Fixed Intel

Knowledge Hub

Guides, playbooks, and learning resources to level up your cybersecurity knowledge and keep your organization secure.

UNC4899 Breached Crypto Firm After Developer AirDropped Trojanized File to Work Device
The Hacker News
Industry News

UNC4899 Breached Crypto Firm After Developer AirDropped Trojanized File to Work Device

UNC4899 breached a crypto firm via AirDrop malware and cloud exploitation in 2025, stealing millions through Kubernetes and Cloud SQL abuse.

The Hacker NewsMar 9, 20264m8
Why Password Audits Miss the Accounts Attackers Actually Want
BleepingComputer
Malware & Threats

Why Password Audits Miss the Accounts Attackers Actually Want

Password audits often focus on complexity rules but miss the accounts attackers actually target. Specops Software explains how breached passwords, orphaned users, and service accounts can leave organizations exposed.

BleepingComputerMar 9, 20265m8
Microsoft still working to fix Windows Explorer white flashes
BleepingComputer
Malware & Threats

Microsoft still working to fix Windows Explorer white flashes

Microsoft has confirmed that it's still working to fully address a known issue that causes bright white flashes when opening the File Explorer on some Windows 11 systems.

BleepingComputerMar 9, 20262m8
⚡ Weekly Recap: Qualcomm 0-Day, iOS Exploit Chains, AirSnitch Attack & Vibe-Coded Malware
The Hacker News
Industry News

⚡ Weekly Recap: Qualcomm 0-Day, iOS Exploit Chains, AirSnitch Attack & Vibe-Coded Malware

Your weekly cybersecurity roundup covering the latest threats, exploits, vulnerabilities, and security news you need to know.

The Hacker NewsMar 9, 202625m9
ClickFix Attack Uses Windows Terminal to Evade Detection
SecurityWeek
Industry News

ClickFix Attack Uses Windows Terminal to Evade Detection

Fake CAPTCHA pages instruct victims to paste malicious commands in the Windows Terminal instead of the Run dialog.

SecurityWeekMar 9, 20262m8
Internet Infrastructure TLD .arpa Abused in Phishing Attacks
SecurityWeek
Industry News

Internet Infrastructure TLD .arpa Abused in Phishing Attacks

Abusing DNS record management controls, the threat actor hides the location of malicious content via Cloudflare.

SecurityWeekMar 9, 20263m8
Industry News

Chinese Cyber Threat Lurks In Critical Asian Sectors for Years

Dark Reading
Industry News

Chinese Cyber Threat Lurks In Critical Asian Sectors for Years

An undefined Chinese-speaking actor wields a combo of custom malware, open source tools, and LOTL binaries against Windows and Linux, likely for spying.

Dark ReadingMar 9, 20261m8
Vulnerabilities

CISA Adds Three Known Exploited Vulnerabilities to Catalog

CISA Alerts
Vulnerabilities

CISA Adds Three Known Exploited Vulnerabilities to Catalog

CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.

CISA AlertsMar 9, 20261m8
Can the Security Platform Finally Deliver for the Mid-Market?
The Hacker News
Industry News

Can the Security Platform Finally Deliver for the Mid-Market?

Bitdefender GravityZone webinar shows how mid-market teams consolidate security tools to reduce complexity and improve resilience.

The Hacker NewsMar 9, 20262m8
Cloned AI Tool Sites Distribute Malware in ‘InstallFix’ Campaign
SecurityWeek
Industry News

Cloned AI Tool Sites Distribute Malware in ‘InstallFix’ Campaign

Threat actors replace legitimate commands on the cloned installation webpages with malicious commands.

SecurityWeekMar 9, 20262m8
Chrome Extension Turns Malicious After Ownership Transfer, Enabling Code Injection and Data Theft
The Hacker News
Industry News

Chrome Extension Turns Malicious After Ownership Transfer, Enabling Code Injection and Data Theft

Malicious Chrome extensions tied to ownership transfers push malware and steal data, exposing thousands to credential theft and system compromise.

The Hacker NewsMar 9, 20267m8
Web Server Exploits and Mimikatz Used in Attacks Targeting Asian Critical Infrastructure
The Hacker News
Industry News

Web Server Exploits and Mimikatz Used in Attacks Targeting Asian Critical Infrastructure

New hacking cluster exploits web servers and Mimikatz to infiltrate Asian infrastructure for long-term espionage in aviation, energy, and govt sectors

The Hacker NewsMar 9, 20264m8