IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 487 matching records.
AUTO-POLL // 2026-10-09 23:45 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P4 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 9

RANSOMWARE
P4
P4
COOL // 67 ARTICLES
THU
Oct 8

RANSOMWARE
P3
P3
COOL // 62 ARTICLES
WED
Oct 7

RANSOMWARE
P5
P5
COOL // 86 ARTICLES
TUE
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
RESET
2026-09-08 14:00 UTC
Vendor Research

GTIG AI Threat Tracker: From Prompting to Autonomy – The Evolution of Adversarial AI

Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-09-08 13:45 UTC

Executive Summary Since the release of our May 2026 report detailing adversarial misuse of artificial intelligence (AI), Google Threat Intelligence Group (GTIG) has observed forward leaning adversaries transition from basic prompting to agentic AI workflows and AI-enabled automation. In these operations, human-in-the-loop latency is dramatically reduced, compressing the traditional window for defenders to respond. In Q2 2026, GTIG observed threat actors compromise a cloud resource, then plan, b…

AI SecurityAPT / Nation-StateCloud SecurityData BreachesDFIRMalwareMicrosoftPhishingRansomwareThreat ActorsThreat IntelligenceVulnerabilities
P35
2026-09-08 10:00 UTC
Vendor Research

StyleSmuggler (CVE-2026-75650): Frequently asked questions about Adobe Commerce and Magento zero-day

Tenable Cyber Exposure Alerts · Satnam Narang · indexed 2026-09-08 14:20 UTC

A critical unauthenticated remote code execution (RCE) zero-day in Adobe Commerce and Magento Open Source, dubbed StyleSmuggler, has been actively exploited since September 4 with attacks observed three days before a vendor patch became available.Key takeawaysCVE-2026-75650 is a critical remote code execution vulnerability in Adobe Commerce, Adobe Commerce B2B and Magento Open Source that can be triggered without authentication.Active exploitation of CVE-2026-75650 began on September 4, 2026, t…

DFIRLinuxMalwareThreat ActorsThreat IntelligenceVulnerabilitiesCVE-2026-75650
P95
2026-09-08 09:13 UTC
Security Journalism

Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-08 10:00 UTC

Adobe on Monday released security patches to address a maximum-severity flaw impacting Adobe Commerce and Magento Open Source that has come under active exploitation in the wild. The vulnerability, now tracked as CVE-2026-75650 (CVSS score: 10.0), has been codenamed StyleSmuggler by Sansec, which discovered zero-day exploitation starting September 4, 2026. "This update resolves a critical

MalwareVulnerabilitiesCVE-2026-75650
P50
2026-09-08 09:11 UTC
Other

North Korea-linked Hackers Hide a Backdoor Inside HAProxy

Security Affairs · Pierluigi Paganini · indexed 2026-09-08 10:10 UTC

North Korea-linked hackers hid a backdoor inside HAProxy, masking C2 traffic and stealing data while keeping the load balancer working normally. North Korean-linked hackers found a genuinely clever hiding spot for their malware: inside the actual source code of HAProxy, the load balancing software running at the edge of two South Korean companies’ networks. Rapid7’s […]

Malware
P0
2026-09-08 08:43 UTC
Security Journalism

BengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support Scams

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-08 10:00 UTC

Cybersecurity researchers have disclosed details of a sprawling search engine optimization (SEO) poisoning campaign that paves the way for malware deployment and tech support scams. The campaign, discovered by the DFIR Report in March 2026, has been codenamed BengalSEO. It has operated out of the Indian state of Rajasthan since at least 2015, driven by two IT service providers named WeConnect

DFIRMalwareSecurity Research
P0
2026-09-08 07:41 UTC
Other

IT Help Desk Impersonation Lets Hackers Bypass MFA

Security Affairs · Pierluigi Paganini · indexed 2026-09-08 08:15 UTC

Attackers bypass endpoint security by posing as IT staff, stealing Microsoft 365 sessions, draining SaaS data and demanding extortion. Forget installing malware because today’s extortionists just pick up the phone instead of writing code. A widespread threat cluster tracked as PREY-0058 bypasses endpoint security entirely by targeting Microsoft 365 and SaaS environments through pure social […]

MalwareMicrosoft
P0
2026-09-07 18:12 UTC
Security Journalism

PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-07 18:40 UTC

Cybersecurity researchers have disclosed details of a complex Chromium-based post-exploitation toolkit called PEEP that masquerades as a bookmarks extension for the web browser. "Requiring prior administrative or code execution access, its installer injects the extension directly into Chrome/Edge profiles, bypassing Web Store checks and user prompts by forging Chromium's own Secure Preferences

MalwareSecurity Research
P0
2026-09-07 17:49 UTC
Other

StyleSmuggler: The Magento Zero-Day Behind New Store Attacks

Security Affairs · Pierluigi Paganini · indexed 2026-09-07 18:00 UTC

StyleSmuggler Magento zero-day is under active attack, letting unauthenticated attackers execute code and install backdoors on stores that may already be patched. A new zero-day flaw, dubbed StyleSmuggler, in Magento and Adobe Commerce is under active attack, giving unauthenticated attackers a path to run code on vulnerable online stores. Sansec researchers say it affects current […]

MalwareVulnerabilities
P25
2026-09-07 12:12 UTC
Security Journalism

North Korean Hackers Deploy New Linux Espionage Toolkit

Security Week · Ionut Arghire · indexed 2026-09-07 17:25 UTC

The stealthy toolkit embeds a backdoor in HAProxy and targets automotive and media organizations in South Korea for long-term surveillance. The post North Korean Hackers Deploy New Linux Espionage Toolkit appeared first on SecurityWeek.

APT / Nation-StateLinuxMalware
P0
2026-09-07 11:58 UTC
Security Journalism

Adobe Commerce Zero-Day Exploited to Backdoor Online Stores

Security Week · Ionut Arghire · indexed 2026-09-07 17:25 UTC

The StyleSmuggler zero-day allows attackers to execute code and deploy a stealthy backdoor on Adobe Commerce and Magento stores. The post Adobe Commerce Zero-Day Exploited to Backdoor Online Stores appeared first on SecurityWeek.

MalwareVulnerabilities
P25
2026-09-07 11:45 UTC
Security Journalism

Modified ScreenConnect Clients Used in Worm-Like Campaign

Security Week · Ionut Arghire · indexed 2026-09-07 17:25 UTC

The attacks rely on backdoored ScreenConnect instances to transfer and execute payloads to newly connected clients. The post Modified ScreenConnect Clients Used in Worm-Like Campaign appeared first on SecurityWeek.

Malware
P0
2026-09-07 10:19 UTC
Other

JSCeal Hides Crypto Malware in V8 Bytecode

Security Affairs · Pierluigi Paganini · indexed 2026-09-07 10:50 UTC

JSCeal hides crypto-stealing malware in V8 bytecode, but researchers built a tool to decompile it and expose its advanced theft capabilities. JSCeal is a cryptocurrency stealer that Check Point Research has tracked since early 2025. Unlike most malware, it hides its code in a format that makes analysis much harder. Check Point presented its latest […]

Malware
P0
2026-09-07 07:53 UTC
Security Journalism

JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-07 08:35 UTC

Cybersecurity researchers have unpacked JSCeal, a sophisticated compiled V8 JavaScript (JSC) malware with credential harvesting, surveillance, and traffic-interception capabilities. "The payloads are protected with javascript-obfuscator, using multiple techniques including RC4-protected strings, control-flow flattening, proxy functions, and operation wrappers," Check Point Research said in a

MalwarePhishingSecurity Research
P0
2026-09-06 08:34 UTC
Security Journalism

Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-06 10:00 UTC

Elastic Security Labs has documented four previously unreported programs associated with REVSTEALER, an emerging Windows information stealer, that remain on an infected machine after the stealer deletes itself. One of them switches off Windows Update and Microsoft Defender before running a cryptocurrency miner. The company named the four programs ProManager, WinUpdate, SoftManager, and

MalwareMicrosoftNetwork Security
P0
2026-09-06 08:27 UTC
Other

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 113

Security Affairs · Pierluigi Paganini · indexed 2026-09-06 08:55 UTC

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Hackers Steal Claude Login Sessions With Infostealer Malware to Hijack Accounts Fire Ant Evolves: From Hypervisors to Trusted Infrastructure Gryxa: The AI-Built Toolkit That Watches How You Remove It ValleyRAT masquerading as adware […]

Malware
P0
2026-09-05 20:14 UTC
Security Journalism

Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-05 20:50 UTC

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is

MalwareVulnerabilities
P25
2026-09-04 14:51 UTC
Security Journalism

New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-04 15:10 UTC

A previously undocumented Linux toolkit has been found compiled directly into the trojanized HAProxy load balancers of two South Korean organizations, where it intercepted web traffic and served altered pages to selected visitors. The attackers named the implant ted in debug strings left in the binary. It is not a HAProxy vulnerability, and installing it requires code execution on the host and

LinuxMalwareVulnerabilities
P0
2026-09-04 12:00 UTC
Vendor Research

DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors

Rapid7 · Rapid7 Intelligence · indexed 2026-09-04 12:25 UTC

OverviewA new Linux toolkit, identified by Rapid7 Labs, has been targeting organizations across South Korea’s automotive and media industries with minimal detection. The campaign made use of a HAProxy instance named “ted backdoor”, alongside trojanized versions of crond, agetty, atd, sshd, and polkitd. This previously undocumented framework enabled threat actors to execute remote commands on compromised servers, inject malicious scripts into web traffic, perform credential harvesting, and engag…

APT / Nation-StateLinuxMalwarePhishingThreat ActorsVulnerabilities
P15
2026-09-03 19:42 UTC
Security Journalism

What We Missed: Did ShinyHunters 'Breach' ReliaQuest?

Dark Reading · Rob Wright, Alexander Culafi · indexed 2026-09-03 20:15 UTC

In this video conversation, Dark Reading editors discuss some of the news they didn't get a chance to cover, from the latest antics of ShinyHunters to new research about the prevalence (or lack thereof) of AI-generated malware.

Malware
P0
2026-09-03 15:26 UTC
Security Journalism

BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-03 16:45 UTC

Cybersecurity researchers have disclosed details of a sophisticated Python-based Windows malware framework called BraZetsu that fuels an underground marketplace commercializing access to compromised hosts. "Unlike the standard infostealer model, BraZetsu is a comprehensive master toolkit that empowers Initial Access Brokers (IABs) by turning compromised systems into highly valuable commercial

CybercrimeMalwareMicrosoftSecurity Research
P0
2026-09-03 13:50 UTC
Security Journalism

Your Employee’s Password Appeared in an Infostealer Log. Now What?

BleepingComputer · Sponsored by Flare · indexed 2026-09-03 14:00 UTC

Infostealers can expose far more than passwords, including authenticated sessions that may let attackers bypass MFA. Flare explains how defenders can prioritize compromised identities, determine whether stolen access is still usable, and respond before it leads to account takeover. [...]

MalwareMicrosoft
P0
2026-09-03 10:43 UTC
Security Journalism

Attackers Turn Trusted Node.js Runtime Into Malware Delivery Tool in Targeted Attacks

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-03 11:30 UTC

Threat actors are leveraging the trusted Node.js JavaScript runtime in multiple cyber attacks as a way to deploy malicious payloads. According to a new report published by the Symantec Threat Hunter Team today, the attack method has been put to use in attacks targeting government departments, technology companies, and hotels since February 2026. "The technique's appeal is that node.exe (the

MalwareThreat Actors
P0
2026-09-03 10:36 UTC
Security Journalism

Shai-Hulud's Reach Just Grew to 469 Credential Locations. Here's What That Means

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-03 11:30 UTC

In early August, GitGuardian researchers found that a recent Shai-Hulud infostealer worm variant had evolved to scan for credentials across 469 locations across developer environments, Continuous Integration/Continuous Deployment (CI/CD) tooling, cloud configurations, and even AI tool configs. Earlier variants of the infostealer worm only checked 189 paths. The jump says a lot. Attackers have

Malware
P0
2026-09-03 08:12 UTC
Other

2,000 Leaked Documents Reveal How Russia Turns Engineering Students Into GRU Cyber Operators

Security Affairs · Pierluigi Paganini · indexed 2026-09-03 08:20 UTC

2,000 leaked files expose Bauman University’s hidden Department No. 4, which trained GRU-linked hackers and propagandists linked to APT28 and Sandworm. Leaked Documents Expose Bauman University’s Hidden Department That Trained Hackers, Propagandists, and Malware Developers for the GRU More than 2,000 internal documents from Bauman Moscow State Technical University have been reviewed by an international […]

APT / Nation-StateMalware
P0
2026-09-02 16:41 UTC
Security Journalism

Fake Software Installers Disable Windows Update and Weaken Microsoft Defender

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-02 17:50 UTC

An active malware campaign is using bogus software-download websites to impersonate trusted vendors and distribute malicious installers. "The campaign has targeted users looking to download popular software and has resulted in compromises across multiple organizations and industries, primarily affecting China-based operations of multinational organizations and Chinese-speaking users," Microsoft

MalwareMicrosoft
P0
5 6 7 8 9