Fixed Intel

Latest Cybersecurity News

Stay informed with real-time threat intelligence, vulnerability disclosures, and expert analysis from the cybersecurity community.

Lotus Wiper Malware Targets Venezuelan Energy Systems in Destructive Attack
The Hacker News
Industry News

Lotus Wiper Malware Targets Venezuelan Energy Systems in Destructive Attack

Lotus Wiper hit Venezuela’s energy sector in late 2025, exploiting pre-Windows 10 1803 systems, wiping drives and crippling operations.

The Hacker NewsApr 22, 20264m5
North Korean Hackers Use AppleScript, ClickFix in Fresh macOS Attacks
SecurityWeek
Industry News

North Korean Hackers Use AppleScript, ClickFix in Fresh macOS Attacks

The campaigns focus on financial organizations, including cryptocurrency, venture capital, and blockchain entities.

SecurityWeekApr 22, 20262m5
Toxic Combinations: When Cross-App Permissions Stack into Risk
The Hacker News
Industry News

Toxic Combinations: When Cross-App Permissions Stack into Risk

Toxic combinations form when AI agents, integrations, or OAuth grants bridge SaaS apps into trust relationships no single admin authorized.

The Hacker NewsApr 22, 20266m5
Microsoft traces Universal Print issues to Graph API code change
BleepingComputer
Malware & Threats

Microsoft traces Universal Print issues to Graph API code change

Microsoft says that an ongoing Universal Print sharing issue that prevents users from creating some printer shares is due to a Microsoft Graph API code change.

BleepingComputerApr 22, 20263m5
New GoGra malware for Linux uses Microsoft Graph API for comms
BleepingComputer
Malware & Threats

New GoGra malware for Linux uses Microsoft Graph API for comms

A Linux variant of the GoGra backdoor uses legitimate Microsoft infrastructure, relying on an Outlook inbox for stealthy payload delivery.

BleepingComputerApr 22, 20263m5
Google Antigravity in Crosshairs of Security Researchers, Cybercriminals
SecurityWeek
Industry News

Google Antigravity in Crosshairs of Security Researchers, Cybercriminals

Researchers discovered a remote code execution vulnerability and cybercriminals are using its reputation to deliver malware.

SecurityWeekApr 22, 20263m5
Microsoft Patches Critical ASP.NET Core CVE-2026-40372 Privilege Escalation Bug
The Hacker News
Industry News

Microsoft Patches Critical ASP.NET Core CVE-2026-40372 Privilege Escalation Bug

CVE-2026-40372 scores 9.1 due to cryptographic flaw in ASP.NET Core 10.0.0–10.0.6, risking SYSTEM access.

The Hacker NewsApr 22, 20262m5
Oracle Patches 450 Vulnerabilities With April 2026 CPU
SecurityWeek
Industry News

Oracle Patches 450 Vulnerabilities With April 2026 CPU

The company released 481 new security patches across 28 product families, including over 300 fixes for remotely exploitable, unauthenticated flaws.

SecurityWeekApr 22, 20263m5
Microsoft releases emergency patches for critical ASP.NET flaw
BleepingComputer
Malware & Threats

Microsoft releases emergency patches for critical ASP.NET flaw

Microsoft has released out-of-band (OOB) security updates to patch a critical ASP.NET Core privilege escalation vulnerability.

BleepingComputerApr 22, 20263m5
Mustang Panda’s New LOTUSLITE Variant Targets India Banks, South Korea Policy Circles
The Hacker News
Industry News

Mustang Panda’s New LOTUSLITE Variant Targets India Banks, South Korea Policy Circles

Updated LOTUSLITE targets India banking sector via CHM and DLL side-loading, expanding espionage campaign to South Korea and U.S. policy circles.

The Hacker NewsApr 22, 20263m5
Cohere AI Terrarium Sandbox Flaw Enables Root Code Execution, Container Escape
The Hacker News
Industry News

Cohere AI Terrarium Sandbox Flaw Enables Root Code Execution, Container Escape

CVE-2026-5752 CVSS 9.3 flaw in Terrarium enables root code execution via Pyodide prototype traversal, risking container escape.

The Hacker NewsApr 22, 20263m5
Over 1,300 Microsoft SharePoint servers vulnerable to spoofing attacks
BleepingComputer
Malware & Threats

Over 1,300 Microsoft SharePoint servers vulnerable to spoofing attacks

Over 1,300 Microsoft SharePoint servers exposed online remain unpatched against a spoofing vulnerability that was exploited as a zero-day and is still being abused in ongoing attacks.

BleepingComputerApr 22, 20263m5