📡 Tech & Security Digest — 2026-08-08
Curated from Hacker News, security blogs, and tech publications.
BleepingComputer
- Metabase SQLi zero-day exploited in customer data-theft attacks — A critical Metabase SQL injection vulnerability was exploited in zero-day attacks to breach customer instances in data theft attacks, known to impact …
- Hackers run khunt post-exploitation toolkit from Oracle database — Hackers exploited a SQL injection vulnerability to install a post-exploitation toolkit directly inside an Oracle database that was used to breach a co…
- Meta AI model hacked a company during misconfigured cyber test — Meta has become the latest AI company to confirm that one of its models hacked a real organization during cybersecurity testing, as similar incidents …
- Swiss government SharePoint breach compromised 200 accounts — Switzerland’s federal IT office says hackers exploited vulnerabilities to breach its Microsoft SharePoint servers and compromised approximately 200 ac…
Hacker News
- What happens if an entire class of workers loses faith in their careers (541 pts)
- Managing AI Coding Costs at Scale (211 pts)
- Oracle bans AI-generated code from OpenJDK (442 pts)
- Captain Bible Reverse Engineering (27 pts)
- NASA to keep its 48-year-old Voyager 2 probe running for yet another year (172 pts)
Krebs on Security
- Microsoft Patches a Record 570 Security Flaws — Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple…
- Felons, Fraudsters Flog Offensive Cybersecurity Startup — A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right co…
- Who Runs the Ransomware Group ‘The Gentlemen?’ — A cybercrime group known as The Gentlemen has emerged as the second most active ransomware gang by victim count, rapidly attracting a talented pool of…
The Hacker News
- CISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation in the Wild — A newly patched security flaw impacting on-premise versions of JetBrains TeamCity has come under active exploitation in the wild, according to the U.S…
- CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromises — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a high-severity security flaw impacting N-able N-central to its Known…
- AI Recommendation Poisoning: How “Ask AI” Buttons Silently Alter LLM Memory — A new class of prompt injection is spreading across commercial websites. It requires no malware, no stolen credentials, and no zero-day exploit. It ab…
- New OVSwrap Linux Kernel Flaw Lets Local Users Gain Root via Open vSwitch — A memory corruption flaw in the Linux kernel’s Open vSwitch datapath gives ordinary local users a path to root on a broad set of default-configured di…
- Claude Mythos 5 Tried to Backdoor a Real Open-Source Project in Testing, Then Vouched for Itself — An agent running Anthropic’s Claude Mythos 5 spent 34 hours trying to get a malware dropper merged into a real open-source project during a cyber eval…
- CISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively Exploited — The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on August 5, 2026, added three flaws to its Known Exploited Vulnerabilities (KEV) ca…
- QuickFox Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Windows Installer — Cybersecurity researchers have disclosed what has been described as a “long-standing supply chain attack” on QuickFox, a virtual private network (VPN)…
- Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets — A GitHub issue opened by an account with no repository privileges was enough to execute code on the CI runners behind Anthropic’s and Google’s own cod…
- New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts — Zapscape, a new Linux kernel vulnerability, could allow an attacker with kernel privileges inside an L1 guest virtual machine (VM) to escape KVM isola…
- Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails — Cybersecurity researchers have called attention to an active “widespread email-driven phishing campaign” that employs adversary-in-the-middle (AitM) t…
The Verge
- OpenAI puts the brakes on a new model because it’s supposedly too powerful — OpenAI says it is pausing “internal activities” around an in-development AI model, Astra, because it doesn’t yet meet new security standards the compa…