Fixed Intel

Knowledge Hub

Guides, playbooks, and learning resources to level up your cybersecurity knowledge and keep your organization secure.

Vulnerabilities

ISC Stormcast For Monday, March 30th, 2026 https://isc.sans.edu/podcastdetail/9870, (Mon, Mar 30th)

SANS ISC
Vulnerabilities

ISC Stormcast For Monday, March 30th, 2026 https://isc.sans.edu/podcastdetail/9870, (Mon, Mar 30th)

No description available.

SANS ISCMar 30, 20261m2
Vulnerabilities

DShield (Cowrie) Honeypot Stats and When Sessions Disconnect, (Mon, Mar 30th)

SANS ISC
Vulnerabilities

DShield (Cowrie) Honeypot Stats and When Sessions Disconnect, (Mon, Mar 30th)

A lot of the information seen on DShield honeypots [1] is repeated bot traffic, especially when looking at the Cowrie [2] telnet and SSH sessions. However, how long a session lasts, how many commands are run per session and what the last commands run before a session disconnects can vary. Some of...

SANS ISCMar 30, 20261m2
FBI confirms hack of Director Patel's personal email inbox
BleepingComputer
Malware & Threats

FBI confirms hack of Director Patel's personal email inbox

The Handala hackers associated with Iran have breached the personal email account of FBI Director Kash Patel and published photos and documents.

BleepingComputerMar 29, 20263m2
File read flaw in Smart Slider plugin impacts 500K WordPress sites
BleepingComputer
Malware & Threats

File read flaw in Smart Slider plugin impacts 500K WordPress sites

A vulnerability in the Smart Slider 3 WordPress plugin, active on more than 800,000 websites, can be exploited to allow subscriber-level users access to arbitrary files on the server.

BleepingComputerMar 29, 20263m3
Iran-Linked Hackers Breach FBI Director’s Personal Email, Hit Stryker With Wiper Attack
The Hacker News
Critical
Industry News
93/10

Iran-Linked Hackers Breach FBI Director’s Personal Email, Hit Stryker With Wiper Attack

Iran-linked Handala Hack breached FBI Director’s email amid MOIS domain seizures, escalating destructive cyber ops.

Handala Hack Team (MOIS-affiliated, also tracked as Banished Kitten, Cobalt Mystique, Red Sandstorm, Void Manticore)GovernmentHealthcare
The Hacker NewsMar 28, 20268m5
Vulnerabilities

TeamPCP Supply Chain Campaign: Update 003 - Operational Tempo Shift as Campaign Enters Monetization Phase With No New Compromises in 48 Hours, (Sat, Mar 28th)

SANS ISC
Critical
Vulnerabilities
88/10

TeamPCP Supply Chain Campaign: Update 003 - Operational Tempo Shift as Campaign Enters Monetization Phase With No New Compromises in 48 Hours, (Sat, Mar 28th)

This is the third update to the TeamPCP supply chain campaign threat intelligence report, "When the Security Scanner Became the Weapon" (v3.0, March 25, 2026). Update 002 covered developments through March 27, including the Telnyx PyPI compromise and Vect ransomware partnership. This update cover...

TeamPCPTechnologySoftware Development
SANS ISCMar 28, 20261m4
New Infinity Stealer malware grabs macOS data via ClickFix lures
BleepingComputer
High
Malware & Threats
78/10

New Infinity Stealer malware grabs macOS data via ClickFix lures

A new info-stealing malware named Infinity Stealer is targeting macOS systems with a Python payload packaged as an executable using the open-source Nuitka compiler.

TechnologyFinance
BleepingComputerMar 28, 20263m2
Cloudflare-Themed ClickFix Attack Drops Infiniti Stealer on Macs
SecurityWeek
High
Industry News
78/10

Cloudflare-Themed ClickFix Attack Drops Infiniti Stealer on Macs

The infection chain includes a fake CAPTCHA page, a Bash script, a Nuitka loader, and the Python-based infostealer.

TechnologyFinance
SecurityWeekMar 28, 20263m2
Citrix NetScaler Under Active Recon for CVE-2026-3055 (CVSS 9.3) Memory Overread Bug
The Hacker News
Critical
Industry News
91/10

Citrix NetScaler Under Active Recon for CVE-2026-3055 (CVSS 9.3) Memory Overread Bug

CVE-2026-3055 targets Citrix NetScaler with active reconnaissance, risking data leaks on SAML IDP setups.

GovernmentFinance
The Hacker NewsMar 28, 20262m2
TA446 Deploys Leaked DarkSword iOS Exploit Kit in Targeted Spear-Phishing Campaign
The Hacker News
Critical
Industry News
92/10

TA446 Deploys Leaked DarkSword iOS Exploit Kit in Targeted Spear-Phishing Campaign

TA446 used leaked DarkSword on March 26 to target iOS devices, prompting Apple alerts and widening mobile espionage risks.

TA446 (Callisto / COLDRIVER / Star Blizzard / SEABORGIUM)GovernmentThink Tanks
The Hacker NewsMar 28, 20264m2
CISA Adds CVE-2025-53521 to KEV After Active F5 BIG-IP APM Exploitation
The Hacker News
Critical
Industry News
93/10

CISA Adds CVE-2025-53521 to KEV After Active F5 BIG-IP APM Exploitation

CISA adds actively exploited F5 BIG-IP APM CVE-2025-53521 (CVSS 9.3) to KEV, ordering FCEB patch by March 30, 2026 to curb RCE risk.

GovernmentFinance
The Hacker NewsMar 28, 20263m2
Backdoored Telnyx PyPI package pushes malware hidden in WAV audio
BleepingComputer
Critical
Malware & Threats
92/10

Backdoored Telnyx PyPI package pushes malware hidden in WAV audio

TeamPCP hackers compromised the Telnyx package on the Python Package Index today, uploading malicious versions that deliver credential-stealing malware hidden inside a WAV file.

TeamPCPTechnologySoftware Development
BleepingComputerMar 27, 20263m4