Check Point VPN 0-day Vulnerability Exploited in the Wild to Deploy Ransomware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 8, 2026 Check Point Research has uncovered active exploitation of CVE-2026-50751, a critical authentication bypass vulnerability (CVSS 9.3) in Check Point Remote Access VPN and Mobile Access deployments, with …

UNC3753 Attacking US Law Firms Using Vishing and RMM Tools to Exfiltrate Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 8, 2026 A sophisticated cybercriminal group known as UNC3753 has been running an aggressive campaign against US law firms since early 2026, using phone calls, screen-sharing tricks, and remote …

OWASP Releases AI Security Report to Empower Security Professionals with New Tools

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 8, 2026 OWASP has released the “State of Agentic AI Security and Governance v2.01” report, a technical blueprint aimed at security teams racing to secure rapidly proliferating autonomous AI …

Multiple VMware Stored XSS Vulnerabilities Allow Attackers to Inject Malicious Scripts

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 8, 2026 Broadcom has disclosed three stored cross-site scripting (XSS) vulnerabilities affecting VMware Cloud Foundation Operations and several related products, warning that authenticated attackers could inject malicious scripts to …

Critical Redis RCE Vulnerability Enable Attackers to Gain Complete Control to Host Server

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 8, 2026 In May 2026, Redis developers fixed a dangerous post-authentication remote code execution vulnerability, dubbed DarkReplica (CVE-2026-23631), that allowed attackers to gain full control of a Redis host. …

Microsoft Warns Claude Code GitHub Action Could Leak CI/CD Workflow Secrets

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

June 8, 2026 AI-powered coding tools are rapidly changing how developers build and ship software. But as these tools enter everyday development pipelines, they are also opening new doors for …

Hackers Can Hijack Claude Code MCP Traffic to Steal OAuth Tokens

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A five-step attack chain that silently redirects Claude Code’s Model Context Protocol (MCP) traffic through attacker-controlled infrastructure, intercepting OAuth bearer tokens that grant persistent, broadly scoped access to connected SaaS …