CVEFeed Newsroom – Latest Cybersecurity Updates
The "Cyber Newsroom Feed" module is a live feed of the latest cyber news enriched with CVE and vulnerability data. The feed is updated every 5 minutes and includes the latest news from the cyber security industry. The feed is designed to provide users with a comprehensive overview of the latest cyber security news and trends.
-
Daily CyberSecurity
CISA Adds 4 Critical Flaws to “Must-Patch” List as Exploits Surge
The Cybersecurity and Infrastructure Security Agency (CISA) has updated its Known Exploited Vulnerabilities (KEV) Catalog with four dangerous new entries, signaling that hackers are actively weaponizi ...
-
The Cyber Express
GitLab Releases Critical Patch Updates to Address Multiple High-Severity Vulnerabilities
GitLab has issued a new GitLab patch release addressing a range of security vulnerabilities and stability issues across multiple supported versions. The latest updates, versions 18.8.2, 18.7.2, and 18 ...
-
Daily CyberSecurity
“New” Path of Attack: Fully Upgraded Fortinet Devices Hit by SSO Exploits
Fortinet is investigating a concerning new wave of attacks targeting its network security devices, where threat actors are successfully compromising systems that have already been fully patched agains ...
-
Daily CyberSecurity
Public Yet Private? Critical Appsmith Flaw Exposes Unpublished Actions (CVSS 9.4)
A critical security flaw has been discovered in Appsmith, the popular open-source platform used by organizations worldwide to build internal tools like dashboards and admin panels. The vulnerability, ...
-
Daily CyberSecurity
Sabotage & Exploited in the Wild: Critical Backdoor Found in LA-Studio Element Kit
A critical security incident has rocked the WordPress community after a “backdoor” vulnerability was discovered in the LA-Studio Element Kit for Elementor, a plugin active on over 20,000 websites. The ...
-
Daily CyberSecurity
CVE-2026-23594: High-Severity Flaw in HPE Alletra & Nimble Grants Admin Access
Hewlett Packard Enterprise (HPE) has issued a security alert for storage administrators, warning of a high-severity vulnerability affecting its flagship enterprise storage arrays. The flaw, tracked as ...
-
Daily CyberSecurity
CVE-2026-22822: Critical Flaw in External Secrets Operator Breaks Namespace Isolation
A critical security vulnerability has been discovered in the External Secrets Operator, a widely used Kubernetes tool that bridges the gap between external secret management systems like AWS Secrets M ...
-
BleepingComputer
SmarterMail auth bypass flaw now exploited to hijack admin accounts
Hackers began exploiting an authentication bypass vulnerability in SmarterTools' SmarterMail email server and collaboration tool that allows resetting admin passwords. An authentication bypass vulnera ...
-
The Hacker News
New Osiris Ransomware Emerges as New Strain Using POORTRY Driver in BYOVD Attack
Cybersecurity researchers have disclosed details of a new ransomware family called Osiris that targeted a major food service franchisee operator in Southeast Asia in November 2025. The attack leverage ...
-
The Hacker News
Critical GNU InetUtils telnetd Flaw Lets Attackers Bypass Login and Gain Root Access
A critical security flaw has been disclosed in the GNU InetUtils telnet daemon (telnetd) that went unnoticed for nearly 11 years. The vulnerability, tracked as CVE-2026-24061, is rated 9.8 out of 10.0 ...