IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 161 matching records.
AUTO-POLL // 2026-10-09 20:40 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P5 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 9

RANSOMWARE
P5
P5
COOL // 58 ARTICLES
THU
Oct 8

RANSOMWARE
P3
P3
COOL // 62 ARTICLES
WED
Oct 7

RANSOMWARE
P5
P5
COOL // 86 ARTICLES
TUE
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
RESET
2026-10-09 16:29 UTC
Security Journalism

P7 DarkSword iOS Exploit Kit Adds Crypto Wallet Data Theft and Remote Commands

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-09 16:50 UTC

Cybersecurity researchers have disclosed details of a previously unseen variant of the DarkSword iOS exploit kit called P7 DarkSword. "Compared with the variants we usually observe, P7 reduces its on-device footprint, adds on-device keychain and crypto-wallet theft, and adds two way C2 communication with the attacker's infrastructure," iVerify said in a new report published Thursday. The name

AppleSecurity Research
P0
2026-10-07 19:27 UTC
Vendor Research

Microsoft, Adobe, Apple, and Foxit vulnerabilities

Cisco Talos Intelligence Blog · Kri Dontje · indexed 2026-10-07 20:00 UTC

Cisco Talos’ Vulnerability Discovery & Research team recently disclosed vulnerabilities in Adobe, Apple, Foxit Reader, and Microsoft.The vulnerabilities mentioned in this blog post have been patched by their respective vendors, in adherence to Cisco’s third-party vulnerability disclosure policy. For Snort coverage that can detect

AppleMicrosoftVulnerabilities
P0
2026-10-06 15:00 UTC
Vendor Research

How to mitigate the risk from AI-generated apps built by your 'citizen coder' employees

Tenable Blog · Phillip Hayes · indexed 2026-10-06 15:20 UTC

AI tools let non-technical employees build workplace apps in minutes with natural language prompts. While these AI-generated apps boost productivity, they can create severe security and data risks. As Cybersecurity Awareness Month kicks off, we’re sharing how Tenable adopted a structured governance framework that allows our “citizen coders” to build secure and compliant apps with AI.Key takeawaysUnsanctioned applications that non-technical staff build using AI tools often bypass quality assuran…

Apple
P0
2026-10-06 11:48 UTC
Security Journalism

Apple to Tighten Full Disk Access Controls in macOS Amid AI Risks

Security Week · Ionut Arghire · indexed 2026-10-06 12:00 UTC

Citing growing risks posed by more capable and autonomous AI agents, Apple will introduce additional controls. The post Apple to Tighten Full Disk Access Controls in macOS Amid AI Risks appeared first on SecurityWeek.

AI SecurityApple
P0
2026-10-05 10:38 UTC
Security Journalism

Apple Plans Tighter macOS Full Disk Access Controls Over AI Agent Data Access

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-05 11:30 UTC

Apple has announced that it's taking steps to tighten controls around a macOS setting called Full Disk Access (FDA) due to security risks posed by artificial intelligence (AI) agents. "Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems—including files, mail, messages, and even browsing history – without users' full knowledge

AI SecurityApple
P0
2026-10-04 07:58 UTC
Community

User Agent Strings Curiosities, (Sun, Oct 4th)

SANS Internet Storm Center · indexed 2026-10-04 08:00 UTC

Sometimes I have to smile, or my interest is triggered, when I review new User Agent Strings in the honeypot logs.

Apple
P0
2026-10-04 07:58 UTC
Other

Security Affairs newsletter Round 598 by Pierluigi Paganini – INTERNATIONAL EDITION

Security Affairs · Pierluigi Paganini · indexed 2026-10-04 09:00 UTC

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. Fake Zoom installer hides macOS backdoor CloudSyncD CVE-2026-90970: Critical GitLab AI Gateway Flaw Fixed Antino Backdoor Lets […]

AppleMalwareVulnerabilitiesCVE-2026-90970
P5
2026-10-03 15:11 UTC
Other

Fake Zoom installer hides macOS backdoor CloudSyncD

Security Affairs · Pierluigi Paganini · indexed 2026-10-03 15:30 UTC

Jamf Threat Labs details CloudSyncD, a fake macOS Zoom installer that hides a phished password using invisible zero-width Unicode characters. Jamf Threat Labs found CloudSyncD while doing routine scanning on VirusTotal, buried inside a disguised Zoom client. They first spotted it on September 15, clearly still under construction, and within two days watched it move […]

AppleMalwarePhishing
P0
2026-10-02 19:21 UTC
Vendor Research

Cisco IOS XE Software Security Hardening Release: August 2026

Cisco Security Advisories · indexed 2026-08-15 14:33 UTC

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. These vulnerabilities were found during internal testing and are not known to be actively exploited. To assist customers in patching and streamline the disclosure process, Cisco has grouped these issues by …

AppleVulnerabilitiesCVE-2026-20267CVE-2026-20268CVE-2026-20269CVE-2026-20270CVE-2026-20271CVE-2026-20272CVE-2026-20273
P30
2026-10-02 13:15 UTC
Security Journalism

macOS Users Targeted by Fake Zoom Installer Carrying CloudSyncD Backdoor

Security Week · Kevin Townsend · indexed 2026-10-02 13:30 UTC

The dropper “carries a complete universal Mach-O inside itself, roughly 756 KB in the development build, and extracts it at runtime. The post macOS Users Targeted by Fake Zoom Installer Carrying CloudSyncD Backdoor appeared first on SecurityWeek.

AppleMalware
P0
2026-10-01 12:08 UTC
Other

Public PoC Released for Apple CoreGraphics Zero-Day CVE-2026-86950

Security Affairs · Pierluigi Paganini · indexed 2026-10-01 12:40 UTC

Apple patched a CoreGraphics zero-day that may have been exploited in targeted attacks. A public PoC for the flaw is now available. Apple patched a zero-day vulnerability, tracked as CVE-2026-86950, in CoreGraphics that attackers may have exploited to target specific individuals. The flaw is an out-of-bounds write that can lead to arbitrary code execution when […]

AppleVulnerabilitiesCVE-2026-86950
P30
2026-10-01 05:54 UTC
Security Journalism

Apple CoreGraphics PoC Emerges as WhatsApp PDF Checks Hint at Possible Delivery Path

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-01 07:20 UTC

Security researchers have published the first public proof-of-concept for CVE-2026-86950, an Apple CoreGraphics flaw Apple says may have been used in attacks against specific targeted individuals. The trigger is a malicious PDF with a crafted embedded font that crashes unpatched iPhones and Macs. The code causes a crash, not an execution error. Turning the memory corruption into a working

AppleSecurity ResearchVulnerabilitiesCVE-2026-86950
P5
2026-09-30 08:04 UTC
Other

U.S. CISA adds Apple Multiple Products flaw to its Known Exploited Vulnerabilities catalog

Security Affairs · Pierluigi Paganini · indexed 2026-09-30 09:10 UTC

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Apple Multiple Products flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added an Apple Multiple Products flaw, tracked as CVE-2026-86950 (CVSS score of 8.8), to its Known Exploited Vulnerabilities (KEV) catalog. This week, Apple has released security updates for iOS, iPadOS […]

AppleVulnerabilitiesCVE-2026-86950
P35
2026-09-29 13:28 UTC
Other

Apple Patches CoreGraphics Zero-Day Linked to Sophisticated Targeted Attacks

Security Affairs · Pierluigi Paganini · indexed 2026-09-29 13:40 UTC

Apple patched zero-day CVE-2026-86950 in CoreGraphics, exploited in sophisticated targeted attacks against specific iOS users. Apple has released security updates for iOS, iPadOS and macOS to fix a zero-day vulnerability, tracked as CVE-2026-86950, in CoreGraphics that may have been exploited in attacks against specific individuals. The flaw is an out-of-bounds write that can lead to […]

AppleVulnerabilitiesCVE-2026-86950
P50
2026-09-28 22:35 UTC
Community

Apple Emergency Patch for iOS 26, macOS26, macOS15 (CVE-2026-86950), (Mon, Sep 28th)

SANS Internet Storm Center · indexed 2026-09-28 22:10 UTC

Apple today released patches for all of its operating systems. However, only patches for older branches include a security fix. The vulnerability being addressed in iOS 26, macOS 26 and macOS 15 is already being exploited. iOS and macOS 27 are not affected. Today's update for the current "27" branch does not address security issues, but fixes some functional issues that got caught after the release two weeks ago. A 27.1 version was also expected to support the new foldable iPhone and w…

AppleVulnerabilitiesCVE-2026-86950
P5
2026-09-28 19:18 UTC
Security Journalism

Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-28 20:10 UTC

Apple has released security updates to address a vulnerability in older versions of iOS, iPadOS, and macOS that it said may have been exploited in targeted attacks. The vulnerability, tracked as CVE-2026-86950, refers to an out-of-bounds write impacting the CoreGraphics component that could lead to arbitrary code execution when processing a maliciously crafted file. The iPhone maker said the

AppleVulnerabilitiesCVE-2026-86950
P5
2026-09-25 13:18 UTC
Security Journalism

PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-25 16:10 UTC

Cybersecurity researchers have flagged a new version of PamStealer that ensures that the main payload can only be recovered using a server-side decryption chain. The latest artifacts, per Jamf Threat Labs, continue to rely on the same JavaScript for Automation (JXA) dropper mechanism, but modify the lure and the delivery method. "Where earlier variants embedded their payload key material

AppleMalwareSecurity Research
P0
2026-09-23 18:05 UTC
Security Journalism

Worries About an AI Internet Takeover Gain New Urgency Among Doomsday Scenarios

Security Week · Associated Press · indexed 2026-09-23 18:10 UTC

The idea that AI could break away and work toward its own agenda is looking increasingly plausible to researchers and experts. The post Worries About an AI Internet Takeover Gain New Urgency Among Doomsday Scenarios appeared first on SecurityWeek.

Apple
P0
2026-09-23 13:52 UTC
Security Journalism

Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-23 14:10 UTC

Unknown threat actors have managed to compromise two legitimate MemTensor packages across the npm and Python Package Index (PyPI) repositories to push a platform-specific Go-based implant dubbed sckit designed for Windows, Linux, and macOS. According to reports from Aikido, SafeDep, Socket, and StepSecurity, the libraries in question below - @memtensor/memos-cloud-openclaw-plugin versions

AppleLinuxMalwareMicrosoftThreat Actors
P0
2026-09-23 10:20 UTC
Security Journalism

A Look at AI Doomsday Scenarios That Researchers Say Could Put Humanity at Risk

Security Week · Associated Press · indexed 2026-09-23 10:30 UTC

Debates over the plausibility of these doomsday scenarios have heated up since several executives endorsed slowing the technology’s development for safety reasons. The post A Look at AI Doomsday Scenarios That Researchers Say Could Put Humanity at Risk appeared first on SecurityWeek.

Apple
P0
1 2 3