Fixed Intel

Knowledge Hub

Guides, playbooks, and learning resources to level up your cybersecurity knowledge and keep your organization secure.

New Python Backdoor Uses Tunneling Service to Steal Browser and Cloud Credentials
The Hacker News
Industry News

New Python Backdoor Uses Tunneling Service to Steal Browser and Cloud Credentials

DEEP#DOOR embeds a Python RAT in a dropper script, using bore[.]pub C2 to steal credentials and evade Windows defenses, complicating detection.

The Hacker NewsApr 30, 20263m1
Critical Gemini CLI Flaw Enabled Host Code Execution, Supply Chain Attacks
SecurityWeek
Industry News

Critical Gemini CLI Flaw Enabled Host Code Execution, Supply Chain Attacks

An attacker could have planted a malicious configuration to execute commands outside the sandbox.

SecurityWeekApr 30, 20262m1
Vulnerabilities

ABB Ability Symphony Plus Engineering

CISA Alerts
Vulnerabilities

ABB Ability Symphony Plus Engineering

View CSAF

CISA AlertsApr 30, 202612m2
Vulnerabilities

ABB PCM600

CISA Alerts
Vulnerabilities

ABB PCM600

View CSAF

CISA AlertsApr 30, 20263m2
Vulnerabilities

ABB AWIN Gateways

CISA Alerts
Vulnerabilities

ABB AWIN Gateways

View CSAF

CISA AlertsApr 30, 20266m2
Vulnerabilities

ABB Edgenius Management Portal

CISA Alerts
Vulnerabilities

ABB Edgenius Management Portal

View CSAF

CISA AlertsApr 30, 20264m2
Vulnerabilities

ABB Ability OPTIMAX

CISA Alerts
Vulnerabilities

ABB Ability OPTIMAX

View CSAF

CISA AlertsApr 30, 20263m2
Vulnerabilities

CISA Adds One Known Exploited Vulnerability to Catalog

CISA Alerts
Vulnerabilities

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.

CISA AlertsApr 30, 20261m2
Vulnerabilities

ABB System 800xA, Symphony Plus IEC 61850

CISA Alerts
Vulnerabilities

ABB System 800xA, Symphony Plus IEC 61850

View CSAF

CISA AlertsApr 30, 202610m2
EnOcean SmartServer Flaws Expose Buildings to Remote Hacking
SecurityWeek
Industry News

EnOcean SmartServer Flaws Expose Buildings to Remote Hacking

Claroty researchers discovered two vulnerabilities that can be exploited for security bypass and remote code execution.

SecurityWeekApr 30, 20262m1
Critical cPanel and WHM bug exploited as a zero-day, PoC now available
BleepingComputer
Malware & Threats

Critical cPanel and WHM bug exploited as a zero-day, PoC now available

The critical CVE-2026-41940 authentication bypass vulnerability in cPanel, WHM, and WP Squared is being actively exploited in the wild and has been leveraged in attempts since late February.

BleepingComputerApr 30, 20263m1
EtherRAT Distribution Spoofing Administrative Tools via GitHub Facades
The Hacker News
Industry News

EtherRAT Distribution Spoofing Administrative Tools via GitHub Facades

44 GitHub facades and Ethereum smart contracts power a March 2026 admin-targeted campaign, enabling resilient C2 rotation and enterprise compromise.

The Hacker NewsApr 30, 202621m1