View all sources for this day →

The Signal

The Metabase case warrants first attention because it places an application boundary ahead of the downstream data and credential exposure it can enable. [1]

Must Know

Metabase exploitation and data-access reporting

Exploitation · Cloud

What happened

Metabase Cloud was attacked through an unknown zero-day in versions 1.58 and above; the company rated the flaw CVSS 10.0 and said it enabled unauthenticated arbitrary SQL injection into the application database. [1]

After exploitation, an attacker could obtain administrator access, change application configuration, steal credentials for connected databases, read accessible data, and export it. [1]

Why it matters

Framework confirmed it was compromised through the flaw; names, login IPs, addresses, phone numbers, and email addresses were accessed, while order and payment information was reportedly not affected. [1]

Unlimited Technology Systems breach reporting

Incident · Identity

What happened

Unlimited Technology Systems disclosed a breach affecting 3,803,750 people after an unauthorized actor accessed a commercial data center between October 5 and 10, 2025. [2]

The potentially obtained information included names, health-insurance details, medical information, scanned identity and insurance documents, Social Security numbers, dates of birth, and contact details. [2]

Why it matters

The company provides billing, financial, and revenue-cycle services to more than 4,500 oncology practices and over 6,500 specialty providers, making the incident relevant to healthcare organizations using its platforms. [2]

Chinese cybersecurity review of Palo Alto Networks

Policy · Platform

What happened

China’s Cyberspace Administration announced a cybersecurity review of Palo Alto Networks products sold in China, citing national-security and cybersecurity laws and the goal of protecting critical information infrastructure. [3]

The public announcement names no specific vulnerability or incident and provides no timeline for when findings may be released. [3]

Why it matters

The article reports that China has been encouraging replacement of listed U.S. and Israeli security products, including Palo Alto Networks products, with domestic alternatives. [3]

Sources (3)
  1. [1] Metabase Zero-Day Exploited in the Wild, Exposing Admin Access and Sensitive Data

    securityaffairs · August 8, 2026

  2. [2] Unlimited Technology Systems Data Breach Exposes Data of 3.8 Million Healthcare Patients

    securityaffairs · August 8, 2026

  3. [3] Palo Alto Networks Faces China Cybersecurity Review Amid Rising Tech Tensions

    securityaffairs · August 8, 2026