Three critical VMware vulnerabilities (CVSS 9.3–9.8) enable authentication bypass, remote code execution, and VM escape; Broadcom recommends immediate patching as no workarounds are available.
Unauthenticated attackers can exploit multiple vulnerabilities in the Terraform MCP Server to bypass access control mechanisms, disclose sensitive information, and manipulate data.
The actively exploited “wp2shell” exploit chain combines WordPress vulnerabilities for unauthenticated remote code execution — upgrade to version 7.0.2 is required.
Zimbra 10.1.20 patches nine vulnerabilities, including a known SNMP-RCE flaw and four XSS weaknesses in the Classic Web Client that Russian groups have already exploited against Ukrainian infrastructure.
Password Podcast Episode 62 consolidates current standards discussions, Cisco Umbrella security vulnerabilities, and international attack methods for security operations.
The BSI warns of multiple Linux kernel vulnerabilities that enable DoS and privilege escalation and pose a significant threat in enterprise environments.