CVEFeed Newsroom – Latest Cybersecurity Updates

The "Cyber Newsroom Feed" module is a live feed of the latest cyber news enriched with CVE and vulnerability data. The feed is updated every 5 minutes and includes the latest news from the cyber security industry. The feed is designed to provide users with a comprehensive overview of the latest cyber security news and trends.

  • hackread.com
30,000 Korean Air Employee Records Stolen as Cl0p Leaks Data Online

In a worrying turn of events for the aviation industry, Korean Air has confirmed that the personal details of roughly 30,000 current and former employees have been stolen. This news, shared on Decembe ...

Published Date: Dec 31, 2025 (1 day, 6 hours ago)
  • BleepingComputer
IBM warns of critical API Connect auth bypass vulnerability

IBM urged customers to patch a critical authentication bypass vulnerability in its API Connect enterprise platform that could allow attackers to access apps remotely. API Connect is an application pro ...

Published Date: Dec 31, 2025 (1 day, 7 hours ago)
  • CybersecurityNews
Critical Apache StreamPipes Vulnerability Let Attackers Seize Admin Control

A security patch addressing a critical privilege escalation vulnerability that allows unauthorized users to gain administrative access to the data streaming platform. The flaw, tracked as CVE-2025-474 ...

Published Date: Dec 31, 2025 (1 day, 10 hours ago)
  • The Cyber Express
Singapore CSA Warns of Critical SmarterMail Flaw Enabling Unauthenticated Remote Code Execution

The Cyber Security Agency of Singapore (CSA) has issued a high-priority alert warning organizations and system administrators about a critical security vulnerability affecting SmarterMail, an enterpri ...

Published Date: Dec 31, 2025 (1 day, 10 hours ago)
  • Help Net Security
Security coverage is falling behind the way attackers behave

Cybercriminals keep tweaking their procedures, trying out new techniques, and shifting tactics across campaigns. Coverage that worked yesterday may miss how those behaviors appear today. The 2025 Thre ...

Published Date: Dec 31, 2025 (1 day, 12 hours ago)
  • Daily CyberSecurity
CVE-2025-47411: Critical Apache StreamPipes Flaw Allows Standard Users to Seize Admin Control

The Apache Software Foundation has released a critical fix for StreamPipes, its self-service Industrial IoT toolbox designed to let non-technical users analyze complex data streams. A newly disclosed ...

Published Date: Dec 31, 2025 (1 day, 15 hours ago)
  • The Register
An early end to the holidays: 'Heartbleed of MongoDB' is now under active exploit

A high-severity MongoDB Server vulnerability, for which proofs of concept emerged over Christmas week, is now under active exploitation, according to the US Cybersecurity and Infrastructure Security A ...

Published Date: Dec 30, 2025 (1 day, 22 hours ago)
  • The Hacker News
CSA Issues Alert on Critical SmarterMail Bug Allowing Remote Code Execution

Dec 30, 2025Ravie LakshmananVulnerability / Email Security The Cyber Security Agency of Singapore (CSA) has issued a bulletin warning of a maximum-severity security flaw in SmarterTools SmarterMail ...

Published Date: Dec 30, 2025 (2 days, 1 hour ago)
  • BleepingComputer
CISA orders feds to patch MongoBleed flaw exploited in attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered government agencies to secure their systems against a high-severity MongoDB flaw that is actively being exploited in attacks. D ...

Published Date: Dec 30, 2025 (2 days, 3 hours ago)
  • DataBreaches.Net
US, Australia say ‘MongoBleed’ bug being exploited

Jonathan Greig reports: U.S. and Australian cyber agencies confirmed that hackers are exploiting a vulnerability that emerged over the Christmas holiday and is impacting data storage systems from the ...

Published Date: Dec 30, 2025 (2 days, 6 hours ago)

Filters

Filter news that are affecting your technology stack
Showing 10 of 8921 Results