CVEFeed Newsroom – Latest Cybersecurity Updates
The "Cyber Newsroom Feed" module is a live feed of the latest cyber news enriched with CVE and vulnerability data. The feed is updated every 10 minutes and includes the latest news from the cyber security industry. The feed is designed to provide users with a comprehensive overview of the latest cyber security news and trends.
-
Huntress
Threat Actors Exploit Critical AhsayCBS Flaws to Drop Webshells and XMRig Cryptominer
Acknowledgements: Special thanks to Dipo Rodipe, John Hammond, Susannah Matt, Ben Nahorney, and Lindsey Welch for their contributions to this investigation and writeup. Update 10/8/26 @ 6pm ETAfter fu ...
-
The Hacker News
FBI Says China-Linked Hackers Ran Portal Giving Third Parties Access to Stolen Emails
Hackers tied to a Chinese cybersecurity company stole email from government organizations, law enforcement agencies, healthcare systems, and religious institutions in Southeast Asia, the FBI and agenc ...
-
The Hacker News
Japan Sees Sharp Rise in Web Data Leaks Amid Mobile API Abuse and Metabase Attacks
Attackers behind a string of personal data leaks at Japanese organizations have abused APIs for mobile apps and targeted known software flaws, the JPCERT Coordination Center (JPCERT/CC) said. The Toky ...
-
TheCyberThrone
CVE-2026-102255: Critical Pre-Auth SSRF Vulnerability in SonicWall SMA1000
A new critical vulnerability in SonicWall SMA1000 appliances deserves immediate attention from organizations using the platform as an internet-facing remote-access gateway.Tracked as CVE-2026-102255, ...
-
security.nl
Google komt met update voor kritiek bluetooth-lek in Pixel-telefoons
Google heeft een beveiligingsupdate voor Pixel-telefoons uitgebracht die meerdere beveiligingslekken verhelpt, waaronder een kritieke bluetooth-kwetsbaarheid. Van de in totaal zes kwetsbaarheden in he ...
-
cert.pl
Vulnerability in Ollama software
Vulnerability in Ollama software CVE ID CVE-2026-103663 Publication date 08 October 2026 Vendor Ollama Product Ollama Vulnerable versions From 0.34.2 to 0.35.0 Vulnerability type (CWE) Relative Path T ...
-
The Hacker News
Eight Malicious npm Packages Downloaded 40,767 Times Deliver Overlord RAT and Stealer
Cybersecurity researchers have disclosed details of a long-running npm supply chain malware campaign that pushes information stealers and remote access trojans (RAT) to compromised hosts. The campaign ...
-
The Hacker News
SonicWall Patches CVSS 10.0 Pre-Authentication SSRF Flaw in SMA1000 Appliances
SonicWall has released hotfixes for four flaws in its SMA1000 appliances, the gateways that give remote workers access to a company's network and applications. The most serious could allow an attacker ...
-
The Hacker News
Unpatched Critical LMCache Flaw Lets Unauthenticated Attackers Run Code Remotely
A critical vulnerability in LMCache, open-source software that speeds up large language model (LLM) servers such as vLLM, lets an attacker run code on the cache server without logging in, and no fixed ...
-
TheCyberThrone
CVE-2026-21589: Critical Atlassian Flaw Enables Unauthenticated File Access
Executive SummaryAtlassian has disclosed CVE-2026-21589, a critical arbitrary file access vulnerability affecting multiple Atlassian Data Center products.The vulnerability carries a CVSS v4.0 score of ...