June 8, 2026 Internet Explorer’s legacy WebBrowser control can still be abused to turn a single user click into full remote code execution (RCE) on Windows systems, even though the …
Multiple VMware Stored XSS Vulnerabilities Allow Attackers to Inject Malicious Scripts
June 8, 2026 Broadcom has disclosed three stored cross-site scripting (XSS) vulnerabilities affecting VMware Cloud Foundation Operations and several related products, warning that authenticated attackers could inject malicious scripts to …
UniFi OS Server Critical RCE Chain Allows Root Access Without Credentials
June 8, 2026 A critical vulnerability chain in the UniFi OS Server software has put thousands of organizations at serious risk. Researchers confirmed that an attacker can gain full root …
Critical Redis RCE Vulnerability Enable Attackers to Gain Complete Control to Host Server
June 8, 2026 In May 2026, Redis developers fixed a dangerous post-authentication remote code execution vulnerability, dubbed DarkReplica (CVE-2026-23631), that allowed attackers to gain full control of a Redis host. …
Microsoft Warns Claude Code GitHub Action Could Leak CI/CD Workflow Secrets
June 8, 2026 AI-powered coding tools are rapidly changing how developers build and ship software. But as these tools enter everyday development pipelines, they are also opening new doors for …
Hackers Can Hijack Claude Code MCP Traffic to Steal OAuth Tokens
A five-step attack chain that silently redirects Claude Code’s Model Context Protocol (MCP) traffic through attacker-controlled infrastructure, intercepting OAuth bearer tokens that grant persistent, broadly scoped access to connected SaaS …
New EDRChoker Tool Uses Policy-Based Quality of Service to Block EDR Processes
June 7, 2026 A newly released open-source red team tool called EDRChoker introduces a novel technique for silencing cloud-connected Endpoint Detection and Response (EDR) agents not by killing their processes or injecting …
Instagram Fixes Password Reset Flaw That Exposes User Emails and Phone Numbers
June 7, 2026 A critical logic bug in Instagram’s web-based password reset flow on June 6, 2026, exposed unredacted email addresses and phone numbers associated with user accounts, including those …
CISA Warns of Linux Kernel Improper Authentication Vulnerability Exploited in Attacks
June 7, 2026 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical Linux kernel vulnerability, tracked as CVE-2022-0492, to its Known Exploited Vulnerabilities (KEV) catalog, warning that …
New ChatGPT Lockdown Mode to Mitigate Prompt Injection and Data Exfiltration Attacks
June 6, 2026 OpenAI has released ChatGPT Lockdown Mode, a new security feature designed to limit outbound network access and reduce the risk of data exfiltration from prompt-injection attacks. The …
