📰 DAILY THREAT BRIEFING
Saturday, August 8, 2026
12 News Items
THN · BleepingComputer · Krebs · Dark Reading · SANS

📰 Cybersecurity News Headlines

Top stories from leading cybersecurity publications as of August 8, 2026.

  1. Metabase SQLi zero-day exploited in customer data-theft attacks
    — Bleeping Computer

    A critical Metabase SQL injection vulnerability was exploited in zero-day attacks to breach customer instances in data theft attacks, known …
  2. Unlimited Technology Systems breach impacts 3.8 million people
    — Bleeping Computer

    Healthcare software company Unlimited Technology Systems reported that more than 3.8 million people were impacted by a data breach incident …
  3. Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer
    — The Hacker News

    A cluster of nearly 800 malicious packages has been published to the npm registry as part of a new campaign designed to deliver cross-platfo…
  4. ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets
    — The Hacker News

    ClickFix-style attacks are being used to deliver a Go-based malware capable of stealing cryptocurrency assets, as well as browser-stored pas…
  5. UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data
    — The Hacker News

    A recent wave of cyber attacks targeting financial services, private equity, and professional services is attributed to a data extortion gro…
  6. AI-Generated Patches Fail Half the Time
    — Dark Reading

    A study of more than 6,000 patches found that even working patches can introduce new bugs, break something else, or are open to bypass.
  7. Levi Strauss & Co. says hackers stole corporate data in cyberattack
    — Bleeping Computer

    Levi Strauss & Co. (Levi's) says that hackers used social engineering on three of its employees to gain access to and steal corporate data s…
  8. Real emails, hijacked payments: Two H1 2026 attack chains
    — Bleeping Computer

    Gen's H1 2026 Threat Report examines two separate attack chains. One used compromised business inboxes and browser manipulation in a banking…
  9. New WordPress Pre-Auth XSS Could Lead to PHP Code Execution – Patch ASAP
    — The Hacker News

    WordPress has fixed a pre-authentication reflected cross-site scripting (XSS) flaw in its login screen that affects every version of the con…
  10. Linux Shell Forensic: Let?s Dive Into Atuin!, (Fri, Aug 7th)
    — SANS ISC

    UNIX systems (including Linux) are well-known to record a lot of activities in many different locations. But there is one domain where they …
  11. ISC Stormcast For Friday, August 7th, 2026 https://isc.sans.edu/podcastdetail/10042, (Fri, Aug 7th)
    — SANS ISC

    (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
  12. The Coordination Gap: How Attackers Are Outpacing Law Enforcement
    — Dark Reading

    The fight against cybercrime continues because threat actors have adapted their strategies to avoid deterrents, but law enforcement still op…

Generated by HiveNet.ai Threat Intelligence Platform · August 8, 2026 · Sources: The Hacker News, Bleeping Computer, Krebs on Security, Dark Reading, SANS ISC