CVEFeed Newsroom – Latest Cybersecurity Updates

The "Cyber Newsroom Feed" module is a live feed of the latest cyber news enriched with CVE and vulnerability data. The feed is updated every 10 minutes and includes the latest news from the cyber security industry. The feed is designed to provide users with a comprehensive overview of the latest cyber security news and trends.

  • Daily CyberSecurity
DeadLock Ransomware Deploys BYOVD EDR Killer by Exploiting Baidu Driver for Kernel-Level Defense Bypass

DeadLock’s ransom note file | Image: Cisco Talos A financially motivated threat group is deploying a new ransomware strain known as “DeadLock,” utilizing advanced “Bring Your Own Vulnerable Driver” (B ...

Published Date: Dec 11, 2025 (9 months, 1 week ago)
  • Daily CyberSecurity
Critical PCIe 6.0 Flaws Risk Secure Data Integrity via Stale Data Injection in IDE Mechanism

The secure foundations of high-speed data transfer have developed a crack. The CERT Coordination Center (CERT/CC) has released a vulnerability note detailing three specification-level flaws in the PCI ...

Published Date: Dec 11, 2025 (9 months, 1 week ago)
  • Trend Micro
SHADOW-VOID-042 Targets Multiple Industries with Void Rabisu-like Tactics

Phishing In November, a targeted spear-phishing campaign was observed using Trend Micro-themed lures against various industries, but this was quickly detected and thwarted by the Trend Vision One™ pla ...

Published Date: Dec 11, 2025 (9 months, 1 week ago)
  • The Register
700+ self-hosted Gits battered in 0-day attacks with no fix imminent

Attackers are actively exploiting a zero-day bug in Gogs, a popular self-hosted Git service, and the open source project doesn't yet have a fix. More than 700 instances have been compromised in the on ...

Published Date: Dec 10, 2025 (9 months, 1 week ago)
  • The Hacker News
React2Shell Exploitation Delivers Crypto Miners and New Malware Across Multiple Sectors

React2Shell continues to witness heavy exploitation, with threat actors leveraging the maximum-severity security flaw in React Server Components (RSC) to deliver cryptocurrency miners and an array of ...

Published Date: Dec 10, 2025 (9 months, 1 week ago)
  • The Hacker News
.NET SOAPwn Flaw Opens Door for File Writes and Remote Code Execution via Rogue WSDL

Dec 10, 2025Ravie LakshmananEnterprise Security / Web Services New research has uncovered exploitation primitives in the .NET Framework that could be leveraged against enterprise-grade applications ...

Published Date: Dec 10, 2025 (9 months, 1 week ago)
  • The Cyber Express
Microsoft Patch Tuesday December 2025: One Zero-Day, Six High-Risk Flaws Fixed

Microsoft patched 57 vulnerabilities in its Patch Tuesday December 2025 update, including one exploited zero-day and six high-risk vulnerabilities. The exploited zero-day is CVE-2025-62221, a 7.8-rate ...

Published Date: Dec 10, 2025 (9 months, 1 week ago)
  • CybersecurityNews
Critical Ivanti EPM Vulnerability Allows Admin Session Hijacking via Stored XSS

A critical stored cross-site scripting vulnerability in Ivanti Endpoint Manager (“EPM”) versions 2024 SU4 and below, that could enable attackers to hijack administrator sessions without authentication ...

Published Date: Dec 10, 2025 (9 months, 1 week ago)
  • CybersecurityNews
Over 644,000 Domains Exposed to Critical React Server Components Vulnerability

The Shadowserver Foundation has released alarming new data regarding the exposure of web applications to CVE-2025-55182, a critical vulnerability affecting React Server Components. Following significa ...

Published Date: Dec 10, 2025 (9 months, 2 weeks ago)
  • hackread.com
North Korean Hackers Deploy EtherRAT Malware in React2Shell Exploits

A team of cybersecurity researchers at Sysdig, a firm specialising in protecting cloud and container-based apps, has found a new malware called EtherRAT being deployed to exploit the severe CVE-2025-5 ...

Published Date: Dec 10, 2025 (9 months, 2 weeks ago)

Filters

Filter news that are affecting your technology stack
Showing 10 of 12349 Results