SECURITYINTEL DAILY BRIEF ■ ThreatIntel BriefSunday, August 09, 2026 INTEL CONFIDENCE 100% | THREAT LEVEL CRITICAL |
|
THREAT OF THE DAY Metabase Zero-Day Exploited in the Wild | CRITICAL |
|
5 C2 IPs | 127 OTX IOCs | 7 ARTICLES |
|
■ ANALYST TLDR Active exploitation of a maximum-severity zero-day vulnerability in Metabase and critical flaws in N-able N-central RMM software present immediate threats to enterprise environments and managed service providers. Concurrently, the Head Mare hacktivist group is actively trojanizing TrueConf installers, while newly discovered CSS injection techniques in webmail clients and prompt injection vulnerabilities in Atlassian's Rovo AI expose sensitive corporate data to unauthorized exfiltration. |
|
■ CRITICAL STORIES Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication A CVSS 10.0 zero-day vulnerability in Metabase business intelligence software is being actively exploited in the wild, granting attackers unauthenticated administrative access to sensitive corporate databases. |
N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist Threat actors are actively exploiting a critical vulnerability in N-able N-central RMM software, allowing them to compromise downstream managed systems and establish long-term persistence. |
Hackers breach TrueConf to trojanize client installers with backdoors The Head Mare hacktivist group compromised TrueConf video conferencing servers to replace legitimate client installers with backdoored versions, executing a highly effective software supply chain attack. |
Critical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise Data The RovoBlast prompt injection technique allows attackers to trick Atlassian's Rovo AI assistant into exfiltrating Jira, Confluence, and SharePoint data to external attacker-controlled servers. |
|
■ CVEs IDENTIFIED [CVE-TBD] Metabase (Authentication Bypass) Metabase — Unauthenticated administrative access and full data compromise |
[CVE-TBD] N-able N-central (RMM Flaw) N-able N-central — Remote monitoring and management compromise allowing persistent access to managed systems |
[CVE-TBD] Progress Kemp LoadMaster (Command Injection) Progress Kemp LoadMaster — Remote command execution leading to full system takeover (Active KEV exploitation) |
[CVE-TBD] Atlassian Rovo (Prompt Injection) Atlassian Rovo — Prompt injection leading to unauthorized data exfiltration of Jira, Confluence, and SharePoint data |
|
■ THREAT ACTORS Head Mare | Hacktivist Group |
Exploiting unpatched TrueConf servers to distribute trojanized client installers containing backdoors. |
Unknown Threat Actors | Cybercriminals / APT |
Actively exploiting a Metabase zero-day vulnerability for unauthorized administrative access. |
Unknown Threat Actors | Cybercriminals / APT |
Exploiting N-able N-central RMM vulnerabilities to gain persistent access to managed downstream systems. |
|
|
|
■ ATT&CK TTPs | T1195.002 | | Compromise Software Supply Chain | Head Mare trojanized TrueConf client installers on compromised servers. |
| T1190 | | Exploit Public-Facing Application | Exploitation of Metabase zero-day, N-able N-central, TrueConf, and Progress Kemp LoadMaster. |
| T1567 | | Exfiltration Over Web Service | Atlassian Rovo manipulated to exfiltrate Jira/Confluence data to external attacker servers. |
| T1204.002 | | User Execution: Malicious Link | RovoBlast attack requiring "one-click" user interaction to trigger prompt injection. |
| T1059 | | Command and Scripting Interpreter | Used in webmail CSS injection attacks to escape message boundaries and steal credentials. |
| T1078 | | Valid Accounts | Attackers obtaining administrative access via Metabase zero-day and N-central exploitation. |
|
■ PATCH PRIORITY Metabase — Zero-day CVSS 10.0 authentication bypass actively exploited in the wild — THN |
N-able N-central — Active exploitation leading to persistent access on managed downstream systems — THN |
Progress Kemp LoadMaster — Added to CISA KEV following hundreds of active exploit attempts — THN |
TrueConf Server — Unpatched servers exploited by Head Mare to distribute trojanized installers — BC |
|
|
|
■ RECOMMENDED ACTIONS TODAY | 1 | [P1] Patch the Metabase zero-day vulnerability ([CVE-TBD] Metabase) immediately to prevent unauthorized administrative access. |
| 2 | [P1] Apply N-able N-central Hotfix 2 ([CVE-TBD] N-able N-central) immediately to block active exploitation and persistent access on managed systems. |
| 3 | [P1] Apply security patches for Progress Kemp LoadMaster ([CVE-TBD] Progress Kemp LoadMaster) to mitigate active exploitation tracked in CISA KEV. |
| 4 | [P2] Update TrueConf Server ([CVE-TBD] TrueConf Server) to the latest secure version and verify the integrity of client installers to prevent supply chain trojanization. |
| 5 | [P2] Implement strict input validation and boundary controls on webmail platforms (Outlook, Gmail, Proton Mail) to mitigate CSS injection attacks. |
|
|
|
C2 IP BLOCKLIST · AbuseCH Feodo · Showing 5 of 5 IP ADDRESS 162.243.103.246 | PORT 8080 | STATUS OFFLINE | MALWARE Emotet | COUNTRY US |
IP ADDRESS 50.16.16.211 | PORT 443 | STATUS ONLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 34.204.119.63 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 178.62.3.223 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY GB |
IP ADDRESS 27.133.154.218 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY JP |
|
FULL IOC EXPORT — GOOGLE SHEET All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs Updated daily · Export as CSV to import directly into your tools ■ Open Full IOC Sheet → |
|
IOC SOURCES: AbuseCH Feodo · AlienVault OTX NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB |