U.S. Defense Manufacturer IEH Hit by Phishing Attack, Exposing Potentially Export-Controlled Data

2026-08-09T20:51:35Z514d681565416cc6d68e67efdd00134f3e2abd8c01ceb70fe98a09ad4ce78429
CVE-2026-8037AI email toolsCISA KEVMFA theftMetabaseProgress LoadMasterWordPressactive exploitationcommand injectioncredential theftcross-site scriptingcyber espionagedata breachdefense industryexport-controlled datahealthcarephishingransomwareremote code executionwebmail securityzero-day

What happened

Security Affairs reporting highlights active exploitation and significant cyber incidents, including a Metabase zero-day used to obtain administrative access and sensitive data, a CISA-listed Progress LoadMaster command-injection vulnerability, a WordPress XSS-to-remote-code-execution chain, phishing and MFA credential theft campaigns, webmail CSS attacks, and major healthcare and defense-sector data exposures.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
514d681565416cc6d68e67efdd00134f3e2abd8c01ceb70fe98a09ad4ce78429
Enrichment time
2026-08-09T20:51:35Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · U.S. Defense Manufacturer IEH Hit by Phishing Attack, Exposing Potentially Export-Controlled Data · Baitaphish