Fixed Intel
Newspaper

Industry News

General cybersecurity industry news, market trends, and analysis

How LiteLLM Turned Developer Machines Into Credential Vaults for Attackers
The Hacker News
Industry News

How LiteLLM Turned Developer Machines Into Credential Vaults for Attackers

LiteLLM 1.82.7–1.82.8 supply chain attack exposed 33,185 secrets across 6,943 machines, leaving 3,760 valid credentials active.

The Hacker NewsApr 6, 20266m5
Guardarian Users Targeted With Malicious Strapi NPM Packages
SecurityWeek
Industry News

Guardarian Users Targeted With Malicious Strapi NPM Packages

Hackers published 36 NPM packages posing as Strapi plugins to execute shells, escape containers, and harvest credentials.

SecurityWeekApr 6, 20262m5
North Korean Hackers Target High-Profile Node.js Maintainers
SecurityWeek
Industry News

North Korean Hackers Target High-Profile Node.js Maintainers

The threat actor behind the Axios supply chain attack has been aiming at other maintainers in its social engineering campaign.

SecurityWeekApr 6, 20263m5
Qilin and Warlock Ransomware Use Vulnerable Drivers to Disable 300+ EDR Tools
The Hacker News
Industry News

Qilin and Warlock Ransomware Use Vulnerable Drivers to Disable 300+ EDR Tools

Qilin disables 300+ EDR drivers using BYOVD in 2025 attacks, delaying encryption six days, increasing breach impact.

The Hacker NewsApr 6, 20264m5
Fortinet Rushes Emergency Fixes for Exploited Zero-Day
SecurityWeek
Industry News

Fortinet Rushes Emergency Fixes for Exploited Zero-Day

The improper access control bug in FortiClient EMS allows unauthenticated attackers to execute arbitrary code remotely.

SecurityWeekApr 6, 20262m5
BKA Identifies REvil Leaders Behind 130 German Ransomware Attacks
The Hacker News
Industry News

BKA Identifies REvil Leaders Behind 130 German Ransomware Attacks

BKA identified REvil leaders tied to 130 German attacks causing €35.4M damage, exposing key ransomware figures.

The Hacker NewsApr 6, 20263m5
$285 Million Drift Hack Traced to Six-Month DPRK Social Engineering Operation
The Hacker News
Industry News

$285 Million Drift Hack Traced to Six-Month DPRK Social Engineering Operation

$285M stolen after six-month DPRK social engineering campaign began fall 2025, exposing Drift’s contributors and cloud assets.

The Hacker NewsApr 5, 20268m5
36 Malicious npm Packages Exploited Redis, PostgreSQL to Deploy Persistent Implants
The Hacker News
Industry News

36 Malicious npm Packages Exploited Redis, PostgreSQL to Deploy Persistent Implants

36 npm packages disguised as Strapi plugins exploit Redis and PostgreSQL via postinstall scripts, enabling persistent access and data theft.

The Hacker NewsApr 5, 20267m5
Fortinet Patches Actively Exploited CVE-2026-35616 in FortiClient EMS
The Hacker News
Industry News

Fortinet Patches Actively Exploited CVE-2026-35616 in FortiClient EMS

CVE-2026-35616 (CVSS 9.1) exploited since March 31, 2026, affects FortiClient EMS 7.4.5–7.4.6, enabling privilege escalation.

The Hacker NewsApr 5, 20263m5
European Commission Confirms Data Breach Linked to Trivy Supply Chain Attack
SecurityWeek
Industry News

European Commission Confirms Data Breach Linked to Trivy Supply Chain Attack

Hackers stole over 300GB of data from the Commission’s AWS environment, including personal information.

SecurityWeekApr 4, 20263m5
Industry News

Inconsistent Privacy Labels Don't Tell Users What They Are Getting

Dark Reading
Industry News

Inconsistent Privacy Labels Don't Tell Users What They Are Getting

Data privacy labels are a great idea for mobile apps, but the current versions just aren't good enough.

Dark ReadingApr 3, 20261m5
China-Linked TA416 Targets European Governments with PlugX and OAuth-Based Phishing
The Hacker News
Industry News

China-Linked TA416 Targets European Governments with PlugX and OAuth-Based Phishing

TA416 targeted European governments from mid-2025 using PlugX and OAuth abuse, enabling cyber espionage against EU and NATO entities.

The Hacker NewsApr 3, 20265m5