MetInfo CMS CVE-2026-29014 Exploited for Remote Code Execution Attacks


Ravie LakshmananMay 05, 2026Vulnerability / Network Security

Threat actors are actively exploiting a critical security flaw impacting an open-source content management system (CMS) known as MetInfo, according to new findings from VulnCheck.

The vulnerability in question is CVE-2026-29014 (CVSS score: 9.8), a code injection flaw that could result in arbitrary code execution.

“MetInfo CMS versions 7.9, 8.0, and 8.1 contain an unauthenticated PHP code injection vulnerability that allows remote attackers to execute arbitrary code by sending crafted requests with malicious PHP code,” the NIST National Vulnerability Database (NVD) states.

“Attackers can exploit insufficient input neutralization in the execution path to achieve remote code execution and gain full control over the affected server.”

Per security researcher Egidio Romano, who discovered the vulnerability, the problem is rooted in the “/app/system/weixin/include/class/weixinreply.class.php” script, and stems from a lack of adequate sanitization of user-supplied input when issuing Weixin (aka WeChat) API requests.

As a result, remote, unauthenticated attackers could exploit this loophole to inject and execute arbitrary PHP code. One key prerequisite for successful exploitation when MetInfo is running on non-Windows servers is that the “/cache/weixin/” directory has to exist beforehand.The directory is created when installing and configuring the official WeChat plugin. 

Patches for CVE-2026-29014 were released by MetInfo on April 7, 2026. The vulnerability has since come under exploitation as of April 25, with a “small number of exploits” deployed against susceptible honeypots located in the U.S. and Singapore.

Although these efforts were initially sparse and associated with automated probing, the activity witnessed a surge on May 1, 2026, focusing on China and Hong Kong IP addresses, Caitlin Condon, vice president of security research at VulnCheck, said. As many as 2,000 instances of MetInfo CMS are accessible online, most of which are in China.



Source link

Broker’s Call: Navin Flourine (Buy)


Target: ₹8,500

CMP: ₹7,009.70

Navin Fluorine International has a strong presence across CDMO, Specialty Chemicals and High-Performance Products (HPP) segments. Leveraging deep fluorine chemistry expertise and backward integration, the company serves global pharma, agrochemical, refrigerant and specialty material customers, with exports (about 70 per cent) forming a significant share of revenues.

Q4FY26 was strong, with revenue up 34 per cent year on year to ₹938 crore. CDMO revenues grew 61 per cent, Specialty Chemicals 39 per cent, while HPP rose 20 per cent on firm HFC-32 pricing and higher utilization.

FY27 is expected to be a milestone year as major investments transition to revenue. R-32 refrigerant ramp-up in HPP will benefit from strong demand and pricing; multi-purpose plants debottlenecking will boost Specialty Chemicals and CDMO output, and the long-term strategic manufacturing and supply agreement with the Chemours company (in the US) will add long-term, high-margin contracted revenues. This is backed by about 80 per cent capacity utilization visibility for Specialty Chemicals and a 50-55 molecule CDMO pipeline.

As per market consensus, Navin Fluorine trades at 43x one-year forward P/E, below its five-year average P/E. The outlook remains positive, supported by strong medium-term revenue visibility, structurally-elevated EBITDA margins (over 30 per cent), rising export mix, a robust CDMO order pipeline, commissioning of the Chemours project, and sustained strength in ref-gas and R-32 capacity ramp-up.

Published on May 5, 2026

Iran’s football team shows World Cup readiness with social media posts | World Cup 2026 News

0

Videos from a tournament kit reveal photo shoot and images from training sessions highlighting Team Melli’s preparations.

Iran’s preparations for the FIFA World Cup appear to be on track, as social media posts from the team’s official account hint at an upcoming tournament kit reveal and show the squad training at an undisclosed location.

Videos posted by Team Melli’s Instagram account on Monday showed players taking part in a photo shoot for what appears to be Iran’s home kit for the World Cup.

Iran are in Group G of the World Cup and will play all their games in the United States, which is cohosting the tournament with Canada and Mexico.

Several members of Iran’s squad, including first-choice goalkeeper Alireza Safar Beiranvand and winger Milad Mohammadi, were shown wearing a new kit in a series of social media posts.

The Team Melli account also posted photos from training sessions, which have been held in Iran before the squad travels to Turkiye for three friendly matches before the World Cup.

The Asian giants’ participation in the tournament became uncertain after the US and Israel launched a war on Iran on February 28, with Iranian officials questioning the US’s role as host and President Donald Trump suggesting Team Melli’s players may not be safe if they travel to his country for the championship.

However, recent statements by FIFA president Gianni Infantino and Iranian football officials have reaffirmed the country’s participation in the World Cup.

Infantino confirmed that Iran will play its games in the US in his opening remarks at the FIFA ⁠⁠Congress in Canada on Thursday.

“Let me start at the outset. Of course, Iran will be participating at the FIFA ⁠⁠World Cup 2026. And of course Iran will play in the United States of America,” Infantino said.

Trump later said he was “OK” with Iran playing in the country.

“If Gianni said it, I’m OK,” Trump told reporters ‌‌at the White House. “You know what? Let ‌‌them ‌‌play.”

Football officials in Iran have outlined the team’s training and preparations for the tournament, which include camps at home and in neighbouring Turkiye before travelling to the US.

“The first phase of the preparation period will end with an intra-team game on Wednesday,” assistant coach Saeed Alhoei told Iranian sport news outlet Varzesh3.

The game will be held at a stadium, and the players will wear official match kits, with an international referee and video assistant referee technology (VAR) to simulate tournament-like conditions.

Alhoei said the squad will depart for Turkiye on Monday for their final leg of preparations before travelling to the US in June.

Team Melli will kick off their ‌‌campaign ‌‌against New Zealand in Los Angeles on June 15 before taking on Belgium at the same stadium on June 21.

“We will have three friendly matches, two of which will probably be against [local] club teams and behind closed doors, and the third against an African team,” Alhoei said. “It is a quality team that can be a good simulation for playing against African teams.”

Iran will face Egypt in their final group match in Seattle on June 26.

On Monday, Iran suffered a significant ⁠⁠blow after it was confirmed that winger Ali Gholizadeh had suffered a season-ending knee injury while playing for his club Lech Poznan in Poland.

Gholizadeh, who would have started on the right ⁠⁠wing at the World Cup, was stretchered off the pitch against Motor Lublin last Saturday, and tests later confirmed he had torn the anterior cruciate ligament in his left knee.

“Gholizadeh will face surgery ⁠⁠in the coming days, followed by several months of rehabilitation,” the club said in a statement.



Source link

3 generations of Florida family killed in Plant City double shooting


NEWYou can now listen to Fox News articles!

A Florida community is reeling after a deadly shooting spree left three generations of a family, including a 4-month-old baby and a 4-year-old child, dead across two crime scenes, authorities said Monday.

Officers first responded early Sunday to a disturbance on a residential street in Plant City, where they found four shooting victims, the Plant City Police Department said. The 4-month-old and 4-year-old children were pronounced dead at the scene. Their 28-year-old mother was rushed to a hospital but later died. A third child was found unharmed.

Investigators soon linked the violence to a second location less than a mile away, where the children’s 55-year-old grandmother was found dead from a gunshot wound. Police said she was the mother of the 28-year-old woman.

Authorities believe individuals traveled on foot between the two scenes during the early morning hours, prompting a citywide search for clues.

ARKANSAS MOM FOUND SHOT TO DEATH WITH TWO CHILDREN WROTE CRYPTIC FACEBOOK POST MONTHS BEFORE KILLINGS

residential street in Plant City

Police in Plant City are investigating the murders of two young children, their mother and grandmother that unfolded across two separate scenes. (FOX13 Tampa WTVT)

Detectives are now urging residents and businesses to review surveillance footage from 5:30 a.m. to 7 a.m. Sunday, especially any video showing a woman walking with three young children near North Burton Street or West Tever Street.

Neighbors say there were warning signs in the days leading up to the killings.

crime scene tape near a tree and wood fence

Police have yet to name a suspect or motive in the killings in Plant City, Florida. (FOX13 Tampa WTVT)

“They had some type of disagreement on Friday to where the police were called by the wife. Then in that time, her mother came,” John Czarniak, who lives near one of the scenes, told FOX13 Tampa. He added that he saw suspicious behavior the night before the shooting, including a man strapping on a bulletproof vest and loading a large duffel bag into a car.

MURDER IN SMALL-TOWN AMERICA: THE CRIMES THAT TORE QUIET COMMUNITIES APART IN 2025

Plant City police cruiser parked outside

Police are asking residents to check footage any home surveillance cameras from between 5 a.m. and 7 a.m. Sunday. (Plant City Police Department/Facebook)

Residents in the area described the aftermath as devastating.

“We’re devastated. Watching everything that unfolded is horrible,” neighbor Jody Kott told the station. “From what I saw, they will need every prayer they can get.”

CLICK HERE TO DOWNLOAD THE FOX NEWS APP

Police have not released the identities of the victims or named a suspect. A motive has yet to be confirmed.

The investigation remains ongoing. Authorities are asking anyone with information to contact the Plant City Police Department at 813-763-3316 or submit tips anonymously.



Source link

Access Denied

0

Access Denied You don’t have permission to access “http://hindi.news18.com/videos/ajab-gajab/west-bengal-bjp-supporters-celebration-after-win-election-against-tms-mamata-benerjee-viral-video-10448162.html” on this server.

Reference #18.4a200117.1777988841.38604e

https://errors.edgesuite.net/18.4a200117.1777988841.38604e

DRC protest in support of US sanctions against former president | Protests

0

NewsFeed

Pro-government protesters set ablaze a party headquarters linked to former DRC President Joseph Kabila as they marched in support of US sanctions against him for allegedly backing rebel groups.



Source link

Broker’s Call: Godrej Properties (Buy)


Target: ₹2,475

CMP: ₹1,809.50

Godrej Properties (GPL) reported Q4 net profit (pre-ex) of ₹650 crore, over 70 per cent up year on year, driven by revenue beat which jumped 63 per cent to a record ₹3,460 crore. Reported P&L remains volatile on a qoq and the beat was driven by a significant uptick in deliveries with GPL completing 7.4-million-sq-ft projects during the quarter; taking FY26 deliveries to 12.1 million sq ft, above 10 million sq ft guidance.

The management guided for 14 per cent rise in pre-sales to ₹39,000 crore for FY27E. The company plans to launch ₹48,000-crore worth of projects in FY27E (vs ₹42,200 crore in FY26), which should help drive pre-sales momentum. While the outlook on broader property markets is mid-cycle growth levels; the company said that guidance is subject to geopolitical situation not deteriorating.

GPL’s reported P&L and FCF generation have improved with PAT over 32 per cent in FY26 and 95 per cent of large land/project expenditure internally funded. The management focus on scaling up deliveries by FY28 to over 20 million sq ft, large pre-sales in base and rising customer collections make us believe that the 20 per cent reported ROE target and net FCF positive are possible by FY28.

The stock is trading at 11x PE on reportable PAT/embedded PAT in FY28 P&L/FY26 pre-sales estimates. Our ₹2,475 PT (₹2,420) is set at 12.0x embedded PAT to March 2028 pre-sales. Maintain Buy.

Published on May 5, 2026

Wisconsin brewery owner Kirk Bangstad runs for governor after FBI probe


NEWYou can now listen to Fox News articles!

Minocqua Brewing Company owner Kirk Bangstad, who offered free beer in the event of President Donald Trump’s death, announced his bid for Wisconsin governor on Sunday.

“I’m running for Governor because I believe Wisconsin needs a battle-hardened fighter to join the rest of America to save our Democracy from Trump’s regime, and that person doesn’t exist in the crowded field of Democrats currently running in Wisconsin’s Gubernatorial primary,” Bangstad wrote in a Substack post on Sunday.

Bangstad’s announcement came a little over a week after his brewery advertised free beer in the event of Trump’s death. The Facebook comments came after news of shots being fired at the White House Correspondents’ Association Dinner, where Trump and several of his Cabinet members attended.

WISCONSIN DEM’S BAR LAMENTS ‘WE ALMOST GOT FREE BEER DAY’ FOR TRUMP ASSASSINATION

Minocqua Brewing Company

The Minocqua Brewing Company in Wisconsin has a history of pushing progressive politics. (Screenshot/Google Earth)

“Well, we almost got #freebeerday. Either a brother or sister in the Resistance needs to work on their marksmanship or he faked another assassination to get a positive news cycle,” the post said. “We’ll never know. Regardless, we stand at the ready to pour free beer the day it happens.”

The post led to Bangstad and his company being investigated by the FBI and Secret Service and disavowed by members of the Wisconsin Democratic Party, according to Bangstad.

“The messaging mistake [State Rep. Francesca] Hong made, as well as [gubernatorial candidate Mandela] Barnes and the rest of the Corporate Democrats, spilled progressive blood into the water that created a feeding frenzy against me, my fiancé, and my company. Trump’s propaganda machine and the corporate media that continuously fails America with its cancerous ‘bothside-ism,’ came after me with full force; and that led to me being interrogated and intimidated by the FBI and the Secret Service,” Bangstad wrote.

INFLUENCER TRISHA PAYTAS SAYS SHE’S CONSIDERING 2026 CONGRESSIONAL BID TO STOP ‘HORRIBLE STUFF’ IN CALIFORNIA

Minocqua brewing wisconsin

Minocqua Brewing Company Kirk Bangstad announced a gubernatorial bid on Sunday. (Google Maps; Facebook/Minocqua Brewing Company)

He continued, “After those two agents left my taproom on Thursday night, I told my lawyer Fred that I was going to run for Governor. Since I couldn’t trust the Democratic Party to have my back nor the current slate of gubernatorial candidates—and because I have a social media reach that dwarfs them all—I might as well stand up for myself and the rest of the working class, who I’ve been standing up for with my loud voice for the last 6 years.”

To qualify for the November election, Bangstad is seeking 2000 signatures by June 1. 

Fox News Digital reached out to Bangstad for comment.

Bangstad previously ran for Congress in 2015 and for the Wisconsin state assembly in 2020. Since then, he has also formed the Minocqua Brewing Company SuperPAC, which “aims to remove Republican federal and state elected officials who perpetuated the election lies that caused the Insurrection of January 6, 2021, and whose downplaying of the seriousness of COVID-19 caused so many unnecessary deaths in our country,” according to the company website.

WASHINGTON, D.C., POLITICAL BAR TAKES DOWN REPUBLICAN SYMBOL AFTER FIERCE BACKLASH

Kirk Bangstad wisconsin

Bangstad previously promoted a “free beer” day in the event of President Donald Trump’s death. (Facebook/Minocqua Brewing Company)

CLICK HERE TO DOWNLOAD THE FOX NEWS APP

The Minocqua Brewing Company is largely known for selling specialty-branded beers based on political trends and figures such as “Resistance Pilsner” and “Tammy Shandy,” after Wisconsin Sen. Tammy Baldwin.



Source link

Access Denied

0

Access Denied You don’t have permission to access “http://hindi.news18.com/cricket/entrepreneur-and-rcb-co-owner-ananya-birla-made-a-viral-met-gala-2026-debut-embracing-the-fashion-is-art-theme-in-a-custom-all-black-robert-wun-couture-outfit-10448029.html” on this server.

Reference #18.4a200117.1777988333.32d4ec

https://errors.edgesuite.net/18.4a200117.1777988333.32d4ec

SAP dives deeper into Iceberg with Dremio acquisition • The Register


SAP has snapped up Dremio, a data integration and analytics provider, to extend the reach of its data analytics and AI agent-building tools into external data sources.

The ERP giant spent an undisclosed sum on the Iceberg-based lakehouse biz in a bid to help its customers eliminate data fragmentation and improve integration. The purchase will, according to SAP, complement its data warehouse and analytics platform, Business Data Cloud, and SAP HANA Cloud.

In a statement, SAP said the Business Data Cloud will become an “Apache Iceberg-native enterprise lakehouse that unifies SAP and non-SAP data to power agentic AI at enterprise scale.”

Apache Iceberg is an open table format that originated at Netflix. It has a rival in Databricks’ Delta Lake format – open source under the Linux Foundation – although Databricks has moved to make the standards more interoperable since its acquisition of Tabular, a company founded by Iceberg’s original authors. In both formats, the promise is to bring analytics to the data, without the cost and effort of moving it, helping to underpin enterprise analytics, machine learning, and AI agent development.

SAP claims Apache Iceberg is the industry-standard open table format, and the Business Data Cloud will natively support it “as its foundation,” meaning no data movement or format conversion is necessary.

SAP has been here before. About three years ago, then-CTO Juergen Mueller pledged to help customers “easily and confidently integrate SAP data with non-SAP data from third-party applications and platforms,” supported by its partnership with Databricks, the data lake and machine learning vendor.

Last year, it deepened ties with Databricks to support bidirectional data sharing between SAP Business Data Cloud and third-party data platforms, with Databricks’ Delta Lake open table format “as the initial delivery.” The setup used Databricks’ Delta Sharing, which was initially based on the Delta format, although the company has more recently announced support for Iceberg.

Dremio was valued at $2 billion during a $160 million funding round in 2022. Whatever SAP paid for the vendor, it obviously felt it was worth the money to get more tech based on the Iceberg open table format, which is repeatedly emphasized in the announcement. It might leave some wondering what it was not getting from the Databricks partnership.

The Register has asked SAP for further comment.

SAP said the Dremio lakehouse platform would “vastly improve the economics of enterprise analytics,” offering a serverless and elastic approach without fixed capacity to provision or performance ceiling.

With the acquisition, SAP will give customers an open catalog built on Apache Polaris and the open Apache Iceberg REST Catalog API, to create a discovery and semantic layer for SAP Business Data Cloud. It promises “a single point of access to unified business context: meaning, relationships, access rights, and data lineage” across enterprise data outside SAP. ®



Source link