Fixed Intel

Knowledge Hub

Guides, playbooks, and learning resources to level up your cybersecurity knowledge and keep your organization secure.

Vulnerabilities

TeamPCP Supply Chain Campaign: Update 008 - 26-Day Pause Ends with Three Concurrent Compromises (Checkmarx KICS, Bitwarden CLI Cascade, xinference PyPI), CanisterSprawl npm Worm Identified, and Tier 1 Coverage Returns, (Mon, Apr 27th)

SANS ISC
Vulnerabilities

TeamPCP Supply Chain Campaign: Update 008 - 26-Day Pause Ends with Three Concurrent Compromises (Checkmarx KICS, Bitwarden CLI Cascade, xinference PyPI), CanisterSprawl npm Worm Identified, and Tier 1 Coverage Returns, (Mon, Apr 27th)

This update succeeds&#;x26;#;xc2;&#;x26;#;xa0;TeamPCP Supply Chain Campaign Update 007, published April 8, 2026, which left the campaign in credential-monetization mode following the Cisco source code theft via Trivy-linked credentials, Google GTIG&#;x26;#;39;s formal designation of the operators...

SANS ISCApr 27, 20261m1
Medtronic confirms breach after hackers claim 9 million records theft
BleepingComputer
Malware & Threats

Medtronic confirms breach after hackers claim 9 million records theft

Medical device giant Medtronic disclosed last week that hackers breached its network and accessed data in "certain corporate IT systems."

BleepingComputerApr 27, 20262m1
⚡ Weekly Recap: Fast16 Malware, XChat Launch, Federal Backdoor, AI Employee Tracking & More
The Hacker News
Industry News

⚡ Weekly Recap: Fast16 Malware, XChat Launch, Federal Backdoor, AI Employee Tracking & More

This week’s ThreatsDay covers supply chain attacks, fake help desks, wiper malware, AI prompt traps, RMM abuse, phishing kits, and more.

The Hacker NewsApr 27, 202614m1
Industry News

20-Year-Old Malware Rewrites History of Cyber Sabotage

Dark Reading
Industry News

20-Year-Old Malware Rewrites History of Cyber Sabotage

Researchers have uncovered a malware framework dubbed "fast16" that predates Stuxnet by 5 years.

Dark ReadingApr 27, 20261m1
Incomplete Windows Patch Opens Door to Zero-Click Attacks
SecurityWeek
Industry News

Incomplete Windows Patch Opens Door to Zero-Click Attacks

The initial vulnerability was exploited by Russia-linked APT28 in attacks against Ukraine and EU countries.

SecurityWeekApr 27, 20263m1
Money launderer linked to $230M crypto heist gets 70 months in prison
BleepingComputer
Malware & Threats

Money launderer linked to $230M crypto heist gets 70 months in prison

​22-year-old Evan Tangeman of Newport Beach, California, was sentenced to 70 months in prison for laundering funds stolen in a massive $230 million cryptocurrency heist.

BleepingComputerApr 27, 20263m1
Deepfake Voice Attacks are Outpacing Defenses: What Security Leaders Should Know
BleepingComputer
Malware & Threats

Deepfake Voice Attacks are Outpacing Defenses: What Security Leaders Should Know

Three seconds of audio is all it takes to clone a voice for fraud. Adaptive Security shows how deepfake calls trick employees into sending real money—and why most defenses don't catch them.

BleepingComputerApr 27, 20266m1
Industry News

Parsing Agentic Offensive Security's Existential Threat

Dark Reading
Industry News

Parsing Agentic Offensive Security's Existential Threat

Some fear frontier LLMs like Claude Mythos and Anthropic's GPT-5.5 will lead to cybersecurity annihilation. Ari Herbert-Voss notes this could be an opportunity.

Dark ReadingApr 27, 20261m1
OpenSSH Flaw Allowing Full Root Shell Access Lurked for 15 Years
SecurityWeek
Industry News

OpenSSH Flaw Allowing Full Root Shell Access Lurked for 15 Years

A code reuse issue enabled comma characters in certificate principals to be interpreted as list separators.

SecurityWeekApr 27, 20263m1
Malicious AI Prompt Injection Attacks Increasing, but Sophistication Still Low: Google
SecurityWeek
Industry News

Malicious AI Prompt Injection Attacks Increasing, but Sophistication Still Low: Google

The tech giant found that many indirect prompt injection attempts are harmless, but some malicious exploits have also been identified.

SecurityWeekApr 27, 20263m1
Microsoft says Outlook.com outage is causing sign‑in failures
BleepingComputer
Malware & Threats

Microsoft says Outlook.com outage is causing sign‑in failures

Microsoft is investigating an ongoing Outlook.com outage that is causing intermittent signing issues and preventing customers from accessing their mailboxes.

BleepingComputerApr 27, 20262m1
Mythos Changed the Math on Vulnerability Discovery. Most Teams Aren't Ready for the Remediation Side
The Hacker News
Industry News

Mythos Changed the Math on Vulnerability Discovery. Most Teams Aren't Ready for the Remediation Side

Claude Mythos’ April 7 launch accelerates vulnerability discovery, but limited access and rising false positives strain remediation workflows.

The Hacker NewsApr 27, 20266m1