CVEFeed Newsroom – Latest Cybersecurity Updates

The "Cyber Newsroom Feed" module is a live feed of the latest cyber news enriched with CVE and vulnerability data. The feed is updated every 10 minutes and includes the latest news from the cyber security industry. The feed is designed to provide users with a comprehensive overview of the latest cyber security news and trends.

  • The Hacker News
Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation

Microsoft has released fixes for a maximum-severity security flaw in Azure AI Foundry that could be exploited to achieve privilege escalation. No customer action is required. The vulnerability, tracke ...

Published Date: Sep 18, 2026 (3 hours, 43 minutes ago)
  • The Hacker News
Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root

A critical vulnerability in Check Point's Security Management and Log Servers could allow an attacker without login credentials to run code as root on those servers over the network. The Security Mana ...

Published Date: Sep 17, 2026 (22 hours, 21 minutes ago)
  • The Hacker News
ThreatsDay: Self-Rewriting Agents, 800+ Flaws Patched, Insider SIM Swaps and 22 More New Stories

Attackers keep finding new keys. The funny part is that defenders keep inventing where to store them.This week, those keys sit in AI tools, exposed services, old bugs, weak logins, and software sold l ...

Published Date: Sep 17, 2026 (22 hours, 58 minutes ago)
  • The Hacker News
Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files

Malicious code running inside a Docker Sandboxes virtual machine on macOS could escape the project directory shared into it and read or change files anywhere else on the host, Docker warns in a securi ...

Published Date: Sep 17, 2026 (1 day ago)
  • The Hacker News
Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone

Every release of the Unbound DNS resolver before 1.26.1 has a critical heap overflow in its DNSSEC validator, maintainer NLnet Labs said in an advisory on Wednesday. An attacker who controls a malicio ...

Published Date: Sep 17, 2026 (1 day, 4 hours ago)
  • The Hacker News
BIND 9 Update Fixes 14 Flaws, Including an Unauthenticated Crash Over DNS-over-HTTPS

The Internet Systems Consortium (ISC) has released BIND 9.20.29 and 9.21.26 to fix fourteen security flaws it disclosed on 16 September in BIND 9, its open-source DNS server software. One of them affe ...

Published Date: Sep 17, 2026 (1 day, 8 hours ago)
  • security.nl
Cisco waarschuwt voor misbruik van kritiek lek in Identity Services Engine

Cisco waarschuwt organisaties voor een kritieke kwetsbaarheid in de Identity Services Engine (ISE) waar aanvallers actief misbruik van maken. De CVSS-impactscore van het beveiligingslek is met de maxi ...

Published Date: Sep 17, 2026 (1 day, 8 hours ago)
  • The Hacker News
Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks

Cisco has warned of a fresh maximum-severity security flaw impacting Identity Services Engine (ISE) that has come under active exploitation. The vulnerability, tracked as CVE-2026-76460 (CVSS score: 1 ...

Published Date: Sep 17, 2026 (1 day, 9 hours ago)
  • TheCyberThrone
Cisco ISE and Secure Email Gateway Enter the KEV Spotlight

The latest Cisco  security disclosures have put two enterprise security products under immediate scrutiny.Cisco Identity Services Engine (ISE) and Cisco Secure Email Gateway are affected by vulnerabil ...

Published Date: Sep 17, 2026 (1 day, 13 hours ago)
  • Dark Reading
BragJack Attack Can Turn a Browser's Agentic AI Against It

5 Min ReadSource: Pattara via Alamy Stock PhotoA new type of proof-of-concept attack called BragJack can compromise five agentic browser environments and steal secrets: Google Chrome with Gemini, Micr ...

Published Date: Sep 16, 2026 (1 day, 23 hours ago)

Filters

Filter news that are affecting your technology stack
Showing 10 of 12306 Results