IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 247 matching records.
AUTO-POLL // 2026-10-09 23:45 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P4 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 9

RANSOMWARE
P4
P4
COOL // 67 ARTICLES
THU
Oct 8

RANSOMWARE
P3
P3
COOL // 62 ARTICLES
WED
Oct 7

RANSOMWARE
P5
P5
COOL // 86 ARTICLES
TUE
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
RESET
2026-07-02 12:00 UTC
Security Journalism

Celebrating Canada Day with Localized Managed Phishing

Huntress · indexed 2026-09-07 17:30 UTC

Huntress Managed SAT now offers localized phishing simulations for Canada, using familiar, country-specific brands and scenarios to provide more effective security awareness training for your learners.

ApplePhishing
P0
2026-07-01 08:35 UTC
Other

Phishing in the Balkans: Fake Traffic Fines, Real Losses

Group-IB · indexed 2026-09-07 17:30 UTC

This blog documents Group-IB’s research into an SMS phishing campaign targeting Serbian road users through the impersonation of Serbia's state road authority, and how it can be linked to both Darcula and Phoenix PhaaS platforms with victims across the globe.

Phishing
P0
2026-06-18 04:45 UTC
Other

GitBait: Phishing dirigido al sector financiero mexicano

Group-IB · indexed 2026-09-07 17:30 UTC

Se ha descubierto una infraestructura de phishing modular dirigida a múltiples bancos mexicanos, que abusa de GitHub Pages, emplea scripts ofuscados y centraliza la exfiltración de credenciales mediante la API de SheetBest, lo que indica una operación de phishing escalable y persistente de múltiples marcas.

MicrosoftPhishing
P0
2026-06-17 06:57 UTC
Other

GitBait: Phishing the Mexican Financial Sector

Group-IB · indexed 2026-09-07 17:30 UTC

A modular phishing infrastructure targeting multiple Mexican banks has been uncovered, abusing GitHub-hosted Pages, employing obfuscated scripts, and featuring a centralized credential exfiltration via SheetBest API, indicating a scalable and persistent multi-brand phishing operation.

MicrosoftPhishing
P0
2026-06-15 14:00 UTC
Vendor Research

Public and Private Medical Community Targeted by China-Nexus Threat Actor Pursuing Artificial Intelligence, Cyber, Medical, and National Defense Research

Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-08-15 18:55 UTC

Written by: Patrick Whitsell, John McGuiness, Muhammad Umair Google Threat Intelligence Group (GTIG) has identified a sophisticated campaign attributed to UNC6508, a People's Republic of China (PRC)-nexus threat actor, targeting institutions in the North American academic, medical, and military research community. While remaining undetected for over a year, the threat actor compromised externally facing web applications, deployed bespoke malware, pivoted to sensitive internal systems, and abuse…

AI SecurityCloud SecurityDFIRMalwareMicrosoftPhishingThreat ActorsThreat Intelligence
P0
2026-06-10 07:33 UTC
Other

SilabRAT, What’s Your Power?

Group-IB · indexed 2026-09-07 17:30 UTC

SilabRAT (aka SnappyClient) is an advanced Remote Access Trojan (RAT) sold as a Malware-as-a-Service (MaaS) on Darkweb forums. Developed by the threat actor "o1oo1," SilabRAT is heavily focused on financial gain through credential theft. It offers stability and is capable of bypassing existing security measures.

MalwarePhishingThreat Actors
P0
2026-06-05 14:00 UTC
Vendor Research

Seeking Counsel: Ongoing Targeted Campaign Against US Law Firms

Google Threat Intelligence / Mandiant · Mandiant · indexed 2026-08-15 18:55 UTC

Written by: Chad Reams, Tufail Ahmed, Keith Knapp, Ashley Frazer, Tyler McLellan Introduction From January through May 2026, Mandiant identified a financially motivated data theft extortion campaign executed by the threat cluster UNC3753 (also tracked as "Luna Moth," “Chatty Spider,” and "Silent Ransom Group") targeting dozens of organizations across professional, legal, and financial services in the United States. UNC3753 leverages voice phishing (vishing) and social engineering deception tech…

Data BreachesDFIRMicrosoftPhishingThreat ActorsThreat Intelligence
P0
2026-05-29 14:19 UTC
Vendor Research

Amazon Cognito 1-Click Open Redirection via OAuth Error Handling Abuse

Tenable Research Advisories · Ben Smith · indexed 2026-08-15 18:55 UTC

Amazon Cognito 1-Click Open Redirection via OAuth Error Handling Abuse Researchers associated with Tenable have discovered a 1-click open redirection technique in Amazon Cognito that can be triggered by abusing the OAuth error-handling mechanism. The vulnerability stems from AWS's OAuth implementation validation sequence: if validation fails due to an unsupported scope, mismatched PKCE parameters, or an unsupported response type, the error handling processes the failure and automatically issues…

AppleCloud SecurityMalwarePhishingSecurity ResearchVulnerabilities
P0
2026-05-29 13:56 UTC
Vendor Research

Microsoft Entra ID 1-Click Open Redirection via OAuth Error Handling Abuse

Tenable Research Advisories · Ben Smith · indexed 2026-08-15 18:55 UTC

Microsoft Entra ID 1-Click Open Redirection via OAuth Error Handling Abuse Researchers associated with Tenable have discovered new techniques to trigger 1-click open redirection attacks in Microsoft Entra ID by abusing the OAuth error-handling mechanism. The attack relies on an initial setup phase where a threat actor registers an OAuth application in an actor-controlled tenant and configures its redirect_uri to point to an attacker-controlled domain. When a victim clicks on a specifically craf…

AppleMalwareMicrosoftPhishingSecurity ResearchThreat Actors
P0
2026-05-27 06:57 UTC
Other

The GHOST STADIUM Score: Billions At Stake At The World’s Largest Football Tournament

Group-IB · indexed 2026-09-07 17:30 UTC

With the 2026 FIFA World Cup just weeks away, Group-IB researchers have uncovered six distinct fraud schemes, four independent threat actors, and over 4,300 fraudulent domains impersonating FIFA's official web presence — including a sophisticated phishing operation run by the Chinese-speaking threat actor GHOST STADIUM, whose campaign could cause losses reaching billions of dollars.

CybercrimePhishingThreat Actors
P0
2026-05-25 14:00 UTC
Vendor Research

2 PhaaS 2 Furious: The Evolution of Chinese-Language Phishing Services

Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-08-15 18:55 UTC

While Russian-speaking threat actors have historically dominated the phishing-as-a-service (PhaaS) landscape, a rival ecosystem is rapidly growing within the Chinese-language underground. Google Threat Intelligence Group (GTIG) analyzed a dozen current PhaaS offerings in the Chinese underground, all of them mature services and many likely tied intricately to the broader criminal ecosystem in that region. These services not only lower the barrier to entry for Chinese cyber criminals, but reveal …

AppleCybercrimePhishingThreat ActorsThreat Intelligence
P0
2026-05-15 14:00 UTC
Vendor Research

Welcome to BlackFile: Inside a Vishing Extortion Operation

Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-08-15 18:55 UTC

Written by: Austin Larsen, Tyler McLellan, Genevieve Stark, Dan Ebreo Introduction Google Threat Intelligence Group (GTIG) has continued to track an expansive extortion campaign by UNC6671, a threat actor operating under the "BlackFile" brand, that targets organizations via sophisticated voice phishing (vishing) and single sign-on (SSO) compromise. By leveraging adversary-in-the-middle (AiTM) techniques to bypass traditional perimeter defenses and multi-factor authentication (MFA), UNC6671 gain…

Data BreachesMicrosoftNetwork SecurityPhishingThreat ActorsThreat IntelligenceVulnerabilities
P0
2026-04-29 06:54 UTC
Other

Phoenix Rising: Exposing the PhaaS Kit Behind Global Mass Phishing Campaigns

Group-IB · indexed 2026-09-07 17:30 UTC

While analyzing global smishing operations spanning APAC, LATAM, Europe, and MEA, Group-IB researchers uncovered the 'Phoenix System' administrative panel, a centralized Phishing-as-a-Service (PhaaS) platform with real-time victim monitoring, geofencing, and live-phishing interventions to bypass multi-factor authentication.

MicrosoftPhishing
P0
2026-04-23 14:00 UTC
Vendor Research

Snow Flurries: How UNC6692 Employed Social Engineering to Deploy a Custom Malware Suite

Google Threat Intelligence / Mandiant · Mandiant · indexed 2026-08-15 18:55 UTC

Written by: JP Glab, Tufail Ahmed, Josh Kelley, Muhammad Umair Introduction Google Threat Intelligence Group (GTIG) identified a multistage intrusion campaign by a newly tracked threat group, UNC6692, that leveraged persistent social engineering, a custom modular malware suite, and deft pivoting inside the victim’s environment to achieve deep network penetration. As with many other intrusions in recent years, UNC6692 relied heavily on impersonating IT helpdesk employees, convincing their victim…

Cloud SecurityMalwareMicrosoftPhishingThreat ActorsThreat Intelligence
P0
2026-04-01 10:32 UTC
Other

Hooking the Archipelago: Dissecting a Phishing Campaign Targeting Philippine Banking Users

Group-IB · indexed 2026-09-07 17:30 UTC

Group-IB researchers uncover an ongoing phishing campaign targeting major banks in the Philippines. This blog details how threat actors abuse trusted and legitimate platforms to deceive users and evade detection. It highlights a significant threat escalation with the successful hijacking of a legitimate domain to host malicious infrastructure, enabling threat actors to operate with even greater credibility and reduced detection.

PhishingThreat Actors
P0
4 5 6 7 8