CVEFeed Newsroom – Latest Cybersecurity Updates
The "Cyber Newsroom Feed" module is a live feed of the latest cyber news enriched with CVE and vulnerability data. The feed is updated every 10 minutes and includes the latest news from the cyber security industry. The feed is designed to provide users with a comprehensive overview of the latest cyber security news and trends.
-
Kaspersky
CVE-2026-87902: Critical Vulnerability in WordPress
vulnerability CVE-2026-87902, a new critical vulnerability in the WordPress core, is already being actively exploited in real-world attacks. Editorial Team September 25, 2026 A critical vulnerability ...
-
security.nl
Roundcube Webmail SQL Injection-lek misbruikt bij aanvallen
Een SQL Injection-kwetsbaarheid in Roundcube wordt misbruikt bij aanvallen. Dat laat het Canadese Centrum voor Cybersecurity weten. Roundcube is opensource-webmailsoftware en wordt door allerlei organ ...
-
The Hacker News
Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild
The Canadian Centre for Cyber Security has warned that a now-patched Roundcube Webmail vulnerability is being actively exploited in the wild. The vulnerability in question is CVE-2026-48842 (CVSS scor ...
-
security.nl
NCSC meldt actief misbruik van kritiek WordPress-lek: 'Update nu'
Aanvallers maken actief misbruik van een kritieke path traversal-kwetsbaarheid in WordPress waardoor websites zijn over te nemen, zo meldt het Nationaal Cyber Security Centrum (NCSC). Er is een update ...
-
The Hacker News
WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added two critical security flaws impacting WSO2 and Adobe Commerce and Magento to its Known Exploited Vulnerabilities (K ...
-
The Hacker News
Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions
A OnePlus 15 running the latest OxygenOS can be rooted by a malicious app the owner installs, one that asks for no special permissions. A researcher, Rasmus Moorats, chained two flaws in OnePlus's own ...
-
The Hacker News
ThreatsDay: AI Search Poisoning, AI Coding Tool Leaking Repos, One-Click Code Execution and 13 More Stories
This week, the dangerous stuff keeps arriving dressed as something boring. An update. A login box. A search answer. A coding tool. A link you have clicked a hundred times before.That is the thread run ...
-
Huntress
The Not So Silent Miner: Threat Actor Compiles Cryptominer on the Endpoint
BackgroundHuntress researchers recently came across a unique incident where, after gaining initial access via exploiting a known Samsung MagicINFO vulnerability and installing a rogue AnyDesk instance ...
-
security.nl
Check Point meldt actief misbruik van kritieke vpn-kwetsbaarheid
Cybersecuritybedrijf Check Point waarschuwt voor actief misbruik van een kritieke kwetsbaarheid in de vpn-producten die het biedt. Via het beveiligingslek (CVE-2026-85102) kan een ongeauthenticeerde a ...
-
security.nl
Adobe dicht kritieke kwetsbaarheden in Connect en AEM Forms
Adobe heeft beveiligingsupdates uitgebracht voor kritieke kwetsbaarheden in Adobe Connect en Adobe Experience Manager (AEM) Forms. Verschillende beveiligingslekken maken het mogelijk om willekeurige c ...