Microsoft August 2026 Update Breaks When Generating PDF/XPS Content

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has confirmed that its August 2026 .NET Framework cumulative updates are causing printing failures and PDF/XPS generation errors in Windows Presentation Foundation (WPF) applications, creating fresh headaches for enterprises …

Multiple Zscaler Client Connector Vulnerabilities Enable RCE Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Multiple vulnerabilities affecting Zscaler Client Connector have been disclosed, potentially allowing remote code execution on vulnerable systems. Tracked as CVE-2026-59568, the critical flaw chain enables an unauthenticated and unprivileged attacker …

91 Spring Vulnerabilities Impact 209,000+ Software Components Across Open-Source Ecosystem

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Broadcom has released a major batch of Spring security advisories, with Sonatype tracking 91 CVEs across Spring Framework and related projects. The August 20, 2026 disclosure affects an estimated 209,569 …

EvilTokens Doesn’t Just Steal Microsoft Sessions—Its AI Tells Attackers Who to Scam Next

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

EvilTokens is pushing phishing beyond the moment a victim clicks a link. The service steals Microsoft 365 session access, then examines the compromised mailbox to help criminals choose the contacts, …

CISA Warns of Oracle HTTP and WebLogic Server Vulnerability Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The U.S. Cybersecurity and Infrastructure Security Agency has added CVE-2026-21962, an improper access control flaw affecting Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in, to its Known Exploited …

Hackers Exploit Critical miniOrange SAML SSO Flaws to Hijack WordPress Admin Accounts

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Two critical flaws in the miniOrange SAML 2.0 Single Sign-On plugin could allow unauthenticated attackers to log in to vulnerable WordPress sites as any existing user, including administrators. The flaws, …

Critical Red Hat Keycloak Flaw Lets Unauthenticated Attackers Take Over Any User Account

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Red Hat has disclosed a critical vulnerability in the Red Hat Build of Keycloak that could allow unauthenticated remote attackers to take over arbitrary user accounts. Tracked as CVE-2026-18963, the …

Fake GTA 6 Demo Is Actually Malware That Steals Your Passwords and Logged-In Sessions

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A fake Grand Theft Auto VI demo is being used to steal passwords and active browser sessions from people looking for early access. The campaign turns excitement around game footage …

Anthropic Rolls Out Enterprise-Managed Auth for Claude’s MCP Connectors

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Anthropic has taken its Model Context Protocol (MCP) connector framework a significant step further, announcing on August 24, 2026, that Enterprise-managed authorization is now generally available. The update expands support …