Data & infrastructure
-
TrueConf compromise turns updates into attack route
Kaspersky says attackers compromised unpatched TrueConf servers and replaced legitimate client installers with backdoored versions, extending exposure from server operators to organisations connecting through affected counterparties.
-
Metabase zero-day reaches n8n user data
A zero-day attack on Metabase Cloud reached data available through German automation company n8n’s analytics environment, exposing how an internal reporting dependency can become a route into user and credential information.
-
Oracle database becomes attacker execution layer
Huntress found attackers using SQL injection to place a post-exploitation toolkit inside an Oracle database and reach operating-system command execution on the underlying Windows server.
-
Critical Jenkins flaw crosses agent-controller boundary
A critical Jenkins vulnerability can allow a compromised agent or suitably privileged user to bypass a deserialisation safeguard and potentially execute code on the higher-trust controller.
-
TeamCity flaw moves into active exploitation
A critical TeamCity vulnerability has moved from disclosure to confirmed exploitation, increasing the exposure around on-premises build systems and the credentials and software pipelines connected to them.
-
European firms weigh US technology dependence
Proton research finds businesses in the UK, France, and Germany increasingly treating dependence on US technology platforms as an operational resilience risk.
-
Kiteworks acquisition adds 500 Japanese customers
Kiteworks has acquired WAMNET Japan, establishing a direct Japanese operation and adding more than 500 enterprise customers to its secure data-exchange business.
-
Router implant exposes unencrypted root access
VulnCheck found an unauthenticated remote-control implant running as root in 20 Zbtlink router models, with no vendor fix identified.
-
Beacon breach exposes charity data backups
Beacon says compromised credentials were used to copy customer database backups, which investigators believe were probably downloaded.
-
Intermarché breach exposes 287,605 customer records
Unauthorised access to Intermarché’s Drive service exposed identity, contact, loyalty, and order information belonging to 287,605 customers.



