CVEFeed Newsroom – Latest Cybersecurity Updates

The "Cyber Newsroom Feed" module is a live feed of the latest cyber news enriched with CVE and vulnerability data. The feed is updated every 5 minutes and includes the latest news from the cyber security industry. The feed is designed to provide users with a comprehensive overview of the latest cyber security news and trends.

  • Daily CyberSecurity
Wear OS Messages Flaw (CVE-2025-12080) Allows Unprivileged Apps to Send SMS/RCS Without Permission, PoC Available

Security researcher Gabriele Digregorio has disclosed a newly identified vulnerability in Google Messages for Wear OS, designated CVE-2025-12080 (CVSS v4 6.9), that allows any installed app to send SM ...

Published Date: Oct 29, 2025 (1 month, 1 week ago)
  • Daily CyberSecurity
Critical Magento Flaw (CVE-2025-54236) Actively Exploited for Session Hijacking and Unauthenticated RCE

The Akamai Security Intelligence Group has issued an urgent warning after observing active exploitation in the wild of a newly disclosed Magento vulnerability known as SessionReaper (CVE-2025-54236). ...

Published Date: Oct 29, 2025 (1 month, 1 week ago)
  • Daily CyberSecurity
Critical MikroTik Flaw (CVE-2025-61481, CVSS 10.0) Exposes Router Admin Credentials Over Unencrypted HTTP WebFig

A newly disclosed vulnerability, CVE-2025-61481, rated a maximum CVSS score of 10.0, affects MikroTik RouterOS (v7.14.2) and SwitchOS (v2.18) and allows remote attackers to execute arbitrary code or i ...

Published Date: Oct 29, 2025 (1 month, 1 week ago)
  • The Register
Firewalls and VPNs are so complex now, they can actually make you less secure

Organizations using Cisco and Citrix VPN devices were nearly seven times as likely to suffer a ransomware infection over a 15-month period, according to At-Bay, a provider of cyber insurance and a ven ...

Published Date: Oct 28, 2025 (1 month, 1 week ago)
  • The Cyber Express
CISA Warns that DELMIA Apriso Vulnerabilities Are Under Attack

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two DELMIA Apriso vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog. Today’s addition of CVE-2025-6204 and ...

Published Date: Oct 28, 2025 (1 month, 1 week ago)
  • BleepingComputer
CISA warns of two more actively exploited Dassault vulnerabilities

The Cybersecurity & Infrastructure Security Agency (CISA) warned today that attackers are actively exploiting two vulnerabilities in Dassault Systèmes' DELMIA Apriso, a manufacturing operations manage ...

Published Date: Oct 28, 2025 (1 month, 1 week ago)
  • Help Net Security
PoC code drops for remotely exploitable BIND 9 DNS flaw (CVE-2025-40778)

A high-severity vulnerability (CVE-2025-40778) affecting BIND 9 DNS resolvers could be leveraged by remote, unauthenticated attackers to manipulate DNS entries via cache poisoning, allowing them to re ...

Published Date: Oct 28, 2025 (1 month, 1 week ago)
  • TheCyberThrone
Google Chrome Zero-Day Delivers Memento Spyware

October 28, 2025A zero-day vulnerability in Google Chrome, CVE-2025-2783, was actively exploited in early 2025 by attackers using spyware linked to Memento Labs (formerly Hacking Team), a notorious It ...

Published Date: Oct 28, 2025 (1 month, 1 week ago)
  • CybersecurityNews
XWiki RCE Vulnerability Actively Exploted In Wild To Deliver Coinminer

A critical remote code execution (RCE) flaw in XWiki, a popular open-source wiki platform, was exploited in the wild to deploy cryptocurrency mining malware on compromised servers. The vulnerability, ...

Published Date: Oct 28, 2025 (1 month, 1 week ago)
  • Help Net Security
Italian-made spyware Dante linked to Chrome zero-day exploitation campaign

CVE-2025-2783, a Chrome zero-day vulnerability that was detected being exploited in March 2025 and was subsequently fixed by Google, was used by unknown attackers to deliver LeetAgent, suspected comme ...

Published Date: Oct 28, 2025 (1 month, 1 week ago)

Filters

Filter news that are affecting your technology stack
Showing 10 of 8512 Results