Fixed Intel

Knowledge Hub

Guides, playbooks, and learning resources to level up your cybersecurity knowledge and keep your organization secure.

PhantomCore Exploits TrueConf Vulnerabilities to Breach Russian Networks
The Hacker News
Industry News

PhantomCore Exploits TrueConf Vulnerabilities to Breach Russian Networks

PhantomCore exploited three TrueConf flaws since September 2025, enabling remote access and lateral movement across Russian networks.

The Hacker NewsApr 27, 20267m1
Industry News

Researchers Uncover 73 Fake VS Code Extensions Delivering GlassWorm v2 Malware

The Hacker News
Industry News

Researchers Uncover 73 Fake VS Code Extensions Delivering GlassWorm v2 Malware

Cybersecurity researchers have flagged dozens of Microsoft Visual Studio Code (VS Code) extensions on the Open VSX repository that are linked to a persistent information-stealing campaign dubbed GlassWorm. The cluster of 73 extensions has been identified as cloned versions of their legitimate cou...

The Hacker NewsApr 27, 20261m1
Energy and Water Management Firm Itron Hacked
SecurityWeek
Industry News

Energy and Water Management Firm Itron Hacked

Itron, which serves utilities and cities around the world, discovered unauthorized access to its systems on April 13.

SecurityWeekApr 27, 20262m1
UNC6692 Uses Email Bombing, Social Engineering to Deploy ‘Snow’ Malware
SecurityWeek
Industry News

UNC6692 Uses Email Bombing, Social Engineering to Deploy ‘Snow’ Malware

The threat actor infected victims with the Snow malware family – Snowbelt, Snowglaze, and Snowbasin – for persistent access.

SecurityWeekApr 27, 20264m1
Easily Exploitable ‘Pack2TheRoot’ Linux Vulnerability Leads to Root Access
SecurityWeek
Industry News

Easily Exploitable ‘Pack2TheRoot’ Linux Vulnerability Leads to Root Access

A race condition in PackageKit allows unprivileged users to escalate privileges when installing packages.

SecurityWeekApr 27, 20262m1
US Launches Sweeping Crackdown on Southeast Asia Cyberscams and Sanctions Cambodian Senator
SecurityWeek
Industry News

US Launches Sweeping Crackdown on Southeast Asia Cyberscams and Sanctions Cambodian Senator

U.S. officials have announced a sweeping crackdown on Southeast Asian cyberscam operations as part of what U.S. Attorney Jeanine Pirro characterized Friday as a “new theater of war” launched by the Trump administration against Chinese transnational organized crime. The crackdown, led by a U.S. go...

SecurityWeekApr 27, 20264m1
Firefox Vulnerability Allows Tor User Fingerprinting
SecurityWeek
Industry News

Firefox Vulnerability Allows Tor User Fingerprinting

The vulnerability is tracked as CVE-2026-6770 and it has been patched with the release of Firefox 150 and Tor 15.0.10.

SecurityWeekApr 27, 20262m1
Fake CAPTCHA IRSF Scam and 120 Keitaro Campaigns Drive Global SMS, Crypto Fraud
The Hacker News
Industry News

Fake CAPTCHA IRSF Scam and 120 Keitaro Campaigns Drive Global SMS, Crypto Fraud

Fake CAPTCHA IRSF scam sends up to 60 SMS messages since June 2020, exploiting 17 countries and costing victims $30 per attack.

The Hacker NewsApr 27, 20266m1
American utility firm Itron discloses breach of internal IT network
BleepingComputer
Malware & Threats

American utility firm Itron discloses breach of internal IT network

Itron, Inc. has disclosed, via an 8-K filing with the U.S. Securities and Exchange Commission (SEC), a cybersecurity incident in which an unauthorized third party accessed certain internal systems.

BleepingComputerApr 26, 20262m1
Microsoft rolls out revamped Windows Insider Program
BleepingComputer
Malware & Threats

Microsoft rolls out revamped Windows Insider Program

Microsoft says it's rolling out a revamped Windows Insider Program experience as part of the broader plans to address performance and reliability concerns affecting Windows 11.

BleepingComputerApr 25, 20264m2
Threat actor uses Microsoft Teams to deploy new “Snow” malware
BleepingComputer
Malware & Threats

Threat actor uses Microsoft Teams to deploy new “Snow” malware

A threat group tracked as UNC6692 uses social engineering to deploy a new "Snow" malware set that includes a browser extension, a tunneler, and a backdoor.

BleepingComputerApr 25, 20263m2
China-Linked APT GopherWhisper Abuses Legitimate Services in Government Attacks
SecurityWeek
Industry News

China-Linked APT GopherWhisper Abuses Legitimate Services in Government Attacks

Dubbed GopherWhisper, the group relies on multiple Go-based backdoors alongside custom loaders and injectors.

SecurityWeekApr 25, 20263m2