Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    The OSINT Newsletter – Issue #104

    April 30, 2026

    ZDI-26-171: Unraid Update Request Path Traversal Remote Code Execution Vulnerability

    April 30, 2026

    CVE-2026-33845 | THREATINT

    April 30, 2026
    Facebook X (Twitter) Instagram
    • Demos
    • Technology
    • Gaming
    • Buy Now
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Canadian Cyber WatchCanadian Cyber Watch
    • Home
    • News
    • Alerts
    • Tips
    • Tools
    • Industry
    • Incidents
    • Events
    • Education
    Subscribe
    Canadian Cyber WatchCanadian Cyber Watch
    Home»News»InfoSec News Nuggets 04/30/2026
    News

    InfoSec News Nuggets 04/30/2026

    adminBy adminApril 30, 2026No Comments2 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Critical cPanel and WHM bug exploited as a zero-day, PoC now available

    cPanel says CVE-2026-41940 is an authentication bypass flaw affecting cPanel, WHM, and WP Squared, and BleepingComputer reports it has already been exploited in the wild, with one hosting provider seeing attempts as early as February. The issue lets attackers potentially take over the cPanel host and the sites it manages, which makes this a high-priority patch item for internet-exposed hosting infrastructure.

     

    Sandhills Medical Says Ransomware Breach Affects 170,000

    Sandhills Medical Foundation disclosed that a 2025 ransomware attack affected nearly 170,000 people and exposed sensitive personal and health information, including Social Security numbers, passports, financial data, and protected health information. The case is notable both for the scope of the data involved and for the lag between the original intrusion and full public disclosure.

     

    Nine-year-old Linux kernel flaw enables reliable local privilege escalation (CVE-2026-31431)

    Researchers disclosed “Copy Fail,” a Linux kernel flaw that affects major distributions released since 2017 and can let an unprivileged local user gain root through a reliable, non-racy exploit path. Theori says it is especially urgent for multi-tenant Linux systems, CI runners, SaaS platforms running user code, and container environments because it can be chained easily after an initial foothold.

     

    AI Finds 38 Security Flaws in Electronic Health Record Platform

    An AI-assisted review of the OpenEMR codebase uncovered 38 previously undisclosed vulnerabilities, including authorization issues, XSS, SQL injection, path traversal, and session-related bugs. Dark Reading reports the flaws have now been patched, but the bigger takeaway is how quickly AI-assisted analysis compressed the discovery timeline in software used by more than 100,000 healthcare providers worldwide.

     

    China-linked hackers led phishing campaigns targeting journalists and activists, researchers say

    Citizen Lab found that China-linked freelance operators used more than 100 malicious domains in two phishing campaigns aimed at journalists, activists, and diaspora communities tied to Tibet, Taiwan, Hong Kong, and the Uyghur region. The reporting suggests a low-cost, contractor-driven model for digital transnational repression that gives Beijing reach while preserving a layer of plausible deniability.

    The post InfoSec News Nuggets 04/30/2026 appeared first on AboutDFIR – The Definitive Compendium Project.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleSSA-028723 V1.1 (Last Update: 2025-08-13): Multiple OpenSSL Vulnerabilities in BFCClient Before V2.17
    Next Article GNU security advisory (AV26-407) – Canadian Centre for Cyber Security
    admin
    • Website

    Related Posts

    News

    The OSINT Newsletter – Issue #104

    April 30, 2026
    News

    VulnCheck go-exploit Goes Scanless | Blog

    April 30, 2026
    News

    What Happens in the First 24 Hours After a New Asset Goes Live

    April 30, 2026
    Add A Comment

    Comments are closed.

    Demo
    Top Posts

    Catchy & Intriguing

    March 17, 202671 Views

    The Grandparent Scam: How AI Voice Technology Makes This Old Con Deadlier Than Ever

    March 18, 202620 Views

    Global Takedown of Massive IoT Botnets Halts Record-Breaking Cyberattacks

    March 20, 202619 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    85
    Featured

    Pico 4 Review: Should You Actually Buy One Instead Of Quest 2?

    January 15, 2021 Featured
    8.1
    Uncategorized

    A Review of the Venus Optics Argus 18mm f/0.95 MFT APO Lens

    January 15, 2021 Uncategorized
    8.9
    Editor's Picks

    DJI Avata Review: Immersive FPV Flying For Drone Enthusiasts

    January 15, 2021 Editor's Picks

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Demo
    Most Popular

    Catchy & Intriguing

    March 17, 202671 Views

    The Grandparent Scam: How AI Voice Technology Makes This Old Con Deadlier Than Ever

    March 18, 202620 Views

    Global Takedown of Massive IoT Botnets Halts Record-Breaking Cyberattacks

    March 20, 202619 Views
    Our Picks

    The OSINT Newsletter – Issue #104

    April 30, 2026

    ZDI-26-171: Unraid Update Request Path Traversal Remote Code Execution Vulnerability

    April 30, 2026

    CVE-2026-33845 | THREATINT

    April 30, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Technology
    • Gaming
    • Phones
    • Buy Now
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.