In partnership with

|
Fact
|
AI-enabled fraud cost Americans more than $893 million across upward of 22,000 FBI complaints in 2025, and testimony before the Senate Special Committee on Aging in July 2026 called that figure a significant undercount.
|
|
|
The breaches that mattered most this week didn't target the obvious stuff, they targeted the plumbing sitting quietly behind everything else. Here's what broke, what a contractor did with a stack of sticky notes, and one patch you genuinely can't skip.
PS: Was this forwarded to you? Subscribe free at exzeccyber.com/subscribe →
|
|
In this edition
|
|
|
|
|
| |
🏛️ Privacy, Power & Policy |
|
|
|
|
|
|
THIRD-PARTY BREACH
📊 A Zero-Day in a Business Intelligence Tool Just Breached LexisNexis, a Laptop Maker, and a Form Startup
Intro
The tool that quietly builds your internal dashboards just became the reason three unrelated companies had a very bad week.
What Happened
Metabase, a widely used open-source business intelligence platform, disclosed a maximum-severity (CVSS 10.0) SQL injection flaw in its unauthenticated password-reset endpoint, letting attackers gain full admin access to any hosted instance running version 1.58 or later. Metabase confirmed active exploitation of its cloud platform starting around August 3. Laptop maker Framework, form-building platform Tally, and data broker LexisNexis (via a third-party vendor) all disclosed that attackers used the flaw to steal customer names, emails, phone numbers, and billing details.
Why It Matters
This is third-party risk in its purest form: three companies with nothing in common except one shared analytics vendor, all breached the same way in the same week.
The Other Side
Metabase patched fast (minimum safe versions 0.58.24 through 0.63.5), and no passwords or financial account data appear to have been exposed, just contact information.
| |
👉 Takeaway
If Metabase touches your customer database, patch now and rotate any credentials that endpoint could have reached.
|
TL;DR: A maximum-severity zero-day in Metabase let attackers steal customer data from Framework, Tally, and LexisNexis in the same week.
|
| |
ACTIVELY EXPLOITED
A critical deserialization vulnerability (CVE-2026-63077, CVSS 9.8) in JetBrains TeamCity's on-premise version lets unauthenticated attackers bypass authentication entirely and execute arbitrary operating system commands. The flaw lives in how the platform's agent-polling protocol handles untrusted data, and CISA confirmed active exploitation in the wild. Federal agencies were given until August 8, just two days after the advisory, to patch. TeamCity sits at the center of software delivery for teams worldwide, building and deploying code automatically, so a compromised server can push malicious code downstream to every project it touches. The full scope of who has actually been hit isn't public yet.
→ If you run TeamCity on-premise, patch immediately: a compromised build server is a supply-chain attack waiting to happen.
|
| |
MALWARE
A new wave of "ClickFix" attacks tricks Mac users into pasting a malicious command into their own terminal by disguising it as a routine "I'm not a robot" verification screen. Once run, a Go-based malware family scans for cryptocurrency wallets and quietly redirects transactions to attacker-controlled addresses, supporting Bitcoin, Ethereum, Litecoin, Dogecoin, Monero, and XRP. The malware also grabs browser-stored passwords and Apple Keychain data for good measure. Researchers traced the staging and command-and-control infrastructure back to Aeza Group, a Russian bulletproof hosting provider already sanctioned by the US, UK, and Australia. The technique requires no software vulnerability at all, just a user willing to paste something they don't understand.
→ Never paste anything into a terminal or Run box because a website told you to, no matter how official the verification screen looks.
|
| |
LEGAL
Connor Riley Moucka, a 26-year-old Canadian, pleaded guilty to computer fraud and aggravated identity theft for his role in the 2024 Snowflake extortion campaign. Between February and October 2024, Moucka and a co-conspirator used stolen credentials to breach at least 165 companies hosted on Snowflake's cloud platform, including AT&T, Ticketmaster, and Santander. Prosecutors say the pair pulled in roughly $3 million combined by extorting victims directly and reselling stolen data on criminal forums. He faces up to 30 years in prison, with sentencing scheduled for October. The case remains one of the largest cloud-platform breaches on record, and the fact that consequences are still landing two years later is itself the story.
→ "We already dealt with that incident" and "the attacker faced consequences" are two very different milestones.
|
|
The GTM Playbook Behind Warmly's Acquisition
Warmly ran pipeline, outreach, and lead scoring on autopilot for hundreds of startups — before a single sales hire.
HubSpot acquired them for it. Now the cofounders are walking you through the exact system, live, before they disappear into product. Join the Builder Session on August 12.
| |
AI FRAUD
The Senate Special Committee on Aging heard testimony that Americans over 60 lost $7.7 billion to scams in 2025. AI-enabled fraud, voice clones, deepfake video, and automated scam scripts, accounted for roughly $893 million of that across more than 22,000 FBI complaints, and witnesses called that figure a significant undercount. One witness described her daughter's voice being cloned for a fake kidnapping call; another described a deepfake video falsely endorsing a "miracle cream." Lawmakers floated stronger advertiser-verification requirements and better law enforcement coordination as next steps. No new legislation passed at the hearing itself, but it signals where regulatory attention is heading next.
→ If a loved one calls in distress asking for money, hang up and call them back on a known number before doing anything else.
|
| |
AI SECURITY
Two separate research teams, PromptArmor and Varonis, found independent flaws in Rovo, Atlassian's AI assistant, that let attackers extract sensitive Jira and Confluence data without a user's knowledge. PromptArmor's technique hides malicious instructions inside an uploaded file, an indirect prompt injection that Rovo follows without question. Varonis found a separate URL-parameter flaw nicknamed "RovoBlast," which Atlassian has since patched server-side. Because Rovo has broad access across whatever enterprise systems it's connected to, the exposure isn't limited to a single app. Neither flaw required the attacker to have any existing access to the target's account.
→ Audit what your AI assistants are actually connected to. Having permission and using that permission unsupervised are not the same thing.
|
|
|
🏛️ Privacy, Power & Policy
|
|
| |
LEGISLATION
The Senate Commerce Committee advanced four bills aimed at protecting minors online: the Kids Online Safety Act, the Youth AI Privacy Act, the CHATBOT Act, and a child-AI-toy-safety measure, sending all four to the floor. EFF argues the bills would push platforms toward broad age verification, creating sweeping new privacy and data-security risks for adults and teens alike rather than solving the underlying problem. A fifth related bill on minors' biometric data failed to advance out of committee. EFF is pushing instead for comprehensive consumer privacy legislation or an outright ban on behavioral advertising targeting minors. If any of the four bills reach the floor, age verification will likely mean new databases of exactly the sensitive data privacy advocates worry about most.
→ Watch this closely: age verification mandates tend to mean new databases of exactly the sensitive data privacy advocates worry about most.
|
| |
REGULATION
The European Commission's AI Office began enforcing new transparency requirements under the EU AI Act on August 2. Chatbots and other interactive AI systems must now disclose that users are dealing with AI, and deepfakes or AI-generated content must carry machine-readable labels so they can be detected. Fines for noncompliance run up to €15 million or 3% of global annual revenue, whichever is higher. A separate delay under the Digital Omnibus pushed high-risk AI system obligations out to December 2027, which has caused confusion, but that carve-out does not cover these disclosure and labeling rules, which are live now. Most organizations reportedly aren't ready, according to compliance trackers watching the rollout.
→ If your company ships AI-generated content or chatbots into the EU, check compliance against the rules that actually took effect, not the ones that got delayed.
|
|
| |
Practical play
CISA added a critical command-injection flaw in Progress's Kemp LoadMaster (CVE-2026-8037) to its Known Exploited Vulnerabilities catalog after confirming active exploitation. The bug lets unauthenticated attackers run arbitrary commands on unpatched appliances by abusing unsanitized API inputs. Progress actually shipped a fix back in June, so this isn't a zero-day, it's a patch a lot of organizations apparently never applied. Federal agencies have three days to remediate under the binding directive. If you run LoadMaster anywhere in your environment, check your patch level today rather than assuming June's release cycle already covered it.
→ If you run LoadMaster and haven't checked your patch level since June, do it today. This is exactly the kind of already-fixed-but-not-applied bug that turns into a breach.
|
|
Avoid Tax Season Scramble
Don’t wait until spring to scramble through deductions, documents, and expenses. BELAY’s experienced tax prep professionals can help you get organized before it turns into an emergency.
Strange but real
📝 An IT Department Taped Everyone's Login Credentials to Their Laptops. A Contractor Took a Photo.
Intro
Somewhere, an IT department solved the new-hire-can't-remember-their-password problem with the one tool everyone already owns: a marker and a stack of sticky notes.
What Happened
During an office move, an IT team handed out laptops with usernames and initial passwords written on sticky notes attached to each device, apparently to make onboarding easier. The laptops sat out in a conference room during the transition, where a contractor photographed the exposed credentials and later used them to remotely access company systems.
Why It Matters
This is a physical-security failure dressed up as an IT convenience: no phishing, no zero-day, just credentials left in plain sight for anyone with a phone camera and no scruples.
The Other Side
To be fair, getting new hires logged in without IT hovering over every desk is a real onboarding problem. This was just a spectacularly bad solution to it.
| |
👉 Takeaway
If your onboarding process writes a password down anywhere a stranger could read it, that is not a shortcut, that is a vulnerability with a due date.
|
TL;DR: An IT department stuck login credentials on sticky notes, and a contractor photographed and used them to break in.
|
Global hiring doesn't come with a playbook. Join Oyster's webinars and events to learn how leading companies are hiring, expanding, and staying compliant across borders.