TL;DR
Atlassian Rovo AI assistant can be tricked into exfiltrating Jira and Confluence data via attacker-controlled instructions; two attack routes exist, one confirmed closed. Metabase zero-day (no CVE) with CVSS 10.0 is actively exploited for unauthenticated admin access. Progress LoadMaster command injection (CVE-2026-8037) added to CISA KEV after 792 confirmed exploit attempts.
Executive Summary
- Atlassian Rovo AI vulnerability allows attacker-controlled instructions to harvest and exfiltrate Confluence and Jira data accessible to authenticated users; two independent exploit routes identified, one remediated.
- Metabase maximum-severity zero-day (CVSS 10.0, no CVE assigned) enables unauthenticated remote admin access and is actively exploited in the wild; Framework and Tally confirmed as breach victims.
- Progress Kemp LoadMaster command injection flaw (CVE-2026-8037) escalated to CISA Known Exploited Vulnerabilities (KEV) catalog following 792 reported exploit attempts in active campaigns.
- N-able N-central RMM hotfix deployments ongoing as attackers persist on managed systems following recent vulnerability disclosure.
- CSS-based webmail attacks can break message boundaries to capture passwords and tokens across Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail.
Top Threats Today
1. Atlassian Rovo Data Exfiltration via Prompt Injection
Severity: HIGH Affected: Technology
Atlassian's Rovo AI assistant can be manipulated through attacker-controlled instructions to collect and send Jira, Confluence, and SharePoint data to external servers ⚠ [1][2]. Security researchers at two independent firms discovered the vulnerability through different attack vectors; only one confirmed exploit route has been closed [1]. The flaw allows an attacker to exfiltrate any data accessible to a signed-in user without requiring additional authentication steps [1][2].
Sources:[1] The Hacker News[2] SecurityWeek
Recommended Action
- Audit Rovo usage logs and data access patterns for signs of suspicious instruction injection or exfiltration.
- Apply all available Atlassian security patches and monitor official advisories for confirmation that both attack routes are remediated.
- Consider restricting Rovo access to non-sensitive data environments until full patch confirmation.
2. Metabase Unauthenticated Admin Access Zero-Day (Active Exploitation)
Severity: CRITICAL Affected: Technology
A maximum-severity Metabase zero-day flaw (CVSS 10.0, no CVE identifier) allows unauthenticated remote attackers to gain full admin access to Metabase instances [1]. The vulnerability is actively exploited in the wild and has been confirmed in data-theft breaches affecting Framework and Tally, as well as unnamed customer instances [1][2]. Metabase has warned of the exploit activity but a CVE identifier has not yet been assigned [1].
Sources:[1] The Hacker News[2] BleepingComputer
Recommended Action
- Immediately identify all Metabase instances in your environment and verify current version against Metabase's security advisories.
- Apply security patches from Metabase as soon as they become available; monitor official vendor communications.
- Implement network segmentation to restrict Metabase admin interface access to trusted IP ranges and require VPN for remote access.
- Review audit logs for suspicious unauthenticated admin session activity dating back to when instances were deployed.
3. Progress LoadMaster Command Injection on CISA KEV (CVE-2026-8037)
Severity: CRITICAL Affected: Technology
CISA added CVE-2026-8037, a critical command injection flaw in Progress Kemp LoadMaster, to its Known Exploited Vulnerabilities catalog on August 7, 2026 [1]. The vulnerability allows unauthenticated attackers to execute arbitrary commands on LoadMaster appliances via unsanitized input in multiple command endpoints; researchers have documented 792 confirmed exploit attempts in active campaigns ⚠[1]. Federal remediation deadline is August 10, 2026 [1].
Sources:[1] The Hacker News
Recommended Action
- Prioritize patching all Progress LoadMaster appliances immediately given the CISA KEV designation and federal remediation deadline.
- Apply vendor security updates and monitor for signs of unauthorized command execution in LoadMaster logs.
- Implement network-level access controls to restrict LoadMaster admin interfaces to internal networks only.
4. Webmail CSS Escape Attacks Targeting Authentication Credentials
Severity: HIGH Affected: Technology
New CSS-based attack techniques can break webmail message boundaries to capture passwords, authentication tokens, and enable account takeover across multiple providers including Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail [1]. Content embedded in email messages can escape its sandbox and interfere directly with the webmail interface, allowing attackers to inject credential-harvesting overlays or token theft mechanisms [1].
Sources:[1] The Hacker News
Recommended Action
- Enable and enforce multi-factor authentication (MFA) on all email accounts to reduce credential-theft impact.
- Review webmail provider security advisories for CSS sandbox isolation patches and apply when available.
- Train users to avoid clicking suspicious links or downloading unexpected attachments in email.
5. N-able N-central Persistence on Managed Systems (Post-Disclosure)
Severity: HIGH Affected: Technology
N-able has released hotfix 2 for N-central RMM software in response to ongoing exploitation of a recently disclosed vulnerability; attackers have successfully reached and persisted on customer-managed systems despite the disclosure [1]. The company is proactively expanding threat detection protections while investigation into the breach scope remains ongoing [1].
Sources:[1] The Hacker News
Recommended Action
- Deploy N-able N-central hotfix 2 immediately to all RMM instances.
- Conduct forensic review of managed systems for signs of attacker persistence, lateral movement, or data exfiltration since the vulnerability disclosure date.
- Implement endpoint detection and response (EDR) monitoring on all systems managed through N-central to catch post-exploitation activity.
Today’s Action Checklist
- ☐ CRITICAL: Patch Progress LoadMaster (CVE-2026-8037) before August 10 federal remediation deadline; verify with network scan.
- ☐ CRITICAL: Inventory Metabase instances; isolate admin interfaces and await vendor patch for CVSS 10.0 zero-day.
- ☐ URGENT: Review Atlassian Rovo access logs and apply available security patches; disable Rovo on sensitive data until both exploit routes confirmed closed.
- ☐ URGENT: Deploy N-able N-central hotfix 2 and conduct system forensics for persistence indicators.
- ☐ Enable or audit MFA deployment across all email providers; review webmail vendor advisories for CSS sandbox patches.