Fixed Intel

Knowledge Hub

Guides, playbooks, and learning resources to level up your cybersecurity knowledge and keep your organization secure.

Actively exploited Apache ActiveMQ flaw impacts 6,400 servers
BleepingComputer
Malware & Threats

Actively exploited Apache ActiveMQ flaw impacts 6,400 servers

Nonprofit security organization Shadowserver found that over 6,400 Apache ActiveMQ servers exposed online are vulnerable to ongoing attacks exploiting a high-severity code injection vulnerability.

BleepingComputerApr 21, 20262m2
Data Breaches at Healthcare Organizations in Illinois and Texas Affect 600,000
SecurityWeek
Industry News

Data Breaches at Healthcare Organizations in Illinois and Texas Affect 600,000

Data breaches were disclosed by Southern Illinois Dermatology, Saint Anthony Hospital, and North Texas Behavioral Health Authority.

SecurityWeekApr 21, 20262m1
Industry News

Google Fixes Critical RCE Flaw in AI-Based Antigravity Tool

Dark Reading
Industry News

Google Fixes Critical RCE Flaw in AI-Based Antigravity Tool

The prompt injection vulnerability in the agentic AI product for filesystem operations was a sanitization issue that allowed for sandbox escape and arbitrary code execution.

Dark ReadingApr 21, 20261m1
NGate Campaign Targets Brazil, Trojanizes HandyPay to Steal NFC Data and PINs
The Hacker News
Industry News

NGate Campaign Targets Brazil, Trojanizes HandyPay to Steal NFC Data and PINs

NGate abuses HandyPay in Brazil since Nov 2025, stealing NFC data and PINs to enable ATM fraud and unauthorized payments.

The Hacker NewsApr 21, 20264m1
Google Patches Antigravity IDE Flaw Enabling Prompt Injection Code Execution
The Hacker News
Industry News

Google Patches Antigravity IDE Flaw Enabling Prompt Injection Code Execution

Antigravity Strict Mode bypass disclosed Jan 7, 2026, patched Feb 28, enables arbitrary code execution via fd -X flag.

The Hacker NewsApr 21, 20267m1
Former ransomware negotiator pleads guilty to BlackCat attacks
BleepingComputer
Malware & Threats

Former ransomware negotiator pleads guilty to BlackCat attacks

41-year-old Angelo Martino, a former employee of cybersecurity incident response company DigitalMint, has pleaded guilty to targeting U.S. companies in BlackCat (ALPHV) ransomware attacks in 2023.

BleepingComputerApr 21, 20263m2
$290 Million Kelp DAO Crypto Heist Blamed on North Korea
SecurityWeek
Industry News

$290 Million Kelp DAO Crypto Heist Blamed on North Korea

The hackers targeted LayerZero’s DVN, compromising certain RPCs and DDoSing others to trigger failover to the poisoned infrastructure.

SecurityWeekApr 21, 20263m2
NGate Android malware uses HandyPay NFC app to steal card data
BleepingComputer
Malware & Threats

NGate Android malware uses HandyPay NFC app to steal card data

A new variant of the NGate malware that steals NFC payment data is targeting Android users by hiding in a trojanized version of HandyPay, a legitimate mobile payments processing tool.

BleepingComputerApr 21, 20263m2
Vulnerabilities

A .WAV With A Payload, (Tue, Apr 21st)

SANS ISC
Vulnerabilities

A .WAV With A Payload, (Tue, Apr 21st)

There have been reports of threat actors using a .wav file as a vector for malware.

SANS ISCApr 21, 20261m2
CISA Adds 8 Exploited Flaws to KEV, Sets April-May 2026 Federal Deadlines
The Hacker News
Industry News

CISA Adds 8 Exploited Flaws to KEV, Sets April-May 2026 Federal Deadlines

CISA adds 8 exploited vulnerabilities to KEV, sets April 23 and May 4, 2026 deadlines, driving urgent federal patching.

The Hacker NewsApr 21, 20263m2
Vulnerabilities

ISC Stormcast For Tuesday, April 21st, 2026 https://isc.sans.edu/podcastdetail/9900, (Tue, Apr 21st)

SANS ISC
Vulnerabilities

ISC Stormcast For Tuesday, April 21st, 2026 https://isc.sans.edu/podcastdetail/9900, (Tue, Apr 21st)

No description available.

SANS ISCApr 21, 20261m2
KelpDAO suffers $290 million heist tied to Lazarus hackers
BleepingComputer
Malware & Threats

KelpDAO suffers $290 million heist tied to Lazarus hackers

State-sponsored North Korean hackers are likely behind the $290 million crypto-heist that impacted the KelpDAO DeFi project on Saturday.

BleepingComputerApr 20, 20263m2