CVEFeed Newsroom – Latest Cybersecurity Updates

The "Cyber Newsroom Feed" module is a live feed of the latest cyber news enriched with CVE and vulnerability data. The feed is updated every 5 minutes and includes the latest news from the cyber security industry. The feed is designed to provide users with a comprehensive overview of the latest cyber security news and trends.

  • Daily CyberSecurity
Critical ZITADEL Flaws (CVE-2025-67494, CVSS 9.3) Risk SSRF Internal Breach and Account Hijack via XSS

The security team behind ZITADEL, the open-source identity management platform, has issued urgent advisories regarding three high-severity vulnerabilities discovered in its V2 Login UI. The flaws, whi ...

Published Date: Dec 10, 2025 (1 day, 10 hours ago)
  • Trend Micro
CVE-2025-55182: React2Shell Analysis, Proof-of-Concept Chaos, and In-the-Wild Exploitation

Key takeaways: The exploit leverages JavaScript’s duck-typing and dynamic code execution through an attack that has four stages: it creates a self-reference loop, tricks JavaScript into calling attack ...

Published Date: Dec 10, 2025 (1 day, 10 hours ago)
  • The Register
Microsoft reports 7.8-rated zero day, plus 56 more in December Patch Tuesday

Happy December Patch Tuesday to all who celebrate. This month's patch party includes one Microsoft flaw under exploitation, plus two others listed as publicly known – but just 57 CVEs in total from Re ...

Published Date: Dec 09, 2025 (1 day, 11 hours ago)
  • krebsonsecurity.com
Microsoft Patch Tuesday, December 2025 Edition

Microsoft today pushed updates to fix at least 56 security flaws in its Windows operating systems and supported software. This final Patch Tuesday of 2025 tackles one zero-day bug that is already bein ...

Published Date: Dec 09, 2025 (1 day, 11 hours ago)
  • BleepingComputer
SAP fixes three critical vulnerabilities across multiple products

SAP has released its December security updates addressing 14 vulnerabilities across a range of products, including three critical-severity flaws. The most severe (CVSS score: 9.9) of all the issues is ...

Published Date: Dec 09, 2025 (1 day, 12 hours ago)
  • BleepingComputer
Windows PowerShell now warns when running Invoke-WebRequest scripts

Microsoft says Windows PowerShell now warns when running scripts that use the Invoke-WebRequest cmdlet to download web content, aiming to prevent potentially risky code from executing. As Microsoft ex ...

Published Date: Dec 09, 2025 (1 day, 14 hours ago)
  • BleepingComputer
Microsoft releases Windows 10 KB5071546 extended security update

Microsoft has released the KB5071546 extended security update to resolve 57 security vulnerabilities, including three zero-day flaws. If you are running Windows 10 Enterprise LTSC or are enrolled in t ...

Published Date: Dec 09, 2025 (1 day, 14 hours ago)
  • BleepingComputer
Microsoft December 2025 Patch Tuesday fixes 3 zero-days, 57 flaws

Today is Microsoft's December 2025 Patch Tuesday, which fixes 57 flaws, including one actively exploited and two publicly disclosed zero-day vulnerabilities. This Patch Tuesday also addresses three "C ...

Published Date: Dec 09, 2025 (1 day, 16 hours ago)
  • BleepingComputer
Fortinet warns of critical FortiCloud SSO login auth bypass flaws

Fortinet has released security updates to address two critical vulnerabilities in FortiOS, FortiWeb, FortiProxy, and FortiSwitchManager that could allow attackers to bypass FortiCloud SSO authenticati ...

Published Date: Dec 09, 2025 (1 day, 16 hours ago)
  • Zero Day Initiative
The December 2025 Security Update Review

It’s the final patch Tuesday of 2025, but that doesn’t make it any less exciting. Put aside your holiday planning for just a moment as we review the latest security offering from Adobe and Microsoft. ...

Published Date: Dec 09, 2025 (1 day, 16 hours ago)

Filters

Filter news that are affecting your technology stack
Showing 10 of 8549 Results