Med
2026-08-14 10:08Z · last 4h · 14 findings
· glm-5.2:cloud
Threat Brief — 2026-08-14 — Metabase 0-Day Behind Trezor Leak
Executive summary. The Trezor customer-data breach via ShipMonk now has an attack vector identified: a CVSS-10 unauthenticated SQL injection 0-day in Metabase. Separately, a new medium-severity CVE in the open-source HKUDS AI-Trader platform exposes research data without authentication. On the threat-landscape side, dark-web malware sellers are adopting legitimate "product line" models, and Twitch has quietly opted all streamers into generative-AI training by default.
Top items
- Metabase 0-day (CVSS 10) caused Trezor / ShipMonk breach. The breach affecting ~14 000 Trezor customers — first reported 2026-08-13 via BleepingComputer — was traced to an unauthenticated SQL injection flaw in Metabase with admin-level access as a bonus. This is the first public identification of the exploit chain behind the incident. (src: SecurityLab) · (src: Xakep)* — first reported 2026-08-13 by BleepingComputer.
- CVE-2026-12203 — HKUDS AI-Trader unauthenticated information disclosure. The open-source agent-native trading platform AI-Trader (up to commit 74caf99) exposes the
/api/research/agents.csvendpoint without authentication, leaking research export data (CWE-200 / CWE-284). Teams running this GitHub project should restrict or disable the endpoint immediately. (src: NVD / Grok)
- Dark-web malware sellers adopting "product line" business models. Analysis shows threat actors are organising malware offerings into structured product lines with versioning and support — mirroring legitimate SaaS practices. Overall listing volume has declined, suggesting market consolidation rather than contraction. (src: SecurityLab)
- Twitch enables generative-AI training on streamers' content by default. A "Training for Generative AI" setting is silently enabled in streamer accounts, meaning silence is treated as consent. Organisations with Twitch presence should review this setting and notify content creators. (src: SecurityLab)
- Google served vandalised Wikipedia edit as fact for Sam Altman "death." A vandalism edit lasting under one hour was ingested by Google search and surfaced as a factual knowledge-panel answer. Highlights the risk of relying on automated knowledge-graph pipelines for reputation-sensitive assertions. (src: SecurityLab)
Themes
- AI-platform attack surface expanding. Between the AI-Trader CVE and Twitch's silent AI-training opt-in, the footprint of AI-adjacent services creating unanticipated exposure continues to grow. Teams deploying open-source AI tooling should treat every API endpoint as externally reachable unless proven otherwise.
- Info-integrity failures compound quickly. The Google/Wikipedia incident shows how a sub-hour vandalism window can produce durable misinformation when automated pipelines lack source-confidence scoring.
===
