CVEFeed Newsroom – Latest Cybersecurity Updates

The "Cyber Newsroom Feed" module is a live feed of the latest cyber news enriched with CVE and vulnerability data. The feed is updated every 5 minutes and includes the latest news from the cyber security industry. The feed is designed to provide users with a comprehensive overview of the latest cyber security news and trends.

  • Daily CyberSecurity
CVE-2025-4660 (CVSS 8.7) in Forescout SecureConnector Allows Remote Endpoint Hijack, PoC Publishes

NetSPI has uncovered a critical vulnerability in Forescout SecureConnector, a security agent meant to enforce endpoint compliance. This same tool—designed for system hardening—could be abused by attac ...

Published Date: Jul 19, 2025 (4 months ago)
  • Daily CyberSecurity
Nvidia Flaws Expose Jetson AI & Robotics Platforms to RCE and Data Theft

Nvidia has released a security update for its Jetson Linux and IGX platforms, addressing two vulnerabilities that could expose systems to code execution, data tampering, denial of service, and informa ...

Published Date: Jul 19, 2025 (4 months ago)
  • BleepingComputer
CrushFTP zero-day exploited in attacks to gain admin access on servers

CrushFTP is warning that threat actors are actively exploiting a zero-day vulnerability tracked as CVE-2025-54309, which allows attackers to gain administrative access via the web interface on vulnera ...

Published Date: Jul 18, 2025 (4 months ago)
  • BleepingComputer
New CrushFTP zero-day exploited in attacks to hijack servers

CrushFTP is warning that threat actors are actively exploiting a zero-day vulnerability tracked as CVE-2025-54309, which allows attackers to gain administrative access via the web interface on vulnera ...

Published Date: Jul 18, 2025 (4 months ago)
  • The Hacker News
Ivanti Zero-Days Exploited to Drop MDifyLoader and Launch In-Memory Cobalt Strike Attacks

Jul 18, 2025Ravie LakshmananMalware / Vulnerability Cybersecurity researchers have disclosed details of a new malware called MDifyLoader that has been observed in conjunction with cyber attacks expl ...

Published Date: Jul 18, 2025 (4 months ago)
  • BleepingComputer
Hackers scanning for TeleMessage Signal clone flaw exposing passwords

Researchers are seeing exploitation attempts for the CVE-2025-48927 vulnerability in the TeleMessage SGNL app, which allows retrieving usernames, passwords, and other sensitive data. TeleMessage SGNL ...

Published Date: Jul 18, 2025 (4 months ago)
  • CybersecurityNews
Fancy Bear Hackers Attacking Governments, Military Entities With New Sophisticated Tools

The notorious Russian cyberespionage group Fancy Bear, also known as APT28, has intensified its operations against governments and military entities worldwide using an arsenal of sophisticated new too ...

Published Date: Jul 18, 2025 (4 months ago)
  • security.nl
Signal-kloon TeleMessage SGNL gebruikte kwetsbare Spring Boot Actuator

Bepaalde versies van TeleMessage SGNL, een versleutelde berichtenapp die specifiek is ontworpen voor overheidsorganisaties en grote bedrijven, zijn kwetsbaar voor cyberaanvallen. Een oude versie van S ...

Published Date: Jul 18, 2025 (4 months ago)
  • CybersecurityNews
Threat Actors Exploiting Ivanti Connect Secure Vulnerabilities to Deploy Cobalt Strike Beacon

A sophisticated malware campaign targeting Ivanti Connect Secure VPN devices has been actively exploiting critical vulnerabilities CVE-2025-0282 and CVE-2025-22457 since December 2024. The ongoing att ...

Published Date: Jul 18, 2025 (4 months ago)
  • CybersecurityNews
Sophos Intercept X for Windows Vulnerabilities Enable Arbitrary Code Execution

Three critical vulnerabilities in the Sophos Intercept X for Windows product family could allow local attackers to achieve arbitrary code execution with system-level privileges. Identified as CVE-2024 ...

Published Date: Jul 18, 2025 (4 months ago)

Filters

Filter news that are affecting your technology stack
Showing 10 of 8175 Results