CVEFeed Newsroom – Latest Cybersecurity Updates

The "Cyber Newsroom Feed" module is a live feed of the latest cyber news enriched with CVE and vulnerability data. The feed is updated every 5 minutes and includes the latest news from the cyber security industry. The feed is designed to provide users with a comprehensive overview of the latest cyber security news and trends.

  • cert.pl
Vulnerability in DaveGamble cJSON library

Vulnerability in DaveGamble cJSON library CVE ID CVE-2026-16554 Publication date 27 July 2026 Vendor DaveGamble Product cJSON Vulnerable versions 1.7.19 Vulnerability type (CWE) Integer overflow or wr ...

Published Date: Jul 27, 2026 (21 minutes ago)
  • The Cyber Express
Two Old Oj Flaws Chained to Trigger GitLab Remote Code Execution

A newly disclosed GitLab vulnerability has revealed how two long-standing memory-safety flaws in the widely used Ruby JSON parsing library, Oj, can be combined to achieve remote code execution on defa ...

Published Date: Jul 27, 2026 (22 minutes ago)
  • security.nl
Honderden Microsoft SharePoint-servers bevatten actief misbruikte lekken

Honderden Microsoft SharePoint-servers die vanaf het internet toegankelijk zijn bevatten bekende kwetsbaarheden waar aanvallers op dit moment actief misbruik van maken. Het gaat ook om 25 SharePoint-s ...

Published Date: Jul 27, 2026 (2 hours, 51 minutes ago)
  • The Hacker News
Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available

Security firms ThreatBook and Imperva say attackers are targeting a critical flaw in Fastjson, Alibaba's JSON library for Java. In affected Spring Boot applications, a malicious JSON request can execu ...

Published Date: Jul 25, 2026 (1 day, 22 hours ago)
  • The Hacker News
Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE

Threat actors linked to the Cl0p (aka Chubby Scorpius, FIN11, Graceful Spider, and Lace Tempest) ransomware campaign are exploiting flaws in internet-exposed PTC Windmill and FlexPLM deployments as pa ...

Published Date: Jul 25, 2026 (2 days, 1 hour ago)
  • Proofpoint
TA488 Targets Zimbra Mailservers with Half-Click Exploits

July 24, 2026 Greg Lesnewich, Nick Attfield, Konstantin Klinger, Saher Naumaan, Mark Kelly, and the Proofpoint Threat Research Team Proofpoint is releasing this report in coordination with NSA and FBI ...

Published Date: Jul 24, 2026 (2 days, 20 hours ago)
  • The Hacker News
Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller

Researchers H0j3n and Aniq Fakhrul published a working exploit on July 24 that lets a low-privileged Active Directory user obtain a certificate for a Domain Controller and authenticate as that machine ...

Published Date: Jul 24, 2026 (2 days, 21 hours ago)
  • The Hacker News
ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link

Cybersecurity researchers have disclosed a critical vulnerability in OpenAI's ChatGPT Workspace Agents that could have allowed a single phishing link to stealthily build, authorize, and deploy an auto ...

Published Date: Jul 24, 2026 (2 days, 23 hours ago)
  • The Hacker News
Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's Servers

A crafted SVG submitted to Bing's image search ran commands as NT AUTHORITY\SYSTEM on Microsoft's production image-processing workers, and as root on the Linux machines in the same fleet. XBOW's testi ...

Published Date: Jul 24, 2026 (2 days, 23 hours ago)
  • cert.pl
Vulnerability in Apereo CAS Client software

Vulnerability in Apereo CAS Client software CVE ID CVE-2026-15243 Publication date 24 July 2026 Vendor Apereo Product Java Apereo CAS ClientJasig CAS Client Vulnerable versions 4.1.0 Java Apereo CAS C ...

Published Date: Jul 24, 2026 (3 days ago)

Filters

Filter news that are affecting your technology stack
Showing 10 of 11892 Results