Daily Security Intel

Archives
Log in
Subscribe
August 9, 2026

[SecurityIntel] 09 Aug | Metabase Zero-Day Exploited in the Wild

SECURITYINTEL DAILY BRIEF

■ ThreatIntel Brief

Sunday, August 09, 2026

INTEL CONFIDENCE  100%

THREAT LEVEL

CRITICAL

THREAT OF THE DAY

Metabase Zero-Day Exploited in the Wild

CRITICAL

5

C2 IPs

127

OTX IOCs

7

ARTICLES

■ ANALYST TLDR

Active exploitation of a maximum-severity zero-day vulnerability in Metabase and critical flaws in N-able N-central RMM software present immediate threats to enterprise environments and managed service providers. Concurrently, the Head Mare hacktivist group is actively trojanizing TrueConf installers, while newly discovered CSS injection techniques in webmail clients and prompt injection vulnerabilities in Atlassian's Rovo AI expose sensitive corporate data to unauthorized exfiltration.

■ CRITICAL STORIES

CRITICAL#1

Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication

A CVSS 10.0 zero-day vulnerability in Metabase business intelligence software is being actively exploited in the wild, granting attackers unauthenticated administrative access to sensitive corporate databases.

CRITICAL#2

N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist

Threat actors are actively exploiting a critical vulnerability in N-able N-central RMM software, allowing them to compromise downstream managed systems and establish long-term persistence.

HIGH#3

Hackers breach TrueConf to trojanize client installers with backdoors

The Head Mare hacktivist group compromised TrueConf video conferencing servers to replace legitimate client installers with backdoored versions, executing a highly effective software supply chain attack.

CRITICAL#4

Critical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise Data

The RovoBlast prompt injection technique allows attackers to trick Atlassian's Rovo AI assistant into exfiltrating Jira, Confluence, and SharePoint data to external attacker-controlled servers.

■ CVEs IDENTIFIED

[CVE-TBD] Metabase (Authentication Bypass)

Metabase — Unauthenticated administrative access and full data compromise

Critical (CVSS 10.0)

[CVE-TBD] N-able N-central (RMM Flaw)

N-able N-central — Remote monitoring and management compromise allowing persistent access to managed systems

Critical

[CVE-TBD] Progress Kemp LoadMaster (Command Injection)

Progress Kemp LoadMaster — Remote command execution leading to full system takeover (Active KEV exploitation)

Critical

[CVE-TBD] Atlassian Rovo (Prompt Injection)

Atlassian Rovo — Prompt injection leading to unauthorized data exfiltration of Jira, Confluence, and SharePoint data

High

■ THREAT ACTORS

Head Mare

Hacktivist Group

Exploiting unpatched TrueConf servers to distribute trojanized client installers containing backdoors.

Unknown Threat Actors

Cybercriminals / APT

Actively exploiting a Metabase zero-day vulnerability for unauthorized administrative access.

Unknown Threat Actors

Cybercriminals / APT

Exploiting N-able N-central RMM vulnerabilities to gain persistent access to managed downstream systems.

■ ATT&CK TTPs

T1195.002
Compromise Software Supply Chain | Head Mare trojanized TrueConf client installers on compromised servers.
T1190
Exploit Public-Facing Application | Exploitation of Metabase zero-day, N-able N-central, TrueConf, and Progress Kemp LoadMaster.
T1567
Exfiltration Over Web Service | Atlassian Rovo manipulated to exfiltrate Jira/Confluence data to external attacker servers.
T1204.002
User Execution: Malicious Link | RovoBlast attack requiring "one-click" user interaction to trigger prompt injection.
T1059
Command and Scripting Interpreter | Used in webmail CSS injection attacks to escape message boundaries and steal credentials.
T1078
Valid Accounts | Attackers obtaining administrative access via Metabase zero-day and N-central exploitation.

■ PATCH PRIORITY

[P1 PATCH NOW]≤24h

Metabase — Zero-day CVSS 10.0 authentication bypass actively exploited in the wild — THN

[P1 PATCH NOW]≤24h

N-able N-central — Active exploitation leading to persistent access on managed downstream systems — THN

[P1 PATCH NOW]≤24h

Progress Kemp LoadMaster — Added to CISA KEV following hundreds of active exploit attempts — THN

[P2 PATCH NOW]≤72h

TrueConf Server — Unpatched servers exploited by Head Mare to distribute trojanized installers — BC

■ RECOMMENDED ACTIONS TODAY

1[P1] Patch the Metabase zero-day vulnerability ([CVE-TBD] Metabase) immediately to prevent unauthorized administrative access.
2[P1] Apply N-able N-central Hotfix 2 ([CVE-TBD] N-able N-central) immediately to block active exploitation and persistent access on managed systems.
3[P1] Apply security patches for Progress Kemp LoadMaster ([CVE-TBD] Progress Kemp LoadMaster) to mitigate active exploitation tracked in CISA KEV.
4[P2] Update TrueConf Server ([CVE-TBD] TrueConf Server) to the latest secure version and verify the integrity of client installers to prevent supply chain trojanization.
5[P2] Implement strict input validation and boundary controls on webmail platforms (Outlook, Gmail, Proton Mail) to mitigate CSS injection attacks.
LIVE IOC FEED

C2 IP BLOCKLIST  ·  AbuseCH Feodo  ·  Showing 5 of 5

IP ADDRESS

162.243.103.246

PORT

8080

STATUS

OFFLINE

MALWARE

Emotet

COUNTRY

US

IP ADDRESS

50.16.16.211

PORT

443

STATUS

ONLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

34.204.119.63

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

178.62.3.223

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

GB

IP ADDRESS

27.133.154.218

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

JP

FULL IOC EXPORT — GOOGLE SHEET

All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs
Updated daily · Export as CSV to import directly into your tools

■  Open Full IOC Sheet  →

IOC SOURCES: AbuseCH Feodo  ·  AlienVault OTX
NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB

Don't miss what's next. Subscribe to Daily Security Intel:
← Newer [SecurityIntel] 10 Aug | Active Scanning Targets Ivanti Connect Secure Gateways Older → [SecurityIntel] 08 Aug | Metabase SQLi Zero-Day Exploited in Data Theft
Powered by Buttondown, the easiest way to start and grow your newsletter.