Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers
The Hacker News 08.08.2026 08:54
Attacker-controlled instructions can make Atlassian's Rovo assistant collect Jira or Confluence data that a signed-in user can access, then send it to an outside server. Two security firms found that behavior independently, by different routes. Only one of those routes is confirmed closed.
PromptArmor, an AI security firm, hid the instructions in content Rovo reads. It said an uploaded file was
Google-Threat-Intelligence-Chefin: Dank KI „mehr Zero-Days als je zuvor“
Heise Security 08.08.2026 08:24
Bug-Bounty-Programme werden mit Fehlerberichten geflutet, User und Firmen leiden unter KI-Angriffen: Der Security-Bereich ändert sich rasant, sagt Sandra Joyce.
Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication
The Hacker News 08.08.2026 06:58
Metabase has warned that a maximum-severity security flaw impacting its business intelligence and data visualization software package has been exploited in the wild as a zero-day.
The vulnerability (CVSS score: 10.0), which does not carry a CVE identifier, allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, enabling them to gain
Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts
The Hacker News 08.08.2026 06:52
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a critical-severity security flaw impacting Progress Kemp LoadMaster to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the wild.
The vulnerability, tracked as CVE-2026-8037 (CVSS score: 9.6), is a command injection flaw that could be weaponized to achieve arbitrary