Salesforce and ServiceNow Portals Exposed for 17 Months Amid Metabase Zero‑Day Exploit

0
3

Key Takeaways

  • GitHub’s Dependabot malware alerts now monitor eight package ecosystems, expanding protection beyond npm.
  • An AI‑driven scan uncovered 84 previously unknown flaws in 5G/4G network software, 23 of which remain unpatched.
  • Post‑quantum migration is hampered by legacy keys and default passwords still held by former employees.
  • A long‑running, stealthy campaign (City‑Forum) has been exfiltrating data from Salesforce and ServiceNow portals worldwide for 17 months.
  • Multiple vendors issued urgent hotfixes for actively exploited zero‑days (N‑able, Metabase, Microsoft, Cisco, SharePoint).
  • The White House authorized vetted U.S. private firms to conduct offensive cyber operations against foreign threat actors.
  • AI‑generated deepfakes and malicious SIM cards are enabling new fraud and device‑ hijacking techniques.
  • Enterprises are improving defense against noisy attacks but still struggle with low‑profile, stealthy threats, according to the Blue Report 2026.
  • CISOs spend excessive time translating technical findings for boards, highlighting a communication gap.
  • Open‑source tools such as Chainloop, PentestGPT, and Slop or Not are maturing to support supply‑chain integrity, automated pentesting, and AI‑generated‑content detection.

GitHub Dependabot Extends Malware Alerts to Eight Ecosystems

GitHub announced that Dependabot’s malware detection, which previously watched only the npm registry, now covers all eight major package ecosystems—npm, PyPI, Maven, RubyGems, NuGet, Go, crates.io, and PHP Composer—as soon as a user enables malware alerts. Because Dependabot already runs across more than 30 million repositories and 34 plus package ecosystems, the expanded scope dramatically increases the scale at which malicious packages can be intercepted before they reach developers.

AI Agents Uncover Dozens of 5G/4G Flaws

Researchers at Nanyang Technological University deployed a swarm of AI agents against the software that powers 4G and 5G phone networks. The agents returned 84 security flaws that had never been reported; developers have confirmed 83 of them, and 81 now carry CVE identifiers. Notably, 23 of the vulnerabilities remain unpatched, highlighting a lingering risk in critical telecommunications infrastructure.

Post‑Quantum Migration Complicated by Legacy Keys

In a Help Net Security interview, Quantus CEO Christopher Smith explained that banks and hospitals often discover default passwords and administrative keys still belonging to former employees when they build cryptographic inventories. These hidden credentials make the transition to post‑quantum cryptography far more difficult, as they create blind spots that attackers could exploit even after new algorithms are deployed.

City‑Forum: A 17‑Month Stealthy Data Harvest

Researchers at Reco traced a campaign dubbed City‑Forum, named after a domain registered in 2002 that was abandoned and now points to a rented German server. From that server, an unknown actor has been silently pulling records from Salesforce and ServiceNow portals around the world for over a year and a half, demonstrating how legitimate‑looking infrastructure can be abused for long‑term espionage without triggering obvious alarms.

Rapid Hotfixes for Actively Exploited Zero‑Days

Several vendors issued emergency patches last week: N‑able released a second hotfix for N‑central addressing CVE‑2026‑18577; Metabase disclosed a zero‑day that led to a breach of Framework customer data (names, emails, phones, addresses, login IPs); Microsoft’s August Patch Tuesday fixed over 400 vulnerabilities, including a zero‑day under active attack (CVE‑2026‑68820); Cisco patched a high‑severity firewall DoS flaw (CVE‑2026‑20349) now listed in CISA’s Known Exploited Vulnerabilities catalog; and Microsoft addressed a critical SharePoint vulnerability (CVE‑2026‑55040) after a public proof‑of‑concept exploit appeared.

White House Authorizes Private Offensive Cyber Operations

On August 12, President Trump signed a National Security Presidential Memorandum permitting vetted U.S. private companies to conduct offensive cyber operations against foreign threat actors, under government oversight. The move aims to bolster the nation’s ability to disrupt adversary networks while retaining accountability and legal boundaries.

Deepfakes, Malicious SIMs, and New Fraud Vectors

Spanish police arrested a man whose deep‑fake video glitch exposed his attempt to spoof a certificate provider’s identity check for financial fraud. Separately, researchers demonstrated that compromised or malicious SIM cards can issue commands to smartphones, steal files, downgrade connections to 2G, and even execute code. A cybercrime forum also offered a ready‑made $500 kit that automates crypto‑scamming, complete with victim tracking and fake balance inflation.

Lazarus Group Leverages Fake Job Offers and Windows Zero‑Day

Check Point researchers linked the North Korea‑affiliated Lazarus group to a campaign that sends trojanized PDF software disguised as job offers, paired with a previously undisclosed Windows zero‑day. The attacks primarily target defense‑sector organizations, illustrating how social engineering continues to be a potent entry point for sophisticated threat actors.

Signal Adds Automatic Key Verification

Signal introduced an automatic key verification feature that lets users confirm that their encrypted chats have not been tampered with silently. The function continuously validates session keys in the background, providing an extra layer of assurance against man‑in‑the‑middle attacks on the platform’s end‑to‑end encryption.

Supply‑Chain Fallout: LiteLLM Leak and Chainloop Response

A supply‑chain attack on LiteLLM exposed a 153 GB archive containing credentials and sensitive data linked to thousands of corporate domains, including AWS, Samsung, Cisco, and Salesforce. Hudson Rock’s analysis attributed over 118 k CI runner dumps to 2 488 organizations. In response, the open‑source project Chainloop offers a command‑line tool that captures build artifacts, stores them in content‑addressable storage, and creates signed in‑toto attestations, giving teams verifiable proof of what actually ran in their pipelines.

Enterprise Defense Improves Against Noise but Falters on Stealth

The Blue Report 2026 from Picus Labs, based on 338 million attack simulations, shows that organizations are getting better at stopping loud, high‑volume attacks. However, detection and mitigation of low‑profile, stealthy techniques have barely improved, leaving a narrow but critical gap in overall resilience.

Corporate Investigation Pitfalls Under Pressure

In a Help Net Security video, BlackBerry’s Christine Gadsby highlighted common missteps made during the first hours of a corporate investigation: prematurely granting access, initiating conversations without proper controls, and making decisions that later jeopardize chain of custody, legal privilege, and regulatory outcomes. She stresses that early‑stage diligence is far more consequential than many leaders assume.

Reporting AI Act Violations in the EU

Since August 2, 2026, the European Commission’s AI Office and national authorities have begun enforcing the EU AI Act. The regulation establishes a unified rule‑set for AI systems placed on the market or used within the EU, aiming to foster innovation while safeguarding safety and fundamental rights. Organizations now have clear channels to report non‑compliant AI practices, though awareness and procedural readiness remain works in progress.

Microsoft Entra ID Streamlines MFA for Windows Hello and macOS PSSO

Starting early October 2026, Microsoft Entra ID will remove an extra multi‑factor authentication step for users who sign in via Windows Hello for Business or macOS Platform Single Sign‑On. The change rolls out worldwide and to GCC tenants, with completion expected by late November, aiming to reduce friction without weakening security for those authentication methods.

Steam Hardware Shipper Breach Exposes Personal Data

Valve notified European customers of a data breach at CEVA Logistics, its Steam hardware‑shipping partner. Compromised information includes names, addresses, and order details; payment data was not affected. The incident underscores the ripple effects that third‑party logistics providers can have on consumer data security.

Polish Energy Plant Breached via Private APN

CERT Polska reported that the December 29 cyberattack on a Polish combined heat and power plant was the first observed intrusion into an OT network through a private APN—a dedicated mobile network set up by a Distribution System Operator. The vector bypassed traditional perimeter defenses, highlighting the need to scrutinize private cellular links in critical infrastructure.

GPT‑5.6‑Cyber Model Lowers Refusals for Dual‑Use Tasks

OpenAI released GPT‑5.6‑Cyber, a variant of GPT‑5.6 Sol tuned to discover zero‑day vulnerabilities and build exploit chains. The model exhibits fewer refusals on higher‑risk, dual‑use requests, making it more amenable to cybersecurity research while still being accessible only through the Daybreak Red tier of OpenAI’s vetted access program.

Ransomware Can Disrupt Production Without ICS Access

Dragos found that ransomware groups need not penetrate industrial control systems to halt production; compromising the IT systems that support OT environments is often sufficient. In Q2 2026, Dragos recorded 1,140 ransomware incidents involving industrial organizations, a 12 % increase over Q1, reinforcing the importance of protecting IT‑OT interfaces.

Open‑Source Pentesting Agent PentestGPT Debuts

PentestGPT is an open‑source framework that points a large language model at a target and lets it perform reconnaissance, exploitation, and post‑exploitation walk‑throughs autonomously. Switching to “pentest mode” reorders the stages to asset discovery, vulnerability identification, and reporting, offering a fully automated alternative to manual testing—though human oversight remains advisable for validation.

Chrome’s Anti‑Abuse Measures Cut Billions of Unwanted Notifications

Google Chrome’s latest updates automatically revoke push‑notification permissions from inactive or suspicious sites, helping block scams, phishing, and deceptive content. The change now blocks an estimated seven billion unwanted Android notifications each day, illustrating how browser‑level hygiene can curb large‑scale abuse vectors.

Wireshark 4.6.8 Patches Numerous File‑Parser Bugs

Wireshark version 4.6.8 resolves 28 security issues, nine of which reside in file parsers that read saved capture files from disk (e.g., pcapng, Endace ERF, Tektronix K12xx, and several Windows‑specific parsers). Because these flaws can be triggered simply by opening a malicious capture file, users are urged to update promptly, especially in environments where packet captures are routinely shared.

Slop or Not Provides Offline AI‑Generated‑Content Detection

Slop or Not is an iOS and macOS app that runs entirely offline, using Apple Neural Engine‑powered models to detect AI‑generated text and images without requiring an account or internet connection. The tool offers a privacy‑preserving way for individuals and organizations to vet potentially synthetic media.

DDoS Attacks Reach Terabit‑Scale Peaks

Cloudflare’s H1 2026 DDoS Threat Report shows that attacks exceeding 1 Tbps have become more common, driven by multi‑vector, network‑layer techniques and increasingly automation. While attack durations have shortened, the sheer volume poses fresh challenges for mitigation strategies that rely on capacity‑based defenses.

Seventeen Draft Cyber Resilience Act Standards Open for Comment

To implement the EU Cyber Resilience Act, which takes effect at the end of 2027, seventeen draft standards are now available for public comment. They provide the technical details manufacturers—such as makers of connected toys—must satisfy to demonstrate compliance, shifting the burden of detailed implementation from the law itself to the standards bodies.

IAM Misconfigurations Plague Cloud Environments

CISA reports that weak identity and access management affects up to 98 % of cloud environments, often due to simple missteps like exposed services, unrotated keys, missing encryption, or logging gaps. The agency now mandates baseline cloud configuration practices for U.S. federal agencies to reduce this widespread risk.

The Real Challenge of Agentic AI: Re‑Engineering Business Processes

Deloitte’s research indicates that while organizations anticipate productivity gains from AI agents, few possess the workflows and processes needed to reap those benefits. The hardest part of adopting agentic AI is not the technology itself but redesigning how work is organized to let agents handle routine tasks while humans focus on higher‑value activities.

AWS Certificate Manager Phases Out Email Validation

AWS Certificate Manager will stop issuing email‑validated public certificates throughout 2027, ahead of the CA/B Forum’s March 15 2028 deadline to retire email‑based domain validation. The move pushes customers toward more robust validation methods such as DNS‑based or HTTP‑based checks.

GPT‑5.6 Sol Runs Up to 14× Faster in Ultrafast Mode

OpenAI’s GPT‑5.6 Sol, when operated in Ultrafast mode powered by Cerebras hardware, can generate up to 750 output tokens per second—up to 14 times faster than standard processing. The mode is currently in limited preview via the OpenAI API, targeting latency‑sensitive applications.

Cybersecurity Job Market and New Product Showcases

The weekly round‑up includes a curated list of open cybersecurity roles spanning various skill levels, as well as a showcase of recent infosec releases from vendors such as A10 Networks, ScienceLogic, Searchlight Cyber, and SelectHub, highlighting the continued flow of tools aimed at threat detection, monitoring, and response.


This synthesis distills the week’s most salient security developments into a concise, readable format while preserving the key details and implications for practitioners and decision‑makers.

SignUpSignUp form

LEAVE A REPLY

Please enter your comment!
Please enter your name here