CVEFeed Newsroom – Latest Cybersecurity Updates

The "Cyber Newsroom Feed" module is a live feed of the latest cyber news enriched with CVE and vulnerability data. The feed is updated every 10 minutes and includes the latest news from the cyber security industry. The feed is designed to provide users with a comprehensive overview of the latest cyber security news and trends.

  • The Hacker News
Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation

Two new unpatched zero-day vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway appliances that allow remote code execution are being actively exploited in the wild, security firm watchTowr s ...

Published Date: Sep 27, 2026 (5 hours, 39 minutes ago)
  • The Hacker News
Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials

The Psychedelic Stealer malware distributed via compromised Ukrainian websites using ClickFix-style Cloudflare verification checks is part of a wider malware-as-a-service (MaaS) platform called Lunex. ...

Published Date: Sep 26, 2026 (19 hours, 4 minutes ago)
  • The Hacker News
Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells

Google is warning of renewed mass exploitation of a known security vulnerability in Oracle PeopleSoft as part of a campaign targeting multiple sectors globally. The ShinyHunters-linked activity involv ...

Published Date: Sep 26, 2026 (1 day, 1 hour ago)
  • The Hacker News
SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added two security flaws impacting Microsoft SharePoint and Mikrotik RouterOS to its Known Exploited Vulnerabilities (KEV) ca ...

Published Date: Sep 26, 2026 (1 day, 4 hours ago)
  • Kaspersky
CVE-2026-87902: Critical Vulnerability in WordPress

vulnerability CVE-2026-87902, a new critical vulnerability in the WordPress core, is already being actively exploited in real-world attacks. Editorial Team September 25, 2026 A critical vulnerability ...

Published Date: Sep 25, 2026 (1 day, 22 hours ago)
  • security.nl
Roundcube Webmail SQL Injection-lek misbruikt bij aanvallen

Een SQL Injection-kwetsbaarheid in Roundcube wordt misbruikt bij aanvallen. Dat laat het Canadese Centrum voor Cybersecurity weten. Roundcube is opensource-webmailsoftware en wordt door allerlei organ ...

Published Date: Sep 25, 2026 (2 days, 1 hour ago)
  • The Hacker News
Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild

The Canadian Centre for Cyber Security has warned that a now-patched Roundcube Webmail vulnerability is being actively exploited in the wild. The vulnerability in question is CVE-2026-48842 (CVSS scor ...

Published Date: Sep 25, 2026 (2 days, 3 hours ago)
  • security.nl
NCSC meldt actief misbruik van kritiek WordPress-lek: 'Update nu'

Aanvallers maken actief misbruik van een kritieke path traversal-kwetsbaarheid in WordPress waardoor websites zijn over te nemen, zo meldt het Nationaal Cyber Security Centrum (NCSC). Er is een update ...

Published Date: Sep 25, 2026 (2 days, 4 hours ago)
  • The Hacker News
WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV

The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added two critical security flaws impacting WSO2 and Adobe Commerce and Magento to its Known Exploited Vulnerabilities (K ...

Published Date: Sep 25, 2026 (2 days, 8 hours ago)
  • The Hacker News
Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions

A OnePlus 15 running the latest OxygenOS can be rooted by a malicious app the owner installs, one that asks for no special permissions. A researcher, Rasmus Moorats, chained two flaws in OnePlus's own ...

Published Date: Sep 24, 2026 (2 days, 19 hours ago)

Filters

Filter news that are affecting your technology stack
Showing 10 of 12360 Results