IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 221 matching records.
AUTO-POLL // 2026-10-09 23:45 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P4 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 9

RANSOMWARE
P4
P4
COOL // 67 ARTICLES
THU
Oct 8

RANSOMWARE
P3
P3
COOL // 62 ARTICLES
WED
Oct 7

RANSOMWARE
P5
P5
COOL // 86 ARTICLES
TUE
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
RESET
2026-08-17 11:29 UTC
Vendor Research

Operation ASTERIX: Anatomy of a Crypto Fraud Pipeline

Rapid7 · Anna Širokova · indexed 2026-08-18 15:35 UTC

Operation ASTERIX overviewRapid7 researchers identified an exposed web directory on infrastructure used to support a cryptocurrency fraud operation. The server contained raw phone-number datasets, account-validation tools, enriched lead records, phishing panels, voice-dialing scripts, fake wallet applications, persistence mechanisms, and Telegram exfiltration code. Among the artifacts was evidence that the operator relied on AI coding assistants throughout the campaign's development; recovered …

AI SecurityAppleCybercrimeMalwareMicrosoftNetwork SecurityPhishing
P0
2026-08-17 07:15 UTC
Other

Akira Ransomware Uses Safe Mode to Bypass EDR

Security Affairs · Pierluigi Paganini · indexed 2026-08-17 07:40 UTC

Akira attackers used Safe Mode to disable EDR before deploying ransomware, but memory issues caused the encryptor to fail. An Akira ransomware affiliate broke into a company through an MFA-less SonicWall VPN on August 4, stole credentials and file shares, and then rebooted the compromised host into Safe Mode with Networking to kill the security […]

Network SecurityRansomware
P15
2026-08-16 07:24 UTC
Other

APT36 Suspected in PATCHCORD Espionage Campaign Using Google Sheets C2

Security Affairs · Pierluigi Paganini · indexed 2026-08-16 18:35 UTC

Acronis uncovered PATCHCORD, a stealthy backdoor targeting Afghan telecom and South Asian infrastructure via fake VPN tools and Google Sheets C2. Researchers at Acronis just documented an espionage operation that reads like it was built by someone with genuinely good taste in disguises. Their Threat Research Unit report tracks a previously undocumented backdoor called PATCHCORD, […]

APT / Nation-StateMalwareNetwork Security
P0
2026-08-14 21:36 UTC
Vendor Research

The Agentic AI threat cluster: Seven incidents, three actors, and what they mean for your exposure

Tenable Blog · Research Special Operations · indexed 2026-08-15 18:55 UTC

Tenable’s Research Special Operations (RSO) team has been tracking a cluster of agentic AI threat activity since late July 2026. The Taiwan autonomous AI cyber attack confirmed what the cluster data already showed: near-autonomous offensive AI has crossed from theoretical risk to operational reality.Key TakeawaysTaiwan's Ministry of Digital Affairs confirmed a near-autonomous AI cyber attack in July 2026 in which autonomous agents mapped 21 connected government systems, compromised 85 accounts,…

AI SecurityAPT / Nation-StateCloud SecurityNetwork SecurityThreat ActorsVulnerabilitiesCVE-2025-3248
P30
2026-08-13 15:00 UTC
Security Journalism

New PATCHCORD Backdoor Targets Afghan Telecom and Indian Critical Infrastructure

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-17 10:50 UTC

Afghan telecom providers and South Asian critical infrastructure organizations have emerged as the target of a new ongoing campaign that delivers a previously undocumented backdoor called PATCHCORD. According to Acronis Threat Research Unit (TRU), the backdoor is a compiled C/C++ implant delivered by means of sector-specific lures, including fake VPN installers impersonating Afghan Telecom (

MalwareNetwork Security
P0
2026-08-13 05:00 UTC
Other

ZDI-26-577: Trend Micro VPN OpenSSL Configuration Uncontrolled Search Path Element Local Privilege Escalation Vulnerability

Zero Day Initiative · indexed 2026-09-07 17:35 UTC

This vulnerability allows local attackers to escalate privileges on affected installations of Trend Micro VPN. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.0. The following CVEs are assigned: CVE-2026-67212.

Network SecurityVulnerabilitiesCVE-2026-67212
P15
2026-08-12 14:09 UTC
Security Journalism

737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-15 14:33 UTC

A massive set of 737 free VPN and proxy extensions have been found to mainly target Russian-speaking users seeking access to blocked services with an aim to intercept browser traffic and route them through a proxy infrastructure. The extensions, published across at least 40 Chrome Web Store developer accounts, racked up 75,486 installs. Of those identified, 274 have been found to impersonate 66

Network Security
P0
2026-08-12 06:15 UTC
Security Journalism

Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-15 14:33 UTC

Cisco has warned that a new vulnerability impacting Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software has been exploited in the wild. The high-severity flaw, tracked as CVE-2026-20349 (CVSS score: 8.6), is a case of insufficient error checking when processing HTTP requests that could allow an unauthenticated, remote attacker to trigger

Network SecurityVulnerabilitiesCVE-2026-20349
P25
2026-08-11 19:36 UTC
Security Journalism

Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-15 14:33 UTC

Cybersecurity researchers have discovered a new version of the Kimwolf/AISURU Android and Internet of Things (IoT) botnet that comes with significant improvements to improve its operational resilience and conduct distributed denial-of-service (DDoS) attacks. The new version, tracked as Kimwolf v7, was discovered by Palo Alto Networks Unit 42 in February 2026. "Kimwolf v7 adds an HTTP/2-based

MalwareMobile SecurityNetwork SecuritySecurity Research
P0
2026-08-11 18:36 UTC
Security Journalism

Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run Commands

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-15 14:33 UTC

The Computer Emergency Response Team of Ukraine (CERT-UA) has disclosed details of a new social engineering campaign orchestrated by Russian nation-state threat actors targeting IT workers in the country by masquerading as recruiters to trick them into installing malware. CERT-UA pinned the activity on a threat cluster it tracks as UAC-0145, which is a subgroup within Sandworm (aka APT44,

APT / Nation-StateMalwareNetwork SecurityThreat Actors
P0
2026-08-11 14:04 UTC
Vendor Research

Microsoft's August 2026 Patch Tuesday addresses 398 CVEs (CVE-2026-68820)

Tenable Blog · Research Special Operations · indexed 2026-08-15 18:55 UTC

42Critical355Important1Moderate0LowMicrosoft addresses 398 CVEs in the eighth Patch Tuesday of 2026, with three zero-days, including one that was exploited in the wild.Microsoft patched 398 CVEs in its August 2026 Patch Tuesday release, with 42 rated critical, 355 rated as important and one rated as moderate. Our counts omitted two CVEs assigned by MITRE; CVE-2026-6726 and CVE-2026-6727.This month’s update includes patches for:.NET.NET Core.NET FrameworkAMD ZenActive Directory Certificate Servi…

Cloud SecurityLinuxMicrosoftMobile SecurityNetwork SecurityVulnerabilitiesCVE-2022-21919CVE-2022-26904CVE-2024-38193CVE-2025-21418CVE-2025-32709CVE-2026-61348CVE-2026-62714CVE-2026-62715CVE-2026-62716CVE-2026-62718CVE-2026-62720CVE-2026-62742CVE-2026-62745CVE-2026-62761CVE-2026-62776CVE-2026-62803CVE-2026-62807CVE-2026-62812CVE-2026-62814CVE-2026-6726CVE-2026-6727CVE-2026-68820CVE-2026-70307
P65
2026-08-11 12:05 UTC
Security Journalism

A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-15 14:33 UTC

A malicious SIM card can order the device it sits in to run commands of the attacker's choosing. On the cellular modules built into electric-vehicle chargers, industrial routers, and car telematics units, that is enough to take the whole device over. Researchers at the University of Birmingham and the security firm Fuzzware tested 26 phones and cellular modules for the capability, found it

Network Security
P0
2026-08-11 09:16 UTC
Security Journalism

Gunra Ransomware Exploits Fortinet FortiOS, FortiProxy Flaws to Breach Networks

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-15 14:33 UTC

Cybersecurity and intelligence agencies from South Korea and the U.S. warned of Gunra ransomware attacks targeting critical infrastructure sectors and organizations across the world. Targets of these attacks include healthcare and public health, financial services, government services and facilities, and professional and nonprofit services. "Gunra is another variant in the ongoing trend of

AppleCloud SecurityNetwork SecurityRansomware
P15
2026-08-11 05:00 UTC
Other

ZDI-26-533: Cisco Secure Firewall Management Center login.cgi Authentication Bypass Vulnerability

Zero Day Initiative · indexed 2026-09-07 17:35 UTC

This vulnerability allows remote attackers to bypass authentication on affected installations of Cisco Secure Firewall Management Center. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8. The following CVEs are assigned: CVE-2026-20316.

Network SecurityVulnerabilitiesCVE-2026-20316
P15
2026-08-10 15:00 UTC
Security Journalism

⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-15 14:33 UTC

A lot of security problems still begin with someone doing a completely normal thing. Cloning a repo. Answering a call. Leaving a box exposed. Trusting the default. That pretty much covers the mood this week. Old bugs are back, supply chains are getting stranger, and some exploit paths are so short you wonder what was supposed to stop them in the first place. That’s only part of it. Here’s

MalwareNetwork SecurityVulnerabilities
P25
2026-08-05 16:01 UTC
Vendor Research

Cisco Advance Notification for Publication of August 5, 2026, Security Advisories

Cisco Security Advisories · indexed 2026-08-15 14:33 UTC

On August 5, 2026, the Cisco Product Security Incident Response Team (PSIRT) published the following advisories: Cisco Security Advisory CVE ID Security Impact Rating CVSS Base Score Cisco Catalyst SD-WAN Software Security Hardening Release: August 2026 CVE-2026-20303CVE-2026-20304CVE-2026-20310CVE-2026-20312CVE-2026-20313 Critical 9.9 Cisco IOS XE Software Security Hardening Release: August 2026 CVE-2026-20267CVE-2026-20268CVE-2026-20269CVE-2026-20270CVE-2026-20271CVE-2026-20272CVE-2026-20273 …

AppleDFIRMicrosoftNetwork SecurityVulnerabilitiesCVE-2026-20028CVE-2026-20124CVE-2026-20198CVE-2026-20263CVE-2026-20289CVE-2026-20294CVE-2026-20301CVE-2026-20311
P5
2026-08-05 16:00 UTC
Vendor Research

Cisco Terminal Services Agent Firewall Rules Bypass Vulnerability

Cisco Security Advisories · indexed 2026-08-15 14:33 UTC

A vulnerability in the network driver of Cisco Terminal Service (TS) Agent could allow an authenticated, remote attacker to bypass firewall rules that are associated with the account of the attacker. This vulnerability is due to an incorrect mapping of network connections to user accounts. An attacker with at least user-level credentials could exploit this vulnerability by sending crafted network traffic to an affected device. A successful exploit could allow the attacker to inherit the firewal…

Network SecurityVulnerabilitiesCVE-2026-20028
P5
2026-07-30 05:00 UTC
Other

ZDI-26-505: (Pwn2Own) Phoenix Contact CHARX SEC-3150 charx-system-config-manager Service CRLF Injection Firewall Bypass Vulnerability

Zero Day Initiative · indexed 2026-09-07 17:35 UTC

This vulnerability allows network-adjacent attackers to bypass firewall rules on affected installations of Phoenix Contact CHARX SEC-3150 devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.0. The following CVEs are assigned: CVE-2026-44092.

Network SecurityVulnerabilitiesCVE-2026-44092
P5
2026-07-30 05:00 UTC
Other

ZDI-26-503: (Pwn2Own) Phoenix Contact CHARX SEC-3150 Race Condition Firewall Bypass Vulnerability

Zero Day Initiative · indexed 2026-09-07 17:35 UTC

This vulnerability allows network-adjacent attackers to bypass firewall rules on affected installations of Phoenix Contact CHARX SEC-3150 devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.4. The following CVEs are assigned: CVE-2026-44108.

Network SecurityVulnerabilitiesCVE-2026-44108
P5
2026-07-20 09:36 UTC
Vendor Research

wp2shell (CVE-2026-63030, CVE-2026-60137): Frequently asked questions about remote code execution chain in WordPress Core

Tenable Cyber Exposure Alerts · Satnam Narang · indexed 2026-08-15 18:55 UTC

An unauthenticated attacker can chain two WordPress Core vulnerabilities, CVE-2026-63030 and CVE-2026-60137, to achieve remote code execution against affected WordPress installations. Multiple security firms have confirmed active in-the-wild exploitation within days of public disclosure, and public proof-of-concept exploits are circulating.Key takeaways:Two WordPress Core vulnerabilities, CVE-2026-63030 and CVE-2026-60137, can be chained together to achieve pre-authentication remote code execut…

Cloud SecurityDFIRMicrosoftNetwork SecurityRansomwareSecurity ResearchThreat ActorsThreat IntelligenceVulnerabilitiesCVE-2026-60137CVE-2026-601377CVE-2026-63030
P70
2026-07-17 10:00 UTC
Vendor Research

Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy

Palo Alto Networks Unit 42 · Emmanuel Zhou, Adam Robbie, Rick Wyble and Miguel Pereira · indexed 2026-08-15 18:55 UTC

A technical analysis of three chained zero-day vulnerabilities in Siemens ROX II OT switches that allow privilege escalation and persistent root access. The post Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy appeared first on Unit 42.

Network SecurityVulnerabilities
P35
2026-07-15 13:14 UTC
Vendor Research

CVE-2026-15409, CVE-2026-15410: SonicWall SMA 1000 zero-day vulnerabilities exploited in the wild

Tenable Cyber Exposure Alerts · Scott Caveza · indexed 2026-08-15 18:55 UTC

SonicWall patched two recently exploited zero-day vulnerabilities in its SMA 1000 Series secure remote access appliances which may have been chained for unauthenticated remote code execution.Key takeawaysCVE-2026-15409 and CVE-2026-15410 are a pair of exploited vulnerabilities that may have been chained together to allow for code execution on SonicWall SMA1000 series appliances. Zero-day exploitation of these vulnerabilities has been observed and confirmed by SonicWall. Patches and indicators o…

Cloud SecurityNetwork SecurityRansomwareSecurity ResearchThreat ActorsThreat IntelligenceVulnerabilitiesCVE-2026-15409CVE-2026-15410
P100
2026-07-15 05:00 UTC
Other

ZDI-26-427: WatchGuard FireWare OS iked ike2_hmac Null Pointer Dereference Denial-of-Service Vulnerability

Zero Day Initiative · indexed 2026-09-07 17:35 UTC

This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of WatchGuard FireWare OS. Authentication is not required to exploit this vulnerability, but only systems using VPN with IKEv2 are vulnerable. The ZDI has assigned a CVSS rating of 5.9. The following CVEs are assigned: CVE-2026-13084.

Network SecurityVulnerabilitiesCVE-2026-13084
P5
2026-07-14 14:23 UTC
Vendor Research

Microsoft’s July 2026 Patch Tuesday Addresses 569 CVEs (CVE-2026-56155, CVE-2026-56164)

Tenable Cyber Exposure Alerts · Research Special Operations · indexed 2026-08-15 18:55 UTC

56Critical510Important3Moderate0LowMicrosoft addresses 569 CVEs in the largest Patch Tuesday release yet. This month’s release includes three zero-days, two of which were exploited in the wild.Microsoft patched 569 CVEs in its July 2026 Patch Tuesday release, with 56 rated critical, 510 rated as important, and 3 rated as moderate. This marks the largest Patch Tuesday release ever, crushing the previous record of 198 CVEs in June. Last week, Microsoft announced that its multi-model agentic scann…

AppleCloud SecurityLinuxMalwareMicrosoftMobile SecurityNetwork SecurityVulnerabilitiesCVE-2026-56155CVE-2026-56164
P65
2026-07-02 14:00 UTC
Vendor Research

Google’s Continued Disruption of Malicious Residential Proxy Networks

Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-08-15 18:55 UTC

Background Today, in coordination with the FBI, Lumen, and others, Google took action against the NetNut residential proxy network, also known as Popa. This action builds on our disruption of the IPIDEA proxy network that took place in January 2026, and is a continuation of Google’s objective to dismantle malicious residential proxy networks. Actions Taken As a part of this disruption we took the following actions: Disabled Google accounts and associated Google services used by NetNut for malwa…

APT / Nation-StateLaw EnforcementMalwareMicrosoftMobile SecurityNetwork SecurityThreat Intelligence
P0
2026-06-24 11:00 UTC
Vendor Research

Zero-Day Exploitation of Vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN Manager

Google Threat Intelligence / Mandiant · Mandiant · indexed 2026-08-15 18:55 UTC

Written by: Chester Sng, Pete Boonyakarn, Logeswaran Nadarajan, Lukasz Lamparski Introduction In early 2026, Mandiant identified a threat actor targeting SD-WAN infrastructure at a service provider. After gaining initial access, the threat actor exploited a zero-day vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN to escalate privileges from a compromised administrative account to root-level access. The vulnerability stems from the device’s file upload feature lacking the ability to prop…

MicrosoftNetwork SecurityThreat ActorsVulnerabilitiesCVE-2026-20127CVE-2026-20182CVE-2026-20245
P40
2026-06-05 19:19 UTC
Vendor Research

CVE-2025-11462 AWS ClientVPN macOS Client Local Privilege Escalation

AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC

Bulletin ID: AWS-2025-020 Scope: AWS Content Type: Important (requires attention) Publication Date: 2025/10/07 01:30 PM PDT Description: AWS Client VPN is a managed client-based VPN service that enables secure access to AWS and on-premises resources. The AWS Client VPN client software runs on end-user devices, supporting Windows, macOS, and Linux and provides the ability for end users to establish a secure tunnel to the AWS Client VPN Service. We have identified CVE-2025-11462, an issue in AWS …

AppleCloud SecurityLinuxMicrosoftNetwork SecurityVulnerabilitiesCVE-2025-11462
P15
4 5 6 7 8