CVEFeed Newsroom – Latest Cybersecurity Updates
The "Cyber Newsroom Feed" module is a live feed of the latest cyber news enriched with CVE and vulnerability data. The feed is updated every 5 minutes and includes the latest news from the cyber security industry. The feed is designed to provide users with a comprehensive overview of the latest cyber security news and trends.
-
The Cyber Express
Russian-Linked Hackers Target Zimbra Users With Zero-Day Exploit
A Zimbra phishing campaign attributed to Russian state-supported cyber actors has targeted Western government and commercial organizations, exploiting CVE-2025-66376 to access sensitive email data and ...
-
Trend Micro
The Signs Were There: What the First Autonomous Ransomware Case Confirms
Cyber Threats An AI agent has run a ransomware intrusion on its own for the first time, from break-in to data destruction. The autonomous attacks TrendAI™ Research predicted are beginning to arrive, ...
-
The Hacker News
Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes
A Russian state-supported espionage group spent months reading Western mailboxes through a then-unknown flaw in Zimbra's webmail client. The payload goes after the last 90 days of email, the organizat ...
-
security.nl
Clop-ransomwaregroep perst bedrijven af met gehackte PTC Windchill-server
De criminelen achter de Clop-ransomware hebben meerdere bedrijven afgeperst, waarbij ze beweren allerlei vertrouwelijke data te hebben gestolen. Als de ondernemingen niet betalen dreigen de criminelen ...
-
Proofpoint
ta458 roundpress exploits
July 23, 2026 Greg Lesnewich, Nick Attfield, Konstantin Klinger, Saher Naumaan, Mark Kelly, and the Proofpoint Threat Research Team This is part 2 of a 2-part blog series Proofpoint is publishing abou ...
-
security.nl
AIVD waarschuwt voor XSS-aanvallen op gebruikers van Zimbra-webmail
Gebruikers van Zimbra-webmail zijn het doelwit van cross-site scripting (XSS)-aanvallen waarbij wordt geprobeerd om e-mails en andere informatie te stelen, zo waarschuwen de AIVD, MIVD en inlichtingen ...
-
TheCyberThrone
CISA adds six vulnerabilities to KEV – July 2026
On 21 and 22 July 2026, the Cybersecurity and Infrastructure Security Agency (CISA) expanded its Known Exploited Vulnerabilities (KEV) Catalog by adding six vulnerabilities spanning enterprise collabo ...
-
SentinelOne
Mount Here, Read There: Twin Path Traversal CVEs in Kubernetes Storage
filepath.Join was never designed to be a security boundary. We found two CSI drivers that shipped on the assumption it was, and the result was cross-tenant data access with optional node destruction, ...
-
security.nl
Nieuw Linux-lek kan lokale aanvaller root maken op systemen met XFS
Onderzoekers waarschuwen voor een nieuwe kwetsbaarheid in de Linux-kernel waardoor een lokale aanvaller root kan worden op systemen met een XFS-bestandssysteem. Miljoenen systemen lopen mogelijk risic ...
-
The Hacker News
China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks
An exposed Alibaba Cloud server has revealed a China-nexus operation that Group-IB tracks as JadeProx. The cluster has targeted government, healthcare, and education organizations across Asia and Lati ...