IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 161 matching records.
AUTO-POLL // 2026-10-09 21:25 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P5 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 9

RANSOMWARE
P5
P5
COOL // 60 ARTICLES
THU
Oct 8

RANSOMWARE
P3
P3
COOL // 62 ARTICLES
WED
Oct 7

RANSOMWARE
P5
P5
COOL // 86 ARTICLES
TUE
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
RESET
2026-09-21 17:19 UTC
Security Journalism

Contagious Interview Campaign Compromises 30,000 Devices, Steals $10.71M in Crypto

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-21 18:15 UTC

The North Korean threat actors behind the Contagious Interview campaign have compromised at least 30,000 devices located in more than 100 countries and siphoned funds or account credentials from over 7,000 cryptocurrency wallets, according to a new joint cybersecurity advisory. The primary targets of the campaign are individual web designers, engineers, and specialists in cryptocurrency,

AppleThreat Actors
P0
2026-09-21 08:27 UTC
Other

The Target Is No Longer the Model. It’s the Agent.

Security Affairs · Pierluigi Paganini · indexed 2026-09-21 09:25 UTC

AI agents are becoming the new attack surface, exposed to poisoned skills, prompt injection, jailbreaks and attacks through connected tools. I read the AI security research published in a single month, February 2026, and when you put it all together, it’s not a list of curiosities. It’s a field guide to a new attack surface. […]

AI SecurityAppleSecurity Research
P0
2026-09-21 06:06 UTC
Security Journalism

Jade Sleet Linked to Indian IT Provider Breach With FLATROOF and ROOFDECK Backdoors

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-21 06:15 UTC

The North Korean threat actor known as Jade Sleet has been attributed to the compromise of an India-based "much smaller organization" in the information technology (IT) services industry, once again highlighting how the adversary continues to target developers to breach target networks. Cybersecurity company SentinelOne, which disclosed details of the activity, said it involved the use of Apple

AppleMalwareThreat Actors
P0
2026-09-17 21:13 UTC
Vendor Research

Cisco IOS XR Software Security Hardening Release: September 2026

Cisco Security Advisories · indexed 2026-09-02 16:10 UTC

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. These vulnerabilities were found during internal testing and are not known to be actively exploited. To assist customers in patching and streamline the disclosure process, Cisco has grouped these issues by …

AppleVulnerabilitiesCVE-2026-20274CVE-2026-20275CVE-2026-20276CVE-2026-20277CVE-2026-20278CVE-2026-20279CVE-2026-20280
P30
2026-09-17 16:00 UTC
Vendor Research

Improving email security outcomes with real-world Microsoft Defender insights

Microsoft Security Blog · Rob Lefferts · indexed 2026-09-17 18:05 UTC

The latest email security benchmarking reports show strong Microsoft Defender performance across pre-delivery and post-delivery scenarios and reveal where threats and defenses continue to evolve. The post Improving email security outcomes with real-world Microsoft Defender insights appeared first on Microsoft Security Blog.

AppleMicrosoft
P0
2026-09-17 15:37 UTC
Security Journalism

Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-18 03:55 UTC

Malicious code running inside a Docker Sandboxes virtual machine on macOS could escape the project directory shared into it and read or change files anywhere else on the host, Docker warns in a security announcement on September 15. The escape runs with the rights of the host account that runs the virtual machine. The flaw, CVE-2026-77179, is rated Critical, affects versions

AppleVulnerabilitiesCVE-2026-77179
P5
2026-09-16 10:00 UTC
Vendor Research

Atomic macOS (AMOS) Stealer Activity

Palo Alto Networks Unit 42 · Bradley Duncan · indexed 2026-09-16 10:20 UTC

Modern macOS malware uses deceptive setup guides to steal credentials and sensitive user data. Learn how to identify and block these threats. The post Atomic macOS (AMOS) Stealer Activity appeared first on Unit 42.

AppleMalware
P0
2026-09-15 15:23 UTC
Community

MacOS 27 - First Boot, (Tue, Sep 15th)

SANS Internet Storm Center · indexed 2026-09-15 15:40 UTC

I have not done this type of diary in a while: What traffic will you see from a system on boot, before a user logs in? I just took a quick look at macOS 27 "Golden Gate" to see what traffic you should expect. Here are some of the highlights:

Apple
P0
2026-09-14 18:33 UTC
Community

Apple Updates Everything, (Mon, Sep 14th)

SANS Internet Storm Center · indexed 2026-09-14 18:50 UTC

Today, Apple released its annual update across all its operating systems. With that, Apple not only released new features but also patched 261 different vulnerabilities. This is the most vulnerabilities Apple has ever patched, but the increase is not as significant as other vendors' "post-AI" patch releases. 

Apple
P0
2026-09-09 05:00 UTC
Other

ZDI-26-641: Oracle VirtualBox VirtioSCSI Out-Of-Bounds Read Information Disclosure Vulnerability

Zero Day Initiative · indexed 2026-09-09 22:50 UTC

This vulnerability allows local attackers to disclose sensitive information on affected installations of Oracle VirtualBox. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.1. The following CVEs are assigned: CVE-2026-71114.

AppleVulnerabilitiesCVE-2026-71114
P5
2026-09-09 05:00 UTC
Other

ZDI-26-640: Oracle VirtualBox VirtioSCSI Uninitialized Memory Information Disclosure Vulnerability

Zero Day Initiative · indexed 2026-09-09 22:50 UTC

This vulnerability allows local attackers to disclose sensitive information on affected installations of Oracle VirtualBox. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.3. The following CVEs are assigned: CVE-2026-71132.

AppleVulnerabilitiesCVE-2026-71132
P5
2026-09-08 11:54 UTC
Security Journalism

WeChat Zero-Click Worm Took Over Accounts on iPhone and Android via Incoming Calls

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-08 13:20 UTC

Researchers at the security firm Calif have built a worm that takes over a WeChat account via an incoming call and demonstrated it spreading among three test phones. The person being called does not have to answer or touch their phone for it to work, but the caller must already be one of their WeChat contacts. Calif reported the flaw to Tencent in July and says the company has since

AppleMobile Security
P0
2026-09-03 21:15 UTC
Vendor Research

Incident response guide for AWS CloudTrail investigations – Part 2

AWS Security Blog · Oscar Diaz · indexed 2026-09-03 21:35 UTC

In Part 1 of this guide, we examined two common incident scenarios: cross-account Amazon Simple Storage Service (Amazon S3) data deletion with ransomware implications, and cryptocurrency mining deployed through AWS CloudFormation using exposed AWS Management Console credentials. We also introduced key incident response terminology and investigative frameworks for analyzing AWS CloudTrail events. In this second […]

AppleCloud SecurityDFIRRansomware
P15
2026-09-03 21:15 UTC
Vendor Research

Incident response guide for AWS CloudTrail investigations – Part 1

AWS Security Blog · Oscar Diaz · indexed 2026-09-03 21:35 UTC

AWS CloudTrail logs contain the evidence you need when investigating suspicious activity in your AWS environment, but knowing which fields matter and how to interpret them can mean the difference between surface-level analysis and uncovering the full scope of an incident. This guide walks you through real-world scenarios, showing you how to analyze CloudTrail events […]

AppleCloud SecurityDFIR
P0
2026-09-03 20:17 UTC
Other

Pegasus and NoviSpy Used Against Serbian Protesters

Security Affairs · Pierluigi Paganini · indexed 2026-09-03 20:25 UTC

Serbian activists were targeted with zero-click Pegasus and NoviSpy spyware, exposing a major surveillance campaign ahead of elections. A member of Serbia’s student protest movement had their iPhone infected with NSO Group‘s Pegasus spyware without ever clicking a link or opening a file. The Citizen Lab confirmed the infection in collaboration with the SHARE Foundation, […]

Apple
P0
2026-09-03 15:52 UTC
Security Journalism

Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-03 16:45 UTC

Cisco has released patches to address a critical security flaw affecting 10 Silicon One-based Nexus 9000 switches that could allow an unauthenticated, remote attacker to execute code as root, alongside an IOS XR hardening release bundling 7 umbrella CVEs, 2 of which are rated 9.8, with no workaround for any IOS XR version. The Nexus vulnerability, tracked as CVE-2026-20212 (CVSS score: 9.8), is

AppleNetwork SecurityVulnerabilitiesCVE-2026-20212
P5
2026-09-03 08:43 UTC
Security Journalism

Pegasus Zero-Click Spyware Exploit Infects Serbian Student Movement Member's iPhone

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-03 10:00 UTC

The iPhone belonging to a member of Serbia's student protest movement was infected with NSO Group's Pegasus spyware, according to new findings from the Citizen Lab in collaboration with the SHARE Foundation. "Our analysis confirmed that an iMessage zero-click exploit was used to infect the device with NSO Group's Pegasus spyware," the Citizen Lab said. "We found high-confidence indicators of

Apple
P0
2026-09-02 16:02 UTC
Vendor Research

Cisco Advance Notification for Publication of September 2, 2026, Security Advisories

Cisco Security Advisories · indexed 2026-08-26 16:20 UTC

On September 2, 2026, the Cisco Product Security Incident Response Team (PSIRT) published the following advisories: Cisco Security Advisory CVE ID Security Impact Rating CVSS Base Score Cisco IOS XR Software Security Hardening Release: September 2026 CVE-2026-20277CVE-2026-20278CVE-2026-20280CVE-2026-20279CVE-2026-20276CVE-2026-20275CVE-2026-20274 Critical 9.8 Cisco Nexus 9000 Series Switches Silicon One Remote Code Execution Vulnerability CVE-2026-20212 Critical 9.8 Cisco Desk Phone 9800 Serie…

AppleDFIRNetwork SecurityVulnerabilitiesCVE-2026-20212CVE-2026-20281
P20
2026-09-01 14:07 UTC
Security Journalism

13 Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Wallet Seeds

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-01 14:45 UTC

Cybersecurity researchers have identified a set of 13 malicious Composer theme packages on Packagist that are designed to inject JavaScript into Vietnamese movie and comic streaming sites that install those libraries and initiate the deployment of spyware aimed at unpatched iOS devices. "The injected code runs two operations against a site's visitors: a mobile ad-fraud and gambling-redirect

AppleCybercrimeSecurity Research
P0
2026-09-01 13:08 UTC
Security Journalism

Iranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding Tests

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-01 13:20 UTC

The Iranian Nimbus Manticore hacking group has been attributed to two previously undocumented malware families that highlight the continued evolution of its toolset and likely expand its targeting footprint to infect Linux and Apple macOS systems using cross-platform remote access trojans (RATs) developed using Node.js and JavaScript. Russian cybersecurity company Kaspersky is tracking the

AppleLinuxMalware
P0
2026-08-31 09:04 UTC
Security Journalism

China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-31 10:35 UTC

A China-nexus cyber espionage actor tracked as Fire Ant has expanded a long-running campaign beyond VMware hypervisors to compromise Cisco IOS XR routers, Terminal Access Controller Access-Control System (TACACS) servers, and Linux management hosts used to route, authenticate, and manage high-value networks. Sygnia, the incident response firm that investigated the intrusion, said the actor

AppleAPT / Nation-StateDFIRLinuxNetwork Security
P0
2026-08-27 14:30 UTC
Vendor Research

How to build an exposure management program the business trusts: Lessons from Tenable’s CSO

Tenable Blog · Robert Huber · indexed 2026-08-27 14:40 UTC

Discover how Tenable’s shift to an AI-driven exposure management program helped Tenable’s CSO, Robert Huber, overcome tool sprawl, unify data silos, mitigate the risk of rapid AI adoption, and shift from presenting granular, technical metrics to communicating business risk that the C-suite and the board can understand.Key takeawaysSecurity tool sprawl and data silos make it difficult for CISOs to holistically and accurately assess their organizations’ cyber risk.An exposure management program c…

AI SecurityAppleCloud SecurityMicrosoftVulnerabilities
P0
2026-08-26 05:47 UTC
Security Journalism

Fake Apple Support AI Calls Target Stolen-Device Owners for Passcodes and 2FA Codes

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-26 07:10 UTC

Cybersecurity researchers have disclosed details of a phishing-as-a-service (PhaaS) platform built to strip Apple's Activation Lock from stolen devices, using rented AI voice agents that call theft victims posing as Apple Support and ask for their device passcode. SOCRadar Threat Research Unit (STRU) said the platform, which it tracks as AnonyMousKIT, is credit-metered and drives lures across

ApplePhishingSecurity Research
P0
1 2 3 4