CVEFeed Newsroom – Latest Cybersecurity Updates

The "Cyber Newsroom Feed" module is a live feed of the latest cyber news enriched with CVE and vulnerability data. The feed is updated every 10 minutes and includes the latest news from the cyber security industry. The feed is designed to provide users with a comprehensive overview of the latest cyber security news and trends.

  • Huntress
Threat Actors Exploit Critical AhsayCBS Flaws to Drop Webshells and XMRig Cryptominer

Acknowledgements: Special thanks to Dipo Rodipe, John Hammond, Susannah Matt, Ben Nahorney, and Lindsey Welch for their contributions to this investigation and writeup. Update 10/8/26 @ 6pm ETAfter fu ...

Published Date: Oct 08, 2026 (20 hours, 12 minutes ago)
  • The Hacker News
FBI Says China-Linked Hackers Ran Portal Giving Third Parties Access to Stolen Emails

Hackers tied to a Chinese cybersecurity company stole email from government organizations, law enforcement agencies, healthcare systems, and religious institutions in Southeast Asia, the FBI and agenc ...

Published Date: Oct 08, 2026 (21 hours, 40 minutes ago)
  • The Hacker News
Japan Sees Sharp Rise in Web Data Leaks Amid Mobile API Abuse and Metabase Attacks

Attackers behind a string of personal data leaks at Japanese organizations have abused APIs for mobile apps and targeted known software flaws, the JPCERT Coordination Center (JPCERT/CC) said. The Toky ...

Published Date: Oct 08, 2026 (1 day ago)
  • TheCyberThrone
CVE-2026-102255: Critical Pre-Auth SSRF Vulnerability in SonicWall SMA1000

A new critical vulnerability in SonicWall SMA1000 appliances deserves immediate attention from organizations using the platform as an internet-facing remote-access gateway.Tracked as CVE-2026-102255, ...

Published Date: Oct 08, 2026 (1 day, 1 hour ago)
  • security.nl
Google komt met update voor kritiek bluetooth-lek in Pixel-telefoons

Google heeft een beveiligingsupdate voor Pixel-telefoons uitgebracht die meerdere beveiligingslekken verhelpt, waaronder een kritieke bluetooth-kwetsbaarheid. Van de in totaal zes kwetsbaarheden in he ...

Published Date: Oct 08, 2026 (1 day, 4 hours ago)
  • cert.pl
Vulnerability in Ollama software

Vulnerability in Ollama software CVE ID CVE-2026-103663 Publication date 08 October 2026 Vendor Ollama Product Ollama Vulnerable versions From 0.34.2 to 0.35.0 Vulnerability type (CWE) Relative Path T ...

Published Date: Oct 08, 2026 (1 day, 5 hours ago)
  • The Hacker News
Eight Malicious npm Packages Downloaded 40,767 Times Deliver Overlord RAT and Stealer

Cybersecurity researchers have disclosed details of a long-running npm supply chain malware campaign that pushes information stealers and remote access trojans (RAT) to compromised hosts. The campaign ...

Published Date: Oct 07, 2026 (1 day, 22 hours ago)
  • The Hacker News
SonicWall Patches CVSS 10.0 Pre-Authentication SSRF Flaw in SMA1000 Appliances

SonicWall has released hotfixes for four flaws in its SMA1000 appliances, the gateways that give remote workers access to a company's network and applications. The most serious could allow an attacker ...

Published Date: Oct 07, 2026 (1 day, 23 hours ago)
  • The Hacker News
Unpatched Critical LMCache Flaw Lets Unauthenticated Attackers Run Code Remotely

A critical vulnerability in LMCache, open-source software that speeds up large language model (LLM) servers such as vLLM, lets an attacker run code on the cache server without logging in, and no fixed ...

Published Date: Oct 07, 2026 (2 days ago)
  • TheCyberThrone
CVE-2026-21589: Critical Atlassian Flaw Enables Unauthenticated File Access

Executive SummaryAtlassian has disclosed CVE-2026-21589, a critical arbitrary file access vulnerability affecting multiple Atlassian Data Center products.The vulnerability carries a CVSS v4.0 score of ...

Published Date: Oct 07, 2026 (2 days, 1 hour ago)

Filters

Filter news that are affecting your technology stack
Showing 10 of 12468 Results