IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 249 matching records.
AUTO-POLL // 2026-10-09 22:15 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P5 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 9

RANSOMWARE
P5
P5
COOL // 62 ARTICLES
THU
Oct 8

RANSOMWARE
P3
P3
COOL // 62 ARTICLES
WED
Oct 7

RANSOMWARE
P5
P5
COOL // 86 ARTICLES
TUE
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
RESET
2026-09-03 13:17 UTC
Other

412,000 The Town 2025 Ticket Buyers’ Data Hits the Dark Web

Security Affairs · Pierluigi Paganini · indexed 2026-09-03 14:00 UTC

412,000 The Town 2025 festival buyer records are being sold for $10,000, with Brazil’s data openly marketed for bank fraud, loans and SIM registration. A seller on a Russian-language data-trading forum listed what they’re calling a Ticketmaster database on September 2, claiming over 412,000 Latin American purchase records with a heavy concentration of Brazilian data. […]

CybercrimeMicrosoft
P0
2026-09-02 13:44 UTC
Security Journalism

Malicious Apache Modules Hijack Brazilian Government Site Traffic to Push Betting Pages

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-02 14:15 UTC

A Chinese-speaking cybercrime cluster known as Gambling Goblin has been observed installing malicious Apache modules on compromised web servers run by Brazilian government and educational institutions, and using them to divert visitors to attacker-controlled pages promoting online gambling and sports betting. Check Point Research said it has tracked the campaign since mid-2025. The modules

Cybercrime
P0
2026-09-02 10:16 UTC
Other

Gaming the system: how a Chinese-speaking actor turned Brazilian government sites into an SEO weapon

Check Point Research · stcpresearch · indexed 2026-09-07 17:30 UTC

Research by: Amit Yardeni Key Points Introduction Since mid-2025, Check Point Research has tracked a sustained campaign against Brazilian organizations. The tradecraft points to a Chinese-speaking cybercrime group connected to Earth Berberoka, an actor first documented targeting gambling sites across Asia. Once inside a victim, the group deploys a broad Linux toolkit: a custom downloader, several backdoors, […] The post Gaming the system: how a Chinese-speaking actor turned Brazilian government…

CybercrimeLinuxMalware
P0
2026-09-01 22:40 UTC
Independent Research

FBI Probes Service Selling 153M+ Drivers Licenses

Krebs on Security · BrianKrebs · indexed 2026-09-01 23:05 UTC

A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada. Based on interviews with individuals whose licenses are available for purchase on this service, it appears to be siphoning images collected by a widely-used identity verification company based in Louisiana. KrebsOnSecurity also has learned that the New Orleans field office of the Federal Bureau of Investigation (FBI) toda…

CybercrimeDFIRLaw Enforcement
P0
2026-09-01 17:19 UTC
Security Journalism

Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-01 18:15 UTC

Brazilian financial services, retail, and e-commerce organizations have become the target of a financially motivated threat actor dubbed Breeze Comet (formerly UNC5669) since 2024. Google Threat Intelligence Group (GTIG) and Mandiant teams described the threat actor as "specializing in manipulating payment systems and banking software in Brazil to conduct fraudulent transfers." The adversary

CybercrimeThreat ActorsThreat Intelligence
P0
2026-09-01 14:07 UTC
Security Journalism

13 Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Wallet Seeds

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-01 14:45 UTC

Cybersecurity researchers have identified a set of 13 malicious Composer theme packages on Packagist that are designed to inject JavaScript into Vietnamese movie and comic streaming sites that install those libraries and initiate the deployment of spyware aimed at unpatched iOS devices. "The injected code runs two operations against a site's visitors: a mobile ad-fraud and gambling-redirect

AppleCybercrimeSecurity Research
P0
2026-09-01 14:00 UTC
Vendor Research

Financially Motivated Threat Actor BREEZE COMET Targets Brazil

Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-09-01 03:50 UTC

Introduction Beginning in 2024 Mandiant investigated a string of compromises affecting Brazilian financial services, retail, and eCommerce organizations. Google Threat Intelligence Group (GTIG) tracks this activity as BREEZE COMET (formerly UNC5669), a financially motivated threat actor specializing in manipulating payment systems and banking software in Brazil to conduct fraudulent transfers. This activity overlaps with operations publicly reported as Plump Spider and SHADOW-AETHER-064. In thi…

AI SecurityCloud SecurityCybercrimeMalwareMicrosoftNetwork SecurityPhishingThreat ActorsThreat Intelligence
P0
2026-08-31 17:24 UTC
Security Journalism

North Korean Job Fraud Expands Beyond IT Into Healthcare and Sales

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-31 18:05 UTC

Threat actors with ties to the Democratic People's Republic of Korea (aka DPRK or North Korea) have been observed seeking job opportunities beyond the information technology (IT) sector, with recent investigations identifying suspected workers employed in sales and marketing and the medical profession. The ongoing insider threat is part of what has been described as the IT worker scheme,

CybercrimeDFIRThreat Actors
P0
2026-08-31 11:47 UTC
Security Journalism

Aurora Ransomware Operators Use Cursor AI in Attacks Against 10 Targets

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-31 12:30 UTC

Threat actors associated with Aurora (aka Aur0ra) ransomware have been observed using SpaceX's artificial intelligence (AI)-powered coding assistant Cursor to break into target networks, according to findings from CloudSEK and Gambit Security. The two independent analyses are based on exposed infrastructure associated with the Russian-speaking cybercrime group, leading to the discovery of its

AI SecurityCybercrimeRansomwareThreat Actors
P15
2026-08-27 14:09 UTC
Other

Australian Police Charge Two Over TeamPCP Credential Theft

Security Affairs · Pierluigi Paganini · indexed 2026-08-27 14:25 UTC

Australian police charged two men linked to TeamPCP over malware hidden in open-source code that stole 500,000+ credentials from 1,000+ organizations. Australian police have charged two men from Western Australia over a global cybercrime operation that allegedly hid malicious code in open-source software and used it to steal data from thousands of organisations. “Two West […]

CybercrimeMalwarePhishing
P0
2026-08-27 13:51 UTC
Vendor Research

Identity-as-a-Service: Uncovering Dark Web Marketplaces Trading Executive SSNs

Rapid7 · Alexandra Blia · indexed 2026-08-27 14:25 UTC

IntroductionDespite modern verification controls, identity theft remains one of the most pervasive threats to both individuals and enterprise organizations. U.S. Federal Trade Commission statistics show over 1 million identity theft reports annually, with related fraud and imposter scams accounting for billions in financial losses each year. While stolen credit cards enable rapid, short-term monetization, Social Security numbers (SSNs) represent a far more permanent and dangerous tier within th…

APT / Nation-StateCybercrimeData BreachesMalwareMicrosoftPhishingThreat Actors
P0
2026-08-27 11:56 UTC
Security Journalism

Alleged TeamPCP Hackers Charged in Australia Over Major Supply Chain Attacks

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-27 12:55 UTC

The Australian Federal Police (AFP) has charged two Western Australian men with a combined total of 14 offences over their alleged role in TeamPCP, the cybercrime group behind the March 2026 compromise of the open-source security scanners Trivy and Checkmarx KICS and the AI gateway LiteLLM. Louis Michael Gaebler, 23, and Ruben Ian Thomson, 21, appeared in Perth Magistrates Court on August 27,

Cybercrime
P0
2026-08-27 11:17 UTC
Other

One Adversary, Two Outcomes: The 0.027% Proof

Group-IB · indexed 2026-09-07 17:30 UTC

One malware campaign, 11,000 compromised devices, two banks with very different outcomes. At the bank with fused defence, fraud succeeded on just 0.027% of compromised devices; nine times less than the market average. Regulators are taking notice too.

CybercrimeMalware
P0
2026-08-27 11:04 UTC
Independent Research

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia

Krebs on Security · BrianKrebs · indexed 2026-08-27 11:20 UTC

Authorities in Australia have arrested two men believed to be members of TeamPCP, a prolific cybercrime and data extortion group blamed for perpetrating the longest running spree of software supply chain attacks ever. In a statement released today, the Australian Federal Police (AFP) said two unnamed suspects from Western Australia, aged 21 and 23, were arrested in connection with a "sophisticated cybercrime syndicate that allegedly created malicious open-source software to rob thousands of glo…

CybercrimeLaw Enforcement
P0
2026-08-26 07:54 UTC
Security Journalism

INTERPOL Operation Jackal IV Arrests 58, Identifies 263 in Global Cyber Fraud Crackdown

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-26 08:50 UTC

An eight-month INTERPOL operation targeting West African organized crime groups has led to arrests of 58 people and the identification of 263 suspects. "The operation, which brought together 22 countries from six continents, is a response to the escalating global threat posed by West African criminal networks – such as the Black Axe and other similar groups," INTERPOL said. "These groups are

CybercrimeLaw Enforcement
P0
2026-08-26 07:17 UTC
Other

Operation Jackal: 58 Arrests Expose the Money Laundering Machine Behind Global Scams

Security Affairs · Pierluigi Paganini · indexed 2026-08-26 07:40 UTC

INTERPOL’s Operation Jackal IV made 58 arrests and exposed global networks laundering money from scams, fraud and sextortion. INTERPOL announced that Operation Jackal IV, running from November 2025 to June 2026, led to 58 arrests and identified 263 suspects tied to West African organized crime networks, groups like Black Axe that are responsible for a […]

CybercrimeLaw Enforcement
P0
2026-08-25 20:33 UTC
Security Journalism

58 arrested in international cybercrime crackdown

The Record · indexed 2026-08-25 20:50 UTC

Interpol officials said it uncovered a crime-as-a-service network in Argentina run by 196 people that provided website domains and money laundering support to West African organized crime groups like Black Axe.

CybercrimeLaw Enforcement
P0
2026-08-24 08:08 UTC
Security Journalism

UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-24 08:45 UTC

Cybersecurity researchers have disclosed details of a Chinese-speaking cybercrime group dubbed UAT-10147 that's targeting Windows and Linux web servers globally across the education, media, technology, and gaming sectors. The vast majority of the targets are located in Brazil, Bolivia, China, Canada, and Vietnam. Details of the threat activity came to light following the discovery of an open

CybercrimeLinuxMalwareMicrosoftSecurity Research
P0
2026-08-24 07:17 UTC
Other

iAuthFlow v2: The $10,000 Phishing Toolkit That Survives Your Password Reset

Security Affairs · Pierluigi Paganini · indexed 2026-08-24 07:35 UTC

iAuthFlow v2 phishing toolkit uses a phished Google session to enroll an attacker-controlled passkey that survives password resets. Abnormal Security researchers have published an analysis of iAuthFlow v2, a phishing toolkit sold on a Russian-language cybercrime forum for $10,000 base price. The author also offers for sale additional capability modules separately. The headline feature is […]

CybercrimePhishingSecurity Research
P0
2026-08-21 15:41 UTC
Security Journalism

Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-21 16:40 UTC

Cybersecurity researchers have flagged a new malware family that's specifically designed to infect Android-based vehicle head unit firmware developed by DoFun. Kaspersky, which discovered the threat in June 2026, said the end goal of the malware is to serve a multi-stage downloader to enable ad fraud and creation of a proxy botnet. "The malware spread through the built-in updaters of

CybercrimeMalwareMobile SecuritySecurity Research
P0
2026-08-20 18:03 UTC
Other

Manic: The Android Malware That Exfiltrates Data Even When the Phone Is Offline

Security Affairs · Pierluigi Paganini · indexed 2026-08-20 18:35 UTC

Manic Android malware combines banking fraud and spyware, using a Bluetooth relay to steal data even when devices are offline. ThreatFabric’s Mobile Threat Intelligence team has identified a new Android malware, dubbed Manic, which has been active in the wild since at least February 2026. The researchers state that the malware is still under development […]

CybercrimeMalwareMobile SecurityThreat Intelligence
P20
1 2 3 4 5