HN · BleepingComputer · Krebs · Dark Reading · SANS · THN Intel · Unit 42 · Security.com
📰 Cybersecurity News Headlines
Top stories from leading cybersecurity publications as of May 3, 2026.
-
Critrical cPanel flaw mass-exploited in "Sorry" ransomware attacks
— Bleeping Computer
A new disclosed cPanel flaw tracked as CVE-2026-41940 is being mass-exploited to breach websites and encrypt data in "Sorry" ransomware atta… -
ConsentFix v3 attacks target Azure with automated OAuth abuse
— Bleeping Computer
A new attack type, dubbed ConsentFix v3, has been circulating on hacker forums, building on the previous technique by adding automation and … -
Trellix Confirms Source Code Breach With Unauthorized Repository Access
— The Hacker News
Cybersecurity company Trellix has announced that it suffered a breach that enabled unauthorized access to a "portion" of its source code. It… -
Microsoft tests modern Windows Run, says it's faster than legacy dialog
— Bleeping Computer
Microsoft has confirmed that Windows 11 is getting a new modern Run dialog with dark mode support and faster performance in a new preview bu… -
The npm Threat Landscape: Attack Surface and Mitigations (Updated May 1)
— Unit 42
Unit 42 analyzes npm supply chain evolution post-Shai Hulud. Discover wormable malware, CI/CD persistence, multi-stage attacks and more. The… -
Essential Data Sources for Detection Beyond the Endpoint
— Unit 42
Unit 42 highlights the need for a comprehensive security strategy that spans every IT zone. Explore the full details here. The post Essentia… -
76% of All Crypto Stolen in 2026 Is Now in North Korea
— Dark Reading
North Korean threat actors are pulling off historic cryptocurrency heists on a yearly, sometimes weekly basis now. AI might be helping them. -
Malicious Ad for Homebrew Leads to MacSync Stealer, (Fri, May 1st)
— SANS ISC
Introduction -
30,000 Facebook Accounts Hacked via Google AppSheet Phishing Campaign
— The Hacker News
A newly discovered Vietnamese-linked operation has been observed using a Google AppSheet as a "phishing relay" to distribute phishing emails… -
If AI's So Smart, Why Does It Keep Deleting Production Databases?
— Dark Reading
The issue isn't artificial intelligence, but rather an industry adding AI agent integrations into production environments before proper secu… -
Cybercrime Groups Using Vishing and SSO Abuse in Rapid SaaS Extortion Attacks
— The Hacker News
Cybersecurity researchers are warning of two cybercrime groups that are carrying out "rapid, high-impact attacks" operating almost within th… -
Name That Toon: Mark of (Security) Progress
— Dark Reading
Feeling creative? Have something to say about the last 20 years of cybersecurity? Our editors will award the best cybersecurity-related capt…
🪲 NVD — Last 20 Scored Vulnerabilities
Latest scored CVEs from the National Vulnerability Database (5728 in last 30 days).
Critical: 0 · High: 6 · Medium: 13 · Low: 1. View full dashboard →
-
CVE-2026-7672
— CVSS 6.3 (MEDIUM)
A security vulnerability has been detected in youlaitech youlai-boot up to 2.21.1. This affects the function getUserList of the file src/main/java/com/youlai/boot/system/controller/UserController.java of the component Us⦠-
CVE-2026-7671
— CVSS 3.7 (LOW)
A vulnerability has been found in CodeWise Tornet Scooter Mobile App 4.75 on iOS/Android. The impacted element is an unknown function of the file /TwoFactor. Such manipulation leads to improper restriction of excessive a⦠-
CVE-2026-7670
— CVSS 7.3 (HIGH)
A flaw has been found in Jinher OA 1.0. The affected element is an unknown function of the file /C6/JHSoft.Web.PlanSummarize/UserSel.aspx. This manipulation of the argument DeptIDList causes sql injection. The attack is ⦠-
CVE-2026-7669
— CVSS 5.6 (MEDIUM)
A vulnerability was detected in sgl-project SGLang up to 0.5.9. Impacted is the function get_tokenizer of the file python/sglang/srt/utils/hf_transformers_utils.py of the component HuggingFace Transformer Handler. The ma⦠-
CVE-2026-7668
— CVSS 7.3 (HIGH)
A vulnerability was identified in MikroTik RouterOS 6.49.8. This vulnerability affects the function ASN1_STRING_data in the library nova/lib/www/scep.p of the component SCEP Endpoint. The manipulation of the argument tra⦠-
CVE-2026-7653
— CVSS 6.3 (MEDIUM)
A security flaw has been discovered in r-huijts mcp-server-rijksmuseum up to 1.0.4. Affected is the function open_image_in_browser of the file src/index.ts of the component MCP Interface. Performing a manipulation of the⦠-
CVE-2026-7645
— CVSS 6.5 (MEDIUM)
A vulnerability was found in ruvnet sublinear-time-solver 1.5.0. Affected by this vulnerability is the function export_state of the file src/consciousness-explorer/mcp/server.js of the component MCP Interface. The manipu⦠-
CVE-2026-7644
— CVSS 7.3 (HIGH)
A vulnerability has been found in ChatGPTNextWeb NextChat up to 2.16.1. Affected is the function addMcpServer of the file app/mcp/actions.ts. The manipulation leads to improper authorization. Remote exploitation of the a⦠-
CVE-2026-7643
— CVSS 4.3 (MEDIUM)
A flaw has been found in ChatGPTNextWeb NextChat up to 2.16.1. This impacts an unknown function of the file Next.js of the component API Endpoint. Executing a manipulation can lead to permissive cross-domain policy with ⦠-
CVE-2026-7642
— CVSS 6.3 (MEDIUM)
A vulnerability was detected in pskill9 website-downloader up to 0.1.0. This affects the function download_website of the file src/index.ts of the component MCP Interface. Performing a manipulation of the argument output⦠-
CVE-2026-7633
— CVSS 6.5 (MEDIUM)
A vulnerability was identified in Totolink N300RH 6.1c.1353_B20190305. This impacts the function setUploadSetting of the file /cgi-bin/cstecgi.cgi. Such manipulation of the argument FileName leads to file inclusion. The ⦠-
CVE-2026-7632
— CVSS 7.3 (HIGH)
A vulnerability was determined in code-projects Online Hospital Management System 1.0. This affects an unknown function of the file /viewappointment.php. This manipulation of the argument delid causes sql injection. The ⦠-
CVE-2026-7631
— CVSS 5.4 (MEDIUM)
A vulnerability was found in code-projects Online Hospital Management System 1.0. The impacted element is an unknown function of the component Registration Handler. The manipulation of the argument Username results in im⦠-
CVE-2026-7630
— CVSS 7.3 (HIGH)
A vulnerability has been found in innocommerce InnoShop up to 0.7.8. The affected element is the function InstallServiceProvider::boot of the file innopacks/install/src/InstallServiceProvider.php of the component Install⦠-
CVE-2026-7629
— CVSS 6.3 (MEDIUM)
A flaw has been found in kleneway awesome-cursor-mpc-server up to 2.0.1. Impacted is the function runCodeReviewTool of the file src/tools/codeReview.ts of the component Ccode-Review Tool. Executing a manipulation can lea⦠-
CVE-2026-3504
— CVSS 5.3 (MEDIUM)
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.3.1 via the '/dokan/v1/stores/{id}/reviews' ⦠-
CVE-2026-2554
— CVSS 8.1 (HIGH)
The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.7.25 via t⦠-
CVE-2026-0703
— CVSS 6.4 (MEDIUM)
The NextMove Lite – Thank You Page for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'xlwcty_current_date' shortcode in all versions up to, and including, 2.23.0 due to ⦠-
CVE-2026-7628
— CVSS 6.3 (MEDIUM)
A vulnerability was detected in crazyrabbitLTC mcp-code-review-server up to 0.1.0. This issue affects the function executeRepomix of the file src/repomix.ts of the component RepoMix Command Handler. Performing a manipula⦠-
CVE-2026-6817
— CVSS 5.8 (MEDIUM)
The Quiz Maker by AYS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'rate_reason' parameter in all versions up to, and including, 6.7.1.29 due to insufficient input sanitization and output escâ¦
Source: NVD CVE API 2.0
Generated by CryptXNet.ai Threat Intelligence Platform · May 3, 2026 · Sources: The Hacker News, Bleeping Computer, Krebs on Security, Dark Reading, SANS ISC, THN Threat Intel, Unit 42, Security.com
Leave a Comment