CVEFeed Newsroom – Latest Cybersecurity Updates

The "Cyber Newsroom Feed" module is a live feed of the latest cyber news enriched with CVE and vulnerability data. The feed is updated every 10 minutes and includes the latest news from the cyber security industry. The feed is designed to provide users with a comprehensive overview of the latest cyber security news and trends.

  • security.nl
DrayTek dicht lekken die aanvaller commando's als root laten uitvoeren

Netwerkfabrikant DrayTek heeft meerdere kwetsbaarheden in switches en access points verholpen, waaronder een aantal die aanvallers commando's als root laten uitvoeren en remote code execution mogelijk ...

Published Date: Aug 25, 2026 (1 day, 12 hours ago)
  • The Hacker News
Marimo Notebook Flaw Could Run MCP Commands Before Cells Execute in Edit Mode

Marimo has addressed a high-severity security flaw in its notebook software that allowed an attacker to execute an attacker-supplied Model Context Protocol (MCP) command in a specially crafted noteboo ...

Published Date: Aug 25, 2026 (1 day, 12 hours ago)
  • The Cyber Express
Ledger Fixes Ethereum App Flaw as Disclosure Timeline Is Disputed

Ledger CTO Charles Guillemet said on Aug. 23, 2026, that the company had fixed a clear-signing flaw in its Ethereum app two weeks before security firm TestMachine publicly disclosed the issue. As of A ...

Published Date: Aug 25, 2026 (1 day, 15 hours ago)
  • The Hacker News
Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access

Bad actors are attempting to exploit two severe unauthenticated authentication bypasses in the Xecurify miniOrange SAML 2.0 Single Sign On plugin that make it possible for an attacker to sign in as an ...

Published Date: Aug 25, 2026 (1 day, 16 hours ago)
  • security.nl
Kritiek lek in Oracle HTTP Server en WebLogic-plug-in misbruikt bij aanvallen

Aanvallers maken misbruik van een kritieke kwetsbaarheid in Oracle HTTP Server en de Oracle Weblogic Server Proxy-plug-in waardoor systemen op afstand zijn over te nemen. De CVSS-impactscore van het b ...

Published Date: Aug 25, 2026 (1 day, 16 hours ago)
  • The Hacker News
Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a maximum-severity security flaw impacting Oracle HTTP Server and Oracle WebLogic Server to its Known Exploited Vulnera ...

Published Date: Aug 25, 2026 (1 day, 18 hours ago)
  • The Hacker News
⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More

A package gets installed. A login prompt opens. A box sits exposed to the internet. Nothing looks unusual yet. That’s roughly the mood this week. Trusted tools turn hostile, old weak spots get fresh a ...

Published Date: Aug 24, 2026 (2 days, 10 hours ago)
  • security.nl
Honderden Zimbra-mailservers gehackt via lek, duizenden nog ongepatcht

Aanvallers hebben de afgelopen weken honderden Zimbra-mailservers gehackt, waarbij gebruikt werd gemaakt van een kwetsbaarheid waarvoor sinds 20 juli een beveiligingsupdate beschikbaar is. Dat meldt T ...

Published Date: Aug 24, 2026 (2 days, 12 hours ago)
  • The Hacker News
Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account

Red Hat and the Keycloak project have released patches to address a critical security flaw in the open-source identity and access management server that could allow an unauthenticated remote attacker ...

Published Date: Aug 24, 2026 (2 days, 13 hours ago)
  • cert.pl
Vulnerabilities in KAON PG5298A/PG5298B routers

Vulnerabilities in KAON PG5298A/PG5298B routers CVE ID CVE-2025-63080 Publication date 24 August 2026 Vendor KAON Product PG5298APG5298B Vulnerable versions PG5298A: All before 3.0.82PG5298B: All befo ...

Published Date: Aug 24, 2026 (2 days, 14 hours ago)

Filters

Filter news that are affecting your technology stack
Showing 10 of 12135 Results