New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens
Read More New research shows content inside an email can escape its message boundary and interfere with the webmail interface. Across attack chains spanning Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail, the techniques can capture passwords, take...
Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication
Read More Metabase has warned that a maximum-severity security flaw impacting its business intelligence and data visualization software package has been exploited in the wild as a zero-day. The vulnerability (CVSS score: 10.0), which does not carry a CVE identifier,...
N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist
Read More N-able has released a fresh round of hotfixes for N‑central as part of its investigation into ongoing exploitation of a recently disclosed security flaw in the Remote Monitoring and Management (RMM) product. “We are proactively expanding protections in...