CVEFeed Newsroom – Latest Cybersecurity Updates
The "Cyber Newsroom Feed" module is a live feed of the latest cyber news enriched with CVE and vulnerability data. The feed is updated every 10 minutes and includes the latest news from the cyber security industry. The feed is designed to provide users with a comprehensive overview of the latest cyber security news and trends.
-
The Hacker News
Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone
Every release of the Unbound DNS resolver before 1.26.1 has a critical heap overflow in its DNSSEC validator, maintainer NLnet Labs said in an advisory on Wednesday. An attacker who controls a malicio ...
-
The Hacker News
BIND 9 Update Fixes 14 Flaws, Including an Unauthenticated Crash Over DNS-over-HTTPS
The Internet Systems Consortium (ISC) has released BIND 9.20.29 and 9.21.26 to fix fourteen security flaws it disclosed on 16 September in BIND 9, its open-source DNS server software. One of them affe ...
-
security.nl
Cisco waarschuwt voor misbruik van kritiek lek in Identity Services Engine
Cisco waarschuwt organisaties voor een kritieke kwetsbaarheid in de Identity Services Engine (ISE) waar aanvallers actief misbruik van maken. De CVSS-impactscore van het beveiligingslek is met de maxi ...
-
The Hacker News
Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks
Cisco has warned of a fresh maximum-severity security flaw impacting Identity Services Engine (ISE) that has come under active exploitation. The vulnerability, tracked as CVE-2026-76460 (CVSS score: 1 ...
-
TheCyberThrone
Cisco ISE and Secure Email Gateway Enter the KEV Spotlight
The latest Cisco security disclosures have put two enterprise security products under immediate scrutiny.Cisco Identity Services Engine (ISE) and Cisco Secure Email Gateway are affected by vulnerabil ...
-
Dark Reading
BragJack Attack Can Turn a Browser's Agentic AI Against It
5 Min ReadSource: Pattara via Alamy Stock PhotoA new type of proof-of-concept attack called BragJack can compromise five agentic browser environments and steal secrets: Google Chrome with Gemini, Micr ...
-
The Hacker News
Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution
A critical security flaw in Issabel Framework, a web-based framework for the open-source unified communications PBX software, has come under active exploitation. The vulnerability in question is CVE-2 ...
-
The Hacker News
Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers
Enterprises in Russia have emerged as the target of three threat activity clusters tracked as NightEagle, Hacking Cat, and Toy Ghouls, according to multiple reports from Kaspersky. The cybersecurity v ...
-
security.nl
300.000 WordPress-sites missen update voor misbruikt lek in Calender-plug-in
Zo'n 300.000 WordPress-sites missen een beveiligingsupdate voor een kritieke kwetsbaarheid in een plug-in waar aanvallers actief misbruik van maken, zo meldt cybersecuritybedrijf Wordfence. Via het be ...
-
The Hacker News
One Extension Could Hijack AI Assistants Across Chrome, Comet, Edge, Opera Neon and Claude
Security researchers at Forever Security have shown that one ordinary browser extension could take control of the AI assistants built into five Chromium-based products: Gemini Live in Chrome, Perplexi ...