CVEFeed Newsroom – Latest Cybersecurity Updates

The "Cyber Newsroom Feed" module is a live feed of the latest cyber news enriched with CVE and vulnerability data. The feed is updated every 5 minutes and includes the latest news from the cyber security industry. The feed is designed to provide users with a comprehensive overview of the latest cyber security news and trends.

  • Daily CyberSecurity
AI-Generated Malware Attacks 230,000 Exposed Ray AI Clusters in Massive ShadowRay 2.0 Botnet Campaign

Security researchers at Oligo Security have uncovered a massive, fast-evolving cyberattack campaign hijacking exposed Ray AI clusters worldwide through the long-standing ShadowRay vulnerability (CVE-2 ...

Published Date: Nov 19, 2025 (1 month ago)
  • Daily CyberSecurity
D-Link DIR-878 Reaches EOL: 3 Unpatched RCE Flaws Allow Unauthenticated Remote Command Execution

D-Link has issued a security advisory warning users of the DIR-878 router series that multiple newly disclosed vulnerabilities—including three unauthenticated remote command execution flaws—will not b ...

Published Date: Nov 19, 2025 (1 month ago)
  • Daily CyberSecurity
Critical METZ CONNECT Flaws (CVSS 9.8) Allow Unauthenticated RCE and Admin Takeover on Industrial Controllers

METZ CONNECT GmbH, in coordination with CERT@VDE, has issued an urgent security advisory warning of multiple critical vulnerabilities affecting its EWIO-2 series, including Energy-Controlling EWIO2-M, ...

Published Date: Nov 19, 2025 (1 month ago)
  • Daily CyberSecurity
9 Million Installs: Malicious Chrome VPN Extensions Hijack User Traffic Via Remote PAC Proxy Injection

One of the Malicious ‘Free Unlimited VPN’ in store | Image: LayerX Security researchers at LayerX Security have uncovered a long-running malicious campaign involving VPN and ad-blocking browser extens ...

Published Date: Nov 19, 2025 (1 month ago)
  • Daily CyberSecurity
Critical SolarWinds Serv-U Flaws (CVSS 9.1) Allow Authenticated Admin RCE and Path Bypass

SolarWinds has released security updates addressing three critical vulnerabilities in Serv-U—its managed file transfer and FTP server platform—each carrying a CVSS score of 9.1 and enabling remote cod ...

Published Date: Nov 19, 2025 (1 month ago)
  • Daily CyberSecurity
Stealth Stealer: New .NET Loader Hides LokiBot Payload in BMP/PNG Images Using Advanced Steganography

The Splunk Threat Research Team (STRT) has uncovered a new variant of a .NET steganographic malware loader that hides malicious payloads inside image files and ultimately deploys LokiBot, one of the m ...

Published Date: Nov 19, 2025 (1 month ago)
  • cloudsecurityalliance.org
Microsoft Entra ID Vulnerability: The Discovery That Shook Identity Security

Written by Shravan Konthalapally and Shubham Takankhar. In July 2025, the cybersecurity world was rocked by security researcher Dirk-jan Mollema’s unveiling of a catastrophic vulnerability within Mic ...

Published Date: Nov 18, 2025 (1 month ago)
  • The Register
Self-replicating botnet attacks Ray clusters

Malefactors are actively attacking internet-facing Ray clusters and abusing the open source AI framework to spread a self-replicating botnet that mines for cryptocurrency, steals data, and launches di ...

Published Date: Nov 18, 2025 (1 month ago)
  • BleepingComputer
New ShadowRay attacks convert Ray clusters into crypto miners

A global campaign dubbed ShadowRay 2.0 hijacks exposed Ray Clusters by exploiting an old code execution flaw to turn them into a self-propagating cryptomining botnet. Developed by Anyscale, the Ray op ...

Published Date: Nov 18, 2025 (1 month ago)
  • The Cyber Express
W3 Total Cache Vulnerability Puts Over One Million WordPress Sites at Risk

A severe security flaw has been discovered in the popular W3 Total Cache WordPress plugin, potentially exposing more than one million websites to remote code execution (RCE). The vulnerability, offici ...

Published Date: Nov 18, 2025 (1 month ago)

Filters

Filter news that are affecting your technology stack
Showing 10 of 8766 Results