IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 487 matching records.
AUTO-POLL // 2026-10-09 22:15 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P5 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 9

RANSOMWARE
P5
P5
COOL // 62 ARTICLES
THU
Oct 8

RANSOMWARE
P3
P3
COOL // 62 ARTICLES
WED
Oct 7

RANSOMWARE
P5
P5
COOL // 86 ARTICLES
TUE
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
RESET
2026-10-09 12:03 UTC
Security Journalism

In Other News: AI Used in Korean Bank Breaches, Poem-Guided Botnet, Empire Admin Gets 40 Years

Security Week · SecurityWeek News · indexed 2026-10-09 12:10 UTC

Noteworthy stories that might have slipped under the radar: Tensorlake npm SDK compromised, Empire Market co-founder gets 40 years, exposed NVIDIA GPU monitors leak telemetry. The post In Other News: AI Used in Korean Bank Breaches, Poem-Guided Botnet, Empire Admin Gets 40 Years appeared first on SecurityWeek.

Malware
P0
2026-10-08 19:20 UTC
Security Journalism

Low-cost Android phones ship with residential proxy malware

BleepingComputer · Lawrence Abrams · indexed 2026-10-08 19:25 UTC

A malware campaign dubbed 'Midnight Mimosa' has been discovered on low-cost Android smartphones that ship with malicious software embedded in their firmware, allowing attackers to silently install apps, perform ad fraud, and turn devices into residential proxies. [...]

CybercrimeMalwareMobile Security
P0
2026-10-08 15:26 UTC
Security Journalism

UAC-0099 Targets Ukrainian Government Personnel With ASHVEIN RAT Hiding Commands in HTML

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-08 15:40 UTC

The Russia-aligned threat actor known as UAC-0099 has been attributed to a previously undocumented .NET infostealer and remote access trojan (RAT) codenamed ASHVEIN. According to TrendAI, the malware has been put to use in attacks targeting Ukrainian government personnel. The cybersecurity company is tracking the cluster under the name Earth Sirrush (previously SHADOW-EARTH-065). ASHVEIN,

MalwareThreat Actors
P0
2026-10-08 12:50 UTC
Vendor Research

Inside the Exchange Inspector: How Tenable uses OpenAI GPT cyber models to review open-source AI agents

Tenable Blog · Robert McSulla · indexed 2026-10-08 13:10 UTC

Community-built AI agents, skills, and MCP servers are landing in SOC workflows fast. Here’s what the Exchange Inspector tests before a listing earns its vetted tag on the CyberAgents Exchange. Three tools have already passed.Key takeawaysEvery Inspector-vetted listing clears three gates: an automated check, a frontier model assessment, and human verification. Tenable uses Tenable One AI Exposure to screen for prompt injection and exposed secrets, and OpenAI GPT Cyber models to assess the code …

AI SecurityCloud SecurityDFIRICS / OTMalwareMicrosoftNetwork SecurityPhishingSecurity ResearchThreat IntelligenceVulnerabilities
P0
2026-10-08 05:46 UTC
Security Journalism

Tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-08 06:40 UTC

The npm package known as "tensorlake," a TypeScript software development kit (SDK) for Tensorlake applications, sandboxes, and cloud services, was compromised as part of a ChainDrop / Shai-Hulud supply chain attack. The malicious version 0.5.144 "contains obfuscated malware that harvests credentials, exfiltrates secrets, establishes persistence, and executes remotely supplied code," Socket said

Malware
P0
2026-10-07 17:43 UTC
Security Journalism

Eight Malicious npm Packages Downloaded 40,767 Times Deliver Overlord RAT and Stealer

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-07 17:55 UTC

Cybersecurity researchers have disclosed details of a long-running npm supply chain malware campaign that pushes information stealers and remote access trojans (RAT) to compromised hosts. The campaign has been codenamed MALFEX by CloudSEK and Checkmarx. The activity is assessed to be the work of a lone threat actor who appears to have published 12 packages since August 2023, eight of which have

MalwareSecurity ResearchThreat Actors
P0
2026-10-07 15:33 UTC
Security Journalism

PoeLLM Malware Infects 3,400+ Servers to Expand Crypto Mining Botnet

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-07 16:15 UTC

Cybersecurity researchers are calling attention to a new malware family that has been observed targeting exposed artificial intelligence (AI) and large language model (LLM) infrastructure with an aim to deploy cryptocurrency miners and further expand the scale of the botnet. The financially motivated campaign, dubbed Canto Incognito, has been found to install cryptocurrency miners, including

AI SecurityMalwareSecurity Research
P0
2026-10-07 13:22 UTC
Other

CERT-UA: Fake Cloudflare Checks Deliver LunexStealer Malware

Security Affairs · Pierluigi Paganini · indexed 2026-10-07 14:30 UTC

Over 100 hacked websites used fake Cloudflare checks to trick visitors into installing LunexStealer through ClickFix commands. The lure is the now-familiar ClickFix technique, dressed up as Cloudflare’s standard bot check. The fake page asks you to run a command, supposedly to confirm you’re not a bot, and that command quietly downloads and installs an […]

Malware
P0
2026-10-07 10:40 UTC
Vendor Research

The ASOS Incident: When Attackers Use the Channels Customers Trust

Rapid7 · Emma Burdett · indexed 2026-10-07 10:50 UTC

This week, ASOS customers opened their phones to find a hostile push notification delivered through the retailer’s own app. The message claimed the company’s Snowflake environment had been compromised and directed ASOS to engage with the sender through Telegram. ASOS later confirmed to Sky News that an unauthorized customer notification had been sent and said it was investigating activity involving third-party platforms used to communicate with customers. The company also said basic personal in…

CybercrimeDFIRMalwarePhishingVulnerabilities
P0
2026-10-07 06:57 UTC
Security Journalism

100+ Compromised Websites Use Fake Cloudflare Checks to Deliver LunexStealer

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-07 07:45 UTC

The Computer Emergency Response Team of Ukraine (CERT-UA) has identified more than 100 compromised websites that have been injected with malicious JavaScript to serve an information-stealing malware called LunexStealer (aka Psychedelic Stealer). The activity, which was observed by the agency in September 2026, has been attributed to a threat cluster dubbed UAC-0277. It did not disclose who the

Malware
P0
2026-10-06 21:00 UTC
Security Journalism

Ninja Forms plugin flaw exploited to hack WordPress sites

BleepingComputer · Bill Toulas · indexed 2026-10-06 21:05 UTC

Hackers are exploiting stored cross-site scripting (XSS) vulnerabilities in two unrelated WordPress plugins, Ninja Forms and WPC Product Bundles for WooCommerce, to install backdoors and create rogue admin accounts. [...]

Malware
P0
2026-10-06 18:24 UTC
Security Journalism

Linux Backdoors Impersonate Email Security Tools to Evade Detection in Korea and Taiwan

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-06 20:15 UTC

Linux backdoors targeting telecom and network appliances in South Korea and Taiwan have been disguising their traffic as email services and seemingly legitimate processes to blend in and evade detection. Threat actors are known to name their malicious software after a legitimate operating system component or a process as a defense evasion measure. By borrowing the name of a real binary, it may

LinuxMalwareThreat Actors
P0
2026-10-06 12:47 UTC
Security Journalism

FBI Arrests ‘Most Wanted’ Developer of Ploutus ATM Malware

Security Week · Ionut Arghire · indexed 2026-10-06 13:00 UTC

An alleged leader of Tren de Aragua’s ATM jackpotting activities, Canelon Aguirre was on the FBI’s top 10 most wanted list since March 2026. The post FBI Arrests ‘Most Wanted’ Developer of Ploutus ATM Malware appeared first on SecurityWeek.

Law EnforcementMalware
P0
2026-10-06 10:34 UTC
Security Journalism

Long-Running NPM Malware Campaign Accumulates 40,000 Downloads

Security Week · Ionut Arghire · indexed 2026-10-06 10:40 UTC

Since August 2023, attackers have published eight malicious packages as part of the MALFEX supply chain campaign. The post Long-Running NPM Malware Campaign Accumulates 40,000 Downloads appeared first on SecurityWeek.

Malware
P0
2026-10-06 10:00 UTC
Vendor Research

Blinder Tunnel Campaign Targets Iraqi Infrastructure

Palo Alto Networks Unit 42 · Unit 42 · indexed 2026-10-06 10:20 UTC

Analysis of Blinder Tunnel, an Iran-nexus campaign using fake Dubai Airports recruitment lures and GitHub C2 malware to target critical infrastructure. The post Blinder Tunnel Campaign Targets Iraqi Infrastructure appeared first on Unit 42.

Malware
P0
2026-10-06 08:15 UTC
Other

From Detonation to Detection: The Sandbox Now Writes the Rules

Group-IB · indexed 2026-10-06 09:25 UTC

Understanding what a malware sample does and being able to detect it are two different jobs, and the second one needs a skill many teams are short of. The Group-IB Malware Detonation Platform now produces indicators, Sigma rules, and hunting queries from the behavior it observes.

Malware
P0
2026-10-06 06:31 UTC
Other

ClingSTUN Linux Backdoor Abuses Public STUN Infrastructure

Security Affairs · Pierluigi Paganini · indexed 2026-10-06 07:10 UTC

Fortinet details ClingSTUN, a Linux backdoor exploiting unpatched IoT devices and abusing public STUN servers to route traffic past NAT. FortiGuard Labs researchers spotted a Linux malware family they call ClingSTUN, and the name gives away its trick immediately. Instead of relying on a dedicated command server, the malicious code leans on STUN, the protocol […]

LinuxMalwareNetwork Security
P0
1 2 3