Fixed Intel

Knowledge Hub

Guides, playbooks, and learning resources to level up your cybersecurity knowledge and keep your organization secure.

Popular WordPress redirect plugin hid dormant backdoor for years
BleepingComputer
Malware & Threats

Popular WordPress redirect plugin hid dormant backdoor for years

The Quick Page/Post Redirect plugin, installed on more than 70,000 WordPress sites, had a backdoor added five years ago that allows injecting arbitrary code into users' sites.

BleepingComputerApr 29, 20263m1
Hackers exploit RCE flaws in Qinglong task scheduler for cryptomining
BleepingComputer
Malware & Threats

Hackers exploit RCE flaws in Qinglong task scheduler for cryptomining

Hackers are exploiting two authentication bypass vulnerabilities in the Qinglong open-source task scheduling tool to deploy cryptominers on developers' servers.

BleepingComputerApr 29, 20263m1
Industry News

Reverse Engineering With AI Unearths High-Severity GitHub Bug

Dark Reading
Industry News

Reverse Engineering With AI Unearths High-Severity GitHub Bug

Wiz used an AI reverse-engineering tool to pinpoint a vulnerability that previously would have been too costly and time-consuming to undertake.

Dark ReadingApr 29, 20261m1
Industry News

AI Finds 38 Security Flaws in Electronic Health Record Platform

Dark Reading
Industry News

AI Finds 38 Security Flaws in Electronic Health Record Platform

Flaws in OpenEMR's platform — used by more than 100,000 healthcare providers — enabled database compromise, remote code execution, and data theft.

Dark ReadingApr 29, 20261m1
Hackers arrested for hijacking and selling 610,000 Roblox accounts
BleepingComputer
Malware & Threats

Hackers arrested for hijacking and selling 610,000 Roblox accounts

The Ukrainian police have arrested three individuals who hacked more than 610,000 Roblox gaming accounts and sold them for a profit of $225,000.

BleepingComputerApr 29, 20263m1
Industry News

Oracle Red Bull Racing Team Revs Up Automation to Boost Security

Dark Reading
Industry News

Oracle Red Bull Racing Team Revs Up Automation to Boost Security

While drivers race to shave off seconds on the track, the team's IT and engineering staff are speeding up how they deliver security.

Dark ReadingApr 29, 20261m1
SAP npm Packages Compromised by “Mini Shai-Hulud” Credential-Stealing Malware
The Hacker News
Industry News

SAP npm Packages Compromised by “Mini Shai-Hulud” Credential-Stealing Malware

SAP npm packages poisoned on April 29, 2026 + AES-256-GCM encrypted credential theft + AI coding tools abused for spread.

The Hacker NewsApr 29, 20263m1
cPanel, WHM emergency update fixes critical auth bypass bug
BleepingComputer
Malware & Threats

cPanel, WHM emergency update fixes critical auth bypass bug

A critical vulnerability affecting all but the latest versions of cPanel and the WebHost Manager (WHM) dashboard could be exploited to obtain access to the control panel without authentication.

BleepingComputerApr 29, 20263m1
Industry News

Vect 2.0 Ransomware Acts as Wiper, Thanks to Design Error

Dark Reading
Industry News

Vect 2.0 Ransomware Acts as Wiper, Thanks to Design Error

The emerging ransomware has been deployed against victims of the TeamPCP supply chain attacks, but organizations should think twice before paying for a decryptor.

Dark ReadingApr 29, 20261m1
New Wave of DPRK Attacks Uses AI-Inserted npm Malware, Fake Firms, and RATs
The Hacker News
Industry News

New Wave of DPRK Attacks Uses AI-Inserted npm Malware, Fake Firms, and RATs

Claude Opus commit added malicious npm dependency in Feb 2026, enabling crypto theft and persistent RAT access.

The Hacker NewsApr 29, 20269m1
European police dismantles €50 million crypto investment fraud ring
BleepingComputer
Malware & Threats

European police dismantles €50 million crypto investment fraud ring

Austrian and Albanian authorities dismantled a criminal ring accused of running a large-scale cryptocurrency investment fraud operation that caused estimated losses of over €50 million ($58.5 million) to victims worldwide.

BleepingComputerApr 29, 20263m1
Vulnerabilities

Today's Odd Web Requests, (Wed, Apr 29th)

SANS ISC
Vulnerabilities

Today's Odd Web Requests, (Wed, Apr 29th)

Today, two different "new" requests hit our honeypots. Both appear to be recon requests and not associated with specific vulnerabilities. But as always, please let me know if you have additional information

SANS ISCApr 29, 20261m2