CVEFeed Newsroom – Latest Cybersecurity Updates
The "Cyber Newsroom Feed" module is a live feed of the latest cyber news enriched with CVE and vulnerability data. The feed is updated every 10 minutes and includes the latest news from the cyber security industry. The feed is designed to provide users with a comprehensive overview of the latest cyber security news and trends.
-
The Hacker News
Parallels Desktop Flaw Lets Non-Admin Mac Users Gain Root, but Intel Macs Can't Install Fix
Parallels Desktop for Mac has a flaw that lets an ordinary local account run code as root, the highest level of access on a Mac, software company JFrog said this week. The attack needs code already ru ...
-
security.nl
Kritiek ConnectWise ScreenConnect-lek gebruikt bij aanvallen meldt VS
Een kritieke kwetsbaarheid in ScreenConnect van softwareleverancier ConnectWise wordt actief gebruikt bij aanvallen, aldus het Amerikaanse cyberagentschap CISA. Op 8 september verscheen er een beveili ...
-
cert.pl
Vulnerabilities in WNC T-Mobile 5G Box IDU routers
Vulnerabilities in WNC T-Mobile 5G Box IDU routers CVE ID CVE-2026-40854 Publication date 16 September 2026 Vendor WNC Product T-Mobile 5G Box IDU Vulnerable versions All before 1.1.0.651412 Vulnerabi ...
-
The Hacker News
Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted Exploitation
Google has disclosed that a high-severity security flaw in its Pixel Cellular Modem has come under exploitation in the wild. The vulnerability, tracked as CVE-2026-58704 (CVSS score: 8.0), is a privil ...
-
The Hacker News
Acronis cPanel Backup Plugin Vulnerability Exploited in Targeted Attacks
Acronis has warned that a high-severity security flaw in its Backup plugin for cPanel and Web Host Manager (WHM) deployments has been exploited in the wild. The vulnerability, tracked as CVE-2026-8788 ...
-
security.nl
Google waarschuwt voor actief misbruik van modem-lek in Pixel-telefoons
Aanvallers maken actief misbruik van een kwetsbaarheid in Pixel-telefoons, zo waarschuwt Google. Er zijn beveiligingsupdates uitgebracht om het probleem te verhelpen. Via de kwetsbaarheid (CVE-2026-58 ...
-
The Hacker News
Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells
Threat actors are exploiting a critical security flaw in WooCommerce Wholesale Lead Capture, a premium WordPress plugin that has more than 6,000 active installs. "This vulnerability can be leveraged b ...
-
The Hacker News
Active Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens
A critical security flaw in WSO2 API Manager has come under active exploitation in the wild, according to findings from watchTowr. The vulnerability, tracked as CVE-2026-5430 (CVSS score: 9.8/10.0), i ...
-
TheCyberThrone
Oracle September 2026 Security Patch Tuesday
673 Security Patches Across the EnterpriseQuick ReferenceRelease Date: 15 September 2026Release: Oracle September 2026 Critical Security Patch Update (CSPU)Security Patches: 673Highest CVSS: 10.0Majo ...
-
The Hacker News
Human Attacker Exploits Marimo RCE, Reaches SSH Bastion in Eight Seconds
With artificial intelligence (AI) shrinking the window between vulnerability discovery and exploitation and lowering the barrier to entry for bad actors, new findings from Sysdig show that skilled hum ...