Multiple VMware Stored XSS Vulnerabilities Allow Attackers to Inject Malicious Scripts

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 8, 2026 Broadcom has disclosed three stored cross-site scripting (XSS) vulnerabilities affecting VMware Cloud Foundation Operations and several related products, warning that authenticated attackers could inject malicious scripts to perform administrative actions within the environment. Tracked as CVE-2026-41722, CVE-2026-41723, …

UniFi OS Server Critical RCE Chain Allows Root Access Without Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 8, 2026 A critical vulnerability chain in the UniFi OS Server software has put thousands of organizations at serious risk. Researchers confirmed that an attacker can gain full root access to affected devices without a single credential, turning one …

Critical Redis RCE Vulnerability Enable Attackers to Gain Complete Control to Host Server

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 8, 2026 In May 2026, Redis developers fixed a dangerous post-authentication remote code execution vulnerability, dubbed DarkReplica (CVE-2026-23631), that allowed attackers to gain full control of a Redis host. Redis provides powerful server-side Lua engines, allowing administrators to run …

Microsoft Warns Claude Code GitHub Action Could Leak CI/CD Workflow Secrets

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 8, 2026 AI-powered coding tools are rapidly changing how developers build and ship software. But as these tools enter everyday development pipelines, they are also opening new doors for attackers. A recently uncovered vulnerability in a widely used AI …

Hackers Can Hijack Claude Code MCP Traffic to Steal OAuth Tokens

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A five-step attack chain that silently redirects Claude Code’s Model Context Protocol (MCP) traffic through attacker-controlled infrastructure, intercepting OAuth bearer tokens that grant persistent, broadly scoped access to connected SaaS platforms like Jira, Confluence, and GitHub with no patch incoming …

New EDRChoker Tool Uses Policy-Based Quality of Service to Block EDR Processes

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 7, 2026 A newly released open-source red team tool called EDRChoker introduces a novel technique for silencing cloud-connected Endpoint Detection and Response (EDR) agents not by killing their processes or injecting code, but by quietly choking their network bandwidth to near-zero …

Instagram Fixes Password Reset Flaw That Exposes User Emails and Phone Numbers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 7, 2026 A critical logic bug in Instagram’s web-based password reset flow on June 6, 2026, exposed unredacted email addresses and phone numbers associated with user accounts, including those belonging to high-profile individuals such as Meta CEO Mark Zuckerberg …

CISA Warns of Linux Kernel Improper Authentication Vulnerability Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 7, 2026 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical Linux kernel vulnerability, tracked as CVE-2022-0492, to its Known Exploited Vulnerabilities (KEV) catalog, warning that the flaw is being actively leveraged in real-world attacks. The …

New ChatGPT Lockdown Mode to Mitigate Prompt Injection and Data Exfiltration Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 6, 2026 OpenAI has released ChatGPT Lockdown Mode, a new security feature designed to limit outbound network access and reduce the risk of data exfiltration from prompt-injection attacks. The feature is now available to eligible personal accounts, self-serve ChatGPT …

CISA Warns of SolarWinds Serv-U Vulnerability Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 6, 2026 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical SolarWinds Serv-U vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, warning that threat actors are actively exploiting the flaw in the wild. Tracked as CVE-2026-28318, …