🔥 Metabase: Unauthenticated SQL Injection to Admin Takeover Analysis
🔴 CVE-2026-72898 & CVE-2026-72899 🔴
🗓️ Publish Date: 10 Aug 2026
ÂLIM rebuilt both, wrote a proof of concept for each, and confirmed it fires on the vulnerable build and stays silent on the patched one.
Metabase has patched CVE-2026-72898 and CVE-2026-72899. Both are unauthenticated SQL injection. Neither one needs a password, a token, or a click.
🔎 Full Technical Analysis and PoCs:
CVE-2026-72898: https://t.co/VwJDS7Ulab
CVE-2026-72899: https://t.co/2fOz7msQ0V
Fixed in 0.58.24, 0.59.21, 0.60.17, 0.61.11, 0.62.9 and 0.63.5.
--
#Metabase #1dayexploit #ALIM #SQLInjection #RedTeam #OffSec #VulnerabilityResearch #CyberSecurity #InfoSec #AppSec #Exploit
🚀 1dayexploit is officially live!! 🎉🎉
Today, we’re excited to open 1dayexploit to the security community.
🌐 https://t.co/pOrVDJIyeK
🦉 Explore ÂLIM: https://t.co/L0yo5w50MN
Built for offensive security researchers, 1dayexploit is a platform focused on high-quality technical research, in-depth CVE analysis, root cause investigations, exploit development, PoCs, and practical security insights.
As part of the platform, we’re also introducing ÂLIM. Our AI-powered research assistant that helps transform CVEs into technical evidence. Rather than simply summarizing vulnerabilities, ÂLIM analyzes root causes, explains the affected code, assists with exploit development, and helps researchers understand the real-world impact of security issues.
This is just the beginning. We’re continuously building new research capabilities, AI-driven workflows, and features to help security researchers move faster and dive deeper into vulnerability research.
We’d love to hear your feedback and suggestions.
✉️ [email protected]
#ALIM #1dayexploit #CyberSecurity #OffensiveSecurity #AppSec #RedTeam #BugBounty #CVE #ExploitDevelopment #VulnerabilityResearch #AI #LLM
NOPcon returns after 6 years. While AI is getting better at finding bugs, we still believe in human curiosity and deep research :) CFP is open, let's submit: https://t.co/oZYPf31VqV
NOPcon is back! Call for Papers is now open. After a long break, we’re opening the doors again to the community.
If you have something cool to share, this is your stage. Submit your work: https://t.co/oZYPf32tgt
#nopcon2026
‼️Tesla was hacked by researchers who chained two vulnerabilities resulting in total control of Tesla's infotainment system
Researchers earned a total of $516,500 after exploiting 37 zero-days on the first day of the Pwn2Own Automotive 2026 competition.
Bu numaradan aranirsaniz acmayin. Acarsaniz da hicbir bilgi paylasmayin. Is bankasi adina aradigini soyleyip kredi karti biglilerinizi ele gecirmeye calisiyor. @BTKbasin@UABakanligi@TRCert@isbankasi
⚠️ Hackers are actively exploiting a Fortinet FortiWeb bug that lets them skip login and make admin accounts.
Fortinet quietly fixed it in v8.0.2 — no CVE, no warning.
If you haven’t patched yet, your device might already be hit.
Learn more here ↓ https://t.co/6MwP7JaUdf
🚨Cyber Espionage Alert‼️
Iran’s MuddyWater Launches Phoenix v4 Backdoor Campaign Against 100+ MEA Government Targets
Iran-linked MuddyWater is conducting a cyberespionage campaign (active since August 19, 2025) targeting 100+ Middle East and Africa government entities using phishing emails with blurred Word docs that require macro activation.
The attack chain installs the Phoenix v4 backdoor via FakeUpdate loader, enabling remote control, persistence, data theft, and command execution. Additional tools include Chromium_Stealer, PDQ RMM, and Action1.
Group-IB attributes the operation to Iran’s MOIS with geopolitical intelligence objectives.
Sector: Gov / Mil / LE
Threat class: Espionage
Status: Confirmed
Source: https://t.co/XkWZdql8HJ
🚨 New Adobe Commerce flaw (CVE-2025-54236, CVSS 9.1) under active attack.
Over 250 exploit attempts in 24 hours—mostly on unpatched Magento sites.
PoC is public. Patch now.
Details → https://t.co/cNYlLIs9xA
🚨 PoC Exploit for 7-Zip Vulnerabilities that Allows Remote Code Execution
Read more: https://t.co/XAQYx6r0Kg
A proof-of-concept exploit for two critical vulnerabilities in the popular file archiver 7-Zip, potentially allowing attackers to execute arbitrary code remotely through malicious ZIP files.
The flaws, tracked as CVE-2025-11001 and CVE-2025-11002, were disclosed by the Zero Day Initiative (ZDI) on October 7, 2025, and stem from improper handling of symbolic links during ZIP extraction on Windows systems.
The core problem lies in 7-Zip's extraction logic, which fails to properly validate symlink targets. When extracting a ZIP containing a Linux symlink pointing to a Windows absolute path like C:\Users, the software misclassifies it as relative due to a flawed absolute path check tailored for Linux or WSL environments.
#cybersecuritynews
⚠️ F5 Breached - Hackers Stole BIG-IP Source Code and Undisclosed Vulnerabilities Data
Read more: https://t.co/3wkIsyG1Zm
F5, a leading provider of application security and delivery solutions, disclosed a major security incident.
The company revealed that a sophisticated nation-state threat actor had gained long-term access to internal systems, exfiltrating sensitive files including BIG-IP source code and details on undisclosed vulnerabilities.
The threat actor downloaded files containing proprietary source code for its flagship BIG-IP software, which powers load balancing and security for millions of enterprise applications worldwide.
#cybersecuirtynews #vulnerability
🚨 Windows Remote Desktop Client Vulnerability Let Attackers Execute Remote Code
Read more: https://t.co/nf7cFUojXj
To Get Daily Security Updates, add Cyber Security News ® as your preferred source on Google -> https://t.co/cDaMGJSfyh
#cybersecuritynews
⚠️ Heads-up!
SAP just re-patched a critical CVSS 10.0 flaw (CVE-2025-42944) in NetWeaver AS Java — a deserialization bug that lets attackers execute commands without authentication.
Apply. The. Fix. → https://t.co/8xfoP2ROOI
🚨 FortiOS CLI Command Bypass Vulnerability Let Attacker Execute System Commands
Read more: https://t.co/qQ06CE5ZM1
Fortinet disclosed a high-severity vulnerability in its FortiOS operating system on October 14, 2025, that could enable local authenticated attackers to execute arbitrary system commands.
Tracked as CVE-2025-58325, the flaw stems from an incorrect provision of specified functionality (CWE-684) in the CLI component, potentially leading to privilege escalation.
This could result in full control over the device, data exfiltration, or further network compromise. No remote exploitation is possible, but the low attack complexity and high impact make it a prime target for insiders or compromised accounts.
To Get Daily Security Updates, add Cyber Security News ® as your preferred source on Google -> https://t.co/N1wthFiEi3
#cybersecuritynews
🚨LockBit 5.0 Has Arrived: Targeting Windows, Linux, and ESXi
A new version of the LockBit ransomware, LockBit 5.0, has been discovered targeting Windows, Linux, and VMware ESXi systems.
Trend Micro analyzed samples of this variant, which continues the Ransomware-as-a-Service (RaaS) model. LockBit 5.0 is capable of disabling security tools, encrypting data quickly, and spreading laterally through networks. The variant uses command-line parameters to customize attacks and supports multiple CPU architectures (e.g., ARM, MIPS, x86, x64). The Linux and ESXi versions include shell scripts that stop virtual machines to enable encryption.
The malware uses legitimate tools, like AnyDesk, Advanced IP Scanner, and netscan, to conduct reconnaissance and maintain persistence. While the exact number of victims or ransom demands was not disclosed, LockBit 5.0’s technical sophistication suggests it is being actively deployed in ongoing campaigns.
Source:https://t.co/hsoelVn9LG