Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
Broadcom released security updates for multiple critical VMware vulnerabilities affecting ESX, vCenter, Workstation, and Fusion. Three critical flaws include: CVE-2026-59309 (CVSS 9.8), an authentication bypass in vCenter allowing unauthorized network access; CVE-2026-59310 (CVSS 9.8), a directory-traversal vulnerability in vCenter enabling arbitrary code execution; and CVE-2026-47876 (CVSS 9.3), a use-after-free vulnerability in Workstation and Fusion allowing VM escape.
Broadcom has issued urgent security updates to address multiple critical vulnerabilities affecting VMware products, including ESX, vCenter, Workstation, and Fusion. Three of these flaws are rated critical, with CVSS scores ranging from 9.8 to 9.3.
If you feel like your phone has turned into a scam megaphone, you’re not alone.
Robocalls, increasingly enhanced by artificial intelligence (AI), remain a significant threat to consumers, with spoofed caller IDs making scams harder to detect. A recent investigation by Transaction Network Services (TNS) reveals that while major telecom providers have adopted the STIR/SHAKEN framework—a cryptographic system designed to authenticate caller IDs—many smaller providers lag behind.
This article examines the rise of AI-enhanced robocalls and the ongoing problem of caller ID spoofing. It notes that while major carriers have adopted STIR/SHAKEN standards, smaller providers are falling behind, leaving vulnerabilities for scammers to exploit.
A joint cybersecurity advisory uncovers the relationship between a state-sponsored hacking group and the Gunra ransomware operation, warning of coordinated attacks against Korean entities.