CVEFeed Newsroom – Latest Cybersecurity Updates
The "Cyber Newsroom Feed" module is a live feed of the latest cyber news enriched with CVE and vulnerability data. The feed is updated every 5 minutes and includes the latest news from the cyber security industry. The feed is designed to provide users with a comprehensive overview of the latest cyber security news and trends.
-
Proofpoint
TA488 Targets Zimbra Mailservers with Half-Click Exploits
July 24, 2026 Greg Lesnewich, Nick Attfield, Konstantin Klinger, Saher Naumaan, Mark Kelly, and the Proofpoint Threat Research Team Proofpoint is releasing this report in coordination with NSA and FBI ...
-
The Hacker News
Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller
Researchers H0j3n and Aniq Fakhrul published a working exploit on July 24 that lets a low-privileged Active Directory user obtain a certificate for a Domain Controller and authenticate as that machine ...
-
The Hacker News
ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link
Cybersecurity researchers have disclosed a critical vulnerability in OpenAI's ChatGPT Workspace Agents that could have allowed a single phishing link to stealthily build, authorize, and deploy an auto ...
-
The Hacker News
Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's Servers
A crafted SVG submitted to Bing's image search ran commands as NT AUTHORITY\SYSTEM on Microsoft's production image-processing workers, and as root on the Linux machines in the same fleet. XBOW's testi ...
-
cert.pl
Vulnerability in Apereo CAS Client software
Vulnerability in Apereo CAS Client software CVE ID CVE-2026-15243 Publication date 24 July 2026 Vendor Apereo Product Java Apereo CAS ClientJasig CAS Client Vulnerable versions 4.1.0 Java Apereo CAS C ...
-
The Hacker News
Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry
Someone installed a popular AI assistant on a rented server, switched off the setting that makes it ask permission before running risky commands, and pointed it at Thailand's Ministry of Finance, whic ...
-
cert.pl
Vulnerabilities in GNU coreutils software
Vulnerabilities in GNU coreutils software CVE ID CVE-2026-56391 Publication date 24 July 2026 Vendor GNU Product coreutils Vulnerable versions From 9.5 through 9.11 Vulnerability type (CWE) Out-of-bou ...
-
The Hacker News
NodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private Chats
Eight security flaws in NodeBB went public on Wednesday, along with the code to exploit them. Aikido Security rates all eight as high severity and says its AI pentest agents found them in a six-hour r ...
-
The Hacker News
Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say
Redis shipped seven security releases on July 23 after researchers published authenticated RCE PoCs for stock Redis 6.2.22, 7.4.9, 8.6.4, and 8.8.0. All four chains require RESTORE. The Streams chains ...
-
The Hacker News
Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks
The Computer Emergency Response Team of Ukraine (CERT-UA) has warned of a new campaign that involves the use of a malicious program that's dressed up as a Notepad++ plugin to compromise Windows system ...