IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 249 matching records.
AUTO-POLL // 2026-10-09 21:25 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P5 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 9

RANSOMWARE
P5
P5
COOL // 60 ARTICLES
THU
Oct 8

RANSOMWARE
P3
P3
COOL // 62 ARTICLES
WED
Oct 7

RANSOMWARE
P5
P5
COOL // 86 ARTICLES
TUE
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
RESET
2026-10-08 19:20 UTC
Security Journalism

Low-cost Android phones ship with residential proxy malware

BleepingComputer · Lawrence Abrams · indexed 2026-10-08 19:25 UTC

A malware campaign dubbed 'Midnight Mimosa' has been discovered on low-cost Android smartphones that ship with malicious software embedded in their firmware, allowing attackers to silently install apps, perform ad fraud, and turn devices into residential proxies. [...]

CybercrimeMalwareMobile Security
P0
2026-10-08 13:37 UTC
Other

MonsterCloud Owner Charged With Secretly Paying Ransomware Demands

Security Affairs · Pierluigi Paganini · indexed 2026-10-08 14:50 UTC

MonsterCloud owner Zohar Pinhasi allegedly paid ransomware demands behind clients’ backs, then charged them millions for the supposed recovery. Zohar Pinhasi, the owner of Florida-based MonsterCloud, was charged this week with wire fraud. Federal prosecutors say his clients were scammed twice during the same ransomware crisis. Pinhasi (50) also used the names “Zack Silver” and […]

CybercrimeRansomware
P15
2026-10-08 10:29 UTC
Security Journalism

Owner of Empire cybercrime market gets 40 years in prison

BleepingComputer · Sergiu Gatlan · indexed 2026-10-08 10:35 UTC

The co-creator of Empire Market, one of the largest dark web marketplaces before its shutdown, has been sentenced to 40 years in prison for facilitating $430 million in illegal transactions from 2018 to 2020. [...]

Cybercrime
P0
2026-10-08 07:41 UTC
Security Journalism

MonsterCloud Owner Accused of Billing Over $19M While Secretly Paying Ransoms to Decrypt Data

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-08 08:10 UTC

The U.S. Department of Justice (DoJ) on Wednesday announced charges against a 50-year-old U.S. and Israeli national for allegedly defrauding ransomware victims by secretly paying the attackers to obtain decryptors while claiming to use proprietary tools to recover their data. Zohar Pinhasi (aka Zack Silver and Zack Green) has been charged with two counts of wire fraud and one count of wire

CybercrimeLaw EnforcementRansomware
P15
2026-10-07 23:04 UTC
Security Journalism

Ransomware recovery CEO charged over secret ransom payments

BleepingComputer · Lawrence Abrams · indexed 2026-10-07 23:15 UTC

The owner of ransomware remediation company MonsterCloud has been charged with allegedly defrauding ransomware victims by secretly paying their attackers for decryptors while claiming to use proprietary technology to recover encrypted data. [...]

CybercrimeRansomware
P15
2026-10-07 10:40 UTC
Vendor Research

The ASOS Incident: When Attackers Use the Channels Customers Trust

Rapid7 · Emma Burdett · indexed 2026-10-07 10:50 UTC

This week, ASOS customers opened their phones to find a hostile push notification delivered through the retailer’s own app. The message claimed the company’s Snowflake environment had been compromised and directed ASOS to engage with the sender through Telegram. ASOS later confirmed to Sky News that an unauthorized customer notification had been sent and said it was investigating activity involving third-party platforms used to communicate with customers. The company also said basic personal in…

CybercrimeDFIRMalwarePhishingVulnerabilities
P0
2026-10-02 13:00 UTC
Vendor Research

Follow the thread: a new dashboard to investigate account abuse

Cloudflare Security · Nicole Justus · indexed 2026-10-02 13:30 UTC

Fraudsters are increasingly using AI to bypass stateless security checks. Cloudflare's new Account Abuse Protection dashboard uses stateful analysis and edge-generated Hashed User IDs to help teams investigate and block account abuse.

Cybercrime
P0
2026-10-02 08:01 UTC
Security Journalism

Android 17 Advanced Protection Locks Accessibility Services to Verified Accessibility Tools

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-02 08:20 UTC

Google has announced a new security measure that limits access to Android's accessibility services to verified applications classified as Accessibility Tools when Advanced Protection is enabled. With malicious Android applications abusing the API serving as the main conduit for malware and financial fraud, the tech giant said the move would block a major attack pathway. Advanced Protection is a

CybercrimeMalwareMobile Security
P0
2026-10-01 18:08 UTC
Other

Operation KillSwitch: Police Dismantle KillSec Ransomware Group

Security Affairs · Pierluigi Paganini · indexed 2026-10-01 19:00 UTC

Operation KillSwitch: Europol says the KillSec ransomware group, allegedly led by a 16-year-old, was dismantled after attacks on about 1,000 victims. Law enforcement seized control of KillSec ‘s dark web leak site, the Tor website the group used to threaten victims with publishing stolen files unless they paid up. That single action locked down more […]

CybercrimeLaw EnforcementNetwork SecurityRansomware
P15
2026-09-30 10:45 UTC
Security Journalism

US-Focused CSuite Phishing Steals Microsoft 365 Sessions and Deploys RMM Tools for Remote Access

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-30 11:45 UTC

ANY.RUN researchers traced a US-focused CSuite phishing campaign across 351 sandbox analyses, with 51% of submissions coming from the United States. Technology, manufacturing, government, and consulting organizations showed the highest exposure. By combining Microsoft 365 session theft with remote-access tool deployment, CSuite can turn a phishing incident into broader account compromise, fraud

CybercrimeMicrosoftPhishing
P0
2026-09-29 08:32 UTC
Vendor Research

Major Cyber Attacks in September 2026: US and EU Face Session Theft, Remote Access, and Payment Fraud

ANY.RUN Blog · ANY.RUN · indexed 2026-10-06 14:56 UTC

Cyberattacks observed in September showed how difficult it has become to separate malicious activity from legitimate business workflows. Attackers used trusted cloud services, familiar document-sharing platforms, legitimate authentication flows, remote-management software, and rapidly changing infrastructure to hide different stages of their operations. For SOC teams, this creates a visibility problem: one alert rarely shows the […] The post Major Cyber Attacks in September 2026: US and EU Face…

Cybercrime
P0
2026-09-29 07:30 UTC
Other

24-Year-Old Arrested in Dutch Investigation Into ShinyHunters

Security Affairs · Pierluigi Paganini · indexed 2026-09-29 08:10 UTC

Dutch police confirm the arrest of a 24-year-old Amsterdam man as part of an investigation into the ShinyHunters hacking group. Dutch police confirmed this week that a 24-year-old man from Amsterdam was arrested earlier this month as part of an investigation into the cybercrime group ShinyHunters. The suspect appears before Rotterdam District Court today, September […]

CybercrimeDFIRLaw Enforcement
P0
2026-09-28 17:42 UTC
Security Journalism

Bitget Says Attacker Exploited Third-Party Security Product Flaw to Steal $388M

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-28 18:40 UTC

The attacker who stole about $388 million from the cryptocurrency exchange Bitget gained access through a vulnerability in a third-party security product the exchange used, Bitget said on Monday. The attacker exploited the flaw to obtain high-level internal credentials and then, on September 24, used them to send fraudulent withdrawal commands to Bitget's wallet system. Exchanges keep most

CybercrimeMicrosoftVulnerabilities
P0
2026-09-27 09:27 UTC
Other

Rydox Admin Faces 20 Years After Selling Stolen Data and Fraud Tools

Security Affairs · Pierluigi Paganini · indexed 2026-09-27 09:40 UTC

Kosovo national Ardit Kutleshi pleaded guilty to running Rydox, a cybercrime marketplace that sold stolen identities and credentials for years. Ardit Kutleshi, 28 years old and a citizen of Kosovo, pleaded guilty last week to building and running the cybercrime marketplace Rydox. The Rydox marketplace has been active since February 2016; it facilitated over 7,600 […]

CybercrimeData Breaches
P0
2026-09-26 14:34 UTC
Other

Exploit.in Database Reveals the Roots of Today’s Ransomware Ecosystem

Security Affairs · Pierluigi Paganini · indexed 2026-09-26 15:40 UTC

Exploit.in data shows how a 2005 cybercrime forum helped shape today’s ransomware ecosystem, with users and practices surviving for decades. Ransomnews researcher Dancho Danchev dug up a database dump of Exploit.in covering its first three years, from February 2005 to May 2008, and the numbers inside it tell a story about Russian cybercrime that enforcement […]

CybercrimeRansomware
P15
2026-09-25 12:16 UTC
Security Journalism

Kosovar Owner of Rydox Marketplace Pleads Guilty in US Court

Security Week · Ionut Arghire · indexed 2026-09-25 12:20 UTC

Ardit Kutleshi created and operated Rydox, which allowed miscreants to trade PII and cybercrime tools and services. The post Kosovar Owner of Rydox Marketplace Pleads Guilty in US Court appeared first on SecurityWeek.

Cybercrime
P0
2026-09-25 11:35 UTC
Security Journalism

Rydox marketplace admin pleads guilty, faces 22 years in prison

BleepingComputer · Sergiu Gatlan · indexed 2026-09-25 11:50 UTC

A Kosovar national has pleaded guilty to operating Rydox, a large illegal online marketplace that sold stolen personal information, login credentials, credit card details, and cybercrime tools. [...]

Cybercrime
P0
2026-09-24 13:00 UTC
Vendor Research

When Business Email Compromise Starts Rewriting Reality

Rapid7 · Douglas McKee, Director, Vulnerability Intelligence · indexed 2026-09-24 13:20 UTC

Business Email Compromise (BEC) operates on a familiar playbook. Threat actors breach a mailbox, silently monitor operations, map approval chains, and ultimately exploit that access to divert funds or exfiltrate sensitive assets.This dynamic is central to our analysis as we kick off a series around Rapid7's collaborative research with Zimbra; upcoming installments will explore technical details and broader findings based within the Zimbra Collaboration Suite. Our investigation disrupted the tra…

CybercrimeDFIRMicrosoftPhishingThreat ActorsVulnerabilitiesCVE-2022-27925CVE-2022-37042CVE-2023-37580CVE-2024-45519CVE-2025-27915CVE-2026-73570
P70
1 2 3