evaluate input boundaries and application access controls to prevent unauthorized data exfiltration.

Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication

Metabase has warned that a maximum-severity security flaw impacting its business intelligence and data visualization software package has been exploited in the wild as a zero-day.

Why it matters
Self-hosted Metabase deployments risk complete administrative compromise, enabling attackers to extract connected database credentials and exfiltrate enterprise data.
What to do
Apply Metabase security patches immediately to all self-hosted deployments.
  • Metabase
  • database
Read the original

Hackers breach TrueConf to trojanize client installers with backdoors

Hacktivist group The Head Mare has been exploiting vulnerabilities in unpatched TrueConf video conferencing servers. The attackers replace legitimate client installers hosted on the servers with trojanized versions designed to drop backdoors onto connecting user devices.

Why it matters
Organizations hosting self-managed TrueConf servers face compromise of internal endpoints downloading infected client installation files.
What to do
Patch TrueConf servers immediately and verify the integrity of client installer binaries hosted on the platform.
  • TrueConf
  • backdoor
Read the original

Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers

Atlassian Rovo contains vulnerabilities that allow indirect prompt injection and parameter manipulation. Attackers can trick the AI assistant using malicious file content or rovoChatPrompt URL parameters to silently exfiltrate Jira and Confluence data to external servers without user consent.

Why it matters
Enterprise users relying on Atlassian Rovo face silent exfiltration of sensitive Jira and Confluence data accessible under their account permissions.
  • Atlassian
  • Rovo
  • Jira
  • Confluence
Read the original

N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist

N-able issued Hotfix 2 for N-central to counter ongoing threat actor activity. Attackers exploited CVE-2026-18577, a flaw resulting from an incomplete fix for CVE-2026-18556, to gain unauthorized access to managed environments and establish persistence.

  • RMM
Read the original

New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens

Security research presented at Black Hat USA 2026 demonstrates CSS-based attack techniques against major webmail providers including Outlook and Gmail. Malicious email content can break out of message sandboxes to hijack UI elements, steal session tokens, and capture user passwords.

Why it matters
Users of webmail applications are vulnerable to interface spoofing and credential theft simply by opening malicious HTML emails.
  • webmail
  • CSS
  • Outlook
  • Gmail
Read the original

Key takeaways

  • Patch self-hosted Metabase instances immediately to address an unauthenticated SQL injection zero-day with a 10.0 CVSS score.
  • Apply N-able N-central Hotfix 2 to mitigate active exploitation of CVE-2026-18577 across managed systems.
  • Atlassian Rovo and webmail clients face data exfiltration risks via prompt injection and CSS boundary bypasses.
  • Metabase
  • ZeroDay
  • RovoBlast
  • CSSBomb
  • TrueConf