Fixed Intel

Knowledge Hub

Guides, playbooks, and learning resources to level up your cybersecurity knowledge and keep your organization secure.

No Patch for New PhantomRPC Privilege Escalation Technique in Windows
SecurityWeek
Industry News

No Patch for New PhantomRPC Privilege Escalation Technique in Windows

A fake RPC server can be used to listen for RPC requests and impersonate the target service to elevate privileges to System.

SecurityWeekApr 28, 20265m1
Industry News

Critical Unpatched Flaw Leaves Hugging Face LeRobot Open to Unauthenticated RCE

The Hacker News
Industry News

Critical Unpatched Flaw Leaves Hugging Face LeRobot Open to Unauthenticated RCE

Cybersecurity researchers have disclosed details of a critical security flaw impacting LeRobot, Hugging Face's open-source robotics platform with nearly 24,000 GitHub stars, that could be exploited to achieve remote code execution. The vulnerability in question is CVE-2026-25874 (CVSS score: 9.3)...

The Hacker NewsApr 28, 20261m1
Germany Suspects Russia Is Behind Signal Phishing That Targeted Top Officials
SecurityWeek
Industry News

Germany Suspects Russia Is Behind Signal Phishing That Targeted Top Officials

Federal prosecutors have been conducting a preliminary investigation since mid-February 2026 into alleged cyberattacks on Signal accounts.

SecurityWeekApr 28, 20263m1
After Mythos: New Playbooks For a Zero-Window Era
The Hacker News
Industry News

After Mythos: New Playbooks For a Zero-Window Era

AI models like Claude Mythos find vulnerabilities in minutes, collapsing patch windows and forcing assume-breach defenses to contain threats.

The Hacker NewsApr 28, 20266m1
Microsoft: New Remote Desktop warnings may display incorrectly
BleepingComputer
Malware & Threats

Microsoft: New Remote Desktop warnings may display incorrectly

Microsoft has confirmed a new issue causing newly introduced Windows security warnings to display incorrectly when opening Remote Desktop (.rdp) files.

BleepingComputerApr 28, 20263m1
French police arrest 21-year-old “HexDex” hacker over 100 alleged data breaches
Graham Cluley
Industry News

French police arrest 21-year-old “HexDex” hacker over 100 alleged data breaches

A 21-year-old man suspected of conducting approximately 100 data breaches since late 2025 - including a hack of the French Ministry of National Education that exposed records on almost a quarter of a million employees — has been arrested at his home in western France.

Graham CluleyApr 28, 20263m1
Microsoft asks iPhone users to reauthenticate after Outlook outage
BleepingComputer
Malware & Threats

Microsoft asks iPhone users to reauthenticate after Outlook outage

After addressing a widespread outage that affected Outlook.com users worldwide on Monday, Microsoft has asked iPhone users to re-enter their credentials to regain access to their Outlook and Hotmail accounts via the default Mail app.

BleepingComputerApr 28, 20263m1
Spectrum Security Emerges From Stealth Mode With $19 Million
SecurityWeek
Industry News

Spectrum Security Emerges From Stealth Mode With $19 Million

The threat detection startup will invest in accelerating its engineering and go-to-market efforts.

SecurityWeekApr 28, 20262m1
Chinese Silk Typhoon Hacker Extradited to U.S. Over COVID Research Cyberattacks
The Hacker News
Industry News

Chinese Silk Typhoon Hacker Extradited to U.S. Over COVID Research Cyberattacks

Chinese hacker extradited after 2020–2021 Exchange zero-day attacks on U.S. vaccine research, intensifying DOJ crackdown.

The Hacker NewsApr 28, 20262m1
Microsoft Patches Entra ID Role Flaw That Enabled Service Principal Takeover
The Hacker News
Industry News

Microsoft Patches Entra ID Role Flaw That Enabled Service Principal Takeover

Agent ID Administrator enabled service principal takeover before April 9, 2026 patch, exposing privilege escalation risk in Entra ID tenants.

The Hacker NewsApr 28, 20263m1
Medtronic Hack Confirmed After ShinyHunters Threatens Data Leak
SecurityWeek
Industry News

Medtronic Hack Confirmed After ShinyHunters Threatens Data Leak

The ShinyHunters cybercrime group claimed to have stolen 9 million records containing personal information from Medtronic.

SecurityWeekApr 28, 20262m1
Microsoft Confirms Active Exploitation of Windows Shell CVE-2026-32202
The Hacker News
Industry News

Microsoft Confirms Active Exploitation of Windows Shell CVE-2026-32202

CVE-2026-32202 actively exploited after April 27 advisory fix, exposing NTLMv2 hashes via zero-click SMB authentication.

The Hacker NewsApr 28, 20263m1