Salesforce ServiceNow Portals Exposed 17 Months Metabase 0-Day Exploit

www.news4hackers.com-salesforce-servicenow-portals-exposed-17-months-metabase-0-day-exploit-salesforce-servicenow-portals-exposed-17-months-metabase-0-day-exploit

Security researchers uncover widespread vulnerabilities, zero-day exploits, and critical infrastructure breaches in the latest cyber updates.

A stranger has been reading Salesforce and ServiceNow portals worldwide for 17 months

Security researchers have identified a campaign dubbed City-Forum, linked to a domain associated with N-able’s N-central software, as attackers continue to exploit the CVE-2026-18577 vulnerability. The breach involved unauthorized access to customer data through misconfigured portals, with the threat actor maintaining persistence for over a year and a half. N-able has since released a second security hotfix to mitigate ongoing attacks targeting its monitoring and management solution.

GitHub Dependabot malware alerts now cover eight ecosystems

The tool, which previously only monitored npm packages, now expands to include PyPI, Maven, RubyGems, NuGet, Go, crates.io, PHP Composer, and others. This update follows reports of malicious packages in these ecosystems, with Dependabot analyzing over 30 million repositories to detect threats. The expansion underscores the growing complexity of software supply chain risks.

Researchers at Nanyang Technological University deployed AI agents to analyze 4G and 5G network software

Uncovering 84 previously unknown vulnerabilities, 83 of which were confirmed by developers, with 81 receiving CVE identifiers. The findings highlight the challenges of securing next-generation telecommunications infrastructure.

Post-quantum cryptography migration faces hurdles as organizations struggle with legacy key management

A study by Quantus revealed that 98% of cloud environments suffer from misconfigurations, including unrotated keys and exposed services. The report emphasized the need for automated inventory systems to track cryptographic assets.

Zero-day vulnerability in Metabase exploited to access customer data at Framework

Attackers obtained names, addresses, phone numbers, and login IP addresses, though financial information remained secure. The breach prompted the company to issue notifications to affected users.

Microsoft addressed 400+ vulnerabilities in its August 2026 Patch Tuesday update

Including one actively exploited zero-day (CVE-2026-68820). The company also patched a high-severity Cisco firewall vulnerability (CVE-2026-20349), which was added to CISA’s Known Exploited Vulnerabilities catalog. Federal agencies are required to remediate the flaw by August 14, 2026.

Novel attack vector compromised a Polish combined heat and power plant

Attackers accessed an operational technology network via a private APN. CERT Polska identified the method as a first-of-its-kind breach, raising concerns about the security of critical infrastructure.

Blue Report 2026 reveals enterprise defenses improved against high-profile attacks

Organizations are better at blocking loud intrusions but struggle to detect low-and-slow breaches, according to Picus Labs. Corporate investigations often fail due to poor initial response protocols.

EU’s AI Act, enforced from August 2, 2026, introduces strict rules for AI systems

The legislation aims to balance innovation with safety, requiring transparency and risk assessments for high-impact applications.

Chainloop provides secure evidence storage for software supply chains

It integrates with CI/CD pipelines to record build artifacts and verify their integrity through signed attestations.

Microsoft Entra ID simplifies multi-factor authentication for Windows Hello and macOS PSSO users

The change, rolling out in October 2026, removes an additional MFA step, improving user experience without compromising security.

Data breach at CEVA Logistics exposed customer names, addresses, and order details

Affected users in Europe received notifications after reports surfaced on social media.

GPT-5.6-Cyber reduces refusal rates for high-risk cybersecurity tasks

Available through Daybreak Red, it is designed to identify zero-day vulnerabilities and construct exploit chains.

Ransomware attacks on industrial organizations rose 12% in Q2 2026

Dragos noted that disrupting IT systems can halt production even without direct access to industrial control systems.

Malicious SIM cards can hijack smartphones, downgrade connections to 2G, and execute code

Researchers warned that compromised cellular credentials pose significant risks to device security.

$500 crypto scam kit features real-time wallet monitoring and fake balance inflation

Discovered by Malwarebytes, the tool targets users through phishing and social engineering tactics.

Spanish police arrested a suspect in Murcia for using deepfake technology

To bypass identity checks and obtain fraudulent digital signatures.

Lazarus group leveraged fake job offers and a Windows zero-day to target defense sector organizations

Check Point researchers linked the attacks to North Korea’s state-sponsored hackers.

Signal introduced automatic key verification to detect tampering in encrypted chats

The feature enhances user confidence in end-to-end encryption.

153GB data leak from the LiteLLM supply chain attack exposed credentials tied to AWS, Cisco, and Salesforce

Hudson Rock analyzed 433,909 files, including 118,829 CI runner dumps from 2,488 domains.

White House authorized private U.S. companies to conduct offensive cyber operations

Under government oversight, expanding cyber capabilities.

Ukrainian police dismantled 94 fraudulent call centers, seizing $2 million in assets

The operation involved over 400 searches and the confiscation of devices and SIM cards.

Group-IB uncovered WindRelay, Android malware that steals payment card data via NFC

The malware is paired with SpyNote, a remote access trojan.

71% of CISOs spend over 10 hours monthly on board reports

Translating technical findings into business terms. The CISO-Board Communication Gap report highlighted the need for better frameworks and context.

Enpass Password Manager offers encrypted vaults for storing sensitive data

The tool avoids proprietary cloud models, prioritizing user control.

OpenAI restricted access to its Astra model due to potential cybersecurity capabilities

The evaluation found advancements in agentic coding, prompting internal security concerns.

Anthropic made auto mode the default for Claude Code, streamlining AI-assisted coding

Users will receive prompts to confirm the change.

Daybreak Cyber Partner Program allows red teams to use OpenAI’s cyber models

Without direct access, ensuring controlled deployment.

OpenSSH 10.5 addressed a vulnerability that disabled local-only key checks

When the ssh-agent was locked. The update restores security for SSH connections.

AI deployments are straining enterprise security, with 90% of CISOs concerned about unapproved tools

NetFoundry’s survey noted a 14% projected increase in attack surfaces.

PentestGPT, an open-source penetration testing framework, automates recon, exploitation, and reporting

Using large language models. The tool operates without human intervention.

Chrome blocked 7 billion unwanted Android notifications daily through anti-abuse measures

Including revoking permissions for suspicious sites.

Wireshark 4.6.8 patched 28 security flaws, including nine in file parsers

That could be exploited via malicious capture files. The update emphasizes the risks of untrusted data.

Slop or Not, an AI content detector for Apple devices, uses on-device models

To identify synthetic media without requiring an internet connection.

DDoS attacks reached record scales in 2026, with 1 Tbps+ campaigns becoming common

Cloudflare’s report highlighted multi-vector attacks and automated tactics.

17 draft Cyber Resilience Act standards are open for public comment

Requiring connected products in Europe to meet security benchmarks by 2027.

Weak identity and access management (IAM) configurations affect 98% of cloud environments

According to CISA. The agency mandates baseline practices for federal agencies.

AWS Certificate Manager will phase out domain validation for public certificates by 2027

Aligning with industry deadlines.

OpenAI’s GPT-5.6 Sol, in Ultrafast mode, delivers 14× speed improvements for specific workloads

Leveraging Cerebras’ hardware for low-latency inference.


Blog Image

About Author

en_USEnglish