Here are today’s top cybersecurity stories for Monday, August 10, 2026.
Metabase CVSS 10.0 SQLi Zero-Day Exploited in Data Theft Attacks
Metabase confirmed a critical SQL injection zero-day, tracked as GHSA-vwf4-m7j8-wcjf with a CVSS score of 10.0, was exploited in the wild before a patch existed. The flaw lives in the publicly accessible POST /api/session/reset_password endpoint and gives unauthenticated attackers full administrator access to affected instances running versions 0.58 through 0.63. At least two organizations — hardware company Framework and accounting software firm Tally — disclosed data theft incidents linked to this vulnerability, with stolen records including names, addresses, phone numbers, and emails. Metabase Cloud customers received an automatic patch; self-hosted deployments must update immediately. BleepingComputer
N-central Servers Taken Over After Incomplete Patch for CVE-2026-18577
N-able confirmed that attackers are actively taking over N-central RMM servers because the original hotfix for CVE-2026-18577 failed to close all exploitation paths. The authentication bypass lets unauthenticated remote attackers seize administrative control of N-central servers, then pivot into managed endpoints using the platform’s built-in Take Control feature. Post-exploitation, attackers deploy Cloudflare Tunnel (cloudflared) for persistent remote access. S-RM responded to multiple ransomware incidents where vulnerable N-central instances served as the initial access point. Customers must upgrade to the latest version immediately. The Hacker News
FBI, CISA, and NSA Issue Joint Advisory on Gunra Ransomware
Six agencies — the FBI, CISA, NSA, Department of Defense Cyber Crime Center, U.S. Secret Service, and South Korea’s National Police Agency — published advisory AA26-222A warning about Gunra, a double-extortion RaaS group built on leaked Conti1 ransomware source code. Affiliates gain initial access by exploiting Fortinet authentication bypass vulnerabilities CVE-2024-55591 and CVE-2025-24472 in FortiOS and FortiProxy. Targeted sectors include healthcare, financial services, critical manufacturing, transportation, and government. CISA
OpenAI Pauses Astra Model Development Over Critical Cybersecurity Capabilities
OpenAI announced it is pausing certain internal activities related to its unreleased Astra AI model after evaluations found it approaching what the company calls its “critical cybersecurity threshold” — the ability to identify and develop zero-day exploits without human intervention. This is the first public instance of an AI company halting model development due to offensive cybersecurity capability concerns. OpenAI has implemented isolated testing environments, tighter network restrictions, stronger model weight encryption, and sandboxed execution to manage risk while development continues. Bloomberg
LexisNexis Takes Three Services Offline After Third-Party Server Breach
LexisNexis shut down its Diligence, Metabase API, and Newsdesk services after detecting unusual activity on servers hosted and managed by an unnamed third-party vendor. The company engaged a cybersecurity forensics firm and is rebuilding affected systems in a new environment before bringing services back online. No threat actor has claimed responsibility, and the scope of any data exposure has not been disclosed. BleepingComputer
Progress Kemp LoadMaster Added to CISA KEV Catalog After 792 Documented Exploit Attempts
CISA added CVE-2026-8037 — a critical command injection vulnerability in Progress Kemp LoadMaster — to its Known Exploited Vulnerabilities catalog following documentation of 792 exploitation attempts. The CVSS 9.6 flaw allows arbitrary code execution on affected load balancers by unauthenticated remote attackers. Organizations running Kemp LoadMaster should apply the vendor patch immediately and review logs for indicators of compromise. The Hacker News
TrueConf Video Conferencing Servers Backdoored by Head Mare Group
The Head Mare hacktivist group exploited vulnerabilities in unpatched TrueConf video conferencing servers to replace legitimate client installers with trojanized versions that deliver backdoors to users. Affected organizations include those that downloaded TrueConf clients from compromised server instances. Administrators should verify the integrity of their TrueConf installations and apply available server patches without delay. BleepingComputer
North Carolina Ports Cyberattack Contained — Investigation Continues
A cyberattack on August 4 disrupted gate operations at all three North Carolina ports: Wilmington, Morehead City, and Charlotte. Officials report the breach has been contained, though shipping delays remain. The U.S. Coast Guard is coordinating with federal and state partners during the ongoing investigation. No threat actor has claimed responsibility for the attack on the port system, which handles more than 320,000 TEU and over four million tons of cargo annually. CyberScoop
Noma Security Raises $100 Million for AI Security Platform
AI security startup Noma Security raised $100 million to expand its platform protecting large language models and agentic AI systems deployed in production environments. The platform addresses risks including model manipulation, prompt injection, and unauthorized data exfiltration from deployed AI systems. SecurityWeek
Outdated Cybercrime Laws Put Security Researchers at Legal Risk
An analysis from Dark Reading examines how broadly written computer fraud statutes across multiple jurisdictions expose ethical security researchers to prosecution risk, even when conducting authorized penetration tests or responsible vulnerability disclosures. The article calls for updated legal frameworks that distinguish between malicious intrusion and sanctioned security research. Dark Reading
Stay tuned for today’s in-depth analysis posts.






