IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 247 matching records.
AUTO-POLL // 2026-10-09 22:15 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P5 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 9

RANSOMWARE
P5
P5
COOL // 62 ARTICLES
THU
Oct 8

RANSOMWARE
P3
P3
COOL // 62 ARTICLES
WED
Oct 7

RANSOMWARE
P5
P5
COOL // 86 ARTICLES
TUE
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
RESET
2026-10-08 12:50 UTC
Vendor Research

Inside the Exchange Inspector: How Tenable uses OpenAI GPT cyber models to review open-source AI agents

Tenable Blog · Robert McSulla · indexed 2026-10-08 13:10 UTC

Community-built AI agents, skills, and MCP servers are landing in SOC workflows fast. Here’s what the Exchange Inspector tests before a listing earns its vetted tag on the CyberAgents Exchange. Three tools have already passed.Key takeawaysEvery Inspector-vetted listing clears three gates: an automated check, a frontier model assessment, and human verification. Tenable uses Tenable One AI Exposure to screen for prompt injection and exposed secrets, and OpenAI GPT Cyber models to assess the code …

AI SecurityCloud SecurityDFIRICS / OTMalwareMicrosoftNetwork SecurityPhishingSecurity ResearchThreat IntelligenceVulnerabilities
P0
2026-10-08 10:30 UTC
Security Journalism

Wazza Phishkit Targets Banking, Government, and Manufacturing Across the US, EU, and Australia

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-08 11:05 UTC

Phishing kits are no longer limited to copying a familiar login page and waiting for a victim to enter credentials. Attackers are increasingly building filtering, session management, and traffic controls into the infrastructure that delivers the phishing page itself. ANY.RUN has identified Wazza, a new phishkit targeting banking, manufacturing, and government organizations across the US, Europe

Phishing
P0
2026-10-07 11:56 UTC
Security Journalism

FBI Warns FortiBleed Remains Active After Amassing 86,644 Fortinet Device Credentials

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-07 12:20 UTC

The U.S. Federal Bureau of Investigation (FBI) and Secret Service (USSS) on Tuesday warned that the FortiBleed credential harvesting campaign remains an active threat aimed at internet-facing Fortinet FortiGate firewalls and secure socket layer (SSL) virtual private network (VPN) gateways. "The campaign exploits reused or leaked credentials and legacy SHA-256 password storage, enabling threat

DFIRLaw EnforcementNetwork SecurityPhishing
P0
2026-10-07 10:40 UTC
Vendor Research

The ASOS Incident: When Attackers Use the Channels Customers Trust

Rapid7 · Emma Burdett · indexed 2026-10-07 10:50 UTC

This week, ASOS customers opened their phones to find a hostile push notification delivered through the retailer’s own app. The message claimed the company’s Snowflake environment had been compromised and directed ASOS to engage with the sender through Telegram. ASOS later confirmed to Sky News that an unauthorized customer notification had been sent and said it was investigating activity involving third-party platforms used to communicate with customers. The company also said basic personal in…

CybercrimeDFIRMalwarePhishingVulnerabilities
P0
2026-10-06 18:38 UTC
Security Journalism

Fake ChatGPT, Gemini, and Claude Ad Portals Capture Credentials and MFA Codes

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-06 20:15 UTC

Cybersecurity researchers have disclosed details of a "human-operated phishing platform" that impersonates advertising products for artificial intelligence (AI) chatbots like Google Gemini, Anthropic Claude, OpenAI ChatGPT, Perplexity, Meta Muse, and Manus. The products, which claim to offer campaign optimization, spend audits, and business-account connections, are designed with one goal in

AI SecurityPhishingSecurity Research
P0
2026-10-05 13:57 UTC
Other

5th October – Threat Intelligence Report

Check Point Research · urias@checkpoint.com · indexed 2026-10-05 14:15 UTC

For the latest discoveries in cyber research for the week of 5th October, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Arizona’s state court system has suffered a phishing-led cyberattack after an employee clicked a malicious link. Attackers copied backup files containing protective-order records and more than 150,000 Foster Care Review Board reports […] The post 5th October – Threat Intelligence Report appeared first on Check Point Research.

PhishingThreat Intelligence
P0
2026-10-04 07:20 UTC
Security Journalism

China-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM Phishing

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-04 07:45 UTC

A new China-nexus cyber espionage group known as TA419 has been attributed to multiple credential phishing campaigns targeting artificial intelligence (AI) experts working for U.S. think tanks, universities, and legal sector organizations. The campaigns have impersonated prominent economists and AI policymakers, as well as a prominent Anthropic employee, to single out an AI policy expert at a

AI SecurityAPT / Nation-StateMicrosoftPhishing
P0
2026-10-03 15:11 UTC
Other

Fake Zoom installer hides macOS backdoor CloudSyncD

Security Affairs · Pierluigi Paganini · indexed 2026-10-03 15:30 UTC

Jamf Threat Labs details CloudSyncD, a fake macOS Zoom installer that hides a phished password using invisible zero-width Unicode characters. Jamf Threat Labs found CloudSyncD while doing routine scanning on VirusTotal, buried inside a disguised Zoom client. They first spotted it on September 15, clearly still under construction, and within two days watched it move […]

AppleMalwarePhishing
P0
2026-10-02 14:30 UTC
Security Journalism

In Other News: $15K iCloud Spoofing Bugs, AI Policy Experts Phished, Adblocker Spies on AI Chats

Security Week · SecurityWeek News · indexed 2026-10-02 14:30 UTC

Noteworthy stories that might have slipped under the radar: Kiteworks patches over 100 vulnerabilities, Microsoft publishes 2026 Digital Defense Report, AI finds 24 Android app flaws. The post In Other News: $15K iCloud Spoofing Bugs, AI Policy Experts Phished, Adblocker Spies on AI Chats appeared first on SecurityWeek.

Cloud SecurityMicrosoftMobile SecurityPhishing
P0
2026-10-01 12:05 UTC
Other

Milk Dragon: Huge Discounts on Social Media? Think Twice Before You Buy

Group-IB · indexed 2026-10-01 14:20 UTC

Milk Dragon, also known as NaiLong is an Adversary-in-the-Middle (AiTM) phishing kit active since October 2025. Unlike conventional phishing tactics that rely on fear and urgency, Milk Dragon lures victims with big discounts on consumer goods distributed via Facebook and TikTok marketplace advertisements.

Phishing
P0
2026-10-01 12:05 UTC
Other

Milk Dragon: Huge Discounts on Social Media? Think Twice Before You Buy

Group-IB · indexed 2026-10-01 12:40 UTC

Milk Dragon, also known as NaiLong is an Adversary-in-the-Middle (AiTM) phishing kit active since October 2025. Unlike conventional phishing tactics that rely on fear and urgency, Milk Dragon lures victims with big discounts on consumer goods distributed via Facebook and TikTok marketplace advertisements.

Phishing
P0
2026-09-30 16:32 UTC
Security Journalism

Attackers Abuse MSP360 to Deploy ScreenConnect in Dual-RMM Phishing Attacks

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-30 17:55 UTC

Microsoft has warned of phishing campaigns distributing an installer for the MSP360 Remote Monitoring and Management (RMM) software under the guise of meeting invitations, PDF-themed lures, software update prompts, and other social-engineering content. "Once executed, the legitimate MSP360 installer, distributed under a deceptive file name established remote management access on affected

MicrosoftPhishing
P0
2026-09-30 10:45 UTC
Security Journalism

US-Focused CSuite Phishing Steals Microsoft 365 Sessions and Deploys RMM Tools for Remote Access

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-30 11:45 UTC

ANY.RUN researchers traced a US-focused CSuite phishing campaign across 351 sandbox analyses, with 51% of submissions coming from the United States. Technology, manufacturing, government, and consulting organizations showed the highest exposure. By combining Microsoft 365 session theft with remote-access tool deployment, CSuite can turn a phishing incident into broader account compromise, fraud

CybercrimeMicrosoftPhishing
P0
2026-09-30 09:51 UTC
Vendor Research

Phishing Response Protocol: 3 Essential SOC Steps Powered by ANY.RUN’s Latest Updates

ANY.RUN Blog · ANY.RUN · indexed 2026-10-06 14:56 UTC

Phishing investigations put pressure on SOC teams at several points at once: analysts need to uncover hidden activity, make a confident decision from incomplete evidence, prepare the case for escalation, and then determine whether the threat extends beyond a single incident. Every manual step adds time to the response. It also ties up analyst capacity […] The post Phishing Response Protocol: 3 Essential SOC Steps Powered by ANY.RUN’s Latest Updates appeared first on ANY.RUN's Cybersecurity Blog.

DFIRPhishing
P0
2026-09-29 21:39 UTC
Vendor Research

Phishing Abuses RMM Tools for Persistent Access

Microsoft Security Blog · Microsoft Security Research, Parasharan Raghavan, Deva Kanna Kannan, Sai Chakri and Microsoft Defender Experts · indexed 2026-09-29 22:40 UTC

Microsoft observed phishing campaigns that abused MSP360 RMM to deploy ScreenConnect, creating redundant remote-access channels for follow-on activity The post Phishing Abuses RMM Tools for Persistent Access appeared first on Microsoft Security Blog.

MicrosoftPhishing
P0
2026-09-29 18:09 UTC
Security Journalism

Former US Air Force members sent to prison over BEC attacks

BleepingComputer · Sergiu Gatlan · indexed 2026-09-29 18:10 UTC

Two former members of the United States Air Force were sentenced to a combined 189 months in federal prison for their roles in a multi-year series of business email compromise (BEC) scams and phishing campaigns. [...]

Phishing
P0
2026-09-29 15:00 UTC
Vendor Research

Star Blizzard refines phishing and malware delivery with the RedFlick technique

Microsoft Security Blog · Microsoft Threat Intelligence · indexed 2026-09-29 15:35 UTC

Since January 2026, Microsoft has observed Russian state threat actor Star Blizzard evolve their detection evasion capabilities through large-scale phishing campaigns, the use of accounts on compromised websites, and a novel malware delivery technique, tracked by Microsoft as “RedFlick”. The post Star Blizzard refines phishing and malware delivery with the RedFlick technique appeared first on Microsoft Security Blog.

MalwareMicrosoftPhishingThreat Actors
P0
2026-09-29 14:00 UTC
Vendor Research

Defending Against Active Exploitation of Citrix NetScaler ADC and Gateway Appliances

Google Threat Intelligence / Mandiant · Mandiant · indexed 2026-09-29 14:00 UTC

Introduction In late September 2026, Mandiant Consulting and Google Threat Intelligence Group (GTIG) identified active, in-the-wild exploitation of a zero-day vulnerability (CVE-2026-88772) affecting Citrix NetScaler ADC and NetScaler Gateway appliances. We have observed evidence that organizations in North America and Europe in the government, financial services, technology, education, and legal and professional services sectors were likely impacted by this exploitation campaign, which has bee…

LinuxMalwareMicrosoftNetwork SecurityPhishingThreat ActorsThreat IntelligenceVulnerabilitiesCVE-2026-88771CVE-2026-88772
P30
2026-09-28 14:00 UTC
Security Journalism

⚡ Weekly Recap: $387M Crypto Hack, Citrix Exploits, AI Agents Go Off-Script, and More Threats

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-28 14:10 UTC

A domain used as harmless placeholder text showed up in roughly 1,700 repositories. Then somebody registered it and started serving malicious lures. That is the kind of week this was: forgotten assumptions turning into live attack surface. Elsewhere, weak service accounts, old bugs, exposed systems, phishing kits, and strangely easy exploit paths kept doing useful work for attackers. Nothing

AI SecurityPhishing
P0
1 2 3