Fixed Intel

Knowledge Hub

Guides, playbooks, and learning resources to level up your cybersecurity knowledge and keep your organization secure.

Robinhood Vulnerability Exploited for Phishing Attacks
SecurityWeek
Industry News

Robinhood Vulnerability Exploited for Phishing Attacks

Legitimate-looking emails coming from Robinhood systems lured recipients to phishing websites.

SecurityWeekApr 28, 20262m1
VECT 2.0 Ransomware Irreversibly Destroys Files Over 131KB on Windows, Linux, ESXi
The Hacker News
Industry News

VECT 2.0 Ransomware Irreversibly Destroys Files Over 131KB on Windows, Linux, ESXi

VECT 2.0 destroys files over 131KB due to nonce flaw, launched December 2025, making ransom payments useless.

The Hacker NewsApr 28, 20265m1
Alleged Chinese State Hacker Extradited to US
SecurityWeek
Industry News

Alleged Chinese State Hacker Extradited to US

A member of Silk Typhoon, Xu Zewei is accused of launching cyberattacks against universities in the US.

SecurityWeekApr 28, 20262m1
Vulnerabilities

HTTP Requests with X-Vercel-Set-Bypass-Cookie Header, (Tue, Apr 28th)

SANS ISC
Vulnerabilities

HTTP Requests with X-Vercel-Set-Bypass-Cookie Header, (Tue, Apr 28th)

This weekend, we saw a few requests to our honeypot that included an "X-Vercel-Set-Bypass-Cookie" header. A sample request:

SANS ISCApr 28, 20261m1
Microsoft to deprecate legacy TLS in Exchange Online starting July
BleepingComputer
Malware & Threats

Microsoft to deprecate legacy TLS in Exchange Online starting July

Microsoft says it will start blocking legacy TLS connections for POP and IMAP email clients in Exchange Online starting in July 2026.

BleepingComputerApr 28, 20263m1
Inside an OPSEC Playbook: How Threat Actors Evade Detection
BleepingComputer
Malware & Threats

Inside an OPSEC Playbook: How Threat Actors Evade Detection

Threat actors are now publishing structured OPSEC playbooks to stay undetected. Flare reveals how these guides outline layered infrastructure, identity separation, and long-term evasion strategies.

BleepingComputerApr 28, 20267m1
Dozens of Open VSX Extension Clones Linked to GlassWorm Malware
SecurityWeek
Industry News

Dozens of Open VSX Extension Clones Linked to GlassWorm Malware

Over 70 cloned Open VSX extensions are likely sleeper extensions designed to distribute malware.

SecurityWeekApr 28, 20263m1
Vulnerabilities

NSA GRASSMARLIN

CISA Alerts
Vulnerabilities

NSA GRASSMARLIN

View CSAF

CISA AlertsApr 28, 20263m1
Sevii Launches Cyber Swarm Defense to Make Agentic AI Security Costs Predictable
SecurityWeek
Industry News

Sevii Launches Cyber Swarm Defense to Make Agentic AI Security Costs Predictable

Agentic AI can be expensive to use, causing further and unpredictable pressure on tight budgets.

SecurityWeekApr 28, 20264m1
Vulnerabilities

CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISA Alerts
Vulnerabilities

CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.

CISA AlertsApr 28, 20261m1
Why Secure Data Movement Is the Zero Trust Bottleneck Nobody Talks About
The Hacker News
Industry News

Why Secure Data Movement Is the Zero Trust Bottleneck Nobody Talks About

84% of leaders say cross-network data sharing raises risk in 2026, as 53% rely on manual transfers, widening Zero Trust gaps.

The Hacker NewsApr 28, 20266m1
Electric Motorcycles and Scooters Face Hacking Risks to Security and Rider Safety
SecurityWeek
Industry News

Electric Motorcycles and Scooters Face Hacking Risks to Security and Rider Safety

Vulnerabilities in Zero Motorcycles electric motorcycles and Yadea electric scooters can pose physical security and safety risks.

SecurityWeekApr 28, 20264m1