Apache MINA Vulnerabilities Enables Remote Code Execution Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 4, 2026 The Apache MINA project has issued urgent security updates to address two critical vulnerabilities that could allow attackers to execute arbitrary code on affected systems. Developers relying on this network application framework are strongly urged to update …

CISA Warns of cPanel & WHM Vulnerability Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 4, 2026 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning regarding a critical security flaw affecting widely used web hosting management platforms. CISA recently added this vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, …

Microsoft Defender Mistakenly Flags DigiCert Root Certificates as Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 3, 2026 Microsoft Defender triggered widespread false positive alerts after a faulty security update caused it to flag two legitimate DigiCert root certificates as malicious, potentially disrupting SSL/TLS validation and code-signing operations across enterprise environments worldwide. A Defender antimalware …

Trellix Source Code Breach – Hackers Gain Unauthorized Access to Repository

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 2, 2026 Cybersecurity giant Trellix has disclosed a significant security incident involving unauthorized access to a portion of its source code repository. The company confirmed the breach in an official statement published on its website, stating it immediately engaged …

Multiple Exim Mail Server Vulnerabilities Leads to Crash with Malicious DNS data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 2, 2026 The Exim development team has released version 4.99.2 to address four newly discovered security vulnerabilities affecting their mail server software. These flaws allow attackers to potentially crash servers, corrupt memory, or leak sensitive information. Because Exim is …

Attackers Deploy AiTM Phishing Pages to Access SharePoint, HubSpot, and Google Workspace

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 2, 2026 Threat actors are rapidly shifting their intrusion tradecraft toward high-speed, SaaS-centric attacks that completely bypass traditional endpoint security. Since October 2025, security researchers have tracked two distinct adversaries, identified as CORDIAL SPIDER and SNARKY SPIDER, conducting aggressive …

Attackers Abuse Google AppSheet, Netlify, and Telegram in Facebook Phishing Campaign

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 2, 2026 A sophisticated cybercriminal operation dubbed “AccountDumpling” has compromised approximately 30,000 Facebook accounts worldwide. Discovered by Guardio Labs, this Vietnamese-linked campaign abuses Google’s AppSheet platform to bypass traditional email security filters. By routing fully authenticated phishing lures through …

cPanelSniper – PoC Exploit Disclosed for cPanel Vulnerability, 44,000 Servers Compromised

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 2, 2026 A weaponized proof-of-concept (PoC) exploit framework dubbed “cPanelSniper” has been publicly released for CVE-2026-41940, a maximum-severity authentication bypass in cPanel & WHM that has already led to the compromise of tens of thousands of servers worldwide with …

Criminal IP and Securonix ThreatQ Collaborate to Enhance Threat Intelligence Operations

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 1, 2026 Torrance, United States / California, May 1st, 2026, CyberNewswire Criminal IP partners with Securonix to integrate Criminal IP’s Threat Intelligence into ThreatQ, allowing organizations to incorporate external IP intelligence into their existing workflows, helping security teams accelerate …

EtherRAT Campaign Uses SEO Poisoning and GitHub Facades to Target Enterprise Admins

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 1, 2026 A new and well-planned malware campaign has been actively targeting enterprise administrators, DevOps engineers, and security analysts by hijacking their everyday search habits. Rather than using mass phishing or broad spam waves, threat actors behind this operation …