Skip to content

Category: Beveiligingsnieuws

VMware critical flaws patched: auth bypass & escape

Broadcom released emergency updates for VMware products to fix multiple VMware critical flaws. Patches address authentication bypass, directory traversal, code execution, and a virtual machine escape scenario.

AnySign4PC watering-hole: Backdoors without prompts

Authorities and security firms report a state-sponsored campaign that compromised trusted South Korean websites. The attackers abused AnySign4PC vulnerabilities so visitors could be infected without downloads or prompts.

Microsoft Copilot for Word Hidden Prompts Risk

A researcher described how hidden instructions in Word files can be copied into Microsoft 365 Copilot drafts and alter document content. The issue requires a Copilot editing or drafting step rather than malware execution.

JetBrains TeamCity RCE: CVE-2026-63077 Explained

JetBrains warns that CVE-2026-63077 can allow authentication bypass and lead to TeamCity remote code execution on TeamCity On-Premises. Cloud customers don’t need action, but administrators should patch quickly.

AI-Based Misuse and Phishing: ThreatsDay Overview

This ThreatsDay roundup shows how AI-based abuse and social engineering increasingly pair with real intrusion paths. From Chrome weaknesses to DNS hijacking and credential stuffing—here are the key takeaways.

Samsung stops Smart TV proxies: why it matters

New research shows that some Samsung Smart TV apps may contain Smart TV proxies. Samsung is taking steps and removing apps that share users’ internet connections with third parties.

SonicWall SMA1000: patched flaws behind ransomware

Two newly reported SonicWall SMA1000 vulnerabilities (CVE-2026-15409 and CVE-2026-15410) have been exploited in ransomware incidents. Security teams urge rapid patching and active threat hunting.