CVEFeed Newsroom – Latest Cybersecurity Updates

The "Cyber Newsroom Feed" module is a live feed of the latest cyber news enriched with CVE and vulnerability data. The feed is updated every 5 minutes and includes the latest news from the cyber security industry. The feed is designed to provide users with a comprehensive overview of the latest cyber security news and trends.

  • Cybersecurity News
Popular Java Security Framework ‘pac4j’ Vulnerable to RCE (CVE-2023-25581)

A new analysis by security researcher Michael Stepankin (@artsploit) of the GitHub Security Lab (GHSL) has uncovered a critical vulnerability in pac4j, a widely-used Java security framework. This vuln ... Read more

Published Date: Oct 14, 2024 (10 months, 4 weeks ago)
  • Cybersecurity News
$50,000 Bounty: Researcher Reveals Critical Zendesk Email Spoofing Flaw (CVE-2024-49193)

Image: DanielIn a detailed analysis by security researcher Daniel, a serious vulnerability in Zendesk’s email management system, tracked as CVE-2024-49193, has been revealed. This flaw exposes compani ... Read more

Published Date: Oct 14, 2024 (10 months, 4 weeks ago)
  • Cybersecurity News
Bitcoin Core Vulnerability (CVE-2024-35202) Enables Remote Node Crashes

A high-severity vulnerability, tracked as CVE-2024-35202 and assigned a CVSS v3.0 base score of 7.5, has been disclosed in the Bitcoin Core software. Exploitation of this vulnerability permits remote ... Read more

Published Date: Oct 14, 2024 (10 months, 4 weeks ago)
  • Cybersecurity News
GitHub Enterprise Server Patches Critical Security Flaw – CVE-2024-9487 (CVSS 9.5)

GitHub has released security updates to address two vulnerabilities in GitHub Enterprise Server, one of which could allow attackers to bypass authentication and gain unauthorized access.The most sever ... Read more

Published Date: Oct 14, 2024 (10 months, 4 weeks ago)
  • Cybersecurity News
Thousands of Fortinet Devices Remain Exposed to RCE CVE-2024-23113 Vulnerability

A recent report from the Shadowserver Foundation has revealed a concerning number of Fortinet devices remain vulnerable to a critical remote code execution (RCE) vulnerability, despite patches being a ... Read more

Published Date: Oct 14, 2024 (10 months, 4 weeks ago)
  • Cybersecurity News
Apache Roller Patches CSRF Flaw CVE-2024-46911 in Latest Update

The Apache Software Foundation has released a security update for Apache Roller, a popular Java-based blogging platform. This update addresses a critical Cross-site Request Forgery (CSRF) vulnerabilit ... Read more

Published Date: Oct 14, 2024 (10 months, 4 weeks ago)
  • Cybersecurity News
Plane Project Management Tool Patches Critical SSRF Flaw – CVE-2024-47830 (CVSS 9.3)

A critical security vulnerability has been discovered and patched in Plane, a popular open-source project management tool. The vulnerability, identified as CVE-2024-47830 and assigned a CVSS score of ... Read more

Published Date: Oct 14, 2024 (10 months, 4 weeks ago)
  • TheCyberThrone
Apache Avro vulnerability CVE-2024-47561

Apache project releases patch for a vulnerability tracked as CVE-2024-47561, that impacts all versions of the software prior to 1.11.4.Apache Avro is a data serialization framework developed as part o ... Read more

Published Date: Oct 14, 2024 (10 months, 4 weeks ago)
  • TheCyberThrone
CISA releases VDP platform Annual report for 2023

The U.S. CISA has released its 2023 Annual Report for the Vulnerability Disclosure Policy (VDP) Platform. Over the past year, the agency concentrated on promoting greater adoption of the VDP Platform ... Read more

Published Date: Oct 13, 2024 (10 months, 4 weeks ago)
  • BleepingComputer
Iranian hackers now exploit Windows flaw to elevate privileges

The Iranian state-sponsored hacking group APT34, aka OilRig, has recently escalated its activities with new campaigns targeting government and critical infrastructure entities in the United Arab Emira ... Read more

Published Date: Oct 13, 2024 (10 months, 4 weeks ago)

Filters

Showing 10 of 8078 Results