CVEFeed Newsroom – Latest Cybersecurity Updates
The "Cyber Newsroom Feed" module is a live feed of the latest cyber news enriched with CVE and vulnerability data. The feed is updated every 5 minutes and includes the latest news from the cyber security industry. The feed is designed to provide users with a comprehensive overview of the latest cyber security news and trends.
-
The Hacker News
AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code
Hidden text on a web page was enough to make Kiro, AWS's agentic coding IDE, rewrite its own configuration file and run an attacker's code on a developer's machine, with no approval step able to stop ...
-
The Hacker News
Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC
A third SharePoint Server flaw patched by Microsoft as part of its Patch Tuesday update for July 2026 has come under active exploitation, per watchTowr. The vulnerability in question is CVE-2026-50522 ...
-
security.nl
Mozilla dicht kritieke Firefox-lekken een week later ook in ESR-versies
Mozilla heeft twee kritieke kwetsbaarheden in Firefox die remote code execution (RCE) mogelijk maken, en waarvoor publieke exploitcode bestaat, een week later ook in de ESR-versies van de browser gedi ...
-
The Hacker News
Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access
Threat actors have been observed exploiting a now-patched high-severity Palo Alto Networks PAN-OS vulnerability as an entry point to deploy Qilin (aka Agenda) ransomware on victim environments. Arctic ...
-
The Hacker News
Zimbra Patches Critical SNMP Command Injection and Four XSS Vulnerabilities
Zimbra has rolled out fixes to address multiple critical security issues, including a command injection flaw in the Simple Network Management Protocol (SNMP) monitoring component. As many as nine secu ...
-
security.nl
Actief misbruik van recent beveiligingslek in Microsoft SharePoint gemeld
Aanvallers maken actief misbruik van een kritieke kwetsbaarheid waardoor remote code execution (RCE) op Microsoft SharePoint-servers mogelijk is. Microsoft kwam precies een week geleden met beveiligin ...
-
The Hacker News
Open-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCs
An Android app that can draw over other windows and write to shared storage can slip instructions to the AI agent driving that phone, in text no human eye will ever see. Two more steps, and the same a ...
-
security.nl
Lek in firewalls Palo Alto Networks misbruikt bij ransomware-aanvallen
Een kwetsbaarheid in de firewalls van Palo Alto Networks wordt misbruikt bij ransomware-aanvallen. Dat laat cybersecuritybedrijf Arctic Wolf in een analyse weten. Via de kwetsbaarheid kan een aanvalle ...
-
The Cyber Express
Estée Lauder Confirms Cyberattack Affecting Personal Information
The Estée Lauder data breach has prompted the global cosmetics company to notify affected individuals after hackers exploited a vulnerability in Oracle E-Business Suite, a platform used for human reso ...
-
The Hacker News
WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning
Attackers have begun to exploit two critical vulnerabilities in WordPress that, when combined together, enable unauthenticated remote code execution (RCE) and complete compromise of vulnerable website ...