IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 221 matching records.
AUTO-POLL // 2026-10-09 22:50 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P5 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 9

RANSOMWARE
P5
P5
COOL // 62 ARTICLES
THU
Oct 8

RANSOMWARE
P3
P3
COOL // 62 ARTICLES
WED
Oct 7

RANSOMWARE
P5
P5
COOL // 86 ARTICLES
TUE
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
RESET
2026-09-10 16:14 UTC
Security Journalism

Cybersecurity M&A Roundup: 33 Deals Announced in August 2026

Security Week · Eduard Kovacs · indexed 2026-09-10 16:25 UTC

Significant cybersecurity M&A deals announced by Brinqa, Cribl, Echo, Fortinet, Kiteworks, Palo Alto Networks, and Visa. The post Cybersecurity M&A Roundup: 33 Deals Announced in August 2026 appeared first on SecurityWeek.

Network Security
P0
2026-09-10 11:45 UTC
Security Journalism

Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-10 13:15 UTC

Check Point has patched two critical vulnerabilities in the way its firewall and management products handle VPN certificates. The company says both could allow an unauthenticated remote attacker to run code, but only "under specific conditions" that it has not described. One flaw affects Check Point's Security Gateways, its firewall appliances. The other affects those gateways and the Security

Cloud SecurityNetwork SecurityVulnerabilities
P15
2026-09-10 10:36 UTC
Security Journalism

CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-10 11:30 UTC

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added three flaws, each impacting Cisco, Citrix, and Fortinet, to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 12, 2026. The vulnerabilities are listed below - CVE-2026-20079 (CVSS score: 10.0) - An authentication

Cloud SecurityNetwork SecurityVulnerabilitiesCVE-2026-20079
P35
2026-09-10 08:20 UTC
Government

2026-012: Critical Vulnerabilities in Check Point Products

CERT-EU Security Advisories · indexed 2026-09-10 08:30 UTC

On 9 September 2026, Check Point released emergency security updates addressing two critical vulnerabilities affecting Check Point Security Gateway, Security Management Server, and Spark Firewall deployments configured to use Remote Access VPN or Site-to-Site VPN. Both vulnerabilities carry a CVSS score of 9.8 and could allow an unauthenticated, remote attacker to execute arbitrary code on affected appliances. CERT-EU strongly recommends applying the available hotfixes as soon as possible, prio…

Network SecurityVulnerabilities
P5
2026-09-09 15:16 UTC
Vendor Research

Credentialed Pre-Port Discovery: Don't Probe the Host, Ask it

Rapid7 · Conor McCormick · indexed 2026-09-09 16:10 UTC

If your scan engine already holds credentials for a host, it can ask that host which ports are open instead of probing for them.Every scan begins with the same question: which ports on this host are open? Everything after it, from identifying services to checking for vulnerabilities to evaluating policy, depends on the answer being right. The traditional answer comes from the outside: the scan engine sends traffic to a range of ports and infers each port's state from how the host responds. That…

MicrosoftNetwork SecurityVulnerabilities
P0
2026-09-09 05:00 UTC
Other

ZDI-26-645: Fortinet FortiSandbox write_remote_backup_to_crontab cronValue Command Injection Remote Code Execution Vulnerability

Zero Day Initiative · indexed 2026-09-09 22:50 UTC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fortinet FortiSandbox. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-84387.

Network SecurityVulnerabilitiesCVE-2026-84387
P20
2026-09-08 15:21 UTC
Security Journalism

Cylake Raises $245 Million Ahead of Cybersecurity Platform Beta

Security Week · Mike Lennon · indexed 2026-09-08 15:25 UTC

The startup founded by Palo Alto Networks’ Nir Zuk has raised $290 million to build an AI-native security platform for highly regulated organizations that cannot rely on the public cloud. The post Cylake Raises $245 Million Ahead of Cybersecurity Platform Beta appeared first on SecurityWeek.

Network Security
P0
2026-09-08 14:07 UTC
Vendor Research

Microsoft’s September 2026 Patch Tuesday addresses 964 CVEs (CVE-2026-81963, CVE-2026-85880)

Tenable Cyber Exposure Alerts · Research Special Operations · indexed 2026-09-08 18:20 UTC

104Critical860Important0Moderate0LowMicrosoft addresses 964 CVEs, smashing July’s release as the largest Patch Tuesday release. This month’s updates include patches for two zero-days that were exploited in the wild.Microsoft patched a record 964 CVEs in its September 2026 Patch Tuesday release, with 104 rated critical and 860 rated as important.This month’s update includes patches for:.NET.NET and Visual StudioASP.NET CoreActive Directory Certificate Services (AD CS)Active Directory Domain Serv…

Cloud SecurityLinuxMicrosoftMobile SecurityNetwork SecurityVulnerabilitiesCVE-2023-21674CVE-2026-81963CVE-2026-85880
P65
2026-09-07 14:36 UTC
Security Journalism

⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-07 16:10 UTC

Turning off email images should at least stop the pictures. This week, attackers had a workaround: a scannable QR code built out of text. It still appears, even with images blocked. A small detail, but an annoying one if that was a precaution you were counting on. Elsewhere, a trusted software source delivered code that stole credentials, and a protocol designed for secure network management

Network SecurityVulnerabilities
P25
2026-09-06 13:46 UTC
Other

Your MikroTik Router May Already Be Compromised: Look for SSH User “-2”

Security Affairs · Pierluigi Paganini · indexed 2026-09-06 14:45 UTC

MikroTik RouterOS SSH zero-day (MikroTrick chain) under active exploitation since Sept 2. Patch to 7.24.2, 7.23.5, or 6.49.21 immediately and check logs. Anyone running a MikroTik router with SSH exposed to the internet should treat it as compromised until proven otherwise. The popular cybersecurity expert Costin Raiu published a detailed technical breakdown of the active […]

Network SecurityVulnerabilities
P25
2026-09-06 09:32 UTC
Security Journalism

Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-06 10:00 UTC

Attackers are exploiting MikroTik routers with their Secure Shell (SSH) remote-access service, which is reachable from the internet, to gain full administrative control without authentication, according to CERT Polska's attack warning, published on September 5. Successful attacks date to at least September 2. The Hacker News’s September 6 review of the warning found no victim count or

Network Security
P0
2026-09-06 08:34 UTC
Security Journalism

Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-06 10:00 UTC

Elastic Security Labs has documented four previously unreported programs associated with REVSTEALER, an emerging Windows information stealer, that remain on an infected machine after the stealer deletes itself. One of them switches off Windows Update and Microsoft Defender before running a cryptocurrency miner. The company named the four programs ProManager, WinUpdate, SoftManager, and

MalwareMicrosoftNetwork Security
P0
2026-09-03 19:47 UTC
Other

Cisco Fixed Critical RCE in Nexus 9000 Series Switches

Security Affairs · Pierluigi Paganini · indexed 2026-09-03 20:25 UTC

Cisco patched a critical Nexus 9000 vulnerability, CVE-2026-20212, allowing unauthenticated remote root code execution. Cisco has released patches for a critical flaw, tracked as tracked as CVE-2026-20212 (CVSS score of 9.8) in 10 Silicon One-based Nexus 9000 switches. The vulnerability could let an unauthenticated remote attacker execute code with root privileges. Cisco’s Technical Assistance Center […]

Network SecurityVulnerabilitiesCVE-2026-20212
P30
2026-09-03 15:52 UTC
Security Journalism

Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-03 16:45 UTC

Cisco has released patches to address a critical security flaw affecting 10 Silicon One-based Nexus 9000 switches that could allow an unauthenticated, remote attacker to execute code as root, alongside an IOS XR hardening release bundling 7 umbrella CVEs, 2 of which are rated 9.8, with no workaround for any IOS XR version. The Nexus vulnerability, tracked as CVE-2026-20212 (CVSS score: 9.8), is

AppleNetwork SecurityVulnerabilitiesCVE-2026-20212
P5
2026-09-02 16:02 UTC
Vendor Research

Cisco Advance Notification for Publication of September 2, 2026, Security Advisories

Cisco Security Advisories · indexed 2026-08-26 16:20 UTC

On September 2, 2026, the Cisco Product Security Incident Response Team (PSIRT) published the following advisories: Cisco Security Advisory CVE ID Security Impact Rating CVSS Base Score Cisco IOS XR Software Security Hardening Release: September 2026 CVE-2026-20277CVE-2026-20278CVE-2026-20280CVE-2026-20279CVE-2026-20276CVE-2026-20275CVE-2026-20274 Critical 9.8 Cisco Nexus 9000 Series Switches Silicon One Remote Code Execution Vulnerability CVE-2026-20212 Critical 9.8 Cisco Desk Phone 9800 Serie…

AppleDFIRNetwork SecurityVulnerabilitiesCVE-2026-20212CVE-2026-20281
P20
2026-09-02 16:00 UTC
Vendor Research

Cisco Nexus 9000 Series Switches Silicon One Remote Code Execution Vulnerability

Cisco Security Advisories · indexed 2026-09-02 16:10 UTC

A vulnerability in the Silicon One integration for Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to execute code with root privileges. This vulnerability exists because TCP ports 43210 and 43211 are accessible in the default Layer 3 (L3) virtual routing and forwarding (VRF). A successful exploit could allow the attacker to connect to an affected device and send crafted input that could be executed as code with root privileges. The exploitation of this vulnerab…

Network SecurityVulnerabilitiesCVE-2026-20212
P20
2026-09-02 14:22 UTC
Other

SonicWall Patches Two New Actively Exploited Zero-Days in SMA 1000 VPNs

Security Affairs · Pierluigi Paganini · indexed 2026-09-02 15:00 UTC

SonicWall patched two zero-days in SMA 1000 VPNs, including a CVSS 10 pre-auth SSRF flaw, after confirming active exploitation. SonicWall has released security updates for two vulnerabilities in its SMA 1000 VPN appliances that are actively exploited in attacks in the wild. SonicWall’s researchers William Perry and Adam Babis discovered the vulnerabilities. SonicWall confirmed that […]

Network SecurityVulnerabilities
P50
2026-09-02 10:53 UTC
Security Journalism

Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-02 11:15 UTC

SonicWall has released security updates to address two security flaws impacting its Secure Mobile Access (SMA) 1000 series VPN appliances that have been exploited in zero-day attacks. The vulnerabilities, discovered internally by SonicWall's William Perry and Adam Babis, are listed below - CVE-2026-83548 (CVSS score: 10.0) - A pre-authentication SSRF vulnerability in the Appliance

Cloud SecurityNetwork SecurityVulnerabilitiesCVE-2026-83548
P30
2026-09-02 07:08 UTC
Security Journalism

Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-02 08:00 UTC

Threat actors are exploiting a severe security vulnerability in Sangoma Switchvox, an enterprise VoIP platform, that could allow unauthenticated remote code execution. The vulnerability in question is CVE-2026-9586 (CVSS score: 9.3), a critical unauthenticated SQL injection vulnerability in Sangoma Switchvox SMB Edition 8.3 (104997) that can allow attackers to remotely execute arbitrary code as

Network SecurityThreat ActorsVulnerabilitiesCVE-2026-9586
P20
2 3 4 5 6