CVEFeed Newsroom – Latest Cybersecurity Updates

The "Cyber Newsroom Feed" module is a live feed of the latest cyber news enriched with CVE and vulnerability data. The feed is updated every 5 minutes and includes the latest news from the cyber security industry. The feed is designed to provide users with a comprehensive overview of the latest cyber security news and trends.

  • CybersecurityNews
Fortinet FortiWeb Vulnerability (CVE-2025-64446) Exploited in the Wild for Full Admin Takeover

Threat actors have been actively exploiting a critical path-traversal vulnerability in Fortinet’s FortiWeb web application firewall since early October 2025, allowing unauthenticated attackers to crea ...

Published Date: Dec 16, 2025 (6 days, 11 hours ago)
  • TheCyberThrone
CISA Adds Gladinet Crypto Flaw and Apple WebKit Zero-Days to KEV Catalog

December 16, 2025CISA has expanded its Known Exploited Vulnerabilities (KEV) catalog with critical flaws in Gladinet CentreStack/Triofox and Apple WebKit components, confirming active real-world explo ...

Published Date: Dec 16, 2025 (6 days, 11 hours ago)
  • CybersecurityNews
Windows Admin Center Vulnerability (CVE-2025-64669) Let Attackers Escalate Privileges

A new local privilege escalation vulnerability in Microsoft’s Windows Admin Center (WAC), affecting versions up to 2.4.2.1 and environments running WAC 2411 and earlier. Tracked as CVE-2025-64669, the ...

Published Date: Dec 16, 2025 (6 days, 11 hours ago)
  • hackread.com
JumpCloud Remote Assist Flaw Lets Users Gain Full Control of Company Devices

A major security problem has been found in the JumpCloud Remote Assist for Windows agent, a tool used by over 180,000 organisations across 160 countries to manage their computers. This issue could all ...

Published Date: Dec 16, 2025 (6 days, 12 hours ago)
  • security.nl
Google en Microsoft melden misbruik van kritiek React2Shell-lek

Aanvallers maken misbruik van een kritieke kwetsbaarheid in React Server Components, ook bekend als React2Shell en CVE-2025-55182, zo stellen Microsoft en Google in analyses.Daarbij spreekt Google zel ...

Published Date: Dec 16, 2025 (6 days, 12 hours ago)
  • CybersecurityNews
FreePBX Vulnerabilities Enables Authentication Bypass that Leads Remote Code Execution

FreePBX has addressed critical vulnerabilities enabling authentication bypass and remote code execution in its Endpoint Manager module. Discovered by Horizon3.ai researchers, these flaws affect teleph ...

Published Date: Dec 16, 2025 (6 days, 13 hours ago)
  • The Hacker News
Amazon Exposes Years-Long GRU Cyber Campaign Targeting Energy and Cloud Infrastructure

Dec 16, 2025Ravie LakshmananCloud Security / Vulnerability Amazon's threat intelligence team has disclosed details of a "years-long" Russian state-sponsored campaign that targeted Western critical i ...

Published Date: Dec 16, 2025 (6 days, 13 hours ago)
  • CybersecurityNews
Critical ScreenConnect Vulnerability Let Attackers Expose Sensitive Configuration Data

ConnectWise has issued a security update for ScreenConnect™ to address a critical vulnerability that could enable attackers to expose sensitive configuration data and install untrusted extensions. The ...

Published Date: Dec 16, 2025 (6 days, 13 hours ago)
  • The Hacker News
Fortinet FortiGate Under Active Attack Through SAML SSO Authentication Bypass

Dec 16, 2025Ravie LakshmananNetwork Security / Vulnerability Threat actors have begun to exploit two newly disclosed security flaws in Fortinet FortiGate devices, less than a week after public discl ...

Published Date: Dec 16, 2025 (6 days, 14 hours ago)
  • security.nl
'Kritieke Fortinet-lekken 3 dagen na bekendmaking misbruikt bij aanvallen'

Twee kritieke kwetsbaarheden in verschillende Fortinet-producten zijn vorige week misbruikt bij aanvallen, drie dagen nadat ze bekend waren gemaakt. Dat meldt securitybedrijf Arctic Wolf. De twee beve ...

Published Date: Dec 16, 2025 (6 days, 14 hours ago)

Filters

Filter news that are affecting your technology stack
Showing 10 of 8808 Results