CVEFeed Newsroom – Latest Cybersecurity Updates
The "Cyber Newsroom Feed" module is a live feed of the latest cyber news enriched with CVE and vulnerability data. The feed is updated every 10 minutes and includes the latest news from the cyber security industry. The feed is designed to provide users with a comprehensive overview of the latest cyber security news and trends.
-
security.nl
Google waarschuwt voor actief misbruik van modem-lek in Pixel-telefoons
Aanvallers maken actief misbruik van een kwetsbaarheid in Pixel-telefoons, zo waarschuwt Google. Er zijn beveiligingsupdates uitgebracht om het probleem te verhelpen. Via de kwetsbaarheid (CVE-2026-58 ...
-
The Hacker News
Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells
Threat actors are exploiting a critical security flaw in WooCommerce Wholesale Lead Capture, a premium WordPress plugin that has more than 6,000 active installs. "This vulnerability can be leveraged b ...
-
The Hacker News
Active Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens
A critical security flaw in WSO2 API Manager has come under active exploitation in the wild, according to findings from watchTowr. The vulnerability, tracked as CVE-2026-5430 (CVSS score: 9.8/10.0), i ...
-
TheCyberThrone
Oracle September 2026 Security Patch Tuesday
673 Security Patches Across the EnterpriseQuick ReferenceRelease Date: 15 September 2026Release: Oracle September 2026 Critical Security Patch Update (CSPU)Security Patches: 673Highest CVSS: 10.0Majo ...
-
The Hacker News
Human Attacker Exploits Marimo RCE, Reaches SSH Bastion in Eight Seconds
With artificial intelligence (AI) shrinking the window between vulnerability discovery and exploitation and lowering the barrier to entry for bad actors, new findings from Sysdig show that skilled hum ...
-
The Hacker News
Mass-Scanning Campaign Exploits Vite Flaw to Extract Cloud Credentials From Exposed Dev Servers
Cybersecurity researchers have disclosed details of a mass-scanning campaign that has targeted Vite deployments siphon sensitive data. The first is an automated effort aimed at internet-exposed Vite d ...
-
security.nl
Bluetooth-lek maakt uitvoeren van code op iPhones en Macs mogelijk
dinsdag 15 september 2026, 11:33 door Redactie, 0 reactiesLaatst bijgewerkt: Vandaag, 11:38 Een bluetooth-kwetsbaarheid in iOS en macOS maakt het mogelijk voor remote aanvallers om willekeurige code o ...
-
security.nl
Webwinkels aangevallen via kritiek uploadlek in WooCommerce-plug-in
Webwinkels worden al maandenlang aangevallen via een kritieke uploadkwetsbaarheid in een plug-in genaamd WooCommerce Wholesale Lead Capture. Via het beveiligingslek (CVE-2026-27540) kan een ongeauthen ...
-
The Cyber Express
4 in 5 Singapore Business Websites Have WordPress Vulnerabilities
A new Singapore Study has found that four in five websites run by local businesses carry at least one detectable WordPress vulnerabilities. The Singapore WordPress Website Cybersecurity Study, release ...
-
security.nl
Cisco waarschuwt voor misbruik van kritiek SQL Injection-lek in Email Gateway
Aanvallers maken actief misbruik van een kritieke SQL Injection-kwetsbaarheid in de Cisco Secure Email Gateway, zo waarschuwt Cisco. Via het beveiligingslek (CVE-2026-76461) kan een aanvaller willekeu ...