CVEFeed Newsroom – Latest Cybersecurity Updates
The "Cyber Newsroom Feed" module is a live feed of the latest cyber news enriched with CVE and vulnerability data. The feed is updated every 5 minutes and includes the latest news from the cyber security industry. The feed is designed to provide users with a comprehensive overview of the latest cyber security news and trends.
-
The Hacker News
Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads
Ruby on Rails has released fixes for a critical Active Storage vulnerability that could let unauthenticated attackers read arbitrary files from application servers through crafted image uploads. Track ...
-
The Hacker News
Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory
Cybersecurity researchers have flagged a maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, that could result in unauthenticated rem ...
-
The Hacker News
Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape
Broadcom has released security updates to address multiple security flaws impacting VMware ESX, vCenter, Workstation, and Fusion, three of which have been designated as critical in severity. The first ...
-
Proofpoint
Cleaning Out Inboxes: TA488 Comes for Outlook with Another Half-Click Exploit
July 29, 2026 By Greg Lesnewich, Stuart Del Caliz, Nick Attfield, Konstantin Klinger, Saher Naumaan, Mark Kelly, and the Proofpoint Threat Research Team Threat Research would like to thank the Proofpo ...
-
cert.pl
Vulnerabilities in MWDB Core software
Vulnerabilities in MWDB Core software CVE ID CVE-2026-66723 Publication date 29 July 2026 Vendor CERT.PL Product MWDB Core Vulnerable versions From 2.2.0 before 2.19.0 Vulnerability type (CWE) Missing ...
-
cert.pl
Vulnerability in Streamsoft Business Intelligence software
Vulnerability in Streamsoft Business Intelligence software CVE ID CVE-2026-50641 Publication date 29 July 2026 Vendor Streamsoft Product Business Intelligence Vulnerable versions All before 6.8.0.0 Vu ...
-
cert.pl
Vulnerability in Quick.CMS software
Vulnerability in Quick.CMS software CVE ID CVE-2026-33385 Publication date 29 July 2026 Vendor OpenSolution Product Quick.CMS Vulnerable versions 6.8 Vulnerability type (CWE) Improper Neutralization o ...
-
security.nl
Kritieke VMware-lekken geven aanvallers toegang tot vCenter-servers
VMware waarschuwt klanten vandaag voor twee kritieke kwetsbaarheden waardoor aanvallers toegang tot vCenter-servers kunnen krijgen. Er zijn updates uitgebracht om de problemen te verhelpen. Daarnaast ...
-
security.nl
Italiaanse overheid meldt bestaan van exploitcode voor 7-Zip RCE-lek
Voor een kwetsbaarheid in de populaire archiveringssoftware 7-Zip is exploitcode online verschenen, zo meldt het Computer Security Incident Response Team van de Italiaanse overheid (CSIRT Italia) vand ...
-
The Hacker News
Researchers Show a Single Malicious Webpage Visit Can Compromise Tor Browser
Nebula Security says a patched Firefox JIT flaw could be triggered by simply visiting a malicious webpage and was also used to compromise Tor Browser. Tracked as CVE-2026-10702, the bug provides arbit ...