IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 487 matching records.
AUTO-POLL // 2026-10-09 22:15 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P5 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 9

RANSOMWARE
P5
P5
COOL // 62 ARTICLES
THU
Oct 8

RANSOMWARE
P3
P3
COOL // 62 ARTICLES
WED
Oct 7

RANSOMWARE
P5
P5
COOL // 86 ARTICLES
TUE
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
RESET
2026-10-05 11:46 UTC
Security Journalism

Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-05 13:20 UTC

Threat actors have been observed attempting to exploit a now-patched critical security flaw impacting the Realtek Jungle software development kit (SDK) to deploy a botnet malware called Cling. "Cling is notable not because it introduces a new propagation technique, but because it repurposes ordinary STUN behavior into a practical command-and-control channel," Nozomi Networks said in a report

MalwareThreat Actors
P0
2026-10-04 14:00 UTC
Other

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 117

Security Affairs · Pierluigi Paganini · indexed 2026-10-04 14:35 UTC

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Lunex Unmasked: A New Information Stealer Deployed Through BYOVD Storm-3168: Agentic-driven cloud attacks using compromised service principals Don’t Call Us, We’ll Call Your APIs | TraderTraitor Backdoors Resurface on Victim With No Crypto Ties […]

Malware
P0
2026-10-04 07:58 UTC
Other

Security Affairs newsletter Round 598 by Pierluigi Paganini – INTERNATIONAL EDITION

Security Affairs · Pierluigi Paganini · indexed 2026-10-04 09:00 UTC

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. Fake Zoom installer hides macOS backdoor CloudSyncD CVE-2026-90970: Critical GitLab AI Gateway Flaw Fixed Antino Backdoor Lets […]

AppleMalwareVulnerabilitiesCVE-2026-90970
P5
2026-10-03 15:11 UTC
Other

Fake Zoom installer hides macOS backdoor CloudSyncD

Security Affairs · Pierluigi Paganini · indexed 2026-10-03 15:30 UTC

Jamf Threat Labs details CloudSyncD, a fake macOS Zoom installer that hides a phished password using invisible zero-width Unicode characters. Jamf Threat Labs found CloudSyncD while doing routine scanning on VirusTotal, buried inside a disguised Zoom client. They first spotted it on September 15, clearly still under construction, and within two days watched it move […]

AppleMalwarePhishing
P0
2026-10-03 09:26 UTC
Other

Antino Backdoor Lets China-Linked UAT-11587 Turn Microsoft 365 Into a C2 Channel

Security Affairs · Pierluigi Paganini · indexed 2026-10-03 10:00 UTC

Cisco Talos details UAT-11587, a China-linked group using the Antino backdoor and Microsoft 365 as cover to spy on Asian governments. Cisco Talos has been tracking a cluster of espionage activity since September 2025 that it calls UAT-11587, and by July 2026 the group had hit at least 16 government and policy organizations across eight […]

APT / Nation-StateMalwareMicrosoft
P0
2026-10-02 17:33 UTC
Security Journalism

Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-02 17:45 UTC

Government and policy organizations across Asia have become the target of a new campaign orchestrated by a China-nexus threat actor. The activity, which has targeted government and policy organizations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, and Myanmar, involves the deployment of a previously undocumented backdoor codenamed Antino. Cisco Talos is tracking the cluster

APT / Nation-StateMalwareThreat Actors
P0
2026-10-02 13:15 UTC
Security Journalism

macOS Users Targeted by Fake Zoom Installer Carrying CloudSyncD Backdoor

Security Week · Kevin Townsend · indexed 2026-10-02 13:30 UTC

The dropper “carries a complete universal Mach-O inside itself, roughly 756 KB in the development build, and extracts it at runtime. The post macOS Users Targeted by Fake Zoom Installer Carrying CloudSyncD Backdoor appeared first on SecurityWeek.

AppleMalware
P0
2026-10-02 13:00 UTC
Vendor Research

SMTP is the key: BPFDoor and AVERAT hitting the network edge

Rapid7 · Rapid7 Intelligence · indexed 2026-10-02 13:30 UTC

OverviewRapid7 tracked a set of Linux samples that blend into the software and device conventions of the telecom environments they target. The set spans a newly observed BPFDoor variant, a BPF Rekoobe build seen against South Korean targets, a dropper, and six builds of a Linux implant we track as AVERAT, deployed against Taiwanese appliances. Additionally, we provide source code details of the Rapid7 BPFDoor controller introduced in our April 2026 blog, Stealthy BPFDoor Variants are a Needle T…

LinuxMalwareNetwork Security
P0
2026-10-02 08:01 UTC
Security Journalism

Android 17 Advanced Protection Locks Accessibility Services to Verified Accessibility Tools

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-02 08:20 UTC

Google has announced a new security measure that limits access to Android's accessibility services to verified applications classified as Accessibility Tools when Advanced Protection is enabled. With malicious Android applications abusing the API serving as the main conduit for malware and financial fraud, the tech giant said the move would block a major attack pathway. Advanced Protection is a

CybercrimeMalwareMobile Security
P0
2026-10-01 14:37 UTC
Security Journalism

WordPress Backdoor Rebuilds Itself After Cleanup Using Files, Database, and Shared Memory

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-01 14:50 UTC

Cybersecurity researchers have shed light on a WordPress compromise in which threat actors deployed multiple persistence mechanisms to ensure that the final payload kept returning without having to infect the site again. The backdoor has been codenamed SC after the "SC_" markers present in the injected content. Sucuri has described the malware as a "self-healing mesh" that's

MalwareSecurity ResearchThreat Actors
P0
2026-10-01 13:13 UTC
Vendor Research

Threat Coverage Digest: New Malware Reports and 1,100+ Detection Rules

ANY.RUN Blog · ANY.RUN · indexed 2026-10-06 14:56 UTC

September saw an expansion of detection coverage across network, file, and behavioral activity, providing analysts with additional visibility into suspicious activity. ANY.RUN added 76 behavior signatures, 16 YARA detections, and 1,098 Suricata rules, strengthening coverage across malware activity, suspicious files, and network communications. These updates provide SOC and MSSP teams with additional evidence during investigations, […] The post Threat Coverage Digest: New Malware Reports and 1,1…

DFIRMalware
P0
2026-10-01 10:51 UTC
Security Journalism

Treasury Blacklists Most-Wanted ATM Malware Developer and His Network

Security Week · Eduard Kovacs · indexed 2026-10-01 11:00 UTC

The US government continues its crackdown on Tren de Aragua over its ATM jackpotting scheme. The post Treasury Blacklists Most-Wanted ATM Malware Developer and His Network appeared first on SecurityWeek.

Malware
P0
2026-09-30 22:35 UTC
Security Journalism

US sanctions 10 over ATM malware scheme tied to Tren de Aragua

The Record · indexed 2026-09-30 22:55 UTC

Treasury’s Office of Foreign Assets Control (OFAC) targeted multiple Venezuelan nationals and several companies they control that are part of the effort to launder the money stolen from dozens of ATMs.

Malware
P0
2026-09-30 15:00 UTC
Security Journalism

Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix Lures

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-30 15:30 UTC

Threat actors are abusing ChatGPT Custom GPTs to disguise them as legitimate product offerings and direct unsuspecting victims to malicious sites that employ ClickFix lures to deliver malware. Huntress, which observed the activity in late September 2026, said it marks the abuse of yet another feature in trusted artificial intelligence (AI) platforms. Prior campaigns have weaponized shared

AI SecurityMalwareThreat Actors
P0
2026-09-30 14:16 UTC
Vendor Research

Higher education is under siege, and fragmented security is making it harder to respond

Rapid7 · Rapid7 · indexed 2026-09-30 15:05 UTC

Higher education faces a difficult security equation. Universities hold large volumes of sensitive student, financial, health, and research data while supporting open networks, distributed users, legacy infrastructure, and increasingly complex cloud environments. Attackers have taken notice, and the pressure on security teams continues to grow.In Q2 2025, universities faced an average of 4,388 cyberattacks per organization per week, up 24% from the same period in 2024. Nine in ten universities …

Data BreachesDFIRMalwareMicrosoftRansomwareThreat IntelligenceVulnerabilities
P40
2026-09-30 10:00 UTC
Vendor Research

China-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoor

Cisco Talos Intelligence Blog · Ashley Shen · indexed 2026-09-30 10:10 UTC

Cisco Talos uncovered a cluster of activity we track as UAT-11587 targeting government and policy organizations across Asia, including in Taiwan, India, the Philippines, and Cambodia, to deliver a previously undocumented backdoor referred to as “Antino” in developer artifacts.

Malware
P0
2026-09-29 20:59 UTC
Security Journalism

Custom ChatGPTs push ClickFix attacks to deploy RAT malware

BleepingComputer · Bill Toulas · indexed 2026-09-29 21:05 UTC

Custom variants of OpenAI's ChatGPT promoted in sponsored Google results are directing unsuspecting users to malicious sites that use ClickFix attacks to deliver malware. [...]

Malware
P0
2026-09-29 17:20 UTC
Security Journalism

Russia's Star Blizzard Targets 100+ Organizations With Fake Event Invites to Deliver Backdoor

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-29 18:35 UTC

Russian state hackers known as Star Blizzard have been using fake event invitations to trick people into installing a backdoor on their Windows computers, according to Microsoft. The campaigns, aimed at people and organizations tied to Ukraine, have affected more than 100 organizations since January, mostly in the U.S. and U.K. At least one computer was infected, but the number of breached

MalwareMicrosoft
P0
1 2 3 4