IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 247 matching records.
AUTO-POLL // 2026-10-09 22:15 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P5 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 9

RANSOMWARE
P5
P5
COOL // 62 ARTICLES
THU
Oct 8

RANSOMWARE
P3
P3
COOL // 62 ARTICLES
WED
Oct 7

RANSOMWARE
P5
P5
COOL // 86 ARTICLES
TUE
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
RESET
2026-09-24 14:00 UTC
Vendor Research

Proactive Defense: Hardening Code Pipelines and CI/CD Infrastructure

Google Threat Intelligence / Mandiant · Mandiant · indexed 2026-09-24 15:25 UTC

Introduction The landscape of software supply chain security has undergone a significant shift. Recent campaigns demonstrate that sophisticated threat actors are systematically targeting the engineering lifecycle by compromising trusted security and programming tools. These intrusions reveal three key tactics: Attackers target trusted security scanners, utility libraries, and AI developer tools to exploit the elevated privileges granted to these systems within build pipelines. Adversaries targe…

AI SecurityMicrosoftPhishingThreat ActorsVulnerabilities
P0
2026-09-24 13:00 UTC
Vendor Research

When Business Email Compromise Starts Rewriting Reality

Rapid7 · Douglas McKee, Director, Vulnerability Intelligence · indexed 2026-09-24 13:20 UTC

Business Email Compromise (BEC) operates on a familiar playbook. Threat actors breach a mailbox, silently monitor operations, map approval chains, and ultimately exploit that access to divert funds or exfiltrate sensitive assets.This dynamic is central to our analysis as we kick off a series around Rapid7's collaborative research with Zimbra; upcoming installments will explore technical details and broader findings based within the Zimbra Collaboration Suite. Our investigation disrupted the tra…

CybercrimeDFIRMicrosoftPhishingThreat ActorsVulnerabilitiesCVE-2022-27925CVE-2022-37042CVE-2023-37580CVE-2024-45519CVE-2025-27915CVE-2026-73570
P70
2026-09-24 06:25 UTC
Community

One URL, Three Different Tricks, (Thu, Sep 24th)

SANS Internet Storm Center · indexed 2026-09-24 06:45 UTC

Yesterday, we received a phishing email with an interesting link. At first sight, it looks like garbage, but every piece of it has been carefully crafted to confuse basic security controls. Here is the defanged link:

Phishing
P0
2026-09-24 06:24 UTC
Other

No One Gets Phished: The New Group-IB Browser Agent Applies Predictive Intelligence At The Click

Group-IB · indexed 2026-09-24 09:10 UTC

One employee reaches a phishing page. The tab closes, the domain is blocked for every browser in the company, and the targeted password is already being reset. The new Group-IB Browser Agent brings the corporate browser under XDR coverage, checking every page against predictive Threat Intelligence in real time.

PhishingThreat Intelligence
P0
2026-09-23 14:45 UTC
Vendor Research

Supporting ASD’s multi-factor authentication campaign: Why MFA matters more than ever

AWS Security Blog · Grace Zhang · indexed 2026-09-23 15:00 UTC

The Australian Signals Directorate (ASD) has this month issued a clear call to action through its Multi-factor authentication: Switch it on campaign, urging businesses, organisations, and individuals to enable multi-factor authentication (MFA) across their online accounts. At AWS, we strongly support this message. As threat actors continue to target credentials through phishing, credential stuffing, and […]

Cloud SecurityNetwork SecurityPhishingThreat Actors
P0
2026-09-23 11:00 UTC
Other

EvilTokens made phishing-as-a-service look easy. Then it got taken down

Security Affairs · Pierluigi Paganini · indexed 2026-09-23 11:10 UTC

Microsoft, Coinbase and law enforcement took down EvilTokens, a phishing kit that compromised 12,000 inboxes through device-code phishing and AI. EvilTokens showed up in February 2026 and moved fast. Within months it had compromised more than 12,000 inboxes across over 10,000 organizations. Microsoft says the EvilTokens platform, operated by Storm-2992, is a phishing-as-a-service kit sold […]

MicrosoftPhishing
P0
2026-09-23 10:31 UTC
Vendor Research

Phishing Risk Across 5 Key US Industries: ANY.RUN Data & Mitigation Strategies

ANY.RUN Blog · ANY.RUN · indexed 2026-10-06 14:56 UTC

According to fresh ANY.RUN data, phishing exposure remains above 70% in several critical industries. This doesn’t happen because organizations aren’t protected enough. Companies have been implementing email filtering, MFA, and phishing-awareness training for years. However, threats continue to evolve, and security methods that were highly effective yesterday can develop visibility gaps as attackers adapt. In […] The post Phishing Risk Across 5 Key US Industries: ANY.RUN Data & Mitigation Strate…

Phishing
P0
2026-09-22 17:03 UTC
Security Journalism

Microsoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox Compromises

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-22 17:55 UTC

Microsoft on Tuesday announced the takedown of the EvilTokens device code phishing service that it said used artificial intelligence (AI) "at every step of the attack chain." The action, carried out with authorization from the U.S. District Court for the Eastern District of Virginia, involved the efforts of Health-ISAC, alongside Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, The Shadowserver

AI SecurityMicrosoftPhishing
P0
2026-09-22 15:00 UTC
Vendor Research

Unmasking EvilTokens: Getting to the root of device code phishing

Microsoft Security Blog · Microsoft Threat Intelligence, Microsoft Defender Experts and Microsoft Security Research · indexed 2026-09-22 16:30 UTC

EvilTokens has quickly become one of the top PhaaS platforms, enabling device code phishing attacks through AI-assisted lures, automated infrastructure, and token theft. In collaboration with partners, Microsoft Digital Crimes Unit (DCU) facilitated a disruption of EvilTokens infrastructure and operations. The post Unmasking EvilTokens: Getting to the root of device code phishing appeared first on Microsoft Security Blog.

MicrosoftPhishing
P0
2026-09-22 11:16 UTC
Vendor Research

CSuite Targets US and EU Organizations with Device-Code Phishing and Remote Access

ANY.RUN Blog · ShiFu · indexed 2026-10-06 14:56 UTC

ANY.RUN researchers investigated CSuite, a phishing and remote-access operation that combines credential theft, Microsoft 365 session hijacking, and the abuse of legitimate management tools. The campaign showed a strong US focus, with 51% of sessions from the United States. By blending trusted business services with legitimate remote-access software, CSuite can give attackers both account and […] The post CSuite Targets US and EU Organizations with Device-Code Phishing and Remote Access appeare…

MicrosoftPhishing
P0
2026-09-22 07:52 UTC
Security Journalism

SideCopy Broadens India Targeting to Academia With ReverseRAT Spear-Phishing

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-22 09:25 UTC

The threat actor known as SideCopy has been observed using spear-phishing lures to target academic institutions in India, expanding their strategic focus beyond government entities. "SideCopy campaign operations typically initiate through spear-phishing campaigns that leverage the abuse of mshta.exe to execute malicious scripts and circumvent standard security protocols," Trellix researchers

PhishingThreat Actors
P0
2026-09-21 13:16 UTC
Security Journalism

Microsoft reminds admins to migrate Entra ID users to passkeys

BleepingComputer · Sergiu Gatlan · indexed 2026-09-21 13:30 UTC

Microsoft has reminded admins to migrate Entra ID users to phishing-resistant authentication methods to avoid sign-in disruptions after it retires SMS first-factor sign-in starting in February 2027. [...]

MicrosoftPhishing
P0
2026-09-19 13:01 UTC
Other

AI Helps Hackers Hijack OpenAI Staff Accounts Through a Forum

Security Affairs · Pierluigi Paganini · indexed 2026-09-19 13:50 UTC

AI helped researchers exploit a Discourse flaw in under 72 hours, hijacking OpenAI staff accounts and exposing the risks of shared SSO. Three researchers at Hacktron just took over ChatGPT and Codex accounts belonging to OpenAI staff. The attack did not rely on phishing techniques or a leaked password. Through an image upload on OpenAI’s […]

Phishing
P0
2026-09-18 10:04 UTC
Other

RatHat Turns Android Accessibility Into an Attack Weapon

Security Affairs · Pierluigi Paganini · indexed 2026-09-18 10:50 UTC

RatHat combines AI-driven screen control, Android debugging abuse and advanced credential theft to give attackers deep control of infected phones. RatHat is the new Android trojan you should know about. Zimperium researchers just published a breakdown of a strain they’ve traced to China-based operators, and what makes it different isn’t the credential theft, which is […]

MalwareMobile SecurityPhishing
P0
2026-09-18 06:17 UTC
Security Journalism

RatHat Android Malware Abuses ADB to Retain Shell Access After Uninstall

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-18 06:30 UTC

Cybersecurity researchers have flagged a new Android malware called RatHat that's assessed to be operated by China-based threat actors and features an artificial intelligence (AI)-powered system to navigate and control compromised devices. "Distributed primarily via targeted smishing (SMS/text phishing) and malvertising campaigns leading to deceptive third-party download portals, RatHat uses

AI SecurityMalwareMobile SecurityPhishingSecurity ResearchThreat Actors
P0
2026-09-17 14:01 UTC
Security Journalism

What Recent AI-Powered Attacks Mean for Your Identity Security

BleepingComputer · Sponsored by Specops Software · indexed 2026-09-17 14:10 UTC

AI is making credential theft faster and easier to scale, giving attackers more opportunities to abuse valid identities. Specops explains why identity security must go beyond successful authentication by verifying that both the user and the device requesting access can be trusted. [...]

Phishing
P0
2026-09-16 11:58 UTC
Security Journalism

N0va Phishkit Targets US and EU Businesses: A New Challenge for Identity Security

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-16 12:45 UTC

N0va is targeting organizations across North America and Europe with phishing campaigns that impersonate trusted services and abuse legitimate authentication flows. Successful attacks can give threat actors access to valid accounts without relying on obvious malware activity. From there, a single compromised identity can open the door to sensitive data, business systems, and additional cloud

MalwarePhishingThreat Actors
P0
2026-09-15 12:22 UTC
Vendor Research

CVE-2026-76461: Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild

Rapid7 · Rapid7 · indexed 2026-09-15 12:55 UTC

OverviewOn September 14, 2026, Cisco published a security advisory for CVE-2026-76461, a critical SQL injection vulnerability affecting Cisco AsyncOS Software for Cisco Secure Email Gateway. The vulnerability has a reported CVSS v3.1 base score of 9.8 and could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on an affected appliance.Cisco Secure Email Gateway, formerly known as IronPort Email Security Appliance, is an enterprise email security produc…

MalwarePhishingThreat ActorsVulnerabilitiesCVE-2026-76461
P80
2026-09-15 11:26 UTC
Security Journalism

Attack Chains, Not Just Attack Surfaces: Why Testing Individual Techniques Misses the Point

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-15 12:25 UTC

Introduction Security teams have gotten pretty good at testing against what can hurt them. Can this EDR agent catch this payload? Will my organization fail the phishing simulation? Does this SIEM rule fire on this particular technique? And, in more mature organizations, this testing happens continuously rather than as a one-off exercise. But no matter how much you validate against these

Phishing
P0
2026-09-15 10:17 UTC
Other

One Exploit Chain, Two Espionage Campaigns: Chrome and Windows Under Fire

Security Affairs · Pierluigi Paganini · indexed 2026-09-15 11:30 UTC

Two China-linked groups ran identical Chrome/Windows zero-day exploits against NGOs, before Chrome’s patch shipped, deploying different backdoors each. Two China-linked threat actors used the same Chrome/Windows zero-day against NGOs starting September 1, 2026, Volexity’s new report lays out the whole chain in detail. On September 1, Volexity detected a spear-phishing campaign by UTA0560 targeting several […]

APT / Nation-StateMalwareMicrosoftPhishingThreat ActorsVulnerabilities
P25
2026-09-15 05:31 UTC
Security Journalism

China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-15 06:25 UTC

A Chinese threat actor has been attributed to a spear-phishing campaign that exploits recently patched security flaws in Google Chrome and Microsoft Windows to deliver a malicious JavaScript backdoor called GRIMWEDGE. Volexity, which is tracking the threat cluster under the moniker UTA0560, said the activity targeted multiple non-governmental organizations (NGOs) on September 1, 2026. "The

Cloud SecurityMalwareMicrosoftPhishingThreat ActorsVulnerabilities
P25
2026-09-14 07:57 UTC
Other

Smish. Click. Drained: Inside the Smishing Triad’s Phishing Cockpit

Group-IB · indexed 2026-09-14 08:30 UTC

A deep technical analysis of the Smishing Triad’s JWR phishing kit and Outsider operator cluster, revealing its real-time victim control, encrypted WebSocket communications, multi-stage credential theft, AES-256-CTR implementation, infrastructure, and actionable indicators for defenders.

MicrosoftPhishing
P0
2026-09-13 10:11 UTC
Security Journalism

Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-13 10:25 UTC

Microsoft has disclosed details of two campaigns in which threat actors are abusing third-party email delivery infrastructure to blast financial fraud scam messages and using passkey-themed social engineering to breach cloud environments. The first campaign, per the tech giant, involved sending over a million scam emails between August 3 and 5, 2026, by masquerading as chief executive officers

CybercrimeMicrosoftPhishingThreat Actors
P0
1 2 3 4