Key takeaways Metabase has confirmed a maximum-severity flaw in its business intelligence platform was exploited as a zero-day, first against its own hosted service. An unauthenticated attacker could reach administrator access, then take the stored credentials for every database the tool connects to. The flaw scores 10.0, the highest possible rating, and has no CVE […]
Read MoreKey takeaways A CVE record is an identifier and a description. It is not, on its own, a judgement about how urgent the vulnerability is for you. CVSS answers how bad exploitation would be, EPSS answers how likely exploitation is in the next 30 days, and CISA’s KEV catalog answers whether exploitation has actually been […]
Read MoreMicrosoft’s November 2025 Patch Tuesday fixes 63 security flaws across Windows, Office, .NET, and developer tools, five of them rated critical. The most urgent is an actively exploited Windows Kernel zero-day, CVE-2025-62215, which attackers are already using to gain full control of affected machines. The single most important action, for home users and businesses alike, […]
Read More