CVEFeed Newsroom – Latest Cybersecurity Updates
The "Cyber Newsroom Feed" module is a live feed of the latest cyber news enriched with CVE and vulnerability data. The feed is updated every 5 minutes and includes the latest news from the cyber security industry. The feed is designed to provide users with a comprehensive overview of the latest cyber security news and trends.
-
security.nl
TeamCity-servers via kritieke kwetsbaarheid op afstand over te nemen
Een kritieke kwetsbaarheid maakt het mogelijk voor ongeauthenticeerde aanvallers om TeamCity-servers op afstand over te nemen. Ontwikkelaar JetBrains heeft een update voor het beveiligingslek (CVE-202 ...
-
The Hacker News
Public Exploit Released for Patched vBulletin Pre-Auth Code Execution Flaw
Public exploit details released on July 27 show how an unauthenticated request can reach PHP's eval() function inside vBulletin and execute code on an unpatched forum server. The attack requires no ac ...
-
The Hacker News
⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and More
Monday starts with the usual promise that everything is under control. Then the logs wake up. This week, trusted tools crossed lines, old flaws found new work, exposed systems stayed exposed, and atta ...
-
The Hacker News
n8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n Process
n8n has patched a high-severity expression-sandbox escape that could let an authenticated workflow editor execute operating-system commands on the server running the automation platform. Security Joes ...
-
cert.pl
Vulnerabilities in proCertum SmartSign software
Vulnerabilities in proCertum SmartSign software CVE ID CVE-2026-57916 Publication date 27 July 2026 Vendor Asseco Product proCertum SmartSign Vulnerable versions All before 9.4.3.90 Vulnerability type ...
-
cert.pl
Vulnerability in DaveGamble cJSON library
Vulnerability in DaveGamble cJSON library CVE ID CVE-2026-16554 Publication date 27 July 2026 Vendor DaveGamble Product cJSON Vulnerable versions 1.7.19 Vulnerability type (CWE) Integer overflow or wr ...
-
The Cyber Express
Two Old Oj Flaws Chained to Trigger GitLab Remote Code Execution
A newly disclosed GitLab vulnerability has revealed how two long-standing memory-safety flaws in the widely used Ruby JSON parsing library, Oj, can be combined to achieve remote code execution on defa ...
-
security.nl
Honderden Microsoft SharePoint-servers bevatten actief misbruikte lekken
Honderden Microsoft SharePoint-servers die vanaf het internet toegankelijk zijn bevatten bekende kwetsbaarheden waar aanvallers op dit moment actief misbruik van maken. Het gaat ook om 25 SharePoint-s ...
-
The Hacker News
Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available
Security firms ThreatBook and Imperva say attackers are targeting a critical flaw in Fastjson, Alibaba's JSON library for Java. In affected Spring Boot applications, a malicious JSON request can execu ...
-
The Hacker News
Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE
Threat actors linked to the Cl0p (aka Chubby Scorpius, FIN11, Graceful Spider, and Lace Tempest) ransomware campaign are exploiting flaws in internet-exposed PTC Windmill and FlexPLM deployments as pa ...