HN · BleepingComputer · Krebs · Dark Reading · SANS · THN Intel · Unit 42 · Security.com
📰 Cybersecurity News Headlines
Top stories from leading cybersecurity publications as of April 27, 2026.
-
American utility firm Itron discloses breach of internal IT network
— Bleeping Computer
Itron, Inc. has disclosed, via an 8-K filing with the U.S. Securities and Exchange Commission (SEC), a cybersecurity incident in which an un… -
Microsoft rolls out revamped Windows Insider Program
— Bleeping Computer
Microsoft says it's rolling out a revamped Windows Insider Program experience as part of the broader plans to address performance and reliab… -
Threat actor uses Microsoft Teams to deploy new “Snow” malware
— Bleeping Computer
A threat group tracked as UNC6692 uses social engineering to deploy a new, custom malware suite named 'Snow' which includes a browser extens… -
Researchers Uncover Pre-Stuxnet ‘fast16’ Malware Targeting Engineering Software
— The Hacker News
Cybersecurity researchers have discovered a new Lua-based malware created years before the notorious Stuxnet worm that aimed to sabotage Ira… -
CISA Adds 4 Exploited Flaws to KEV, Sets May 2026 Federal Deadline
— The Hacker News
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added four vulnerabilities impacting SimpleHelp, Samsung MagicINF… -
Helping Romance Scam Victims Require a Proactive, Empathic Approach
— Dark Reading
People targeted by confidence schemes find getting help is a lonely road. Experts want law enforcement, financial and government institution… -
The npm Threat Landscape: Attack Surface and Mitigations
— Unit 42
Unit 42 analyzes npm supply chain evolution post-Shai Hulud. Discover wormable malware, CI/CD persistence, multi-stage attacks and more. The… -
TGR-STA-1030: New Activity in Central and South America
— Unit 42
Unit 42 research reports that TGR-STA-1030 remains an active threat, particularly in Central and South America. The post TGR-STA-1030: New A… -
FIRESTARTER Backdoor Hit Federal Cisco Firepower Device, Survives Security Patches
— The Hacker News
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has revealed that an unnamed federal civilian agency's Cisco Firepower devi… -
US Busts Myanmar Ring Targeting US Citizens in Financial Fraud
— Dark Reading
Some 29 people were charged, including a Cambodian senator, and authorities seized more than 500 Web domains tied to fake investment sites. -
Glasswing Secured the Code. The Rest of Your Stack Is Still on You
— Dark Reading
Forgotten integrations, shadow IT, SaaS, and now shadow AI and agents are everywhere, and attackers don't need sophisticated AI models to ta… -
ISC Stormcast For Friday, April 24th, 2026 https://isc.sans.edu/podcastdetail/9906, (Fri, Apr 24th)
— SANS ISC
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
🪲 NVD — Last 20 Scored Vulnerabilities
Latest scored CVEs from the National Vulnerability Database (5676 in last 30 days).
Critical: 1 · High: 17 · Medium: 2 · Low: 0. View full dashboard →
-
CVE-2026-7069
— CVSS 8.0 (HIGH)
A security flaw has been discovered in D-Link DIR-825 up to 3.00b32. This impacts the function AddPortMapping of the file upnpsoap.c of the component miniupnpd. Performing a manipulation of the argument NewPortMappingDes⦠-
CVE-2026-7068
— CVSS 8.8 (HIGH)
A vulnerability was identified in D-Link DIR-825 3.00b32. This affects the function NMBD_process of the file sserver.c of the component nmbd. Such manipulation leads to buffer overflow. The attack can only be initiated w⦠-
CVE-2026-7067
— CVSS 7.3 (HIGH)
A vulnerability was determined in D-Link DIR-822 A_101. The impacted element is the function system of the file /udhcpcd/dhcpd.c of the component udhcpd DHCP Service. This manipulation of the argument Hostname causes com⦠-
CVE-2026-7066
— CVSS 7.3 (HIGH)
A vulnerability was found in choieastsea simple-openstack-mcp up to 767b2f4a8154cca344344b9725537a58399e6036. The affected element is the function exec_openstack of the file server.py. The manipulation results in os comm⦠-
CVE-2026-7065
— CVSS 7.3 (HIGH)
A vulnerability has been found in BidingCC BuildingAI up to 26.0.1. Impacted is the function uploadRemoteFile of the file packages/core/src/modules/upload/services/file-storage.service.ts of the component Remote Upload A⦠-
CVE-2026-42363
— CVSS 9.3 (CRITICAL)
An insufficient encryption vulnerability exists in the Device Authentication functionality of GeoVision GV-IP Device Utility 9.0.5. Listening to broadcast packets can lead to credentials leak. An attacker can listen to b⦠-
CVE-2026-33566
— CVSS 4.3 (MEDIUM)
There is a cypher injection issue in LogonTracer prior to v2.0.0. If specially crafted Windows event log data is loaded, the contents of the database may be altered. -
CVE-2026-33277
— CVSS 8.8 (HIGH)
An OS command Injection issue exists in LogonTracer prior to v2.0.0. An arbitrary OS command may be executed by a logged-in user. -
CVE-2026-7064
— CVSS 7.3 (HIGH)
A flaw has been found in AgentDeskAI browser-tools-mcp up to 1.2.0. This issue affects some unknown processing of the file browser-tools-server/browser-connector.ts. Executing a manipulation can lead to os command inject⦠-
CVE-2026-7063
— CVSS 7.3 (HIGH)
A vulnerability was detected in code-projects Employee Management System 1.0. This vulnerability affects unknown code of the file /370project/process/eprocess.php of the component Endpoint. Performing a manipulation of t⦠-
CVE-2026-7062
— CVSS 7.3 (HIGH)
A security vulnerability has been detected in Intina47 context-sync up to 2.0.0. This affects an unknown part of the file src/git-integration.ts of the component Git Integration. Such manipulation leads to os command inj⦠-
CVE-2026-7061
— CVSS 7.3 (HIGH)
A weakness has been identified in Toowiredd chatgpt-mcp-server up to 0.1.0. Affected by this issue is some unknown functionality of the file src/services/docker.service.ts of the component MCP/HTTP. This manipulation cau⦠-
CVE-2026-7060
— CVSS 7.3 (HIGH)
A vulnerability was determined in liyupi yu-picture up to a053632c41340152bf75b66b3c543d129123d8ec. This impacts the function PageRequest of the file yu-picture-backend/src/main/java/com/yupi/yupicturebackend/service/imp⦠-
CVE-2026-7059
— CVSS 5.3 (MEDIUM)
A vulnerability was found in 666ghj MiroFish up to 0.1.2. This affects the function get_simulation_posts of the file backend/app/api/simulation.py of the component Query Parameter Handler. Performing a manipulation of th⦠-
CVE-2026-7058
— CVSS 7.3 (HIGH)
A vulnerability has been found in 666ghj MiroFish up to 0.1.2. The impacted element is the function SimulationIPCClient.send_command of the file backend/app/services/simulation_ipc.py of the component Inter-Process Commu⦠-
CVE-2026-7057
— CVSS 8.8 (HIGH)
A flaw has been found in Tenda F456 1.0.0.5. The affected element is an unknown function of the file /goform/setcfm of the component httpd. This manipulation of the argument funcname/funcpara1 causes buffer overflow. It ⦠-
CVE-2026-7056
— CVSS 8.8 (HIGH)
A vulnerability was detected in Tenda F456 1.0.0.5. Impacted is the function fromSafeUrlFilter of the file /goform/SafeUrlFilter of the component httpd. The manipulation of the argument page results in buffer overflow. T⦠-
CVE-2026-7055
— CVSS 8.8 (HIGH)
A security vulnerability has been detected in Tenda F456 1.0.0.5. This issue affects the function fromVirtualSer of the file /goform/VirtualSer of the component httpd. The manipulation of the argument menufacturer/Go lea⦠-
CVE-2026-7054
— CVSS 8.8 (HIGH)
A weakness has been identified in Tenda F456 1.0.0.5. This vulnerability affects the function fromPptpUserAdd of the file /goform/PPTPDClient of the component httpd. Executing a manipulation of the argument opttype/usern⦠-
CVE-2026-7053
— CVSS 8.8 (HIGH)
A security flaw has been discovered in Tenda F456 1.0.0.5. This affects the function frmL7ProtForm of the file /goform/L7Prot of the component httpd. Performing a manipulation of the argument page results in buffer overfâ¦
Source: NVD CVE API 2.0
Generated by CryptXNet.ai Threat Intelligence Platform · April 27, 2026 · Sources: The Hacker News, Bleeping Computer, Krebs on Security, Dark Reading, SANS ISC, THN Threat Intel, Unit 42, Security.com