Fixed Intel
Newspaper

Industry News

General cybersecurity industry news, market trends, and analysis

French police arrest 21-year-old “HexDex” hacker over 100 alleged data breaches
Graham Cluley
Industry News

French police arrest 21-year-old “HexDex” hacker over 100 alleged data breaches

A 21-year-old man suspected of conducting approximately 100 data breaches since late 2025 - including a hack of the French Ministry of National Education that exposed records on almost a quarter of a million employees — has been arrested at his home in western France.

Graham CluleyApr 28, 20263m4
Spectrum Security Emerges From Stealth Mode With $19 Million
SecurityWeek
Industry News

Spectrum Security Emerges From Stealth Mode With $19 Million

The threat detection startup will invest in accelerating its engineering and go-to-market efforts.

SecurityWeekApr 28, 20262m4
Chinese Silk Typhoon Hacker Extradited to U.S. Over COVID Research Cyberattacks
The Hacker News
Industry News

Chinese Silk Typhoon Hacker Extradited to U.S. Over COVID Research Cyberattacks

Chinese hacker extradited after 2020–2021 Exchange zero-day attacks on U.S. vaccine research, intensifying DOJ crackdown.

The Hacker NewsApr 28, 20262m4
Microsoft Patches Entra ID Role Flaw That Enabled Service Principal Takeover
The Hacker News
Industry News

Microsoft Patches Entra ID Role Flaw That Enabled Service Principal Takeover

Agent ID Administrator enabled service principal takeover before April 9, 2026 patch, exposing privilege escalation risk in Entra ID tenants.

The Hacker NewsApr 28, 20263m4
Medtronic Hack Confirmed After ShinyHunters Threatens Data Leak
SecurityWeek
Industry News

Medtronic Hack Confirmed After ShinyHunters Threatens Data Leak

The ShinyHunters cybercrime group claimed to have stolen 9 million records containing personal information from Medtronic.

SecurityWeekApr 28, 20262m4
Microsoft Confirms Active Exploitation of Windows Shell CVE-2026-32202
The Hacker News
Industry News

Microsoft Confirms Active Exploitation of Windows Shell CVE-2026-32202

CVE-2026-32202 actively exploited after April 27 advisory fix, exposing NTLMv2 hashes via zero-click SMB authentication.

The Hacker NewsApr 28, 20263m4
Industry News

UNC6692 Combines Social Engineering, Malware, Cloud Abuse

Dark Reading
Industry News

UNC6692 Combines Social Engineering, Malware, Cloud Abuse

A newly discovered threat actor is using Microsoft Teams, AWS S3 buckets, and custom "Snow" malware in a multipronged campaign.

Dark ReadingApr 27, 20261m4
Industry News

Unpatched 'PhantomRPC' Flaw in Windows Enables Privilege Escalation

Dark Reading
Industry News

Unpatched 'PhantomRPC' Flaw in Windows Enables Privilege Escalation

A researcher discovered five different exploit paths that stem from an architectural weakness in how Windows' Remote Procedure Call (RPC) mechanism handles connections to unavailable services.

Dark ReadingApr 27, 20261m4
Checkmarx Confirms GitHub Repository Data Posted on Dark Web After March 23 Attack
The Hacker News
Industry News

Checkmarx Confirms GitHub Repository Data Posted on Dark Web After March 23 Attack

Checkmarx data surfaced after March 23, 2026 supply chain attack, prompting repository lockdown and investigation, raising exposure concerns.

The Hacker NewsApr 27, 20262m4
⚡ Weekly Recap: Fast16 Malware, XChat Launch, Federal Backdoor, AI Employee Tracking & More
The Hacker News
Industry News

⚡ Weekly Recap: Fast16 Malware, XChat Launch, Federal Backdoor, AI Employee Tracking & More

This week’s ThreatsDay covers supply chain attacks, fake help desks, wiper malware, AI prompt traps, RMM abuse, phishing kits, and more.

The Hacker NewsApr 27, 202614m4
Industry News

20-Year-Old Malware Rewrites History of Cyber Sabotage

Dark Reading
Industry News

20-Year-Old Malware Rewrites History of Cyber Sabotage

Researchers have uncovered a malware framework dubbed "fast16" that predates Stuxnet by 5 years.

Dark ReadingApr 27, 20261m4
Incomplete Windows Patch Opens Door to Zero-Click Attacks
SecurityWeek
Industry News

Incomplete Windows Patch Opens Door to Zero-Click Attacks

The initial vulnerability was exploited by Russia-linked APT28 in attacks against Ukraine and EU countries.

SecurityWeekApr 27, 20263m4