CVEFeed Newsroom – Latest Cybersecurity Updates
The "Cyber Newsroom Feed" module is a live feed of the latest cyber news enriched with CVE and vulnerability data. The feed is updated every 10 minutes and includes the latest news from the cyber security industry. The feed is designed to provide users with a comprehensive overview of the latest cyber security news and trends.
-
cert.pl
Vulnerability in GNU wget software
Vulnerability in GNU wget software CVE ID CVE-2026-16599 Publication date 25 August 2026 Vendor GNU Product wget Vulnerable versions All through 1.25.0 Vulnerability type (CWE) Unchecked input for loo ...
-
TheCyberThrone
CISA adds TrueConf and Zimbra and Oracle WebLogic to KEV
August 25, 2026CISA has added multiple vulnerabilities affecting TrueConf Server, Zimbra Collaboration Suite and Oracle HTTP Server/WebLogic Server Proxy Plug-in to its Known Exploited Vulnerabilities ...
-
The Hacker News
A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw
Oasis Security has disclosed a weakness in NVIDIA NemoClaw that could let an attacker-controlled webpage take unauthenticated control of the local Ollama instance serving an AI agent and plant hidden ...
-
security.nl
Konami patcht kritiek RCE-beveiligingslek in Metal Gear Online 3
Gameontwikkelaar Konami heeft een kritieke kwetsbaarheid in het spel Metal Gear Online 3 gepatcht waardoor aanvallers code op het systeem van spelers konden uitvoeren als die in een lobby van de aanva ...
-
security.nl
DrayTek dicht lekken die aanvaller commando's als root laten uitvoeren
Netwerkfabrikant DrayTek heeft meerdere kwetsbaarheden in switches en access points verholpen, waaronder een aantal die aanvallers commando's als root laten uitvoeren en remote code execution mogelijk ...
-
The Hacker News
Marimo Notebook Flaw Could Run MCP Commands Before Cells Execute in Edit Mode
Marimo has addressed a high-severity security flaw in its notebook software that allowed an attacker to execute an attacker-supplied Model Context Protocol (MCP) command in a specially crafted noteboo ...
-
The Cyber Express
Ledger Fixes Ethereum App Flaw as Disclosure Timeline Is Disputed
Ledger CTO Charles Guillemet said on Aug. 23, 2026, that the company had fixed a clear-signing flaw in its Ethereum app two weeks before security firm TestMachine publicly disclosed the issue. As of A ...
-
The Hacker News
Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access
Bad actors are attempting to exploit two severe unauthenticated authentication bypasses in the Xecurify miniOrange SAML 2.0 Single Sign On plugin that make it possible for an attacker to sign in as an ...
-
security.nl
Kritiek lek in Oracle HTTP Server en WebLogic-plug-in misbruikt bij aanvallen
Aanvallers maken misbruik van een kritieke kwetsbaarheid in Oracle HTTP Server en de Oracle Weblogic Server Proxy-plug-in waardoor systemen op afstand zijn over te nemen. De CVSS-impactscore van het b ...
-
The Hacker News
Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a maximum-severity security flaw impacting Oracle HTTP Server and Oracle WebLogic Server to its Known Exploited Vulnera ...