Malspam Attack Uses Google DoubleClick Redirects to Deliver Fileless .NET Loader

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 8, 2026 Cybercriminals have found a new way to sneak malware past email security tools, and this time they are hiding behind a name that most systems trust without question. A recent malspam campaign has been caught using Google’s …

UNC3753 Attacking US Law Firms Using Vishing and RMM Tools to Exfiltrate Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 8, 2026 A sophisticated cybercriminal group known as UNC3753 has been running an aggressive campaign against US law firms since early 2026, using phone calls, screen-sharing tricks, and remote monitoring software to break into corporate systems and steal sensitive …

OWASP Releases AI Security Report to Empower Security Professionals with New Tools

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 8, 2026 OWASP has released the “State of Agentic AI Security and Governance v2.01” report, a technical blueprint aimed at security teams racing to secure rapidly proliferating autonomous AI agents in production. The report, part of the OWASP GenAI …

Internet Explorer WebBrowser Control Attack Chain Turns Clicks Into RCE

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 8, 2026 Internet Explorer’s legacy WebBrowser control can still be abused to turn a single user click into full remote code execution (RCE) on Windows systems, even though the browser is officially retired. PT Security observed that by exploiting …

Multiple VMware Stored XSS Vulnerabilities Allow Attackers to Inject Malicious Scripts

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 8, 2026 Broadcom has disclosed three stored cross-site scripting (XSS) vulnerabilities affecting VMware Cloud Foundation Operations and several related products, warning that authenticated attackers could inject malicious scripts to perform administrative actions within the environment. Tracked as CVE-2026-41722, CVE-2026-41723, …

UniFi OS Server Critical RCE Chain Allows Root Access Without Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 8, 2026 A critical vulnerability chain in the UniFi OS Server software has put thousands of organizations at serious risk. Researchers confirmed that an attacker can gain full root access to affected devices without a single credential, turning one …

Critical Redis RCE Vulnerability Enable Attackers to Gain Complete Control to Host Server

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 8, 2026 In May 2026, Redis developers fixed a dangerous post-authentication remote code execution vulnerability, dubbed DarkReplica (CVE-2026-23631), that allowed attackers to gain full control of a Redis host. Redis provides powerful server-side Lua engines, allowing administrators to run …

Microsoft Warns Claude Code GitHub Action Could Leak CI/CD Workflow Secrets

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 8, 2026 AI-powered coding tools are rapidly changing how developers build and ship software. But as these tools enter everyday development pipelines, they are also opening new doors for attackers. A recently uncovered vulnerability in a widely used AI …

Hackers Can Hijack Claude Code MCP Traffic to Steal OAuth Tokens

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A five-step attack chain that silently redirects Claude Code’s Model Context Protocol (MCP) traffic through attacker-controlled infrastructure, intercepting OAuth bearer tokens that grant persistent, broadly scoped access to connected SaaS platforms like Jira, Confluence, and GitHub with no patch incoming …

New EDRChoker Tool Uses Policy-Based Quality of Service to Block EDR Processes

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 7, 2026 A newly released open-source red team tool called EDRChoker introduces a novel technique for silencing cloud-connected Endpoint Detection and Response (EDR) agents not by killing their processes or injecting code, but by quietly choking their network bandwidth to near-zero …