Daily Digest

Metabase, Gitea Exploits Active; Chrome Patches 327 Flaws

Metabase, Gitea Exploits Active; Chrome Patches 327 Flaws

August 26, 2026
8 articles (6 new, 2 updated)
24 min read

Summary

August 26, 2026 - This daily summary highlights critical security updates and new threats impacting organizations.

Critical Vulnerabilities Under Active Exploitation:

  • Metabase Zero-Day (CVE-2026-72898): This SQL injection vulnerability, now on CISA's KEV list, allows for full administrator privileges. Affected versions are v0.58.0 through v1.63.4. Patched versions include v1.63.5 and later. Recommendations include network segmentation and WAF usage.
  • Gitea RCE (CVE-2026-60004): Also added to CISA's KEV catalog, this critical flaw allows arbitrary code execution with repository write access. Federal agencies must patch by August 28; all users should upgrade immediately.

Microsoft Defender Bypass:

  • 'ShieldBreak' (CVE-2026-69414): A local privilege escalation vulnerability has been identified that bypasses a previous Microsoft Defender patch. Microsoft rates its exploitation as 'more likely.' Defenders should monitor MsMpEng.exe for unusual child processes and file modifications, and implement enhanced EDR/XDR monitoring for privilege escalation behaviors.

New Threats and Advisories:

  • 'SLEEPWALKER' Backdoor: A new, stealthy Windows backdoor has been discovered. It remains dormant until triggered by a specific network packet, then executes commands via a custom bytecode language.
  • Google Chrome 152: This update addresses 327 vulnerabilities, including 10 critical flaws, primarily use-after-free memory corruption issues. Immediate updates are strongly advised.
  • US Treasury Quantum Task Force: The U.S. Treasury has formed a task force to accelerate the financial sector's transition to post-quantum cryptography (PQC) to prepare for future quantum computing threats.
  • VCU Security Campaign: Following phishing and hacking incidents, Virginia Commonwealth University has launched an awareness campaign, "Stop, Verify, Report," to educate its community on identifying and handling suspicious communications.
  • Ransomware Surge: NCC Group reports that global ransomware activity reached a 2026 high in July, with 894 cases recorded, a 22% increase from June. The Industrials sector and organizations in North America and Europe remain primary targets.

Filter by Category

New Articles (6)

Updated Articles (2)

📢 Share This Publication

Help others stay informed about cybersecurity threats

📅 Daily Edition

Curated and deduplicated every day from dozens of trusted sources — giving you one clean, consolidated view of what matters in cybersecurity.

🔢 Deduplication Applied

Related stories are merged into a single evolving article rather than repeated as separate entries — cutting through noise so you only read what's new.

🔗 Full Articles Linked

Every entry links to its full enriched article — complete with MITRE ATT&CK mappings, extracted IOCs, and actionable detection and mitigation guidance.