Common Vulnerabilities and Exposures (CVE) stories

Armis offers free access to real-time cyber threat database
Today
#
network security
#
ai
#
cybersecurity
Armis launches free Vulnerability Intelligence Database to help security teams anticipate and tackle cyber threats with real-time, AI-driven insights.

Funding crisis sparks fears for future of global CVE system
Last week
#
cybersecurity
#
software development
#
critical infrastructure
US government funding for the crucial CVE cybersecurity programme is set to lapse, raising fears over global vulnerability tracking and defence efforts.

CVE system secures 11-month extension worth USD $44 million
Last week
#
advanced persistent threat protection
#
cybersecurity
#
cyber threats
CISA extends its contract with MITRE for another 11 months at USD $44 million, securing the critical CVE vulnerability programme amid funding concerns.

Future of CVE repository in doubt as MITRE contract ends
Last week
#
advanced persistent threat protection
#
cybersecurity
#
cyber threats
Concerns rise as MITRE's contract to manage the CVE vulnerability database nears expiry, risking disruption to global cybersecurity infrastructure.

US funding lapse casts uncertainty over global CVE system
Last week
#
cybersecurity
#
incident response
#
infosecurity europe
US government funding for MITRE's CVE programme has expired, risking disruption to global cybersecurity efforts and vulnerability tracking systems.

How to protect legacy medical devices from modern cyber threats
Last week
#
ransomware
#
risk & compliance
#
cybersecurity
Healthcare providers in Australia and New Zealand face growing cyber threats, with legacy medical devices proving vulnerable due to outdated security measures.

Microsoft April Patch Tuesday highlights zero-day risks
This month
#
ransomware
#
cybersecurity
#
microsoft
Microsoft's recent Patch Tuesday sparked scrutiny with a 40-minute delay in updates and notable vulnerabilities, including a critical zero-day in the CLFS Driver.

Zscaler report urges shift from VPNs to Zero Trust
This month
#
vpns
#
ransomware
#
cloud security
Zscaler's 2025 ThreatLabz VPN Risk Report reveals soaring VPN usage in Australia but warns of heightened security risks, urging a shift to Zero Trust architectures.

N-able launches new feature to boost vulnerability management
This month
#
advanced persistent threat protection
#
cybersecurity
#
personal computing devices
N-able has launched a new Vulnerability Management feature for its UEM products, enhancing risk mitigation for organisations amid rising cyber threats.

April Patch Tuesday: Microsoft announces 121 vulnerabilities
This month
#
cybersecurity
#
microsoft
#
patch tuesday
Microsoft has unveiled 121 vulnerabilities in its April 2025 Patch Tuesday update, marking a significant increase from last month's total.

RunZero expands platform for enhanced exposure management
This month
#
risk & compliance
#
omdia
#
asset discovery
runZero has unveiled an expanded platform to enhance exposure management, promising to aid organisations in effectively managing risk across their attack surfaces.

Kaspersky discovers & patches zero-day Chrome flaw
This month
#
malware
#
edutech
#
endpoint protection
Kaspersky has uncovered and patched a critical zero-day vulnerability in Google Chrome, enabling attackers to bypass sandbox protections via malicious links.

GitHub Action compromise affects over 23,000 repositories
Last month
#
open source
#
software development
#
security vulnerabilities
A malicious commit in the tj-actions/changed-files GitHub Action, used in over 23,000 repositories, threatens software security across numerous CI pipelines.

Building a culture of cyber hygiene
Last month
#
data protection
#
phishing
#
physical security
As cyber attacks surge, the World Economic Forum warns of a widening skills gap, urging organisations to foster a culture of cyber hygiene for better security.

JFrog & Hugging Face join forces to secure AI models
Last month
#
advanced persistent threat protection
#
supply chain & logistics
#
ai security
JFrog has partnered with Hugging Face to enhance security for machine learning models, boosting safety measures on the Hugging Face Hub against potential threats.

Microsoft patches 56 vulnerabilities, 7 zero days fixed
Last month
#
phishing
#
email security
#
cybersecurity
Microsoft has patched 56 vulnerabilities in its latest update, including seven zero-day flaws, six of which have been actively exploited.

February 2025 reports record spike in ransomware attacks
Last month
#
ransomware
#
soc
#
edr
A recent Bitdefender report reveals February 2025 as the worst month for ransomware, with victims rising 126% to 962, including a notable impact on Australia.

Mandiant uncovers UNC3886 cyber-attack on Juniper routers
Last month
#
malware
#
firewalls
#
network infrastructure
Mandiant has uncovered a sophisticated cyber espionage campaign by the China-linked group UNC3886, targeting outdated Juniper Networks routers with advanced malware.

March Patch Tuesday reveals 57 vulnerabilities
Last month
#
cybersecurity
#
microsoft
#
windows 11
Microsoft has revealed it will fix 57 vulnerabilities in its March 2025 Patch Tuesday update, including six previously exploited in the wild.

Exclusive: Cyber threats escalate as Australian organisations face sophisticated attacks
Last month
#
ransomware
#
cryptocurrency
#
blockchain
Australian organisations face escalating cyber threats as ransomware groups adopt advanced tactics previously seen only in state-sponsored attacks.