← All issues
cybersecurityCyberBubbleAI security

Your AI Assistant Can Be Hijacked — Plus Two Critical Bugs Under Active Attack

🌐  World Intel
USA: North Carolina Ports Hit by Cyberattack

The North Carolina Ports Authority confirmed a cyberattack disrupted IT systems at three ports — Port of Wilmington, Port of Morehead City, and Charlotte Inland Port. Operations slowed while staff worked to contain the damage. No group has claimed responsibility yet, but the incident is a reminder that physical infrastructure increasingly depends on digital systems that can be knocked offline.

↗ BleepingComputer
Switzerland: Federal SharePoint Servers Breached, 200 Accounts Compromised

Switzerland's federal IT office says attackers exploited vulnerabilities in its Microsoft SharePoint servers and got into roughly 200 government accounts. The breach affects the country's central administration. Swiss officials are investigating the extent of what was accessed or stolen.

↗ BleepingComputer
USA: Healthcare Data Breach Hits 3.8 Million People

Healthcare software company Unlimited Technology Systems disclosed that a breach from October 2025 affected more than 3.8 million people. The company only publicly reported it now. If you use a healthcare provider that relies on their software, your personal or medical data may be among the records exposed — watch for any unusual mail or account activity tied to your health information.

↗ BleepingComputer
⚔️  Active Attacks
Metabase Zero-Day: Attackers Getting Full Admin Access With No Password

A zero-day flaw in Metabase — software that companies use to build dashboards and reports from their databases — is being actively exploited right now. The bug scores a perfect 10 out of 10 on the severity scale, meaning it's as bad as it gets. An attacker with no account and no password can send a specially crafted request to a Metabase server, inject their own SQL commands, and instantly gain full administrator access. From there they can read, steal, or delete any data connected to that Metabase instance. Two companies — Framework and Tally — are confirmed victims of data theft. Metabase Cloud has already been patched automatically; self-hosted users are still at risk unless they update.

🛡 What to do: If your organization runs a self-hosted Metabase instance, apply the security patch Metabase released immediately — do not wait. Check with your IT team today.
Phishing Emails Are Spoofing RingCentral to Steal Microsoft 365 Logins

A phishing service is sending fake emails that look like they come from RingCentral, the popular business phone and video platform. The goal is to get recipients to click a link and enter their Microsoft 365 credentials on a fake login page. Criminals then collect those usernames and passwords to break into corporate email and files. These emails can look very convincing because they copy real RingCentral branding.

🛡 What to do: Never click a login link in an unexpected email — open your browser and go directly to the site instead. Turn on multi-factor authentication on your Microsoft 365 account so a stolen password alone isn't enough to get in.
🔓  New Vulnerabilities
No CVE Yet Metabase (versions 1.58 and above) CRITICAL 10.0

Any attacker on the internet — no login required — can send a malicious request to a Metabase server, execute database commands, and take full control. They can steal database credentials, read all connected data, and change application settings at will. This is already being actively exploited in real attacks.

Status: Patch available — Metabase Cloud auto-updated; self-hosted users must update manually now.

CVE-2026-8037 Progress Kemp LoadMaster CRITICAL 9.6

Progress Kemp's LoadMaster is a load balancer used in corporate networks. This flaw lets an unauthenticated attacker run any command they want on the device by slipping malicious instructions past a part of the software that doesn't clean up user input properly. CISA added it to its official list of actively exploited vulnerabilities after 792 reported exploit attempts. An attacker who owns a load balancer can intercept or reroute traffic on that network.

Status: Added to CISA's Known Exploited Vulnerabilities catalog — federal agencies must patch by deadline; all organizations should prioritize immediately.

CVE-2026-18577 N-able N-central RMM HIGH 8.2

N-able's N-central is RMM software that IT service providers use to manage clients' computers remotely. Attackers exploited this flaw in the wild starting July 31, using it to reach into managed systems — meaning the computers of N-central's customers — and persist there. N-able has released a second hotfix (Hotfix 2), which replaces the first. If you applied Hotfix 1, you still need to apply Hotfix 2.

Status: Hotfix 2 released and required — Hotfix 1 alone is not sufficient.

🛠  New Tech
CSS-Based Email Attacks: Researchers Crack Open a Hidden Webmail Threat Class

PortSwigger researcher Gareth Heyes presented new research at Black Hat USA 2026 showing that carefully crafted CSS inside an email can break out of the email's boundaries and interfere with the surrounding webmail app. This matters because the technique works across Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail. Heyes built proof-of-concept chains that can capture passwords you type, steal account tokens, and even manipulate AI tools that read your inbox. The research is being shared publicly so email providers can fix the underlying issues — Fastmail has already patched two bugs found in the work. No malicious use in the wild has been confirmed yet, but the findings represent a new category of email-based attack that the security community will be working to close.

💡  Deep Dive
Your AI Work Assistant Can Be Tricked Into Stealing Your Company's Data

Atlassian's Rovo is an AI assistant built into Jira and Confluence — the project management and wiki tools used by millions of companies worldwide. This week, two separate security firms independently discovered that Rovo can be manipulated into collecting internal company data and quietly sending it to an attacker's server. No special hacking skills required on the victim's end. Just a click, or even just opening a file.

Here's how it works. AI assistants like Rovo read content to answer questions and summarize information. Security firm PromptArmor found they could hide instructions inside an uploaded file — instructions that look like normal text to a human but read like commands to the AI. When Rovo reads that file, it follows those hidden commands, gathers whatever internal data the logged-in user can access, and sends it to a URL the attacker controls. This type of attack is called prompt injection. A second firm, Varonis, found a different route: a specially crafted link that preloads malicious instructions into Rovo Chat before the conversation even begins. One click from an authenticated employee is all it takes.

For regular people working at companies that use Atlassian tools, this is a meaningful risk. You don't have to do anything obviously wrong. You might open a document a colleague shared, or click a link in a chat message, and your AI assistant could silently hand your company's internal data to someone outside the organization. The data at risk includes whatever you, the signed-in user, are allowed to see — project plans, customer records, strategy documents, code, anything living in your Jira or Confluence workspace.

Atlassian has confirmed one of the two attack routes has been closed, but the other remains unconfirmed as fixed as of August 8. The broader lesson here applies well beyond Atlassian: as AI assistants get wired deeper into workplace tools, they become a new channel attackers can exploit. Watch for Atlassian's official advisories, be cautious about which files you let Rovo read, and ask your IT or security team whether any mitigations are in place at your organization.

🛡️

Stay sharp. It's free.

Join thousands of readers who get daily cybersecurity news in plain English.

Subscribe Free →