CVEFeed Newsroom – Latest Cybersecurity Updates
The "Cyber Newsroom Feed" module is a live feed of the latest cyber news enriched with CVE and vulnerability data. The feed is updated every 10 minutes and includes the latest news from the cyber security industry. The feed is designed to provide users with a comprehensive overview of the latest cyber security news and trends.
-
The Hacker News
Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure
Threat actors are exploiting a newly patched critical security flaw impacting JFrog Artifactory merely days after public disclosure, according to watchTowr. The vulnerability in question is CVE-2026-8 ...
-
The Hacker News
13 Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Wallet Seeds
Cybersecurity researchers have identified a set of 13 malicious Composer theme packages on Packagist that are designed to inject JavaScript into Vietnamese movie and comic streaming sites that install ...
-
security.nl
22.000 Exchange-servers missen update voor kritiek beveiligingslek
Zo'n 22.000 Microsoft Exchange-servers, waarvan ruim vijfhonderd in Nederland, missen een update voor een kritiek beveiligingslek. Dat meldt The Shadowserver Foundation op basis van eigen onderzoek. V ...
-
The Hacker News
Attackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 Activity
Threat actors are exploiting two critical flaws impacting Langflow and Ruby on Rails, according to new findings from VulnCheck. The vulnerabilities in question are listed below - CVE-2026-0768 (CVSS s ...
-
Kaspersky
This Android malware steals banking credentials even without an internet connection | Kaspersky official blog
Cybersecurity researchers have discovered a new family of Android malware, and it goes by the name of Manic. It lets criminals spy on their victims, steal banking credentials, and take remote control ...
-
The Hacker News
⚡ Weekly Recap: Chinese Spy Proxy, AI Agents Go Off-Task, Router Backdoors and More
The boring parts caused most of the trouble. A router shipped ready to listen. A fake check turned the user into the installer. Trusted systems collected traffic and passwords, then cleaned the logs. ...
-
security.nl
Wordpress-sites actief aangevallen via kritiek beveiligingslek in ACPT
Aanvallers maken actief misbruik van een kritieke kwetsbaarheid in de WordPress-plug-in ACPT (Pro) voor het aanvallen van websites. Dat laat cybersecuritybedrijf Defused weten. Via het beveiligingslek ...
-
The Cyber Express
PaperCut Issues Second Emergency Patch as Researchers Break Fix for Exploited Zero-Days
PaperCut released a second emergency patch last Friday, for two vulnerabilities in its NG and MF print management servers that attackers are already exploiting, after security researchers demonstrated ...
-
The Cyber Express
AshSqlite Vulnerability (CVE-2026-77846) Exposes Hidden JSON Fields
CVE-2026-77846, a newly disclosed AshSqlite vulnerability, can allow attackers to access hidden or sensitive fields stored inside JSON and map columns when applications pass untrusted input to AshSqli ...
-
security.nl
PaperCut publiceert tweede noodpatch wegens aanvallen op NG/MF-servers
Softwarebedrijf PaperCut heeft een tweede noodpatch uitgebracht wegens aanvallen op PaperCut NG/MF-servers. PaperCut NG en MF zijn oplossingen waarmee organisaties allerlei printgerelateerde zaken kun ...