Daily Security Intel

Archives
Log in
Subscribe
August 8, 2026

[SecurityIntel] 08 Aug | Metabase SQLi Zero-Day Exploited in Data Theft

SECURITYINTEL DAILY BRIEF

■ ThreatIntel Brief

Saturday, August 08, 2026

INTEL CONFIDENCE  100%

THREAT LEVEL

CRITICAL

THREAT OF THE DAY

Metabase SQLi Zero-Day Exploited in Data Theft

CRITICAL

5

C2 IPs

80

OTX IOCs

32

ARTICLES

■ ANALYST TLDR

Today's threat landscape is highlighted by the active exploitation of a critical Metabase SQL injection zero-day vulnerability targeting customer data, alongside persistent voice phishing (vishing) campaigns by threat group UNC6671 targeting enterprise SaaS environments. Additionally, critical updates have been released to address severe vulnerabilities in WordPress, Google Chrome, and the Linux Kernel's SCTP networking code, the latter of which allows container escapes.

■ CRITICAL STORIES

CRITICAL#1

Metabase SQLi zero-day exploited in customer data-theft attacks

Threat actors are actively exploiting a critical SQL injection zero-day vulnerability in Metabase to breach customer instances and steal sensitive data, impacting organizations like Framework and Tally.

CRITICAL#2

New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP

A newly disclosed pre-authentication reflected XSS vulnerability in the WordPress login screen affects all versions and can be chained to achieve full remote PHP code execution on the host.

HIGH#3

UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data

The extortion group UNC6671 (rebranding under BlackFile, Redact, Pink, Helix, and Falcon) is targeting enterprise employees' personal phones via voice phishing to bypass MFA and compromise corporate SaaS environments.

HIGH#4

North Carolina Ports confirms cyberattack disrupting operations

A cyberattack has disrupted IT systems and slowed physical operations at major North Carolina ports, highlighting the persistent threat of cyber incidents to critical maritime infrastructure.

■ CVEs IDENTIFIED

[CVE-TBD]

Metabase — SQL Injection leading to unauthorized customer data theft

Critical

[CVE-TBD]

WordPress CMS — Pre-authentication reflected XSS leading to PHP code execution

Critical

[CVE-TBD]

Linux Kernel (SCTP) — Use-after-free bug allowing local root privilege escalation and container escape

High

[CVE-TBD]

Bendix EC80 Brake Controller — Remote code execution and denial-of-service vulnerabilities

Critical

■ THREAT ACTORS

UNC6671

Extortion Group

Targeting personal phones of enterprise employees via vishing to steal SaaS data; also operates as BlackFile, Redact, Pink, Helix, and Falcon.

Irregular

AI Hacking Group

Conducting ongoing security investigations and hacking incidents targeting Anthropic, OpenAI, and Meta AI models.

Scammers

Cybercriminals

Deploying AI chat bots to send automated friend requests on Riot Games' League of Legends platform.

■ ATT&CK TTPs

T1190
Exploit Public-Facing Application | Metabase SQL injection zero-day exploited for data theft.
T1566.004
Phishing: Voice | UNC6671 targeting employee personal phones to compromise SaaS credentials.
T1566.001
Phishing: Spearphishing Attachment/Link | ClickFix attacks delivering macOS infostealers; AitM phishing targeting Microsoft 365.
T1195.002
Supply Chain Compromise: Malicious Software | Nearly 800 malicious npm packages delivering cross-platform RATs and infostealers.
T1611
Escape to Host | Linux SCTP use-after-free bug used to escape containers to the host.
T1539
Steal Web Session Cookie | AitM phishing campaigns hijacking Microsoft 365 accounts to collect payroll and finance emails.

■ PATCH PRIORITY

[P1 PATCH NOW]≤24h

Metabase — SQL injection zero-day actively exploited in the wild for data theft — [BC]

[P1 PATCH NOW]≤24h

WordPress — Pre-auth XSS leading to remote PHP code execution — [THN]

[P1 PATCH NOW]≤24h

Linux Kernel — SCTP use-after-free bug allows local root and container escape — [THN]

[P1 PATCH NOW]≤24h

Google Chrome — Over two dozen critical use-after-free and memory safety bugs patched in version 151 — [SW]

■ RECOMMENDED ACTIONS TODAY

1[P1] Apply urgent updates to Metabase instances immediately to remediate the actively exploited [CVE-TBD] SQL injection zero-day.
2[P1] Patch all WordPress installations immediately to resolve the pre-authentication reflected XSS vulnerability ([CVE-TBD]) that leads to PHP code execution.
3[P1] Update Linux Kernel deployments to resolve the 18-year-old SCTP use-after-free container escape vulnerability ([CVE-TBD]).
4[P1] Upgrade Google Chrome to version 151 or later to mitigate critical memory safety and use-after-free vulnerabilities.
5[P2] Implement strict vishing awareness training and robust MFA policies to defend against UNC6671 targeting corporate SaaS environments.
LIVE IOC FEED

C2 IP BLOCKLIST  ·  AbuseCH Feodo  ·  Showing 5 of 5

IP ADDRESS

162.243.103.246

PORT

8080

STATUS

OFFLINE

MALWARE

Emotet

COUNTRY

US

IP ADDRESS

50.16.16.211

PORT

443

STATUS

ONLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

34.204.119.63

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

178.62.3.223

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

GB

IP ADDRESS

27.133.154.218

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

JP

FULL IOC EXPORT — GOOGLE SHEET

All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs
Updated daily · Export as CSV to import directly into your tools

■  Open Full IOC Sheet  →

IOC SOURCES: AbuseCH Feodo  ·  AlienVault OTX
NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB

Don't miss what's next. Subscribe to Daily Security Intel:
← Newer [SecurityIntel] 09 Aug | Metabase Zero-Day Exploited in the Wild Older → [SecurityIntel] 07 Aug | Active Exploitation of Critical JetBrains TeamCity Vulnerability
Powered by Buttondown, the easiest way to start and grow your newsletter.