VMware Stored XSS Flaws Put Enterprise Environments at Risk
VMware has disclosed three high-severity security vulnerabilities affecting VMware Cloud Foundation (VCF) Operations that could allow attackers to inject malicious scripts into management interfaces. The vulnerabilities, tracked as CVE-2026-41722, CVE-2026-41723, [...]
Hackers Exploit Trusted Tools Malware for Attacks
Cybercriminals are increasingly abusing legitimate system tools to launch Trusted Tools Malware attacks while avoiding detection. According to a recent Q1 2026 Cyber Risk Report from ANY.RUN, attackers are relying [...]
Critical UniFi OS Vulnerabilities Allow Root RCE
Ubiquiti has released security updates for three critical vulnerabilities affecting UniFi OS that could allow attackers to gain full control of vulnerable systems without needing a username, password, or any [...]
Stolen Gemini API Keys Power Automated Telegram Campaign
Researchers have uncovered a long-running operation in which a single threat actor used stolen Google Gemini API keys and modified AI tools to automate content creation, fraud activities, and online [...]
Meta AI Flaw Linked to Instagram Password Resets
A recently disclosed issue involving Meta’s AI-powered support system has raised concerns about the security of Instagram accounts. Researchers claim that attackers were able to abuse the platform’s account recovery [...]