CVEFeed Newsroom – Latest Cybersecurity Updates
The "Cyber Newsroom Feed" module is a live feed of the latest cyber news enriched with CVE and vulnerability data. The feed is updated every 5 minutes and includes the latest news from the cyber security industry. The feed is designed to provide users with a comprehensive overview of the latest cyber security news and trends.
-
The Hacker News
New Gitea RCE Lets Repository Writers Plant a Git Hook to Run Shell Commands
Gitea, the self-hosted Git platform, has patched a critical remote code execution vulnerability. A user with ordinary repository write access can turn attacker-controlled patch content into a live Git ...
-
security.nl
Kritiek lek in forumsoftware vBulletin maakt remote code execution mogelijk
Een kritieke kwetsbaarheid in forumsoftware vBulletin maakt remote code execution door ongeauthenticeerde aanvallers mogelijk. Er zijn updates uitgebracht om de kwetsbaarheid (CVE-2026-61511) te verhe ...
-
TheCyberThrone
CISA Expands KEV Catalog with FortiOS and Arista VeloCloud Flaws
July 29, 2026The Cybersecurity and Infrastructure Security Agency (CISA) has expanded its Known Exploited Vulnerabilities (KEV) Catalog by adding two vulnerabilities affecting Fortinet FortiOS and Ari ...
-
Ars Technica
We now have a better understanding how OpenAI hacked into Hugging Face
Last week’s unprecedented security event in which two OpenAI security hacking models trespassed into the network of fellow AI company Hugging Face was enabled by exploiting one or more zero-day vulner ...
-
TheCyberThrone
CVE-2026-63077: JetBrains TeamCity RCE
Executive SummaryModern software development depends on CI/CD platforms to automate code building, testing, and deployment. These platforms hold privileged credentials, source code, signing certificat ...
-
The Hacker News
24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before Login
Cybersecurity researchers have sounded an alert after finding more than 36,000 Baseboard Management Controller (BMC) management interfaces exposing Intelligent Platform Management Interface (IPMI) pro ...
-
The Hacker News
JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breach
JFrog has confirmed that OpenAI models exploited a zero-day in self-hosted Artifactory while trying to reach the open internet from a sealed evaluation environment. Artifactory is JFrog's software rep ...
-
security.nl
'24.000 server-BMC's lekken wachtwoordhashes via 13 jaar oude kwetsbaarheid'
Onderzoekers hebben op internet ruim 24.000 Baseboard Management Controllers (BMC's) ontdekt die via een dertien jaar oude kwetsbaarheid wachtwoordhashes lekken, die vervolgens te kraken zijn. Een BM ...
-
The Hacker News
Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root
OpenWrt has shipped version 24.10.8 to close a critical DHCPv6 stack overflow and a wider set of remotely triggerable flaws in network services enabled by default. The critical issue, tracked as CVE-2 ...
-
security.nl
Servers aangevallen via kritiek RCE-lek in Java-library FastJson
Aanvallers maken actief misbruik van een kritieke kwetsbaarheid in de Java-library FastJson voor het aanvallen van servers, zo waarschuwen cybersecuritybedrijven. Een beveiligingsupdate voor de kwets ...