Fixed Intel

Knowledge Hub

Guides, playbooks, and learning resources to level up your cybersecurity knowledge and keep your organization secure.

Industry News

MetInfo CMS CVE-2026-29014 Exploited for Remote Code Execution Attacks

The Hacker News
Industry News

MetInfo CMS CVE-2026-29014 Exploited for Remote Code Execution Attacks

Threat actors are actively exploiting a critical security flaw impacting an open-source content management system (CMS) known as MetInfo, according to new findings from VulnCheck. The vulnerability in question is CVE-2026-29014 (CVSS score: 9.8), a code injection flaw that could result in arbitra...

The Hacker News2d ago1m1
Vulnerabilities

Cleartext Passwords in MS Edge? In 2026?, (Mon, May 4th)

SANS ISC
Vulnerabilities

Cleartext Passwords in MS Edge? In 2026?, (Mon, May 4th)

Yup, that is for real.

SANS ISC2d ago1m1
Vulnerabilities

SSL.com rotates their root certificate today, (Tue, May 5th)

SANS ISC
Vulnerabilities

SSL.com rotates their root certificate today, (Tue, May 5th)

I just got an email from SSL.com last night, they are rotating &#;x26;#;xc2;&#;x26;#;xa0;out their root certificate today (May 5,2026). &#;x26;#;xc2;&#;x26;#;xa0;This is normal, business as usual stuff for a CA, but certificates get used for all kinds of things, and sometimes they aren&#;x26;#;39...

SANS ISC2d ago1m1
Google now offers up to $1.5 million for some Android exploits
BleepingComputer
Malware & Threats

Google now offers up to $1.5 million for some Android exploits

Google overhauls its Android and Chrome vulnerability rewards programs, offering bounties of up to $1.5 million for the most difficult exploits while scaling back payouts for flaws that artificial intelligence (AI) has made easier to find.

BleepingComputer2d ago2m1
Critical, High-Severity Vulnerabilities Patched in Apache MINA, HTTP Server
SecurityWeek
Industry News

Critical, High-Severity Vulnerabilities Patched in Apache MINA, HTTP Server

The most severe of these security defects could allow remote attackers to execute arbitrary code.

SecurityWeek2d ago2m1
Karakurt Ransomware Negotiator Sentenced to Prison
SecurityWeek
Industry News

Karakurt Ransomware Negotiator Sentenced to Prison

Deniss Zolotarjovs was directly involved in extortion strategies and in negotiations with victim companies.

SecurityWeek2d ago2m1
We Scanned 1 Million Exposed AI Services. Here's How Bad the Security Actually Is
The Hacker News
Industry News

We Scanned 1 Million Exposed AI Services. Here's How Bad the Security Actually Is

AI infrastructure exposes 1M services from 2M hosts due to weak defaults, increasing risk of data leaks and system compromise

The Hacker News2d ago6m1
Karakurt extortion gang ‘cold case’ negotiator gets 8.5 years in prison
BleepingComputer
Malware & Threats

Karakurt extortion gang ‘cold case’ negotiator gets 8.5 years in prison

A Latvian national extradited to the United States was sentenced to 8.5 years in prison for his "cold case" negotiator role in the Russian Karakurt ransomware group.

BleepingComputer2d ago3m1
CloudZ malware abuses Microsoft Phone Link to steal SMS and OTPs
BleepingComputer
Malware & Threats

CloudZ malware abuses Microsoft Phone Link to steal SMS and OTPs

A new version of the CloudZ remote access tool (RAT) is deploying a previously unseen malicious plugin called Pheno that hijacks the Microsoft Phone Link connection to steal sensitive codes from mobile devices.

BleepingComputer2d ago3m1
MetInfo, Weaver E-cology Vulnerabilities in Attackers’ Crosshairs
SecurityWeek
Industry News

MetInfo, Weaver E-cology Vulnerabilities in Attackers’ Crosshairs

The security defects allow unauthenticated, remote attackers to execute arbitrary code through crafted requests.

SecurityWeek2d ago2m1
ScarCruft Hacks Gaming Platform to Deploy BirdCall Malware on Android and Windows
The Hacker News
Industry News

ScarCruft Hacks Gaming Platform to Deploy BirdCall Malware on Android and Windows

ScarCruft spreads BirdCall via sqgame.net since late 2024, targeting Android users, enabling surveillance and data theft.

The Hacker News2d ago4m1
ScarCruft hackers push BirdCall Android malware via game platform
BleepingComputer
Malware & Threats

ScarCruft hackers push BirdCall Android malware via game platform

The North Korean hacker group APT37 has been delivering an Android version of a backdoor called BirdCall in a supply-chain attack through a video game platform.

BleepingComputer2d ago3m1