CVEFeed Newsroom – Latest Cybersecurity Updates
The "Cyber Newsroom Feed" module is a live feed of the latest cyber news enriched with CVE and vulnerability data. The feed is updated every 10 minutes and includes the latest news from the cyber security industry. The feed is designed to provide users with a comprehensive overview of the latest cyber security news and trends.
-
The Hacker News
LibreOffice and OpenOffice Flaws Let Malicious Spreadsheets Run Code Without Macro Warnings
A malicious spreadsheet can make LibreOffice and Apache OpenOffice run an attacker's code as soon as the file is opened, security researchers have shown. There is no warning first, of the kind either ...
-
TheCyberThrone
Microsoft Releases Out-of-Band Exchange Security Update
October 6, 2026Executive SummaryMicrosoft has released an out-of-band security update for Exchange Server to address CVE-2026-96940, an Elevation of Privilege vulnerability that could allow an authent ...
-
cert.pl
Vulnerabilities in GNU Aspell software
Vulnerabilities in GNU Aspell software CVE ID CVE-2026-75818 Publication date 06 October 2026 Vendor GNU Product Aspell Vulnerable versions All before 0.60.8.3 Vulnerability type (CWE) Heap-based buff ...
-
security.nl
Kritiek lek in OpenOffice kan aanvaller controle over systeem geven
dinsdag 6 oktober 2026, 09:38 door Redactie, 1 reactiesLaatst bijgewerkt: Vandaag, 10:02 Een kritieke kwetsbaarheid in Apache OpenOffice kan een aanvaller controle over het systeem van gebruikers geve ...
-
The Hacker News
Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 Products
A critical flaw in 8 Atlassian Data Center products, which customers host themselves, allows an attacker with no login access to read specific files in each product's web application root directory. T ...
-
The Hacker News
FBI Removes Accenture Contractor After Patch Failure Led to ShinyHunters Breach
The U.S. Federal Bureau of Investigation (FBI) has removed an Accenture contractor for their alleged role in a ShinyHunters-breach that led to the theft of personal details of thousands of bureau empl ...
-
The Hacker News
ClickFix Smuggles Payloads Through Browser Cache to Bypass Windows Run Limits
A new type of ClickFix attack is using compromised websites to trick users into executing a malicious payload cached in a web browser's cache. "Instead of downloading and executing remote payloads lik ...
-
Ars Technica
MCP for agent-to-agent comms may be the riskiest protocol you've never heard of
LOST IN TRANSLATION Trust gaps in the new protocol spread malicious prompts from one agent to another. Credit: Getty Images The adoption of AI agents in millions of organizations is creating new oppor ...
-
Dark Reading
ClingSTUN Turns Vulnerable IoT Devices Into Proxy Nodes
4 Min ReadSource: Nikola Fific via ShutterstockResearchers have uncovered a new Linux malware strain that exploits a growing list of known vulnerabilities in Internet of Things (IoT) devices to mainta ...
-
The Hacker News
Microsoft Exchange Flaw Lets Authenticated Attackers Read Other Users' Mailboxes
Microsoft has released out-of-band security updates to address a high-severity flaw in Microsoft Exchange Server that could allow an attacker to escalate privileges under certain conditions. The vulne ...