CVEFeed Newsroom – Latest Cybersecurity Updates
The "Cyber Newsroom Feed" module is a live feed of the latest cyber news enriched with CVE and vulnerability data. The feed is updated every 10 minutes and includes the latest news from the cyber security industry. The feed is designed to provide users with a comprehensive overview of the latest cyber security news and trends.
-
The Cyber Express
Critical GitLab Flaw Lets Hackers Alter or Delete Public Projects
GitLab has patched two security flaws, including CVE-2026-19478, a critical code injection vulnerability that could allow unauthenticated attackers to remotely modify or delete public projects and use ...
-
The Hacker News
Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data
A JavaServer Pages (JSP) web shell deployed following the exploitation of a critical security flaw in PTC Windchill and FlexPLM servers is specifically designed for the enterprise Product Lifecycle Ma ...
-
TheCyberThrone
GitLab 19.2.4: Critical GraphQL Vulnerability patched
GitLab has released an ad-hoc critical security patch for its Community Edition (CE) and Enterprise Edition (EE), addressing a critical GraphQL-related vulnerability that could allow an unauthenticat ...
-
The Hacker News
Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps
Varonis Threat Labs has disclosed three vulnerabilities in Microsoft Copilot Personal that it said could allow a single click on a crafted link to silently pull data from connected apps and other info ...
-
The Hacker News
Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets
Two critical vulnerabilities impacting MLflow, an open-source artificial intelligence (AI) platform, and FUXA, an open-source, web-based SCADA / HMI software built for operational technology (OT) and ...
-
security.nl
Microsoft verhelpt kritiek Copilot-lek waardoor informatie kon lekken
Microsoft heeft een kritieke kwetsbaarheid in AI-assistent Copilot verholpen waardoor informatie kon lekken. Het beveiligingslek werd gevonden door cybersecuritybedrijf Varonis, dat het probleem 'CoSn ...
-
cert.pl
Vulnerability in Carbone software
Vulnerability in Carbone software CVE ID CVE-2026-18929 Publication date 18 August 2026 Vendor Carbone Product Carbone Vulnerable versions All before 3.8.2 Vulnerability type (CWE) Improper handling o ...
-
security.nl
Kritieke Citrix NetScaler RCE-kwetsbaarheid misbruikt bij aanvallen
dinsdag 18 augustus 2026, 10:20 door Redactie, 1 reactiesLaatst bijgewerkt: Vandaag, 12:02 Een kritieke kwetsbaarheid in Citrix NetScaler ADC en Citrix NetScaler Gateway die remote code execution (RCE ...
-
security.nl
Apple dicht lek waardoor afbeelding code op iPhones en Macs kan uitvoeren
Apple heeft beveiligingsupdates voor iOS, iPadOS en macOS uitgebracht die meerdere kwetsbaarheden verhelpen, waaronder een beveiligingslek dat het uitvoeren van willekeurige code maakt bij het verwerk ...
-
The Hacker News
CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a critical flaw impacting Ray to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitat ...