IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 4,757 matching records.
AUTO-POLL // 2026-10-09 19:45 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P5 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 9

RANSOMWARE
P5
P5
COOL // 56 ARTICLES
THU
Oct 8

RANSOMWARE
P3
P3
COOL // 62 ARTICLES
WED
Oct 7

RANSOMWARE
P5
P5
COOL // 86 ARTICLES
TUE
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
RESET
2026-10-09 18:13 UTC
Vendor Research

CVE-2026-108096: Improper authorization in query resolvers for SQL-backed models in AWS Amplify API Category

AWS Security Bulletins · aws@amazon.com · indexed 2026-10-09 18:30 UTC

Bulletin ID: 2026-133-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 10/09/2026 11:00 AM PDT Description: AWS Amplify API Category is a CDK Construct library for defining GraphQL data models with authorization rules as AWS AppSync APIs. We identified CVE-2026-108096, where improper authorization in the query resolvers generated by @aws-amplify/graphql-index-transformer might allow an authenticated remote user to read records owned by other users of the same applic…

Cloud SecurityVulnerabilitiesCVE-2026-108096
P5
2026-10-09 17:45 UTC
Security Journalism

FBI Arrests Another ShinyHunters Suspect Reportedly Involved in Its Jobs Portal Hack

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-09 19:00 UTC

The FBI has arrested another suspected co-conspirator of ShinyHunters, FBI Director Kash Patel said on October 9 in a post on X. ShinyHunters is the extortion group that said in September it had breached the FBI's jobs portal and stolen sensitive data on almost all FBI agents and job applicants. The FBI has not named the suspect, and no charges have been made public. The

Law Enforcement
P0
2026-10-09 17:21 UTC
Security Journalism

What We Missed: FBI Strikes Back at ShinyHunters

Dark Reading · Rob Wright, Alexander Culafi · indexed 2026-10-09 17:35 UTC

In this video conversation, Dark Reading editors discuss some of the news they didn't get a chance to cover, from the arrest of a suspected ShinyHunters operative to the compromise of a Pentagon-run data center.

Law Enforcement
P0
2026-10-09 16:29 UTC
Security Journalism

P7 DarkSword iOS Exploit Kit Adds Crypto Wallet Data Theft and Remote Commands

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-09 16:50 UTC

Cybersecurity researchers have disclosed details of a previously unseen variant of the DarkSword iOS exploit kit called P7 DarkSword. "Compared with the variants we usually observe, P7 reduces its on-device footprint, adds on-device keychain and crypto-wallet theft, and adds two way C2 communication with the attacker's infrastructure," iVerify said in a new report published Thursday. The name

AppleSecurity Research
P0
2026-10-09 15:56 UTC
Vendor Research

CVE-2026-107783 - Insertion of sensitive information into log file in AWS Tools for PowerShell

AWS Security Bulletins · aws@amazon.com · indexed 2026-10-09 16:30 UTC

Bulletin ID: 2026-132-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 10/09/2026 08:30 AM PDT Description: AWS Tools for PowerShell V5 lets developers and administrators manage their AWS services from the PowerShell scripting environment. We identified CVE-2026-107783, where insertion of sensitive information into log file in AWS Tools for PowerShell before 5.0.306 might allow local users to recover an IAM user's cleartext AWS Management Console password from comma…

Cloud SecurityVulnerabilitiesCVE-2026-107783
P5
2026-10-09 15:15 UTC
Vendor Research

Hermes Agent - PKCE Session Takeover via Redirect-URI Parser Confusion

Tenable Research Advisories · Joshua Martinelle · indexed 2026-10-09 15:25 UTC

Hermes Agent - PKCE Session Takeover via Redirect-URI Parser Confusion Note: Another researcher identified the same vulnerability during the disclosure process with the Nous Researcher team.In Hermes Agent, the public GET /auth/native/authorize flow validates the redirect_uri with Python's urllib.parse.urlparse, then hands the raw, unnormalized value back to the browser after authentication.The two parsers treat backslashes differently. Python's parser and the browser's WHATWG parser therefore …

MicrosoftVulnerabilities
P0
2026-10-09 15:13 UTC
Vendor Research

Hermes Agent - Pre-Authentication Disk Consumption

Tenable Research Advisories · Joshua Martinelle · indexed 2026-10-09 15:25 UTC

Hermes Agent - Pre-Authentication Disk Consumption In Hermes Agent the public POST /auth/password-login route copies the client-supplied provider value, with no size limit, into the audit log before rejecting an unknown provider.Because the middleware treats this route as public, an unauthenticated client with no account can cause arbitrarily large, attacker-controlled data to be written persistently to the server's disk.In hermes_cli/dashboard_auth/routes.py, _PasswordLoginBody.provider is dec…

P0
2026-10-09 15:07 UTC
Vendor Research

Hermes Agent - Pre-Authentication Memory Exhaustion

Tenable Research Advisories · Joshua Martinelle · indexed 2026-10-09 15:25 UTC

Hermes Agent - Pre-Authentication Memory Exhaustion In Hermes Agent the dashboard's public authentication routes (/auth/native/token, /auth/native/refresh, and /auth/password-login) read and parse the entire JSON request body before any authentication check, with no application-level size limit.The gated_auth_middleware in hermes_cli/dashboard_auth/middleware.py lets these paths through via _GATE_PUBLIC_PREFIXES before checking for a session. The handlers in routes.py rely on Pydantic models wh…

P0
2026-10-09 14:52 UTC
Vendor Research

WordPress - Post Author Second Order SQLi

Tenable Research Advisories · Joshua Martinelle · indexed 2026-10-09 15:25 UTC

WordPress - Post Author Second Order SQLi A regression was introduced in version 4.0.0 of WP Post Author, the multi-authors module stores the co-author list in the wpma_author post meta and later interpolates each stored value directly into a SQL query. Neither end of that path is safe.On write, awpa_ma_save_metabox() takes $_POST['wpma_metabox_authors_list'], splits it on commas, and stores each element verbatim. The handler computes a sanitized copy and then stores the raw value instead:// in…

Law Enforcement
P0
2026-10-09 14:40 UTC
Vendor Research

WordPress - Post Author Authenticated SQLi

Tenable Research Advisories · Joshua Martinelle · indexed 2026-10-09 15:25 UTC

WordPress - Post Author Authenticated SQLi Two REST handlers build SQL queries by concatenating client-supplied request parameters straight into the query string. There is no $wpdb->prepare(), no esc_like(), and no whitelisting. The only processing applied is sanitize_text_field(), which trims whitespace and strips tags and control characters. It does not escape quotes and offers no protection against SQL injection.// includes/api-request/free/multi-authors/class-multiauthors.php — awpa_list_gu…

P0
2026-10-09 14:01 UTC
Security Journalism

How to keep AI agents within their permissions

BleepingComputer · Sponsored by Token Security · indexed 2026-10-09 14:15 UTC

AI agents can use valid credentials to perform actions beyond their assigned permissions, creating risks that traditional access controls may not prevent. Token Security explains how organizations can enforce agent-specific policies without sacrificing autonomy. [...]

AI Security
P0
2026-10-09 13:56 UTC
Other

Claude Helps Secure Open Source as Anthropic Offers Free Vulnerability Scanning

Security Affairs · Pierluigi Paganini · indexed 2026-10-09 14:20 UTC

Anthropic launches free OSS Scanner, using AI to find open-source vulnerabilities and help maintainers fix bugs before attackers exploit them. Anthropic is launching OSS Scanner, a vulnerability scanner for open-source code that costs nothing for projects to join. It grew directly out of lessons learned running Claude against real-world targets during Project Glasswing. The backdrop […]

Vulnerabilities
P0
1 2 3