SECURITYINTEL DAILY BRIEF ■ ThreatIntel BriefSaturday, August 08, 2026 INTEL CONFIDENCE 100% | THREAT LEVEL CRITICAL |
|
THREAT OF THE DAY Metabase SQLi Zero-Day Exploited in Data Theft | CRITICAL |
|
5 C2 IPs | 80 OTX IOCs | 32 ARTICLES |
|
■ ANALYST TLDR Today's threat landscape is highlighted by the active exploitation of a critical Metabase SQL injection zero-day vulnerability targeting customer data, alongside persistent voice phishing (vishing) campaigns by threat group UNC6671 targeting enterprise SaaS environments. Additionally, critical updates have been released to address severe vulnerabilities in WordPress, Google Chrome, and the Linux Kernel's SCTP networking code, the latter of which allows container escapes. |
|
■ CRITICAL STORIES Metabase SQLi zero-day exploited in customer data-theft attacks Threat actors are actively exploiting a critical SQL injection zero-day vulnerability in Metabase to breach customer instances and steal sensitive data, impacting organizations like Framework and Tally. |
New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP A newly disclosed pre-authentication reflected XSS vulnerability in the WordPress login screen affects all versions and can be chained to achieve full remote PHP code execution on the host. |
UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data The extortion group UNC6671 (rebranding under BlackFile, Redact, Pink, Helix, and Falcon) is targeting enterprise employees' personal phones via voice phishing to bypass MFA and compromise corporate SaaS environments. |
North Carolina Ports confirms cyberattack disrupting operations A cyberattack has disrupted IT systems and slowed physical operations at major North Carolina ports, highlighting the persistent threat of cyber incidents to critical maritime infrastructure. |
|
■ CVEs IDENTIFIED [CVE-TBD] Metabase — SQL Injection leading to unauthorized customer data theft |
[CVE-TBD] WordPress CMS — Pre-authentication reflected XSS leading to PHP code execution |
[CVE-TBD] Linux Kernel (SCTP) — Use-after-free bug allowing local root privilege escalation and container escape |
[CVE-TBD] Bendix EC80 Brake Controller — Remote code execution and denial-of-service vulnerabilities |
|
■ THREAT ACTORS Targeting personal phones of enterprise employees via vishing to steal SaaS data; also operates as BlackFile, Redact, Pink, Helix, and Falcon. |
Irregular | AI Hacking Group |
Conducting ongoing security investigations and hacking incidents targeting Anthropic, OpenAI, and Meta AI models. |
Deploying AI chat bots to send automated friend requests on Riot Games' League of Legends platform. |
|
|
|
■ ATT&CK TTPs | T1190 | | Exploit Public-Facing Application | Metabase SQL injection zero-day exploited for data theft. |
| T1566.004 | | Phishing: Voice | UNC6671 targeting employee personal phones to compromise SaaS credentials. |
| T1566.001 | | Phishing: Spearphishing Attachment/Link | ClickFix attacks delivering macOS infostealers; AitM phishing targeting Microsoft 365. |
| T1195.002 | | Supply Chain Compromise: Malicious Software | Nearly 800 malicious npm packages delivering cross-platform RATs and infostealers. |
| T1611 | | Escape to Host | Linux SCTP use-after-free bug used to escape containers to the host. |
| T1539 | | Steal Web Session Cookie | AitM phishing campaigns hijacking Microsoft 365 accounts to collect payroll and finance emails. |
|
■ PATCH PRIORITY Metabase — SQL injection zero-day actively exploited in the wild for data theft — [BC] |
WordPress — Pre-auth XSS leading to remote PHP code execution — [THN] |
Linux Kernel — SCTP use-after-free bug allows local root and container escape — [THN] |
Google Chrome — Over two dozen critical use-after-free and memory safety bugs patched in version 151 — [SW] |
|
|
|
■ RECOMMENDED ACTIONS TODAY | 1 | [P1] Apply urgent updates to Metabase instances immediately to remediate the actively exploited [CVE-TBD] SQL injection zero-day. |
| 2 | [P1] Patch all WordPress installations immediately to resolve the pre-authentication reflected XSS vulnerability ([CVE-TBD]) that leads to PHP code execution. |
| 3 | [P1] Update Linux Kernel deployments to resolve the 18-year-old SCTP use-after-free container escape vulnerability ([CVE-TBD]). |
| 4 | [P1] Upgrade Google Chrome to version 151 or later to mitigate critical memory safety and use-after-free vulnerabilities. |
| 5 | [P2] Implement strict vishing awareness training and robust MFA policies to defend against UNC6671 targeting corporate SaaS environments. |
|
|
|
C2 IP BLOCKLIST · AbuseCH Feodo · Showing 5 of 5 IP ADDRESS 162.243.103.246 | PORT 8080 | STATUS OFFLINE | MALWARE Emotet | COUNTRY US |
IP ADDRESS 50.16.16.211 | PORT 443 | STATUS ONLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 34.204.119.63 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 178.62.3.223 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY GB |
IP ADDRESS 27.133.154.218 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY JP |
|
FULL IOC EXPORT — GOOGLE SHEET All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs Updated daily · Export as CSV to import directly into your tools ■ Open Full IOC Sheet → |
|
IOC SOURCES: AbuseCH Feodo · AlienVault OTX NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB |