CVEFeed Newsroom – Latest Cybersecurity Updates

The "Cyber Newsroom Feed" module is a live feed of the latest cyber news enriched with CVE and vulnerability data. The feed is updated every 5 minutes and includes the latest news from the cyber security industry. The feed is designed to provide users with a comprehensive overview of the latest cyber security news and trends.

  • Daily CyberSecurity
Apache Tomcat Under Attack: Massive Brute-Force Campaign Targets Manager Interfaces

A significant surge in brute-force attacks is targeting Apache Tomcat Manager interfaces, according to a new report from GreyNoise. On June 5, 2025, analysts observed a large-scale campaign where atta ...

Published Date: Jun 13, 2025 (5 months, 1 week ago)
  • Daily CyberSecurity
Flaw in PostgreSQL JDBC Driver (CVE-2025-49146) Exposes Database Connections to MITM Attacks!

A recently disclosed vulnerability in the PostgreSQL JDBC Driver (PgJDBC) could allow attackers to intercept database connections even when security settings are configured to prevent such attacks. Tr ...

Published Date: Jun 13, 2025 (5 months, 1 week ago)
  • Daily CyberSecurity
High-Severity Flaw in HashiCorp Nomad (CVE-2025-4922) Allows Privilege Escalation

HashiCorp has disclosed a high-severity vulnerability in its workload orchestration tool, Nomad, which could allow attackers to escalate privileges by exploiting a flaw in the system’s Access Control ...

Published Date: Jun 13, 2025 (5 months, 1 week ago)
  • Daily CyberSecurity
HelloTDS Unmasked: Covert Traffic System Funnels Millions to FakeCaptcha Malware!

A complex and evasive infrastructure dubbed HelloTDS is silently steering millions of internet users into the clutches of malware—particularly FakeCaptcha, a social engineering attack masquerading as ...

Published Date: Jun 13, 2025 (5 months, 1 week ago)
  • The Register
Ransomware scum disrupted utility services with SimpleHelp attacks

Ransomware criminals infected a utility billing software providers' customers, and in some cases disrupted services, after exploiting unpatched versions of SimpleHelp’s remote monitoring and managemen ...

Published Date: Jun 12, 2025 (5 months, 1 week ago)
  • Dark Reading
Researchers Detail Zero-Click Copilot Exploit 'EchoLeak'

Source: Adrian Vidal via Alamy Stock PhotoA critical vulnerability could have enabled attackers to unleash prompt injection attacks against Copilot users, though Microsoft ultimately addressed the iss ...

Published Date: Jun 12, 2025 (5 months, 1 week ago)
  • BleepingComputer
Trend Micro fixes critical vulnerabilities in multiple products

Trend Micro has released security updates to address multiple critical-severity remote code execution and authentication bypass vulnerabilities that impact its Apex Central and Endpoint Encryption (TM ...

Published Date: Jun 12, 2025 (5 months, 1 week ago)
  • BleepingComputer
Graphite spyware used in Apple iOS zero-click attacks on journalists

Forensic investigation has confirmed the use of Paragon's Graphite spyware platform in zero-click attacks that targeted Apple iOS devices of at least two journalists in Europe. Researchers at Citizen ...

Published Date: Jun 12, 2025 (5 months, 1 week ago)
  • security.nl
IPhones Europese journalisten via iOS zero click-lek besmet met spyware

De iPhones van in ieder geval twee Europese journalisten zijn via een zero-click kwetsbaarheid in iOS besmet geraakt met de Graphite-spyware van Paragon Solutions. Het bestaan van het beveiligingslek, ...

Published Date: Jun 12, 2025 (5 months, 1 week ago)
  • Cyber Security News
OpenPGP.js Vulnerability Let Attackers Spoof Message Signature Verification

A critical vulnerability in the widely-used OpenPGP.js library has been discovered that allows attackers to forge digital signatures and deceive users into believing malicious content was legitimately ...

Published Date: Jun 12, 2025 (5 months, 1 week ago)

Filters

Filter news that are affecting your technology stack
Showing 10 of 8182 Results