Fixed Intel

Knowledge Hub

Guides, playbooks, and learning resources to level up your cybersecurity knowledge and keep your organization secure.

Learning from the Vercel breach: Shadow AI & OAuth sprawl
BleepingComputer
Malware & Threats

Learning from the Vercel breach: Shadow AI & OAuth sprawl

A single third-party OAuth integration can become a direct path into your environment. Push explains how the Vercel breach shows a compromised OAuth app can lead to widespread impact across downstream customers.

BleepingComputerApr 29, 20268m2
Fresh LiteLLM Vulnerability Exploited Shortly After Disclosure
SecurityWeek
Industry News

Fresh LiteLLM Vulnerability Exploited Shortly After Disclosure

The vulnerability allows attackers to read data from a LiteLLM proxy’s database and potentially modify it.

SecurityWeekApr 29, 20262m2
Industry News

Lotus Wiper Attack Targeted Venezuelan Energy Firms, Utilities

Dark Reading
Industry News

Lotus Wiper Attack Targeted Venezuelan Energy Firms, Utilities

An analysis of the destructive malware reveals sophisticated living-off-the-land (LotL) techniques and detailed strategies for the widespread deletion of data.

Dark ReadingApr 29, 20261m2
GitHub fixes RCE flaw that gave access to millions of private repos
BleepingComputer
Malware & Threats

GitHub fixes RCE flaw that gave access to millions of private repos

In early March, GitHub patched a critical remote code execution vulnerability (CVE-2026-3854) that could have allowed attackers to access millions of private repositories.

BleepingComputerApr 29, 20263m2
Alleged Silk Typhoon hacker extradited to the United States to face charges
Graham Cluley
Industry News

Alleged Silk Typhoon hacker extradited to the United States to face charges

A man accused of working as a hacker for China's Ministry of State Security has been extradited to the USA from Italy, and faces - if found guilty - the prospect of decades behind bars.

Graham CluleyApr 29, 20263m2
Hundreds of Internet-Facing VNC Servers Expose ICS/OT
SecurityWeek
Industry News

Hundreds of Internet-Facing VNC Servers Expose ICS/OT

Forescout has identified tens of thousands of exposed RDP and VNC servers that can be mapped to specific industries.

SecurityWeekApr 29, 20263m2
Webinar: How to Automate Exposure Validation to Match the Speed of AI Attacks
The Hacker News
Industry News

Webinar: How to Automate Exposure Validation to Match the Speed of AI Attacks

AI-driven attacks uncovered in February 2026 automate kill chain and seize Domain Admin credentials in minutes, forcing faster defenses.

The Hacker NewsApr 29, 20262m2
Vulnerabilities

Adapting Zero Trust Principles to Operational Technology

CISA Alerts
Vulnerabilities

Adapting Zero Trust Principles to Operational Technology

This guidance provides a roadmap for organizations to reference as they transition toward a zero trust architecture.

CISA AlertsApr 29, 20262m1
What to Look for in an Exposure Management Platform (And What Most of Them Get Wrong)
The Hacker News
Industry News

What to Look for in an Exposure Management Platform (And What Most of Them Get Wrong)

Integrated exposure platforms validate exploitability, correlate paths, and reduce priorities to 2%, improving enterprise risk reduction.

The Hacker NewsApr 29, 20267m2
Checkmarx Confirms Data Stolen in Supply Chain Attack
SecurityWeek
Industry News

Checkmarx Confirms Data Stolen in Supply Chain Attack

The hackers exfiltrated the data from Checkmarx’s GitHub environment on March 30, a week after publishing malicious code.

SecurityWeekApr 29, 20263m2
Iranian Cyber Group Handala Targets US Troops in Bahrain
SecurityWeek
Industry News

Iranian Cyber Group Handala Targets US Troops in Bahrain

US service members received WhatsApp messages claiming they would be targeted with drones and missiles.

SecurityWeekApr 29, 20263m2
CISA orders feds to patch Windows flaw exploited as zero-day
BleepingComputer
Malware & Threats

CISA orders feds to patch Windows flaw exploited as zero-day

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to secure their Windows systems against a vulnerability exploited in zero-day attacks.

BleepingComputerApr 29, 20263m1