CVEFeed Newsroom – Latest Cybersecurity Updates

The "Cyber Newsroom Feed" module is a live feed of the latest cyber news enriched with CVE and vulnerability data. The feed is updated every 5 minutes and includes the latest news from the cyber security industry. The feed is designed to provide users with a comprehensive overview of the latest cyber security news and trends.

  • BleepingComputer
Ivanti warns of maximum severity CSA auth bypass vulnerability

Today, Ivanti warned customers about a new maximum-severity authentication bypass vulnerability in its Cloud Services Appliance (CSA) solution. The security flaw (tracked as CVE-2024-11639 and reporte ... Read more

Published Date: Dec 10, 2024 (8 months, 4 weeks ago)
  • Zero Day Initiative
The December 2024 Security Update Review

We have made it to the end of the year and the final Patch Tuesday of 2024. As expected, Microsoft and Adobe have released what (hopefully) will be their last patches of the year. Take a break from yo ... Read more

Published Date: Dec 10, 2024 (8 months, 4 weeks ago)
  • BleepingComputer
Microsoft December 2024 Patch Tuesday fixes 1 exploited zero-day, 71 flaws

Today is Microsoft's December 2024 Patch Tuesday, which includes security updates for 71 flaws, including one actively exploited zero-day vulnerability.This Patch Tuesday fixed sixteen critical vulner ... Read more

Published Date: Dec 10, 2024 (8 months, 4 weeks ago)
  • Hackread - Latest Cybersecurity, Tech, Crypto & Hacking News
Dell Urges Immediate Update to Fix Critical Power Manager Vulnerability

SUMMARY: Critical Vulnerability Alert: Dell Power Manager versions before 3.17 have a high-severity access control flaw (CVE-2024-49600) allowing attackers to gain elevated privileges. Exploitation Ri ... Read more

Published Date: Dec 10, 2024 (8 months, 4 weeks ago)
  • Ars Technica
AMD’s trusted execution environment blown wide open by new BadRAM attack

Attack bypasses AMD protection promising security, even when a server is compromised. One of the oldest maxims in hacking is that once an attacker has physical access to a device, it’s game over for i ... Read more

Published Date: Dec 10, 2024 (8 months, 4 weeks ago)
  • BleepingComputer
US sanctions Chinese firm for hacking firewalls in ransomware attacks

The U.S. Treasury Department has sanctioned Chinese cybersecurity company Sichuan Silence and one of its employees for their involvement in a series of Ragnarok ransomware attacks targeting U.S. criti ... Read more

Published Date: Dec 10, 2024 (8 months, 4 weeks ago)
  • The Register
AMD secure VM tech undone by DRAM meddling

Researchers have found that the security mechanism AMD uses to protect virtual machine memory can be bypassed with $10 of hardware – and perhaps not even that. AMD Secure Encrypted Virtualization (SEV ... Read more

Published Date: Dec 10, 2024 (8 months, 4 weeks ago)
  • The Hacker News
Cleo File Transfer Vulnerability Under Exploitation – Patch Pending, Mitigation Urged

Users of Cleo-managed file transfer software are being urged to ensure that their instances are not exposed to the internet following reports of mass exploitation of a vulnerability affecting fully pa ... Read more

Published Date: Dec 10, 2024 (8 months, 4 weeks ago)
  • BleepingComputer
New Cleo zero-day RCE flaw exploited in data theft attacks

Update added to bottom of the article. Hackers are actively exploiting a zero-day vulnerability in Cleo managed file transfer software to breach corporate networks and conduct data theft attacks. The ... Read more

Published Date: Dec 10, 2024 (8 months, 4 weeks ago)
  • TheCyberThrone
Mauri Ransomware exploiting Apache ActiveMQ flaw CVE-2024-46604

The Apache ActiveMQ server is currently facing a critical vulnerability identified as CVE-2023-46604. This vulnerability allows attackers to exploit the system by manipulating serialized class types w ... Read more

Published Date: Dec 10, 2024 (8 months, 4 weeks ago)

Filters

Showing 10 of 7968 Results