The Canadian Centre for Cyber Security published three security advisories on 2026-07-17 covering critical vulnerabilities in FreePBX (unauthenticated RCE and SQL injection), VMware Avi Load Balancer (seven CVEs under VMSA-2026-0005), and Google Chrome for Desktop. All advisories urge immediate patching to the latest versions.
VMware
7 posts
Cyber Centre Daily Advisory Digest — 2026-07-17 (3 advisories) Cyber Centre Daily Advisory Digest — 2026-07-10 (4 advisories) The Canadian Centre for Cyber Security published four security advisories on 2026-07-10 covering critical vulnerabilities in Roundcube Webmail, Broadcom/VMware Tanzu products, Microsoft Edge, and Bitwarden Server. The most urgent advisory (AL25-007 Update 1) confirms ongoing exploitation of CVE-2024-42009 and CVE-2025-49113 in Roundcube Webmail, where attackers first obtain valid credentials via CVE-2024-42009 and then leverage CVE-2025-49113 (a Post-Auth RCE via PHP Object Deserialization) to achieve remote code execution. Both CVEs are listed in CISA's KEV catalog, and a proof-of-concept exists for CVE-2025-49113.
Cyber Centre Daily Advisory Digest — 2026-07-07 (6 advisories) The Canadian Centre for Cyber Security released a daily advisory digest containing 6 security advisories for 2026-07-07. The advisories cover critical vulnerabilities in a range of products including Android and Samsung mobile devices, VMware Tanzu, ABB industrial control systems, Django web framework, and Zimbra collaboration software. Administrators are urged to review the referenced bulletins and apply the necessary patches and mitigations.
Cyber Centre Daily Advisory Digest — 2026-06-23 (1 advisories) The Canadian Centre for Cyber Security issued an advisory regarding critical vulnerabilities across multiple Broadcom VMware Tanzu products, including RabbitMQ, Greenplum, and GemFire. Organizations are advised to review the Broadcom security advisories and apply the patched versions to mitigate potential exploitation risks.
Cyber Centre Daily Advisory Digest — 2026-06-08 (7 advisories) The Canadian Centre for Cyber Security released a daily digest covering seven security advisories from major vendors. Notably, Check Point has observed active exploitation of a critical authentication bypass vulnerability (CVE-2026-50751) affecting its VPN and Firewall products, requiring immediate mitigation.
Cyber Centre Daily Advisory Digest — 2026-05-06 (3 advisories) The Canadian Centre for Cyber Security released a daily digest highlighting three security advisories. The most critical is an actively exploited, unauthenticated buffer overflow vulnerability (CVE-2026-0300) affecting the Palo Alto Networks PAN-OS User-ID Authentication Portal. Additional routine security updates were announced for Google Chrome and VMware Tanzu GemFire Management Console.
BlueNoroff Uses ClickFix, Fileless PowerShell, and AI-Generated Fake Zoom Meetings to Target Web3 Sector Arctic Wolf Labs identified a highly targeted campaign by the DPRK-nexus threat actor BlueNoroff against the Web3 sector. The attackers utilize sophisticated social engineering, including AI-generated deepfakes and stolen webcam footage, to lure victims into fake Zoom or Teams meetings. Once engaged, a ClickFix clipboard injection attack deploys a fileless PowerShell C2 implant, leading to the theft of cryptocurrency wallets, browser credentials, and Telegram sessions.