Fixed Intel

Knowledge Hub

Guides, playbooks, and learning resources to level up your cybersecurity knowledge and keep your organization secure.

Google adds ‘Advanced Flow’ for safe APK sideloading on Android
BleepingComputer
Malware & Threats

Google adds ‘Advanced Flow’ for safe APK sideloading on Android

Google has announced a new mechanism in Android called Advanced Flow that will allow sideloading APKs from unverified developers for power users in a more secure way.

BleepingComputerMar 21, 20263m2
Microsoft Azure Monitor alerts abused in callback phishing campaigns
BleepingComputer
Malware & Threats

Microsoft Azure Monitor alerts abused in callback phishing campaigns

Microsoft Azure Monitor alerts are being abused to send callback phishing emails that impersonate warnings from the Microsoft Security Team about unauthorized charges on your account.

BleepingComputerMar 21, 20264m2
FBI Warns Russian Hackers Target Signal, WhatsApp in Mass Phishing Attacks
The Hacker News
Industry News

FBI Warns Russian Hackers Target Signal, WhatsApp in Mass Phishing Attacks

Russian-linked phishing hits thousands of messaging accounts via fake support tactics, enabling impersonation and data access.

The Hacker NewsMar 21, 20264m1
Critical Quest KACE Vulnerability Potentially Exploited in Attacks
SecurityWeek
Industry News

Critical Quest KACE Vulnerability Potentially Exploited in Attacks

The vulnerability is tracked as CVE-2025-32975 and it may have been exploited in attacks against the education sector.

SecurityWeekMar 21, 20262m2
Oracle Patches Critical CVE-2026-21992 Enabling Unauthenticated RCE in Identity Manager
The Hacker News
Industry News

Oracle Patches Critical CVE-2026-21992 Enabling Unauthenticated RCE in Identity Manager

Oracle fixes CVE-2026-21992 (CVSS 9.8) flaw enabling unauthenticated RCE via HTTP, risking full system compromise.

The Hacker NewsMar 21, 20262m2
CISA Flags Apple, Craft CMS, Laravel Bugs in KEV, Orders Patching by April 3, 2026
The Hacker News
Industry News

CISA Flags Apple, Craft CMS, Laravel Bugs in KEV, Orders Patching by April 3, 2026

CISA adds 5 exploited flaws (CVSS up to 10.0) to KEV, mandates April 3, 2026 patching to prevent malware and espionage attacks.

The Hacker NewsMar 21, 20264m2
Trivy Supply Chain Attack Triggers Self-Spreading CanisterWorm Across 47 npm Packages
The Hacker News
Industry News

Trivy Supply Chain Attack Triggers Self-Spreading CanisterWorm Across 47 npm Packages

CanisterWorm infects 28 npm packages via ICP-based C2, enabling self-propagation and persistent backdoor access across developer systems.

The Hacker NewsMar 21, 20265m1
FBI links Signal phishing attacks to Russian intelligence services
BleepingComputer
Malware & Threats

FBI links Signal phishing attacks to Russian intelligence services

The FBI has issued a public service announcement warning that Russian intelligence-linked threat actors are actively targeting users of encrypted messaging apps such as Signal and WhatsApp in phishing campaigns that have already compromised thousands of accounts.

BleepingComputerMar 20, 20263m2
Industry News

Patch Now: Oracle's Fusion Middleware Has Critical RCE Flaw

Dark Reading
Industry News

Patch Now: Oracle's Fusion Middleware Has Critical RCE Flaw

Attackers can execute arbitrary code without authentication if Oracle's Identity or Web Services Managers are exposed to the Web.

Dark ReadingMar 20, 20261m1
Oracle pushes emergency fix for critical Identity Manager RCE flaw
BleepingComputer
Malware & Threats

Oracle pushes emergency fix for critical Identity Manager RCE flaw

Oracle has released an out-of-band security update to fix a critical unauthenticated remote code execution vulnerability in Identity Manager and Web Services Manager tracked as CVE-2026-21992.

BleepingComputerMar 20, 20262m2
Trivy Security Scanner GitHub Actions Breached, 75 Tags Hijacked to Steal CI/CD Secrets
The Hacker News
Industry News

Trivy Security Scanner GitHub Actions Breached, 75 Tags Hijacked to Steal CI/CD Secrets

Trivy attack force-pushed 75 tags via GitHub Actions, exposing CI/CD secrets, enabling data theft and persistence across developer systems.

The Hacker NewsMar 20, 20265m1
Police take down 373,000 fake CSAM sites in Operation Alice
BleepingComputer
Malware & Threats

Police take down 373,000 fake CSAM sites in Operation Alice

An international law enforcement action called Operation Alice has shut down over 373,000 dark web sites that offered fake CSAM packages.

BleepingComputerMar 20, 20262m2