CVEFeed Newsroom – Latest Cybersecurity Updates
The "Cyber Newsroom Feed" module is a live feed of the latest cyber news enriched with CVE and vulnerability data. The feed is updated every 10 minutes and includes the latest news from the cyber security industry. The feed is designed to provide users with a comprehensive overview of the latest cyber security news and trends.
-
Daily CyberSecurity
High-Severity GitLab XSS Flaw (CVE-2025-12716) Risks Session Hijack via Malicious Wiki Pages
In a critical mid-week security sprint, GitLab has rolled out a series of important updates for its Community Edition (CE) and Enterprise Edition (EE), squashing a high-severity bug that could allow a ...
-
Daily CyberSecurity
Unpatched TOTOLINK AX1800 Router Flaw Allows Unauthenticated Telnet & Root RCE
A critical security vulnerability has been uncovered in the popular TOTOLINK AX1800 wireless router, a device widely used in small businesses and home offices. The flaw, which currently has no officia ...
-
Daily CyberSecurity
Critical CCTV Flaw (CVE-2025-13607) Risks Video Feed Hijack & Credential Theft via Missing Authentication
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a high-severity alert regarding a critical flaw affecting networked CCTV cameras, warning that malicious actors could easily hija ...
-
Daily CyberSecurity
“React2Shell” Crisis: Critical Vulnerability Triggers Global Cyberattacks by State-Sponsored Groups
A critical security flaw in the popular React web framework has ignited a wave of cyberattacks, with state-sponsored actors and cybercriminals rushing to exploit the vulnerability before organizations ...
-
Daily CyberSecurity
Makop Ransomware Evolves: GuLoader and BYOVD EDR Killers Used to Attack RDP-Exposed Networks
A familiar threat has returned with new tricks, proving that cybercriminals don’t need sophisticated custom code to cause widespread damage—they just need the right off-the-shelf tools. A new report f ...
-
Daily CyberSecurity
DeadLock Ransomware Deploys BYOVD EDR Killer by Exploiting Baidu Driver for Kernel-Level Defense Bypass
DeadLock’s ransom note file | Image: Cisco Talos A financially motivated threat group is deploying a new ransomware strain known as “DeadLock,” utilizing advanced “Bring Your Own Vulnerable Driver” (B ...
-
Daily CyberSecurity
Critical PCIe 6.0 Flaws Risk Secure Data Integrity via Stale Data Injection in IDE Mechanism
The secure foundations of high-speed data transfer have developed a crack. The CERT Coordination Center (CERT/CC) has released a vulnerability note detailing three specification-level flaws in the PCI ...
-
Trend Micro
SHADOW-VOID-042 Targets Multiple Industries with Void Rabisu-like Tactics
Phishing In November, a targeted spear-phishing campaign was observed using Trend Micro-themed lures against various industries, but this was quickly detected and thwarted by the Trend Vision One™ pla ...
-
The Register
700+ self-hosted Gits battered in 0-day attacks with no fix imminent
Attackers are actively exploiting a zero-day bug in Gogs, a popular self-hosted Git service, and the open source project doesn't yet have a fix. More than 700 instances have been compromised in the on ...
-
The Hacker News
React2Shell Exploitation Delivers Crypto Miners and New Malware Across Multiple Sectors
React2Shell continues to witness heavy exploitation, with threat actors leveraging the maximum-severity security flaw in React Server Components (RSC) to deliver cryptocurrency miners and an array of ...