June 9, 2026 The Apache Software Foundation released Apache HTTP Server version 2.4.68 on June 8, 2026, addressing 13 security vulnerabilities spanning multiple modules. The patched flaws include use-after-free conditions, …
21 0-Day Vulnerabilities in FFmpeg Enables Remote Code Execution Attacks
June 9, 2026 An autonomous security agent uncovered 21 zero-day vulnerabilities in FFmpeg, the world’s most widely deployed media processing library, including a critical RCE-capable heap buffer overflow reachable with …
New China-Linked Threat Cluster OP-512 Targets IIS Servers With Cryptographically Unique Web Shell Framework
June 8, 2026 A newly identified threat cluster with suspected ties to China has been caught targeting Internet Information Services (IIS) web servers using a purpose-built web shell framework. Tracked …
Check Point VPN 0-day Vulnerability Exploited in the Wild to Deploy Ransomware
June 8, 2026 Check Point Research has uncovered active exploitation of CVE-2026-50751, a critical authentication bypass vulnerability (CVSS 9.3) in Check Point Remote Access VPN and Mobile Access deployments, with …
Malspam Attack Uses Google DoubleClick Redirects to Deliver Fileless .NET Loader
June 8, 2026 Cybercriminals have found a new way to sneak malware past email security tools, and this time they are hiding behind a name that most systems trust without …
UNC3753 Attacking US Law Firms Using Vishing and RMM Tools to Exfiltrate Data
June 8, 2026 A sophisticated cybercriminal group known as UNC3753 has been running an aggressive campaign against US law firms since early 2026, using phone calls, screen-sharing tricks, and remote …
OWASP Releases AI Security Report to Empower Security Professionals with New Tools
June 8, 2026 OWASP has released the “State of Agentic AI Security and Governance v2.01” report, a technical blueprint aimed at security teams racing to secure rapidly proliferating autonomous AI …
Internet Explorer WebBrowser Control Attack Chain Turns Clicks Into RCE
June 8, 2026 Internet Explorer’s legacy WebBrowser control can still be abused to turn a single user click into full remote code execution (RCE) on Windows systems, even though the …
Multiple VMware Stored XSS Vulnerabilities Allow Attackers to Inject Malicious Scripts
June 8, 2026 Broadcom has disclosed three stored cross-site scripting (XSS) vulnerabilities affecting VMware Cloud Foundation Operations and several related products, warning that authenticated attackers could inject malicious scripts to …
UniFi OS Server Critical RCE Chain Allows Root Access Without Credentials
June 8, 2026 A critical vulnerability chain in the UniFi OS Server software has put thousands of organizations at serious risk. Researchers confirmed that an attacker can gain full root …
