Threat Brief — 2026-08-08 — Zero-days, KEV additions, and RMM persistence
Executive summary: Three actively-exploited vulnerabilities remain the dominant operational risk today: a CVSS 10.0 Metabase zero-day, a Progress Kemp LoadMaster command-injection flaw now confirmed with 792 exploit attempts, and a deepening N-able N-central compromise chain where attackers are reaching downstream managed systems. A new Russian-language write-up on VPN deanonymization techniques is also worth awareness for anyone relying on IP masking as an anonymity control.
Top items
- Metabase zero-day (CVSS 10.0) actively exploited for unauthenticated admin access. A maximum-severity SQL injection flaw in Metabase's BI/data-visualization software is being exploited in the wild as a zero-day, enabling admin-level access without authentication and leading to customer data theft. First reported 2026-08-07 by BleepingComputer; today's development adds confirmation of the CVSS 10.0 score and zero-day exploitation timeline. (src: The Hacker News)
- Progress Kemp LoadMaster command injection — 792 exploit attempts confirmed. CISA added this critical flaw to its KEV catalog on 2026-08-07 (first reported by CISA). Today's development: researchers now report 792 documented exploit attempts, confirming widespread active exploitation. If LoadMaster appliances are internet-exposed, treat as compromised and patch immediately. (src: The Hacker News)
- N-able N-central exploitation deepens — Hotfix 2 released as attackers reach managed systems. First reported 2026-08-03 (The Hacker News). Today's development: N-able has issued a second hotfix as investigation reveals attackers are not just compromising N-central servers but pivoting to reach downstream managed systems and establishing persistence. MSPs using N-central should apply Hotfix 2 and audit managed endpoints for indicators of compromise. (src: The Hacker News)
- VPN IP masking no longer sufficient for deanonymization protection. A new analysis details how websites can determine real location via GPS, timezone, DNS, system language, and account history even when a VPN is active. Relevant for anyone relying on IP-based anonymity for sensitive operations or threat-actor attribution. (src: SecurityLab.ru)
Themes
Active exploitation of RMM and admin-interface flaws. All three high-severity items (Metabase, LoadMaster, N-central) share a pattern: critical-severity, unauthenticated or low-privilege attack surface on administrative/management interfaces that are often internet-exposed. The N-able development specifically shows attackers using compromised RMM platforms as pivots to reach downstream managed systems — the supply-chain lateral movement pattern we've seen repeatedly this quarter.
===
