Critical VMware Workstation and Fusion Bugs Let Attackers Break Out of the Virtual Machine
Broadcom has patched two vulnerabilities in VMware Workstation and Fusion that allow an attacker with access to a guest virtual machine to execute code on the underlying host,...
GitSpawn Turns Booby-Trapped Repositories Into Silent Code Execution Across AI Coding Tools
GitSpawn weaknesses allow specially prepared project folders to execute local commands when AI coding agents perform routine Git checks. Several vendors have patched variants, but researchers say four...
New WhatsApp Video Call Trick Bypasses Android Lock Screens to Expose Your Photos
A newly disclosed WhatsApp flaw lets anyone answer a video call on a locked Android phone and, through the in-call background editor, browse the device's entire photo gallery...
High-Severity Cleo Harmony Bug Lets Attackers Forge Their Way to Admin Access
A high-severity flaw in Cleo Harmony's JWT refresh-token handling, tracked as CVE-2026-84115, lets remote attackers escalate privileges to admin level with a working exploit already public. Cleo has...
Attackers Exploit Critical Langflow and Rails Flaws to Hunt Cloud Secrets
Attackers are actively exploiting critical flaws in Langflow and Ruby on Rails, with observed activity focused on credentials, application secrets and paths to remote code execution. Defenders should...
Critical Artifactory Bypass Is Being Used to Mint Administrator Tokens
A critical JFrog Artifactory authentication bypass is under active exploitation, with attackers reportedly creating administrator tokens on vulnerable servers. Self-hosted customers should upgrade immediately, revoke suspicious credentials and...
BGP Hijack Poisoned Virtualizor Updates and Put Hosting Servers at Root-Level Risk
A routing hijack diverted Softaculous infrastructure and enabled a malicious Virtualizor update to reach a small number of hosting servers. Because update packages lacked cryptographic verification, valid TLS...
D-Link Fixes Router Flaws That Exposed Admin and Wi-Fi Credentials on Local Networks
D-Link has patched access-control failures in the DIR-X1860Z that could let an unauthenticated local attacker reset the administrator password and retrieve wireless credentials. Owners should install the corrected...