Fixed Intel

Knowledge Hub

Guides, playbooks, and learning resources to level up your cybersecurity knowledge and keep your organization secure.

In Other News: ChatGPT Data Leak, Android Rootkit, Water Facility Hit by Ransomware
SecurityWeek
Industry News

In Other News: ChatGPT Data Leak, Android Rootkit, Water Facility Hit by Ransomware

Other noteworthy stories that might have slipped under the radar: Symantec vulnerability, anti-ClickFix mechanism added to macOS, FBI hack classified as major incident.

SecurityWeekApr 3, 20265m1
Critical ShareFile Flaws Lead to Unauthenticated RCE
SecurityWeek
Industry News

Critical ShareFile Flaws Lead to Unauthenticated RCE

The vulnerabilities can be chained together to bypass authentication and upload arbitrary files to the server.

SecurityWeekApr 3, 20262m1
Industry News

CrowdStrike Next-Gen SIEM Can Now Ingest Microsoft Defender Telemetry

Dark Reading
Industry News

CrowdStrike Next-Gen SIEM Can Now Ingest Microsoft Defender Telemetry

Once CrowdStrike’s nemesis, Microsoft is now a collaborator. A shared interest in Formula 1 helped thaw the years-long fierce rivalry.

Dark ReadingApr 3, 20261m1
Microsoft still working to fix Exchange Online mailbox access issues
BleepingComputer
Malware & Threats

Microsoft still working to fix Exchange Online mailbox access issues

Microsoft is investigating and working to resolve Exchange Online mailbox access issues that have intermittently affected Outlook mobile and macOS users for weeks.

BleepingComputerApr 3, 20262m2
UNC1069 Social Engineering of Axios Maintainer Led to npm Supply Chain Attack
The Hacker News
Industry News

UNC1069 Social Engineering of Axios Maintainer Led to npm Supply Chain Attack

UNC1069 compromised Axios 1.14.1 and 0.30.4 via social engineering, impacting 100M weekly downloads and exposing supply chains.

The Hacker NewsApr 3, 20263m1
Mobile Attack Surface Expands as Enterprises Lose Control
SecurityWeek
Industry News

Mobile Attack Surface Expands as Enterprises Lose Control

Shadow AI embedded in everyday apps, combined with outdated mobile devices and zero-click exploits, is creating a new and largely unseen mobile risk.

SecurityWeekApr 3, 20266m1
Industry News

Why Third-Party Risk Is the Biggest Gap in Your Clients' Security Posture

The Hacker News
Industry News

Why Third-Party Risk Is the Biggest Gap in Your Clients' Security Posture

The next major breach hitting your clients probably won't come from inside their walls. It'll come through a vendor they trust, a SaaS tool their finance team signed up for, or a subcontractor nobody in IT knows about. That's the new attack surface, and most organizations are underprepared for it...

The Hacker NewsApr 3, 20261m1
React2Shell Exploited in Large-Scale Credential Harvesting Campaign
SecurityWeek
Industry News

React2Shell Exploited in Large-Scale Credential Harvesting Campaign

Using automated scanning and the Nexus Listener collection framework, the hackers compromised over 750 systems.

SecurityWeekApr 3, 20263m1
T-Mobile Sets the Record Straight on Latest Data Breach Filing
SecurityWeek
Industry News

T-Mobile Sets the Record Straight on Latest Data Breach Filing

The cybersecurity incident involved an insider and had a limited impact, the telecoms giant told SecurityWeek.

SecurityWeekApr 3, 20262m1
North Korean Hackers Drain $285 Million From Drift in 10 Seconds
SecurityWeek
Industry News

North Korean Hackers Drain $285 Million From Drift in 10 Seconds

The attackers prepared infrastructure and multiple nonce-based transactions, took over an admin key, and drained five vaults.

SecurityWeekApr 3, 20264m1
Nigerian romance scammer jailed after being caught out by fellow fraudster
Graham Cluley
Industry News

Nigerian romance scammer jailed after being caught out by fellow fraudster

A Nigerian man who posed as a woman online to swindle men out of their savings has been sentenced to 15 years in a US prison.

Graham CluleyApr 3, 20263m1
New SparkCat Variant in iOS, Android Apps Steals Crypto Wallet Recovery Phrase Images
The Hacker News
Industry News

New SparkCat Variant in iOS, Android Apps Steals Crypto Wallet Recovery Phrase Images

SparkCat resurfaces in three app store apps, scanning crypto wallet images via OCR, increasing global risk.

The Hacker NewsApr 3, 20262m1