CVEFeed Newsroom – Latest Cybersecurity Updates
The "Cyber Newsroom Feed" module is a live feed of the latest cyber news enriched with CVE and vulnerability data. The feed is updated every 10 minutes and includes the latest news from the cyber security industry. The feed is designed to provide users with a comprehensive overview of the latest cyber security news and trends.
-
The Hacker News
MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key
Two MikroTik RouterOS SSH vulnerabilities chained together let attackers take full administrative control of Internet-exposed routers without a password, SSH key, or completed authentication. The chai ...
-
security.nl
Check Point waarschuwt voor Path Traversal kwetsbaarheid
Check Point waarschuwt voor een Path Traversal en File Upload kwetsbaarheid in de Check Point Management Server. Met behulp van deze kwetsbaarheid (CVE 2026 93616) kunnen aanvallers, zonder enige vorm ...
-
cert.pl
Vulnerability in WEBCON BPS software
Vulnerability in WEBCON BPS software CVE ID CVE-2026-92419 Publication date 23 September 2026 Vendor WEBCON Product WEBCON BPS Vulnerable versions From 2024.1.1.145 before 2025.2.1.177From 2026.1.1.1 ...
-
The Hacker News
New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control
A flaw in cPanel's CalDAV and CardDAV service lets anyone with a cPanel hosting account run code as root and take "full control of the server," the company said on September 22. A second bug in the WP ...
-
The Hacker News
Exploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container Escape
A use-after-free in the Linux kernel's AF_UNIX socket subsystem can be used to escape a container and gain root on the host, security firm DepthFirst said in research published September 22. The flaw, ...
-
security.nl
Chrome 154 verhelpt in totaal 108 kwetsbaarheden
Google heeft een nieuwe Chrome versie beschikbaar gesteld waarin 108 kwetsbaarheden zijn verholpen. Van de 108 kwetsbaarheden worden 11 aangemerkt als "critical", 25 als "high", 47 als "medium" en 25 ...
-
security.nl
CISA en NCSC waarschuwen voor kwetsbaarheid in Arista VeloCloud
Het Amerikaanse Cybersecurity and Infrastructure Security Agency (CISA) en het Nederlandse Nationaal Cyber Security Centrum (NCSC) waarschuwen voor een actief aangevallen kwetsbaarheid in Arista VeloC ...
-
The Hacker News
F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers
Attackers are exploiting a critical flaw in F5 BIG-IP Access Policy Manager (APM) that lets them run code on a BIG-IP system without logging in, F5 says. The flaw, CVE-2026-94127, affects only systems ...
-
The Hacker News
Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware
A Chinese threat actor codenamed UTA0565 has been observed exploiting the recently disclosed Google Chrome-Microsoft Windows exploit chain as zero-days through fake websites. The attacks, detected on ...
-
security.nl
NCSC waarschuwt voor actief misbruikt zerodaylek in F5 BIG-IP
Het Nationaal Cyber Security Centrum (NCSC) waarschuwt organisaties voor een ernstige kwetsbaarheid in F5 BIG-IP Access Policy Manager (APM) die monenteel actief wordt misbruikt. F5 heeft beveiligings ...