CVEFeed Newsroom – Latest Cybersecurity Updates

The "Cyber Newsroom Feed" module is a live feed of the latest cyber news enriched with CVE and vulnerability data. The feed is updated every 10 minutes and includes the latest news from the cyber security industry. The feed is designed to provide users with a comprehensive overview of the latest cyber security news and trends.

  • The Hacker News
JPCERT Confirms Active Command Injection Attacks on Array AG Gateways

Dec 05, 2025Ravie LakshmananVulnerability / Network Security A command injection vulnerability in Array Networks AG Series secure access gateways has been exploited in the wild since August 2025, ac ...

Published Date: Dec 05, 2025 (9 months ago)
  • CybersecurityNews
China-Nexus Hackers Actively Exploiting React2Shell Vulnerability in The Wild

China-nexus threat groups are racing to weaponize the new React2Shell bug, tracked as CVE-2025-55182, only hours after its public disclosure. The flaw sits in React Server Components and lets an attac ...

Published Date: Dec 05, 2025 (9 months ago)
  • CybersecurityNews
PoC Exploit Released for Critical React, Next.js RCE Vulnerability (CVE-2025-55182)

A proof-of-concept (PoC) exploit for CVE-2025-55182, a maximum-severity remote code execution (RCE) flaw in React Server Components, surfaced publicly this week, heightening alarms for developers worl ...

Published Date: Dec 05, 2025 (9 months ago)
  • Daily CyberSecurity
Russia Imposes Network-Level Blockade on Apple’s End-to-End Encrypted FaceTime

Russia has recently imposed a network-level blockade on Apple’s video-calling service FaceTime, which is developed and operated entirely by Apple and provides users with end-to-end encrypted audio and ...

Published Date: Dec 05, 2025 (9 months ago)
  • Daily CyberSecurity
Apache HTTP Server 2.4.66 Fixes SSRF Flaw (CVE-2025-59775) Exposing NTLM Hashes on Windows and suexec Bypass

The Apache Software Foundation has rolled out a crucial update for the ubiquitous Apache HTTP Server, addressing five distinct security vulnerabilities. The release of version 2.4.66 serves as a cumul ...

Published Date: Dec 05, 2025 (9 months ago)
  • Daily CyberSecurity
The PDF Trap: Critical Vulnerability (CVE-2025-66516, CVSS 10.0) Hits Apache Tika Core

The Apache Tika toolkit, the industry standard for detecting and extracting metadata from over a thousand file types, has issued a maximum-severity alert. A critical XML External Entity (XXE) vulnerab ...

Published Date: Dec 05, 2025 (9 months ago)
  • Daily CyberSecurity
“React2Shell” Storm: China-Nexus Groups Weaponize Critical React Flaw Hours After Disclosure

Only hours after the public disclosure of a critical vulnerability in the React ecosystem, state-sponsored cyber espionage groups have already launched active exploitation campaigns. Amazon threat int ...

Published Date: Dec 05, 2025 (9 months ago)
  • TheCyberThrone
React2Shell CVE-2025-55182- Shaking React and Next.js Ecosystems

React Server Components promised a revolution in web development—seamless server-side rendering with client interactivity. But a critical flaw dubbed React2Shell has turned that promise into a widespr ...

Published Date: Dec 05, 2025 (9 months ago)
  • Daily CyberSecurity
High-Severity Splunk Flaw Allows Local Privilege Escalation via Incorrect File Permissions on Windows

Splunk administrators managing Windows environments are being urged to patch immediately following the discovery of two high-severity vulnerabilities affecting both the Enterprise platform and Univers ...

Published Date: Dec 05, 2025 (9 months ago)
  • Daily CyberSecurity
High-Severity Cacti Flaw (CVE-2025-66399) Risks Remote Code Execution via SNMP Community String Injection

Image: Cacti A high-severity security flaw has been uncovered in Cacti, the popular open-source network graphing solution. The vulnerability, tracked as CVE-2025-66399, exposes Cacti installations to ...

Published Date: Dec 05, 2025 (9 months ago)

Filters

Filter news that are affecting your technology stack
Showing 10 of 12215 Results