Fixed Intel

Latest Cybersecurity News

Stay informed with real-time threat intelligence, vulnerability disclosures, and expert analysis from the cybersecurity community.

Researchers Discover Critical GitHub CVE-2026-3854 RCE Flaw Exploitable via Single Git Push
The Hacker News
Industry News

Researchers Discover Critical GitHub CVE-2026-3854 RCE Flaw Exploitable via Single Git Push

CVE-2026-3854 (CVSS 8.7) enabled GitHub RCE via git push, risking cross-tenant access to millions of repositories.

The Hacker NewsApr 28, 20264m4
Brazilian LofyGang Resurfaces After Three Years With Minecraft LofyStealer Campaign
The Hacker News
Industry News

Brazilian LofyGang Resurfaces After Three Years With Minecraft LofyStealer Campaign

LofyGang resurfaces with LofyStealer disguised as Minecraft hack, exfiltrating IBANs and passwords to 24.152.36[.]241, escalating gaming threats.

The Hacker NewsApr 28, 20265m4
Vimeo Confirms User and Customer Data Breach
SecurityWeek
Industry News

Vimeo Confirms User and Customer Data Breach

The ShinyHunters group is threatening to leak stolen files unless Vimeo agrees to pay a ransom.

SecurityWeekApr 28, 20262m4
The Mythos Moment: Enterprises Must Fight Agents with Agents
SecurityWeek
Industry News

The Mythos Moment: Enterprises Must Fight Agents with Agents

Only with the right platform and an agentic, AI-driven defense, will enterprises be able to protect themselves in the agentic era.

SecurityWeekApr 28, 20265m4
US reportedly charges Scattered Spider hacker arrested in Finland
BleepingComputer
Malware & Threats

US reportedly charges Scattered Spider hacker arrested in Finland

A 19-year-old dual United States and Estonian citizen arrested in Finland earlier this month faces federal charges in the U.S. alleging he was a prolific member of the notorious Scattered Spider hacking collective.

BleepingComputerApr 28, 20263m4
Webinar Today: A Step-by-Step Approach to AI Governance
SecurityWeek
Industry News

Webinar Today: A Step-by-Step Approach to AI Governance

Join the webinar to explore a practical, multi-layered roadmap to transition from fragmented AI usage to a governed, scalable ecosystem.

SecurityWeekApr 28, 20262m4
Industry News

Fresh Wave of GlassWorm VS Code Extensions Slices Through Supply Chain

Dark Reading
Industry News

Fresh Wave of GlassWorm VS Code Extensions Slices Through Supply Chain

Attackers continue to scale a campaign to seed Open VSX with seemingly benign VS Code extensions that spread self-propagating malware.

Dark ReadingApr 28, 20261m4
Checkmarx confirms LAPSUS$ hackers leaked its stolen GitHub data
BleepingComputer
Malware & Threats

Checkmarx confirms LAPSUS$ hackers leaked its stolen GitHub data

Application security company Checkmarx has confirmed that the LAPSUS$ threat group leaked data stolen from its private GitHub repository.

BleepingComputerApr 28, 20263m4
Robinhood Vulnerability Exploited for Phishing Attacks
SecurityWeek
Industry News

Robinhood Vulnerability Exploited for Phishing Attacks

Legitimate-looking emails coming from Robinhood systems lured recipients to phishing websites.

SecurityWeekApr 28, 20262m4
VECT 2.0 Ransomware Irreversibly Destroys Files Over 131KB on Windows, Linux, ESXi
The Hacker News
Industry News

VECT 2.0 Ransomware Irreversibly Destroys Files Over 131KB on Windows, Linux, ESXi

VECT 2.0 destroys files over 131KB due to nonce flaw, launched December 2025, making ransom payments useless.

The Hacker NewsApr 28, 20265m4
Alleged Chinese State Hacker Extradited to US
SecurityWeek
Industry News

Alleged Chinese State Hacker Extradited to US

A member of Silk Typhoon, Xu Zewei is accused of launching cyberattacks against universities in the US.

SecurityWeekApr 28, 20262m4
Vulnerabilities

HTTP Requests with X-Vercel-Set-Bypass-Cookie Header, (Tue, Apr 28th)

SANS ISC
Vulnerabilities

HTTP Requests with X-Vercel-Set-Bypass-Cookie Header, (Tue, Apr 28th)

This weekend, we saw a few requests to our honeypot that included an "X-Vercel-Set-Bypass-Cookie" header. A sample request:

SANS ISCApr 28, 20261m4