CVEFeed Newsroom – Latest Cybersecurity Updates
The "Cyber Newsroom Feed" module is a live feed of the latest cyber news enriched with CVE and vulnerability data. The feed is updated every 10 minutes and includes the latest news from the cyber security industry. The feed is designed to provide users with a comprehensive overview of the latest cyber security news and trends.
-
The Hacker News
Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access
Bad actors are attempting to exploit two severe unauthenticated authentication bypasses in the Xecurify miniOrange SAML 2.0 Single Sign On plugin that make it possible for an attacker to sign in as an ...
-
security.nl
Kritiek lek in Oracle HTTP Server en WebLogic-plug-in misbruikt bij aanvallen
Aanvallers maken misbruik van een kritieke kwetsbaarheid in Oracle HTTP Server en de Oracle Weblogic Server Proxy-plug-in waardoor systemen op afstand zijn over te nemen. De CVSS-impactscore van het b ...
-
The Hacker News
Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a maximum-severity security flaw impacting Oracle HTTP Server and Oracle WebLogic Server to its Known Exploited Vulnera ...
-
The Hacker News
⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More
A package gets installed. A login prompt opens. A box sits exposed to the internet. Nothing looks unusual yet. That’s roughly the mood this week. Trusted tools turn hostile, old weak spots get fresh a ...
-
security.nl
Honderden Zimbra-mailservers gehackt via lek, duizenden nog ongepatcht
Aanvallers hebben de afgelopen weken honderden Zimbra-mailservers gehackt, waarbij gebruikt werd gemaakt van een kwetsbaarheid waarvoor sinds 20 juli een beveiligingsupdate beschikbaar is. Dat meldt T ...
-
The Hacker News
Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account
Red Hat and the Keycloak project have released patches to address a critical security flaw in the open-source identity and access management server that could allow an unauthenticated remote attacker ...
-
cert.pl
Vulnerabilities in KAON PG5298A/PG5298B routers
Vulnerabilities in KAON PG5298A/PG5298B routers CVE ID CVE-2025-63080 Publication date 24 August 2026 Vendor KAON Product PG5298APG5298B Vulnerable versions PG5298A: All before 3.0.82PG5298B: All befo ...
-
TheCyberThrone
CVE-2026-69836: Critical RCE Vulnerability in Microsoft Entra ID
August 24, 2026Microsoft has disclosed CVE-2026-69836, a critical remote-code-execution vulnerability affecting Microsoft Entra ID.The vulnerability is classified as CWE-502 — Deserialization of Untru ...
-
security.nl
Australische overheid meldt misbruik van kritiek lek TeamCity-servers
TeamCity-servers die zich in Australië bevinden zijn het doelwit van aanvallen, zo meldt de Australische inlichtingendienst ASD. De aanvallers maken misbruik van een kritieke kwetsbaarheid aangeduid a ...
-
The Hacker News
UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit
Cybersecurity researchers have disclosed details of a Chinese-speaking cybercrime group dubbed UAT-10147 that's targeting Windows and Linux web servers globally across the education, media, technology ...