Fixed Intel

Knowledge Hub

Guides, playbooks, and learning resources to level up your cybersecurity knowledge and keep your organization secure.

13-year-old bug in ActiveMQ lets hackers remotely execute commands
BleepingComputer
Malware & Threats

13-year-old bug in ActiveMQ lets hackers remotely execute commands

Security researchers discovered a remote code execution (RCE) vulnerability in Apache ActiveMQ Classic that has gone undetected for 13 years and could be exploited to execute arbitrary commands.

BleepingComputerApr 8, 20263m2
Vulnerabilities

TeamPCP Supply Chain Campaign: Update 007 - Cisco Source Code Stolen via Trivy-Linked Breach, Google GTIG Tracks TeamPCP as UNC6780, and CISA KEV Deadline Arrives with No Standalone Advisory, (Wed, Apr 8th)

SANS ISC
Vulnerabilities

TeamPCP Supply Chain Campaign: Update 007 - Cisco Source Code Stolen via Trivy-Linked Breach, Google GTIG Tracks TeamPCP as UNC6780, and CISA KEV Deadline Arrives with No Standalone Advisory, (Wed, Apr 8th)

This is the seventh update to the TeamPCP supply chain campaign threat intelligence report,&#;x26;#;xc2;&#;x26;#;xa0;"When the Security Scanner Became the Weapon"&#;x26;#;xc2;&#;x26;#;xa0;(v3.0, March 25, 2026).&#;x26;#;xc2;&#;x26;#;xa0;Update 006&#;x26;#;xc2;&#;x26;#;xa0;covered developments thr...

SANS ISCApr 8, 20261m2
Masjesu Botnet Emerges as DDoS-for-Hire Service Targeting Global IoT Devices
The Hacker News
Industry News

Masjesu Botnet Emerges as DDoS-for-Hire Service Targeting Global IoT Devices

Masjesu botnet drives global DDoS attacks since 2023, with nearly 50% traffic from Vietnam, threatening enterprises and IoT devices.

The Hacker NewsApr 8, 20263m1
Industry News

Fraud Rockets Higher in Mobile-First Latin America

Dark Reading
Industry News

Fraud Rockets Higher in Mobile-First Latin America

Cyber-fraudsters move quickly from compromised devices to account takeover to funds transfer, shifting money before many financial institutions can react.

Dark ReadingApr 8, 20261m1
Data Leakage Vulnerability Patched in OpenSSL
SecurityWeek
Industry News

Data Leakage Vulnerability Patched in OpenSSL

A total of seven vulnerabilities, most of which can be exploited for DoS attacks, have been patched in OpenSSL.

SecurityWeekApr 8, 20262m1
Industry News

Full Sail University to Open IBM Cyber Defense Range Powered by AWS and Cloud Range on Campus

Dark Reading
Industry News

Full Sail University to Open IBM Cyber Defense Range Powered by AWS and Cloud Range on Campus

No description available.

Dark ReadingApr 8, 20261m1
RCE Bug Lurked in Apache ActiveMQ Classic for 13 Years
SecurityWeek
Industry News

RCE Bug Lurked in Apache ActiveMQ Classic for 13 Years

The vulnerability requires authentication for successful exploitation, but another flaw exposes the Jolokia API without authentication.

SecurityWeekApr 8, 20262m1
Vulnerabilities

More Honeypot Fingerprinting Scans, (Wed, Apr 8th)

SANS ISC
Vulnerabilities

More Honeypot Fingerprinting Scans, (Wed, Apr 8th)

One question that often comes up when I talk about honeypots: Are attackers able to figure out if they are connected to a honeypot? The answer is pretty simple: Yes!

SANS ISCApr 8, 20261m2
Industry News

Niobium Introduces The Fog

Dark Reading
Industry News

Niobium Introduces The Fog

No description available.

Dark ReadingApr 8, 20261m1
Industry News

Pluralsight Launches SecureReady to Help Organizations Build Job-Ready Cybersecurity Teams

Dark Reading
Industry News

Pluralsight Launches SecureReady to Help Organizations Build Job-Ready Cybersecurity Teams

No description available.

Dark ReadingApr 8, 20261m1
Is a $30,000 GPU Good at Password Cracking?
BleepingComputer
Malware & Threats

Is a $30,000 GPU Good at Password Cracking?

A $30,000 AI GPU doesn't outperform consumer GPUs at password cracking. Specops explains why attackers don't need exotic hardware to break weak passwords.

BleepingComputerApr 8, 20265m2
APT28 Deploys PRISMEX Malware in Campaign Targeting Ukraine and NATO Allies
The Hacker News
Industry News

APT28 Deploys PRISMEX Malware in Campaign Targeting Ukraine and NATO Allies

APT28 deploys PRISMEX using zero-day CVEs since September 2025, targeting Ukraine’s supply chains and NATO partners for espionage and sabotage.

The Hacker NewsApr 8, 20264m1