Vulnerabilities & CVEs

Latest vulnerabilities & cves news, vulnerabilities, CVEs, and threat intelligence from 50+ trusted cybersecurity sources.

Iran enforces new 'sovereign' transit rules in Strait of Hormuz; mandates prior permits for vessels

• NewsAPI.org

Iran enforces new 'sovereign' transit rules in Strait of Hormuz; mandates prior permits for vessels

Iran's new maritime transit authorization system in the Strait of Hormuz requires prior electronic permits for vessels, mandating compliance with electronically issued passage rules. This affects international shipping and naval operations transiting the Strait, increasing risks of navigational disruptions and geopolitical escalations. Failure to comply may lead to interceptions or detentions.

#RCE

Read full article →

vmware-nsx-security 1.5.19

• NewsAPI.org

VMware NSX Distributed Firewall (DFW) version 1.5.19 contains a critical vulnerability in its microsegmentation and security group tagging features that could allow unauthorized lateral movement or privilege escalation within virtualized environments. The flaw affects VMware NSX environments relying on security policies, tags, or traceflow for access control, potentially exposing virtual machines and network segments to exploitation. Immediate patching of NSX-T or NSX-V environments is recommended.

#security #news

Read full article →

Future of TV Briefing: The upfront glossary, 2026 edition

• NewsAPI.org

Future of TV Briefing: The upfront glossary, 2026 edition

The article titled 'Future of TV Briefing: The upfront glossary, 2026 edition' highlights emerging terms and market trends in the TV upfront advertising ecosystem for 2026. While not directly exposing a specific vulnerability, the piece underscores potential security risks in programmatic advertising pipelines, including supply chain and data integrity threats. Ad buyers and sellers relying on automated bidding systems and third-party data streams are particularly exposed to malvertising, ad fraud, or API abuse risks.

#security #news

Read full article →

Tax-free allowances rise, so do employer costs: The salary structuring dilemma under the Social Security Code

• NewsAPI.org

Tax-free allowances rise, so do employer costs: The salary structuring dilemma under the Social Security Code

India's Income-Tax Rules amendment for 2026 expands tax-free allowances, increasing employees' net take-home pay but inadvertently raising employer costs under the Social Security Code, 2020. This creates a financial and compliance dilemma for businesses restructuring salary packages, potentially increasing gratuity and social security liabilities for all sectors in India.

#security #news

Read full article →

Tax-free allowances rise, so do employer costs: The salary structuring dilemma under the Social Security Code

• NewsAPI.org

Tax-free allowances rise, so do employer costs: The salary structuring dilemma under the Social Security Code

The Social Security Code, 2020 expands the definition of 'wages' to include tax-free allowances, increasing gratuity and social security liabilities for employers. This policy change affects payroll systems, particularly those in India, by increasing compliance risks and operational costs. Employers must reassess salary structures to mitigate financial and legal exposure.

#security #news

Read full article →

Former ICE Official Loses Republican Primary In Ohio

• NewsAPI.org

Former ICE Official Loses Republican Primary In Ohio

A former ICE official's campaign emphasizing her security background failed to secure a Republican primary win in Ohio, highlighting potential vulnerabilities in political messaging strategies and public perception of security credentials. The incident affects local political stakeholders and underscores broader concerns about trust in security-related leadership claims. No direct cybersecurity vulnerabilities or attacks were identified in this instance.

#security #news

Read full article →

cyberxyz-scanner 1.4.15

• NewsAPI.org

The CyberXYZ Vulnerability Scanner CLI version 1.4.15 was released with real-time vulnerability intelligence features, including XYZ scoring, EPSS, and depalert scores. Users of this CLI tool may be affected by potential inaccuracies or false positives in vulnerability scoring and alerting mechanisms, which could lead to misprioritization of security risks.

#security #news

Read full article →

What is Trump’s Project Freedom plan? #world

• NewsAPI.org

What is Trump’s Project Freedom plan? #world

The US temporarily paused and later resumed 'Project Freedom', a strategic initiative aimed at guiding commercial ships through the Strait of Hormuz amid ongoing Iran negotiations. The geopolitical uncertainty and operational adjustments could expose maritime logistics and critical infrastructure to disruptions or cyber-physical risks.

#security #news

Read full article →

titanvault added to PyPI

• NewsAPI.org

titanvault added to PyPI

The 'titanvault' package was added to the Python Package Index (PyPI) repository, potentially posing a risk to users relying on third-party Python libraries. The package's description claims to offer secure local storage but lacks verification of its legitimacy or security posture. Users downloading or integrating this package may be exposed to supply chain attacks or data exfiltration risks.

#security #news

Read full article →

What happened with ‘Project Freedom’ in Hormuz? #politics

• NewsAPI.org

What happened with ‘Project Freedom’ in Hormuz? #politics

The Trump administration paused and later expanded 'Project Freedom,' a military initiative to escort ships through the Strait of Hormuz, citing unspecified security concerns. The operation's operational security (OPSEC) vulnerabilities risked exposing sensitive military logistics and strategic movements to adversaries like Iran or non-state actors. The scale of impact includes potential disruptions to global oil shipping and heightened geopolitical tensions in the region.

#security #news

Read full article →

Bread Financial Announces Pricing of an Offering of Depositary Shares Representing Interests in Its Series B Preferred Stock

• NewsAPI.org

Bread Financial Announces Pricing of an Offering of Depositary Shares Representing Interests in Its Series B Preferred Stock

Bread Financial announced a public offering of 4.8M depositary shares representing Series B Preferred Stock via underwriting, which may expose the financial infrastructure to market manipulation or insider trading risks due to potential vulnerabilities in disclosure systems. The offering could impact investors, regulators, and stakeholders relying on accurate and timely financial data for decision-making.

#security #news

Read full article →

Gaza flotilla activists ripped for provocative dance while demanding release of accused sex predator

• NewsAPI.org

Gaza flotilla activists ripped for provocative dance while demanding release of accused sex predator

Pro-Hamas activists were criticized for performing a provocative dance while demanding the release of an accused sex predator, raising concerns about coordinated disinformation campaigns exploiting social media platforms. This incident highlights the vulnerability of public discourse to manipulation by threat actors leveraging sensitive political and social issues. Platforms hosting such content may face reputational and operational risks.

#security #news

Read full article →

Megaport Launches Built-In DDoS Protection Enabling On-Demand Network Resilience

• NewsAPI.org

Megaport launched built-in DDoS protection to address enterprise network resilience challenges, eliminating the trade-off between security, performance, and cost. This affects Megaport's automated infrastructure platform (ASX: MP1), providing on-demand mitigation for DDoS attacks without requiring additional hardware or services. The solution aims to reduce downtime and operational overhead for enterprises reliant on Megaport's network.

#DoS

Read full article →

New stealthy Quasar Linux malware targets software developers

• NewsAPI.org

New stealthy Quasar Linux malware targets software developers

A previously undocumented Linux implant named Quasar Linux (QLNX) has been discovered targeting developers' systems with rootkit, backdoor, and credential-stealing capabilities. The malware specifically affects Linux-based development environments and poses a high risk to software supply chains and intellectual property. System administrators must immediately investigate and remediate compromised hosts.

#Malware

Read full article →

To avoid risk of mines, Navy directs ships on path farther from Iran

• NewsAPI.org

To avoid risk of mines, Navy directs ships on path farther from Iran

Iran laid naval mines in the Strait of Hormuz, creating an extremely hazardous risk for U.S. Navy ships and commercial vessels transiting the normal route. The impacted parties include U.S. Naval vessels, allied maritime traffic, and global oil shipping lanes, threatening regional stability and maritime security. Alternative routes are now mandated to avoid the mined areas.

#security #news

Read full article →

Apple's iPhone 17 Is the Best-Selling Phone for the First Quarter of 2026

• NewsAPI.org

Apple's iPhone 17 Is the Best-Selling Phone for the First Quarter of 2026

Apple's iPhone 17 series dominated global smartphone sales in Q1 2026, but reports indicate potential security vulnerabilities in its firmware and hardware-based security modules. These issues could expose millions of users to unauthorized access, data exfiltration, or persistent malware infections if exploited. Affected devices include all iPhone 17, 17 Pro, and 17 Pro Max models, with no confirmed CVE IDs as of publication.

#security #news

Read full article →

Ukraine’s Shadow War in Africa: Overreach?

• NewsAPI.org

Ukraine’s Shadow War in Africa: Overreach?

Ukrainian special forces have reportedly expanded covert operations into western Libya as part of a shadow war in Africa, leveraging geopolitical influence beyond Eastern Europe. This covert campaign could escalate regional instability and draw African nations into proxy conflicts, potentially involving cyber operations or sabotage. The scale and specific targets of these operations remain unclear but raise concerns about unintended consequences in already volatile regions.

#RCE

Read full article →

Defiant border czar Tom Homan says ‘mass deportations are coming’

• NewsAPI.org

Defiant border czar Tom Homan says ‘mass deportations are coming’

White House border czar Tom Homan publicly dismissed criticisms of insufficient deportations, signaling an escalation in immigration enforcement actions. The statement may embolden state and local agencies to accelerate deportation-related operations, potentially exposing vulnerable systems and data in immigration enforcement databases to misuse or unauthorized access. No specific CVE is mentioned, but the policy shift could correlate with increased targeting of immigration-related infrastructure.

#security #news

Read full article →

Chrome for Android Update

• NewsAPI.org

Google released Chrome 148.0.7778.120 for Android, addressing unspecified stability and performance improvements without explicit mention of vulnerabilities. Users of Chrome for Android are affected, and while no CVE IDs are listed, security patches are typically included in such updates, requiring immediate installation.

#Patch

Read full article →