DAILY BRIEFING
Hackers breach TrueConf to trojanize client installers with backdoors
Today's security briefing covers an active Metabase zero-day, mandatory N-able hotfixes, backdoored TrueConf installers, webmail CSS exploits, and Atlassian Rovo prompt injection risks.
5 stories2 min read

Critical infrastructure and enterprise software face heightened exposure as attackers actively exploit zero-day flaws and compromise distribution channels. System administrators and security personnel must prioritize immediate patching for business intelligence and monitoring tools that grant elevated privileges.
Beyond server-side exploits, client software integrity and AI-assisted workflows present expanding attack vectors. Organizations operating self-hosted platforms or using integrated assistants need to evaluate input boundaries and application access controls to prevent unauthorized data exfiltration.
Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication
Metabase has warned that a maximum-severity security flaw impacting its business intelligence and data visualization software package has been exploited in the wild as a zero-day.
- Why it matters
- Self-hosted Metabase deployments risk complete administrative compromise, enabling attackers to extract connected database credentials and exfiltrate enterprise data.
- What to do
- Apply Metabase security patches immediately to all self-hosted deployments.
Hackers breach TrueConf to trojanize client installers with backdoors
Hacktivist group The Head Mare has been exploiting vulnerabilities in unpatched TrueConf video conferencing servers. The attackers replace legitimate client installers hosted on the servers with trojanized versions designed to drop backdoors onto connecting user devices.
- Why it matters
- Organizations hosting self-managed TrueConf servers face compromise of internal endpoints downloading infected client installation files.
- What to do
- Patch TrueConf servers immediately and verify the integrity of client installer binaries hosted on the platform.
Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers
Atlassian Rovo contains vulnerabilities that allow indirect prompt injection and parameter manipulation. Attackers can trick the AI assistant using malicious file content or rovoChatPrompt URL parameters to silently exfiltrate Jira and Confluence data to external servers without user consent.
- Why it matters
- Enterprise users relying on Atlassian Rovo face silent exfiltration of sensitive Jira and Confluence data accessible under their account permissions.
N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist
N-able issued Hotfix 2 for N-central to counter ongoing threat actor activity. Attackers exploited CVE-2026-18577, a flaw resulting from an incomplete fix for CVE-2026-18556, to gain unauthorized access to managed environments and establish persistence.
New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens
Security research presented at Black Hat USA 2026 demonstrates CSS-based attack techniques against major webmail providers including Outlook and Gmail. Malicious email content can break out of message sandboxes to hijack UI elements, steal session tokens, and capture user passwords.
- Why it matters
- Users of webmail applications are vulnerable to interface spoofing and credential theft simply by opening malicious HTML emails.
Key takeaways
- Patch self-hosted Metabase instances immediately to address an unauthenticated SQL injection zero-day with a 10.0 CVSS score.
- Apply N-able N-central Hotfix 2 to mitigate active exploitation of CVE-2026-18577 across managed systems.
- Atlassian Rovo and webmail clients face data exfiltration risks via prompt injection and CSS boundary bypasses.