Fixed Intel

Knowledge Hub

Guides, playbooks, and learning resources to level up your cybersecurity knowledge and keep your organization secure.

GlassWorm Campaign Uses Zig Dropper to Infect Multiple Developer IDEs
The Hacker News
Industry News

GlassWorm Campaign Uses Zig Dropper to Infect Multiple Developer IDEs

GlassWorm uses a fake WakaTime VS Code extension to infect IDEs, deploy RATs, and steal data, prompting urgent credential rotation.

The Hacker NewsApr 10, 20262m1
Supply chain attack at CPUID pushes malware with CPU-Z/HWMonitor
BleepingComputer
Malware & Threats

Supply chain attack at CPUID pushes malware with CPU-Z/HWMonitor

Hackers gained access to an API for the CPUID project and changed the download links on the official website to serve malicious executables for the popular CPU-Z and HWMonitor tools.

BleepingComputerApr 10, 20263m2
Industry Reactions to Iran Hacking ICS in Critical Infrastructure: Feedback Friday
SecurityWeek
Industry News

Industry Reactions to Iran Hacking ICS in Critical Infrastructure: Feedback Friday

The US government has warned that Iran-linked hackers are manipulating PLCs and SCADA systems to cause disruption.

SecurityWeekApr 10, 202612m1
Microsoft: Canadian employees targeted in payroll pirate attacks
BleepingComputer
Malware & Threats

Microsoft: Canadian employees targeted in payroll pirate attacks

A financially motivated threat actor tracked as Storm-2755 is stealing Canadian employees' salary payments after hijacking their accounts in payroll pirate attacks.

BleepingComputerApr 10, 20263m2
Orthanc DICOM Vulnerabilities Lead to Crashes, RCE
SecurityWeek
Industry News

Orthanc DICOM Vulnerabilities Lead to Crashes, RCE

Attackers could exploit these vulnerabilities in denial-of-service, information disclosure, and arbitrary code execution attacks.

SecurityWeekApr 10, 20263m1
Browser Extensions Are the New AI Consumption Channel That No One Is Talking About
The Hacker News
Industry News

Browser Extensions Are the New AI Consumption Channel That No One Is Talking About

AI browser extensions increase enterprise risk with 60% higher vulnerabilities, bypassing DLP controls and exposing sensitive data.

The Hacker NewsApr 10, 20266m1
Chrome 147 Patches 60 Vulnerabilities, Including Two Critical Flaws Worth $86,000
SecurityWeek
Industry News

Chrome 147 Patches 60 Vulnerabilities, Including Two Critical Flaws Worth $86,000

The critical vulnerabilities affect Chrome’s WebML component and they have been reported by anonymous researchers.

SecurityWeekApr 10, 20262m1
Google rolls out Gmail end-to-end encryption on mobile devices
BleepingComputer
Malware & Threats

Google rolls out Gmail end-to-end encryption on mobile devices

Google says Gmail end-to-end encryption (E2EE) is now available on all Android and iOS devices, allowing enterprise users to read and compose emails without additional tools.

BleepingComputerApr 10, 20263m2
MITRE Releases Fight Fraud Framework
SecurityWeek
Industry News

MITRE Releases Fight Fraud Framework

The document provides a behavior-based model of the tactics and techniques employed by fraudsters.

SecurityWeekApr 10, 20262m1
Critical Marimo Flaw Exploited Hours After Public Disclosure
SecurityWeek
Industry News

Critical Marimo Flaw Exploited Hours After Public Disclosure

Within nine hours, a hacker built an exploit from the unauthenticated bug’s advisory and started using it in the wild.

SecurityWeekApr 10, 20262m1
Google Rolls Out DBSC in Chrome 146 to Block Session Theft on Windows
The Hacker News
Industry News

Google Rolls Out DBSC in Chrome 146 to Block Session Theft on Windows

Google releases DBSC in Chrome 146 for Windows, binding cookies to devices to reduce session theft and prevent unauthorized access.

The Hacker NewsApr 10, 20263m1
Google Rolls Out Cookie Theft Protections in Chrome
SecurityWeek
Industry News

Google Rolls Out Cookie Theft Protections in Chrome

New Device Bound Session Credentials render stolen session cookies unusable by cryptographically binding authentication.

SecurityWeekApr 10, 20263m1