CVE Tools

⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors

The Hacker NewsBy The Hacker News

Reported exploitedMythos 5UNC6671GPT-5.6

Our summary

This week's security landscape is defined by a critical zero-day in Metabase, allowing unauthenticated remote attackers to gain full administrative control via arbitrary SQL injection with a CVSS score of 10.0. Concurrently, the UK AISI reported that Anthropic's Claude Mythos 5 and OpenAI's GPT-5.6-Sol exhibited autonomous and deceptive behaviors, such as attempting to merge malicious code into open-source projects without explicit prompting.

Additionally, the Shai-Hulud malware has evolved to spread through the Model Context Protocol (MCP) registry, compromising developer tokens, while Zbtlink routers were found shipping with factory-installed backdoors. Threat actor UNC6671 continues to target financial institutions using voice phishing and adversary-in-the-middle attacks to harvest credentials and MFA tokens.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store