CVEFeed Newsroom – Latest Cybersecurity Updates
The "Cyber Newsroom Feed" module is a live feed of the latest cyber news enriched with CVE and vulnerability data. The feed is updated every 10 minutes and includes the latest news from the cyber security industry. The feed is designed to provide users with a comprehensive overview of the latest cyber security news and trends.
-
SentinelOne
Bring Your Own Vulnerable Device: The EDR Killer Economy
Bring your own vulnerable driver (BYOVD) is having a moment in endpoint security. Some of the buzz is earned. Some of it is overblown. This series unpacks both and shows the evidence for each. This pi ...
-
The Hacker News
Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation
Two new unpatched zero-day vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway appliances that allow remote code execution are being actively exploited in the wild, security firm watchTowr s ...
-
The Hacker News
Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials
The Psychedelic Stealer malware distributed via compromised Ukrainian websites using ClickFix-style Cloudflare verification checks is part of a wider malware-as-a-service (MaaS) platform called Lunex. ...
-
The Hacker News
Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells
Google is warning of renewed mass exploitation of a known security vulnerability in Oracle PeopleSoft as part of a campaign targeting multiple sectors globally. The ShinyHunters-linked activity involv ...
-
The Hacker News
SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added two security flaws impacting Microsoft SharePoint and Mikrotik RouterOS to its Known Exploited Vulnerabilities (KEV) ca ...
-
Kaspersky
CVE-2026-87902: Critical Vulnerability in WordPress
vulnerability CVE-2026-87902, a new critical vulnerability in the WordPress core, is already being actively exploited in real-world attacks. Editorial Team September 25, 2026 A critical vulnerability ...
-
security.nl
Roundcube Webmail SQL Injection-lek misbruikt bij aanvallen
Een SQL Injection-kwetsbaarheid in Roundcube wordt misbruikt bij aanvallen. Dat laat het Canadese Centrum voor Cybersecurity weten. Roundcube is opensource-webmailsoftware en wordt door allerlei organ ...
-
The Hacker News
Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild
The Canadian Centre for Cyber Security has warned that a now-patched Roundcube Webmail vulnerability is being actively exploited in the wild. The vulnerability in question is CVE-2026-48842 (CVSS scor ...
-
security.nl
NCSC meldt actief misbruik van kritiek WordPress-lek: 'Update nu'
Aanvallers maken actief misbruik van een kritieke path traversal-kwetsbaarheid in WordPress waardoor websites zijn over te nemen, zo meldt het Nationaal Cyber Security Centrum (NCSC). Er is een update ...
-
The Hacker News
WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added two critical security flaws impacting WSO2 and Adobe Commerce and Magento to its Known Exploited Vulnerabilities (K ...