Here are the main stories you missed last week. 1. Metabase: A CVSS 10.0 zero-day in the password reset endpoint gave unauthenticated attackers admin access to every database the platform had ever connected to The headline: Metabase disclosed CVE-2026-72898 on August 6, a maximum-severity SQL injection vulnerability in the publicly accessible /api/session/reset_password endpoint that allows […] The post Cyber Roundup — Week of August 10th appeared first on CybelAngel .