Fixed Intel
Shield

Malware & Threats

Malware analysis, threat intelligence, and emerging cyber threats

Learning from the Vercel breach: Shadow AI & OAuth sprawl
BleepingComputer
Malware & Threats

Learning from the Vercel breach: Shadow AI & OAuth sprawl

A single third-party OAuth integration can become a direct path into your environment. Push explains how the Vercel breach shows a compromised OAuth app can lead to widespread impact across downstream customers.

BleepingComputerApr 29, 20268m2
GitHub fixes RCE flaw that gave access to millions of private repos
BleepingComputer
Malware & Threats

GitHub fixes RCE flaw that gave access to millions of private repos

In early March, GitHub patched a critical remote code execution vulnerability (CVE-2026-3854) that could have allowed attackers to access millions of private repositories.

BleepingComputerApr 29, 20263m2
CISA orders feds to patch Windows flaw exploited as zero-day
BleepingComputer
Malware & Threats

CISA orders feds to patch Windows flaw exploited as zero-day

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to secure their Windows systems against a vulnerability exploited in zero-day attacks.

BleepingComputerApr 29, 20263m1
Microsoft says backend change broke Teams Free chat and calls
BleepingComputer
Malware & Threats

Microsoft says backend change broke Teams Free chat and calls

Microsoft is working to resolve a known issue that prevents some Microsoft Teams Free users from chatting and calling others.

BleepingComputerApr 29, 20262m1
Broken VECT 2.0 ransomware acts as a data wiper for large files
BleepingComputer
Malware & Threats

Broken VECT 2.0 ransomware acts as a data wiper for large files

Researchers are warning that the VECT 2.0 ransomware has a problem in the way it handles encryption nonces that leads to permanently destroying larger files rather than encrypt them.

BleepingComputerApr 28, 20263m1
Hackers are exploiting a critical LiteLLM pre-auth SQLi flaw
BleepingComputer
Malware & Threats

Hackers are exploiting a critical LiteLLM pre-auth SQLi flaw

Hackers are targeting sensitive information stored in the LiteLLM open-source large-language model (LLM) gateway by exploiting a critical vulnerability  tracked as CVE-2026-42208.

BleepingComputerApr 28, 20263m1
Video service Vimeo confirms Anodot breach exposed user data
BleepingComputer
Malware & Threats

Video service Vimeo confirms Anodot breach exposed user data

Vimeo has disclosed that data belonging to some of its customers and users has been accessed without authorization following the recent breach at the Anodot data anomaly detection company.

BleepingComputerApr 28, 20263m1
US reportedly charges Scattered Spider hacker arrested in Finland
BleepingComputer
Malware & Threats

US reportedly charges Scattered Spider hacker arrested in Finland

A 19-year-old dual United States and Estonian citizen arrested in Finland earlier this month faces federal charges in the U.S. alleging he was a prolific member of the notorious Scattered Spider hacking collective.

BleepingComputerApr 28, 20263m1
Checkmarx confirms LAPSUS$ hackers leaked its stolen GitHub data
BleepingComputer
Malware & Threats

Checkmarx confirms LAPSUS$ hackers leaked its stolen GitHub data

Application security company Checkmarx has confirmed that the LAPSUS$ threat group leaked data stolen from its private GitHub repository.

BleepingComputerApr 28, 20263m1
Microsoft to deprecate legacy TLS in Exchange Online starting July
BleepingComputer
Malware & Threats

Microsoft to deprecate legacy TLS in Exchange Online starting July

Microsoft says it will start blocking legacy TLS connections for POP and IMAP email clients in Exchange Online starting in July 2026.

BleepingComputerApr 28, 20263m1
Inside an OPSEC Playbook: How Threat Actors Evade Detection
BleepingComputer
Malware & Threats

Inside an OPSEC Playbook: How Threat Actors Evade Detection

Threat actors are now publishing structured OPSEC playbooks to stay undetected. Flare reveals how these guides outline layered infrastructure, identity separation, and long-term evasion strategies.

BleepingComputerApr 28, 20267m1
Microsoft: New Remote Desktop warnings may display incorrectly
BleepingComputer
Malware & Threats

Microsoft: New Remote Desktop warnings may display incorrectly

Microsoft has confirmed a new issue causing newly introduced Windows security warnings to display incorrectly when opening Remote Desktop (.rdp) files.

BleepingComputerApr 28, 20263m1