Security news.
Today's security landscape highlights critical vulnerabilities across major platforms and increased activity from nation-state actors. Patches are available for significant flaws in VMware products and Azure Cosmos DB, while North Korean groups are linked to sophisticated supply chain and malvertising campaigns.
VMware fixes critical auth bypass and VM escape flaws
Broadcom released security updates for VMware vCenter, ESX, Workstation, and Fusion, addressing three critical vulnerabilities that could allow authentication bypass, arbitrary code execution, or VM escape.
Azure Cosmos DB flaw exposed platform-wide key
A critical vulnerability, codenamed "CosmosEscape," in Azure Cosmos DB could have allowed attackers to escape the Gremlin query sandbox and gain full read/write access to databases across customer tenants.
Amazon links NPM supply-chain attacks to North Korean hackers
Amazon has attributed multiple high-profile open-source software supply chain attacks targeting the Node Package Manager (npm) ecosystem, specifically the `debug` and `chalk` packages, to North Korean threat actors.
DPRK-linked macOS malvertising delivers crypto-stealing malware
Threat actors tied to North Korea are using a sophisticated macOS malvertising campaign, redirecting users to fake update pages to deliver crypto-stealing malware as part of the "Contagious Interview" campaign.
Microsoft Teams vishing attacks deploy Chaos ransomware
Threat actors are impersonating IT support in Microsoft Teams calls to gain remote access to corporate devices and deploy Chaos ransomware against North American organizations.
Critical Ruflo flaw allows rogue AI swarm generation
A critical vulnerability in the AI hosting platform Ruflo could allow unauthenticated attackers to send HTTP requests to an exposed endpoint, executing commands inside the MCP bridge container and potentially spawning malicious AI agent swarms.
Cisco warns of exploited FMC static credential zero-day
Cisco has issued a warning about active exploitation of a high-severity static credential vulnerability (CVE-2026-20316) in Secure Firewall Management Center (FMC), leading to unauthorized access.
CISA warns of critical RCU II+/Multiload II+ vulnerability
A successful exploit of CVE-2026-12562 in Toptech Systems RCU II+ and Multiload II+ could grant full system control, allowing access or manipulation of connected networks and resources.