ClickFix attacks deliver a Go-based macOS stealer that steals passwords and Keychain data and can drain part or all of cryptocurrency wallets.
WordPress fixes CVE-2026–64638, a pre-auth login XSS affecting every version, with a demonstrated path to PHP execution under specific conditions.
A critical Metabase SQL injection vulnerability was exploited in zero-day attacks to breach customer instances in data theft attacks, known to impact Framework and Tally.
Metabase disclosed the attacks on Thursday, warning that its Metabase Cloud SaaS platform was compromised through a previously unknown vulnerability affecting versions 1.58 and above. The company warns that self-hosted installations are also vulnerable.
“We recently identified that Metabase Cloud was attacked by someone utilizing an unknown (“0-day”) security vulnerability in versions 1.58 and above,” Metabase CEO Sameer Al-Sakran warned in a blog post.
Healthcare software company Unlimited Technology Systems reported that more than 3.8 million people were impacted by a data breach incident that occurred in October 2025.
The organization submitted data breach notification samples to the authorities this year on July 1st without revealing the exact number of impacted individuals.
An entry on the breach notification portal of the U.S. Dept. of Health and Human Services now shows that a company server was breached and data of 3,803,750 people was exposed to an unauthorized party.
Address books or allowlists reduce repeated manual entry, while first-time or changed destinations deserve a full comparison rather than a check of only the opening and closing characters.
In both campaigns, the first trust decision could look legitimate while the surrounding workflow had already been changed. Detection and verification need to cover the steps between the authenticated email, the copied value and the final action.
Gen’s H1 2026 Threat Report covers the broader picture across scams, malware, identity exposure, privacy and AI-driven attacks.