Apache HTTP Server 2.4.68 Released With Fix For Use-After-Free, DoS, XSS, and Buffer Overflow Flaws

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 9, 2026 The Apache Software Foundation released Apache HTTP Server version 2.4.68 on June 8, 2026, addressing 13 security vulnerabilities spanning multiple modules. The patched flaws include use-after-free conditions, cross-site scripting, heap-based buffer overflows, denial-of-service, privilege escalation, and out-of-bounds …

21 0-Day Vulnerabilities in FFmpeg Enables Remote Code Execution Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 9, 2026 An autonomous security agent uncovered 21 zero-day vulnerabilities in FFmpeg, the world’s most widely deployed media processing library, including a critical RCE-capable heap buffer overflow reachable with a single 183-byte network packet. FFmpeg quietly powers media processing …

New China-Linked Threat Cluster OP-512 Targets IIS Servers With Cryptographically Unique Web Shell Framework

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 8, 2026 A newly identified threat cluster with suspected ties to China has been caught targeting Internet Information Services (IIS) web servers using a purpose-built web shell framework. Tracked as OP-512, this group stands out for deploying tools designed …

Check Point VPN 0-day Vulnerability Exploited in the Wild to Deploy Ransomware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 8, 2026 Check Point Research has uncovered active exploitation of CVE-2026-50751, a critical authentication bypass vulnerability (CVSS 9.3) in Check Point Remote Access VPN and Mobile Access deployments, with confirmed post-compromise activity linked to the Qilin ransomware gang. CVE-2026-50751 …

Malspam Attack Uses Google DoubleClick Redirects to Deliver Fileless .NET Loader

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 8, 2026 Cybercriminals have found a new way to sneak malware past email security tools, and this time they are hiding behind a name that most systems trust without question. A recent malspam campaign has been caught using Google’s …

UNC3753 Attacking US Law Firms Using Vishing and RMM Tools to Exfiltrate Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 8, 2026 A sophisticated cybercriminal group known as UNC3753 has been running an aggressive campaign against US law firms since early 2026, using phone calls, screen-sharing tricks, and remote monitoring software to break into corporate systems and steal sensitive …

OWASP Releases AI Security Report to Empower Security Professionals with New Tools

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 8, 2026 OWASP has released the “State of Agentic AI Security and Governance v2.01” report, a technical blueprint aimed at security teams racing to secure rapidly proliferating autonomous AI agents in production. The report, part of the OWASP GenAI …

Internet Explorer WebBrowser Control Attack Chain Turns Clicks Into RCE

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 8, 2026 Internet Explorer’s legacy WebBrowser control can still be abused to turn a single user click into full remote code execution (RCE) on Windows systems, even though the browser is officially retired. PT Security observed that by exploiting …

Multiple VMware Stored XSS Vulnerabilities Allow Attackers to Inject Malicious Scripts

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 8, 2026 Broadcom has disclosed three stored cross-site scripting (XSS) vulnerabilities affecting VMware Cloud Foundation Operations and several related products, warning that authenticated attackers could inject malicious scripts to perform administrative actions within the environment. Tracked as CVE-2026-41722, CVE-2026-41723, …

UniFi OS Server Critical RCE Chain Allows Root Access Without Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 8, 2026 A critical vulnerability chain in the UniFi OS Server software has put thousands of organizations at serious risk. Researchers confirmed that an attacker can gain full root access to affected devices without a single credential, turning one …