IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 165 matching records.
AUTO-POLL // 2026-10-09 22:50 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P5 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 9

RANSOMWARE
P5
P5
COOL // 62 ARTICLES
THU
Oct 8

RANSOMWARE
P3
P3
COOL // 62 ARTICLES
WED
Oct 7

RANSOMWARE
P5
P5
COOL // 86 ARTICLES
TUE
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
RESET
2026-05-06 16:00 UTC
Vendor Research

Cisco SG350 and SG350X Series Managed Switches SNMP Denial of Service Vulnerability

Cisco Security Advisories · indexed 2026-08-15 14:33 UTC

A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco 350 Series Managed Switches (SG350) and Cisco 350X Series Stackable Managed Switches (SG350X) firmware could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper error handling when parsing response data for a specific SNMP request. An attacker could exploit this vulnerability by sending a specific SNMP request to an aff…

DFIRNetwork SecurityVulnerabilitiesCVE-2026-20185
P5
2026-04-17 14:00 UTC
Security Journalism

Untangling a Linux Incident With an OpenAI Twist

Huntress · indexed 2026-09-07 17:30 UTC

A Linux user recently tried to respond to potentially malicious behavior on their machine using OpenAI’s Codex coding agent, before installing the Huntress agent. What ensued shows the unexpected impacts of this AI use case on DFIR investigations.

DFIRLinux
P0
2026-04-16 14:00 UTC
Vendor Research

Defending Your Enterprise When AI Models Can Find Vulnerabilities Faster Than Ever

Google Threat Intelligence / Mandiant · Francis deSouza · indexed 2026-08-15 18:55 UTC

Introduction Advances in AI model-powered exploitation have demonstrated that general-purpose AI models can excel at vulnerability discovery, even without being purpose-built for the task. Eventually, capabilities such as these will be integrated directly into the development cycle, and code will be more difficult to exploit than ever; however, this transition creates a critical window of risk. As we harden existing software with AI, threat actors will use it to discover and exploit novel vulne…

AI SecurityAPT / Nation-StateCloud SecurityDFIRMicrosoftRansomwareThreat ActorsVulnerabilities
P60
2026-03-23 18:03 UTC
Government

2026-003: Multiple Vulnerabilities in Citrix NetScaler and Citrix ADC

CERT-EU Security Advisories · indexed 2026-08-15 18:50 UTC

On 23 March 2026, Citrix published a security advisory addressing multiple vulnerabilities affecting NetScaler ADC and NetScaler Gateway. These vulnerabilities may lead to sensitive information disclosure and user session mix-up under specific configurations. At the time of writing, there is no public evidence of active exploitation. It is strongly recommended updating affected gateways, prioritising internet-facing assets. It is also recommended to preserve evidence for further investigation.

DFIR
P0
2026-03-18 07:04 UTC
Other

AI Exposure and CTEM: The Next Frontier of External Risk

Red Hunt Labs · Sudhanshu Chauhan · indexed 2026-09-07 17:30 UTC

Prepared by: Sudhanshu Chauhan 🔗 (Director, RedHunt Labs) and Devang Solanki 🔗 (Security Researcher, RedHunt Labs) There is a loop in cybersecurity. A new technology enters the enterprise. Adoption moves faster than governance. Security teams hear about it during incident response instead of during planning. And the exposure window, that gap between deployment and visibility, gets exploited before anyone realizes it even existed. We saw it with open cloud storage buckets. We saw it with expos…

AI SecurityCloud SecurityDFIRSecurity ResearchVulnerabilities
P15
2026-01-15 15:00 UTC
Security Journalism

SDFlags | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

While investigating LDAP filters and attributes, I completely missed "SDFlags" in my Event 1644 logs. When I finally noticed it, the investigation led to nTSecurityDescriptor, attack path discovery, and a high-confidence detection signature.

DFIR
P0
2026-01-13 06:39 UTC
Other

PCI DSS v4.0.1 for Payment Integrations: A Realistic Security-First Approach

Red Hunt Labs · Lohit · indexed 2026-09-07 17:30 UTC

Modern payment integrations are fast, flexible, and increasingly complex. APIs talk to gateways, webhooks trigger state changes, third parties handle fraud, retries, refunds, and orchestration layers quietly sit in between. In most teams, the signal that things are “working” is simple: transactions go through. That signal is misleading. At RedHunt Labs, we found that the real-world payment pentests reveal the common mistake of treating PCI DSS as a finish line instead of a baseline. This blog r…

AppleCybercrimeDFIR
P0
2025-12-22 11:40 UTC
Other

Explore Payment Gateways Through an Attacker’s Lens | Inside the Payment Gateway Integrations Security Handbook

Red Hunt Labs · Lohit · indexed 2026-09-07 17:30 UTC

Payment gateways are built to move money reliably. Attackers view them as systems built on trust, timing, and assumptions. A gateway that works consistently is not a sign of safety. It is a stable environment to study, probe, and eventually abuse. This blog examines payment gateways from an attacker’s perspective, grounded in real exploitation patterns and reinforced with direct insights from industry experts. These patterns are documented extensively in the RedHunt Labs Payment Gateway Integra…

AppleCloud SecurityCybercrimeDFIR
P0
2025-12-09 17:00 UTC
Vendor Research

Further Hardening Android GPUs

Google Online Security Blog · Edward Fernandez · indexed 2026-08-15 14:33 UTC

Posted by Liz Prucka, Hamzeh Zawawy, Rishika Hooda, Android Security and Privacy Team Last year, Google's Android Red Team partnered with Arm to conduct an in-depth security analysis of the Mali GPU, a component used in billions of Android devices worldwide. This collaboration was a significant step in proactively identifying and fixing vulnerabilities in the GPU software and firmware stack. While finding and fixing individual bugs is crucial, and progress continues on eliminating them entirely…

Cloud SecurityDFIRLinuxMobile SecurityThreat Intelligence
P0
2025-11-24 16:27 UTC
Other

Sha1-Hulud: The Second Coming – GitHub Patterns Exposes a Deeper NPM Attack

Red Hunt Labs · redhuntAdmin · indexed 2026-09-07 17:30 UTC

On 24th Nov 2025, our Internet-scale monitoring systems detected a sharp and anomalous spike in newly indexed Git commits matching highly uniform characteristics. The volume of commits containing the message “Add file” surged from a baseline average of approximately 200/day to more than 13,000 within a single hour. This deviation breached automated anomaly-detection thresholds and initiated an urgent investigation. Subsequent analysis confirmed the emergence of a new variant of the Shai-Hulud N…

DFIR
P0
2025-11-20 15:00 UTC
Security Journalism

Velociraptor WSUS Exploitation, Pt. I: WSUS-Up?

Huntress · indexed 2026-09-07 17:30 UTC

Huntress has seen an uptick in threat actors abusing the Velociraptor open-source DFIR tool in a range of attacks, including a recent incident involving WSUS exploitation.

DFIRThreat Actors
P0
2025-10-28 09:06 UTC
Other

The Illusion of Wealth: Inside the Engineered Reality of Investment Scam Platforms

Group-IB · indexed 2026-09-07 17:30 UTC

This blog details online investment scam campaigns, including fraudulent cryptocurrency, forex, and trading platforms, while offering a technical investigation guide for investigators, based on Group-IB’s technical investigation methodology. It outlines the social engineering tactics and victim manipulation models employed, describes the fraud actor structures behind these schemes, and highlights key infrastructure artifacts identified by Group-IB High-Tech Investigations analysts that can be l…

CybercrimeDFIR
P0
2025-10-21 05:00 UTC
Security Journalism

Dealing with Imperfect Telemetry

Huntress · indexed 2026-09-07 17:30 UTC

See how the Huntress Tactical Response team tackles security telemetry gaps. We share real-world techniques for working with missing logs, degraded telemetry, and cloud logging challenges to uncover critical insights and improve investigations.

DFIR
P0
2025-09-29 05:58 UTC
Other

E-commerce Fraud-as-a-Service: How Scammers Exploit Brand Trust at Scale

Red Hunt Labs · Hariharan M · indexed 2026-09-07 17:30 UTC

In the rapidly evolving digital marketplace, e-commerce brands have become prime targets for cybercriminals. Beyond traditional data breaches, these brands now face sophisticated scams that exploit their reputation, deceive consumers, and erode trust. Drawing from investigations conducted by RedHunt Labs’ threat intelligence team, this blog delves into some of the most prevalent scams targeting e-commerce platforms and highlights how a Digital Risk Protection (DRP) solution can help fortify you…

CybercrimeData BreachesDFIRPhishingThreat ActorsThreat Intelligence
P0
2025-09-22 05:00 UTC
Security Journalism

How EDR Telemetry Powers Managed Investigations

Huntress · indexed 2026-09-07 17:30 UTC

Learn more about what it actually means to go up against hackers–and why creative, human-led investigations are essential for keeping your organization safe from modern threats.

DFIR
P0
2025-05-06 05:00 UTC
Security Journalism

Do Tigers Really Change Their Stripes?

Huntress · indexed 2026-09-07 17:30 UTC

Across the larger cybersecurity community, an often-used adage is that “threat actors always change their tactics.” However, when we really start to look at and track incident data, we begin to see that while some changes may be necessitated based on infrastructures and other challenges the threat actor may encounter, there are times when tactics remain consistent across incidents. Recent investigations into exploitation activity for CVE-2025-31151 and CVE-2025-30406 show similar TTPs across di…

DFIRThreat ActorsThreat IntelligenceVulnerabilitiesCVE-2025-30406CVE-2025-31151
P5
2025-03-20 09:09 UTC
Other

The Cybercriminal with Four Faces: Revealing Group-IB’s Investigation into ALTDOS, DESORDEN, GHOSTR and 0mid16B

Group-IB · indexed 2026-09-07 17:30 UTC

Following the arrest of the cybercriminal behind the aliases ALTDOS, DESORDEN, GHOSTR, and 0mid16B, Group-IB provides a deep dive into his activities, uncovering striking similarities and unmasking the cybercriminal that breached more than 90 instances of data leaks worldwide over the span of four years in operation.

Data BreachesDFIR
P0
2024-06-17 00:00 UTC
Other

GCP HMAC Keys are not discoverable or revokable other than for self

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

GCP administrators face challenges in managing HMAC keys within their organizations, lacking visibility into which user accounts have generated these keys and whether they are actively being used to access storage objects. Additionally, there's a lack of functionality to revoke keys associated with other users, restricting their ability to enforce security policies effectively. Similarly, GCP incident response teams rely on Cloud Logging to monitor Cloud Storage object access, but they lack spe…

DFIR
P0
2024-02-29 00:00 UTC
Security Journalism

Attacking MSSQL Servers, Pt. II | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

The publication of the first blog post led a Huntress SOC analyst to identify and escalate a second, similar incident. A deeper investigation into the activity made it clear that the Huntress SOC had obviated several Trigona ransomware attacks, protecting customers from the impact of a ransomware infection.

DFIRRansomware
P15
3 4 5 6