CVEFeed Newsroom – Latest Cybersecurity Updates
The "Cyber Newsroom Feed" module is a live feed of the latest cyber news enriched with CVE and vulnerability data. The feed is updated every 5 minutes and includes the latest news from the cyber security industry. The feed is designed to provide users with a comprehensive overview of the latest cyber security news and trends.
-
The Hacker News
CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a critical flaw impacting Ray to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitat ...
-
The Hacker News
Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects
GitLab has released security updates to address a critical vulnerability impacting its Community Edition (CE) and Enterprise Edition (EE) software that, under certain conditions, could allow an unauth ...
-
The Hacker News
Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads
A critical security flaw has been disclosed in Forminator Forms, a WordPress plugin with more than 600,000 active installations, that could be exploited to achieve arbitrary code execution on suscepti ...
-
Kaspersky
ClickFix on Steam forums: how malicious PowerShell commands install a crypto miner | Kaspersky official blog
This year has seen a real boom in ClickFix attacks. It’s such a hit with criminals that we barely finish writing about one variation before it’s time to cover the next. This time, attackers are target ...
-
The Hacker News
⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More
The expensive attacks are not always the clever ones. This week had plenty of proof. Exposed services got hit, old bugs found fresh use, browser sessions became attack paths, and supply-chain problems ...
-
The Hacker News
How MCP Servers Can Expose Enterprise Secrets
MCP servers can expose enterprise secrets through plaintext configuration files, over-permissioned access and prompt injection, often before security teams even know the server is running. As more org ...
-
cert.pl
Vulnerability in OutSystems Service Center software
Vulnerability in OutSystems Service Center software CVE ID CVE-2026-40126 Publication date 17 August 2026 Vendor OutSystems Product Service Center Vulnerable versions All before 11.41.2 Vulnerability ...
-
The Hacker News
Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel Access
Security researchers at SSD Secure Disclosure have published a two-stage exploit chain that achieves full Android kernel access on devices running Unisoc modem firmware through a VoLTE video call, wit ...
-
The Hacker News
Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies
Cybersecurity researchers have flagged a previously undocumented Linux botnet family dubbed Evooo1Bot that derives its core functionality from the Mirai botnet source code and is equipped to turn inte ...
-
security.nl
Duizenden Metabase-installaties missen update voor actief aangevallen lek
Ruim tweeduizend installaties van Metabase, waaronder zo'n vijftig in Nederland, missen een beveiligingsupdate voor een actief aangevallen kwetsbaarheid. Dat meldt The Shadowserver Foundation op basis ...