Fixed Intel
Newspaper

Industry News

General cybersecurity industry news, market trends, and analysis

SAP NPM Packages Targeted in Supply Chain Attack
SecurityWeek
Industry News

SAP NPM Packages Targeted in Supply Chain Attack

The Mini Shai-Hulud attack introduced a preinstall hook to fetch and execute a Bun binary and bypass security monitoring.

SecurityWeekApr 30, 20263m2
ThreatsDay Bulletin: SMS Blaster Busts, OpenEMR Flaws, 600K Roblox Hacks and 25 More Stories
The Hacker News
Industry News

ThreatsDay Bulletin: SMS Blaster Busts, OpenEMR Flaws, 600K Roblox Hacks and 25 More Stories

Latest ThreatsDay: SMS blasters, npm supply chain hits, and unpatched Windows flaws. Stay ahead of new phishing kits and exposed servers.

The Hacker NewsApr 30, 202618m2
New Python Backdoor Uses Tunneling Service to Steal Browser and Cloud Credentials
The Hacker News
Industry News

New Python Backdoor Uses Tunneling Service to Steal Browser and Cloud Credentials

DEEP#DOOR embeds a Python RAT in a dropper script, using bore[.]pub C2 to steal credentials and evade Windows defenses, complicating detection.

The Hacker NewsApr 30, 20263m2
Critical Gemini CLI Flaw Enabled Host Code Execution, Supply Chain Attacks
SecurityWeek
Industry News

Critical Gemini CLI Flaw Enabled Host Code Execution, Supply Chain Attacks

An attacker could have planted a malicious configuration to execute commands outside the sandbox.

SecurityWeekApr 30, 20262m2
EnOcean SmartServer Flaws Expose Buildings to Remote Hacking
SecurityWeek
Industry News

EnOcean SmartServer Flaws Expose Buildings to Remote Hacking

Claroty researchers discovered two vulnerabilities that can be exploited for security bypass and remote code execution.

SecurityWeekApr 30, 20262m2
EtherRAT Distribution Spoofing Administrative Tools via GitHub Facades
The Hacker News
Industry News

EtherRAT Distribution Spoofing Administrative Tools via GitHub Facades

44 GitHub facades and Ethereum smart contracts power a March 2026 admin-targeted campaign, enabling resilient C2 rotation and enterprise compromise.

The Hacker NewsApr 30, 202621m2
Critical cPanel & WHM Vulnerability Exploited as Zero-Day for Months
SecurityWeek
Industry News

Critical cPanel & WHM Vulnerability Exploited as Zero-Day for Months

The authentication bypass flaw allows attackers to gain administrative access to vulnerable servers.

SecurityWeekApr 30, 20263m2
‘Copy Fail’ Logic Flaw in Linux Kernel Enables System Takeover
SecurityWeek
Industry News

‘Copy Fail’ Logic Flaw in Linux Kernel Enables System Takeover

Affecting the kernel’s authencesn cryptographic template, the vulnerability was introduced in 2017 and impacts all distributions.

SecurityWeekApr 30, 20262m2
New Linux 'Copy Fail' Vulnerability Enables Root Access on Major Distributions
The Hacker News
Industry News

New Linux 'Copy Fail' Vulnerability Enables Root Access on Major Distributions

CVE-2026-31431 CVSS 7.8 flaw since 2017 enables root via 732-byte exploit, impacting major Linux distributions.

The Hacker NewsApr 30, 20263m2
Sandhills Medical Says Ransomware Breach Affects 170,000
SecurityWeek
Industry News

Sandhills Medical Says Ransomware Breach Affects 170,000

It took the healthcare organization nearly one year to publicly disclose a data breach after it was targeted by Inc Ransom.

SecurityWeekApr 30, 20262m2
Iran-linked Handala hackers leak US Marines data, send chilling WhatsApp threats
Graham Cluley
Industry News

Iran-linked Handala hackers leak US Marines data, send chilling WhatsApp threats

US Marines stationed around the Persian Gulf have been receiving WhatsApp messages from strangers suggesting they call home and make their final goodbyes.

Graham CluleyApr 30, 20263m2
Google Fixes CVSS 10 Gemini CLI CI RCE and Cursor Flaws Enable Code Execution
The Hacker News
Industry News

Google Fixes CVSS 10 Gemini CLI CI RCE and Cursor Flaws Enable Code Execution

Gemini CLI CVSS 10.0 flaw in versions below 0.39.1 enabled RCE in CI workflows, forcing Google to mandate explicit workspace trust.

The Hacker NewsApr 30, 20265m2