21 0-Day Vulnerabilities in FFmpeg Enables Remote Code Execution Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 9, 2026 An autonomous security agent uncovered 21 zero-day vulnerabilities in FFmpeg, the world’s most widely deployed media processing library, including a critical RCE-capable heap buffer overflow reachable with …

New China-Linked Threat Cluster OP-512 Targets IIS Servers With Cryptographically Unique Web Shell Framework

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 8, 2026 A newly identified threat cluster with suspected ties to China has been caught targeting Internet Information Services (IIS) web servers using a purpose-built web shell framework. Tracked …

Check Point VPN 0-day Vulnerability Exploited in the Wild to Deploy Ransomware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 8, 2026 Check Point Research has uncovered active exploitation of CVE-2026-50751, a critical authentication bypass vulnerability (CVSS 9.3) in Check Point Remote Access VPN and Mobile Access deployments, with …

UNC3753 Attacking US Law Firms Using Vishing and RMM Tools to Exfiltrate Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 8, 2026 A sophisticated cybercriminal group known as UNC3753 has been running an aggressive campaign against US law firms since early 2026, using phone calls, screen-sharing tricks, and remote …

OWASP Releases AI Security Report to Empower Security Professionals with New Tools

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 8, 2026 OWASP has released the “State of Agentic AI Security and Governance v2.01” report, a technical blueprint aimed at security teams racing to secure rapidly proliferating autonomous AI …

Multiple VMware Stored XSS Vulnerabilities Allow Attackers to Inject Malicious Scripts

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 8, 2026 Broadcom has disclosed three stored cross-site scripting (XSS) vulnerabilities affecting VMware Cloud Foundation Operations and several related products, warning that authenticated attackers could inject malicious scripts to …

Critical Redis RCE Vulnerability Enable Attackers to Gain Complete Control to Host Server

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 8, 2026 In May 2026, Redis developers fixed a dangerous post-authentication remote code execution vulnerability, dubbed DarkReplica (CVE-2026-23631), that allowed attackers to gain full control of a Redis host. …