CVEFeed Newsroom – Latest Cybersecurity Updates
The "Cyber Newsroom Feed" module is a live feed of the latest cyber news enriched with CVE and vulnerability data. The feed is updated every 5 minutes and includes the latest news from the cyber security industry. The feed is designed to provide users with a comprehensive overview of the latest cyber security news and trends.
-
security.nl
N-able komt na aanvallen op N-central RMM-servers met tweede hotfix
N-able is na aanvallen op N-central RMM-servers met een tweede hotfix gekomen die klanten moeten installeren. Ook wordt aangeraden om te controleren of er geen verkeer naar CloudflareTunnel is. N-cent ...
-
The Hacker News
New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP
WordPress has fixed a pre-authentication reflected cross-site scripting (XSS) flaw in its login screen that affects every version of the content management system. pwn.ai demonstrated how the flaw can ...
-
The Hacker News
18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers
A use-after-free bug in Linux's SCTP networking code can be turned into full root on a host, and Tencent researchers say they used it to escape a container and reach the machine underneath. The flaw h ...
-
The Hacker News
AI-Assisted HTTP Terminator Finds Novel HTTP Desync Techniques and Apache Zero-Day
PortSwigger says HTTP Terminator, an artificial intelligence (AI)-assisted research system built by James Kettle, generated and proved new HTTP desynchronization techniques after exploring 30,000 cand ...
-
The Hacker News
New NatJack Attacks Hijack TCP Sessions and Spoof DNS by Manipulating NAT Tables
Security researcher Malcolm Stagg has disclosed a new attack class called NatJack that manipulates network address translation (NAT) connection state to hijack active TCP sessions, spoof DNS responses ...
-
The Hacker News
Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets
A GitHub issue opened by an account with no repository privileges was enough to execute code on the CI runners behind Anthropic's and Google's own coding-agent repositories. On OpenAI's, it was enough ...
-
security.nl
WinRAR-lek gebruikt bij ransomware-aanvallen, meldt Amerikaanse overheid
Een bekende kwetsbaarheid in het populaire archiveringsprogramma WinRAR wordt gebruikt bij ransomware-aanvallen, zo meldt het Amerikaanse cyberagentschap CISA. Het beveiligingslek, aangeduid als CVE-2 ...
-
security.nl
Apple dicht Screen Sharing-lek dat aanvaller toegang tot Macs kan geven
Apple heeft een beveiligingsupdate voor macOS uitgebracht die een kwetsbaarheid verhelpt waardoor ongeauthenticeerde aanvallers toegang tot Macs kunnen krijgen. Het beveiligingslek (CVE-2026-65400) is ...
-
OS X Daily
Security Updates MacOS Tahoe 26.6.1, macOS Sequoia 15.7.9, macOS Sonoma 14.8.9 Released for Mac
Apple has released security updates for MacOS Tahoe 26.6.1, MacOS Sequoia 15.7.9, and MacOS Sonoma 14.8.9, each addressing the same security flaw relating to the Screen Sharing service where an attack ...
-
The Hacker News
New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts
Zapscape, a new Linux kernel vulnerability, could allow an attacker with kernel privileges inside an L1 guest virtual machine (VM) to escape KVM isolation and execute code on the host. The risk applie ...