IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 229 matching records.
AUTO-POLL // 2026-10-09 21:25 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P5 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 9

RANSOMWARE
P5
P5
COOL // 60 ARTICLES
THU
Oct 8

RANSOMWARE
P3
P3
COOL // 62 ARTICLES
WED
Oct 7

RANSOMWARE
P5
P5
COOL // 86 ARTICLES
TUE
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
RESET
2026-10-09 18:45 UTC
Other

Germany Arrests Suspected Qilin Ransomware Leader After Japan Detention

Security Affairs · Pierluigi Paganini · indexed 2026-10-09 19:50 UTC

Japan helped extradite a Russian suspect linked to Qilin ransomware to Germany, but the gang continued attacking victims after his arrest. Germany has arrested a Russian national believed to be a leading figure in the Qilin ransomware group, and Japan’s National Police Agency just put its own role in that arrest on the record. The […]

Law EnforcementRansomware
P15
2026-10-08 20:09 UTC
Security Journalism

Ransomware attack disrupts Japan's IDCF Cloud used by govt clients

BleepingComputer · Bill Toulas · indexed 2026-10-08 20:20 UTC

IDC Frontier, a major Japanese cloud and digital infrastructure company, disclosed that its IDCF Cloud service was targeted in a ransomware attack that caused an outage at a data center cluster serving the eastern part of the country. [...]

Ransomware
P15
2026-10-08 17:58 UTC
Security Journalism

ThreatsDay: Ransomware Affiliate Betrayal, WhatsApp RAT, Exposed Hacker Tools and 12 More Stories

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-08 18:55 UTC

The crooks have trust problems of their own. One ransomware affiliate decided to keep the profits for himself. Elsewhere, an attacker left a server exposed, complete with tools and traces of an intrusion. Apparently, keeping things secure is a problem on both sides of the fence. The rest of the week isn't much more reassuring. Malicious code turned up in developer packages and extensions that

Ransomware
P15
2026-10-08 13:37 UTC
Other

MonsterCloud Owner Charged With Secretly Paying Ransomware Demands

Security Affairs · Pierluigi Paganini · indexed 2026-10-08 14:50 UTC

MonsterCloud owner Zohar Pinhasi allegedly paid ransomware demands behind clients’ backs, then charged them millions for the supposed recovery. Zohar Pinhasi, the owner of Florida-based MonsterCloud, was charged this week with wire fraud. Federal prosecutors say his clients were scammed twice during the same ransomware crisis. Pinhasi (50) also used the names “Zack Silver” and […]

CybercrimeRansomware
P15
2026-10-08 09:27 UTC
Security Journalism

Fake Decryption Tools Masked $11M Markup in Ransomware Recovery Scheme

Security Week · Ionut Arghire · indexed 2026-10-08 09:30 UTC

Zohar Pinhasi was paying ransoms to obtain decryption keys and then charging victims substantially more for remediation. The post Fake Decryption Tools Masked $11M Markup in Ransomware Recovery Scheme appeared first on SecurityWeek.

Ransomware
P15
2026-10-08 07:41 UTC
Security Journalism

MonsterCloud Owner Accused of Billing Over $19M While Secretly Paying Ransoms to Decrypt Data

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-08 08:10 UTC

The U.S. Department of Justice (DoJ) on Wednesday announced charges against a 50-year-old U.S. and Israeli national for allegedly defrauding ransomware victims by secretly paying the attackers to obtain decryptors while claiming to use proprietary tools to recover their data. Zohar Pinhasi (aka Zack Silver and Zack Green) has been charged with two counts of wire fraud and one count of wire

CybercrimeLaw EnforcementRansomware
P15
2026-10-07 23:04 UTC
Security Journalism

Ransomware recovery CEO charged over secret ransom payments

BleepingComputer · Lawrence Abrams · indexed 2026-10-07 23:15 UTC

The owner of ransomware remediation company MonsterCloud has been charged with allegedly defrauding ransomware victims by secretly paying their attackers for decryptors while claiming to use proprietary technology to recover encrypted data. [...]

CybercrimeRansomware
P15
2026-10-07 19:29 UTC
Vendor Research

Four compliance frameworks, one security team: Why fragmented university security raises regulatory risk

Rapid7 · Rapid7 · indexed 2026-10-07 19:50 UTC

In Part 1 of this series, we looked at the security challenges created by fragmented, campus-by-campus environments. Higher education also faces a second pressure that makes that fragmentation harder to sustain: overlapping compliance obligations across FERPA, GLBA, HIPAA, and CMMC.Each framework brings different requirements, reporting timelines, and consequences for failure. Managing them across one institution is already complex, but across a multi-campus university system with separate tool…

DFIRMicrosoftRansomware
P15
2026-10-07 14:01 UTC
Security Journalism

Ransomware has a new target. Is your backup ready?

BleepingComputer · Sponsored by Kaseya · indexed 2026-10-07 14:10 UTC

Ransomware groups are increasingly targeting backup infrastructure to eliminate recovery options and increase pressure on victims to pay. Kaseya explains why organizations need isolated, immutable, and regularly tested backups that attackers cannot easily reach. [...]

Ransomware
P15
2026-10-06 11:27 UTC
Vendor Research

IronChain Ransomware Threatens Businesses with Permanent Data Loss and Costly Downtime

ANY.RUN Blog · Himanshu Anand · indexed 2026-10-06 14:56 UTC

Editor’s note: This research was conducted by Himanshu Anand, an independent cybersecurity researcher (follow Himanshu on X). During Cybersecurity Awareness Month, ransomware remains one of the clearest examples of how a cyber incident can become a business continuity issue. IronChain shows why. It puts business-critical data at risk of permanent loss and can bring operations […] The post IronChain Ransomware Threatens Businesses with Permanent Data Loss and Costly Downtime appeared first on AN…

RansomwareSecurity Research
P15
2026-10-06 08:19 UTC
Security Journalism

Engineer sentenced for locking over 3,000 devices on employer network

BleepingComputer · Sergiu Gatlan · indexed 2026-10-06 08:20 UTC

A former core infrastructure engineer at an industrial company headquartered in New Jersey was sentenced to 32 months in prison for locking thousands of devices on his employer's network in a ransomware-style attack. [...]

Ransomware
P15
2026-10-05 14:20 UTC
Security Journalism

⚡ Weekly Recap: NetScaler and FortiMail 0-Days, AI Coding Leaks, Spectre v2 and Ransomware Arrests

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-05 15:15 UTC

A blank field. A public repo. One reply to an email. A box left exposed. None of this sounds dramatic, which is partly the problem. This week’s threats keep finding leverage in small things that were easy to overlook. There are actively exploited bugs in the mix, cleaner intrusion paths, smarter automation, and a long patch list waiting behind them. Some attacks are getting more capable. Others

RansomwareVulnerabilities
P40
2026-10-04 07:49 UTC
Other

Warlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical Infrastructure

Security Affairs · Pierluigi Paganini · indexed 2026-10-04 08:00 UTC

Warlock ransomware continues to exploit unpatched SharePoint flaws to breach water utilities, telecoms, governments, and universities worldwide. Warlock ransomware made headlines back in mid-2025 for exploiting a chain of SharePoint zero-days collectively dubbed ToolShell. More than a year later, the same group is still using that door, and it’s still getting in. Symantec tracks the […]

Cloud SecurityMicrosoftRansomwareVulnerabilities
P40
2026-10-03 14:36 UTC
Security Journalism

Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-03 15:25 UTC

The suspected China-linked threat actor known as Warlock is still continuing to weaponize Microsoft SharePoint vulnerabilities, likely both old and new, in attacks targeting organizations in Portuguese- and Spanish-speaking countries. The activity, observed by the Symantec and Carbon Black Threat Hunter Team, has hit critical infrastructure, government, and education organizations. "In the

Cloud SecurityMicrosoftRansomwareThreat Actors
P15
2026-10-01 18:08 UTC
Other

Operation KillSwitch: Police Dismantle KillSec Ransomware Group

Security Affairs · Pierluigi Paganini · indexed 2026-10-01 19:00 UTC

Operation KillSwitch: Europol says the KillSec ransomware group, allegedly led by a 16-year-old, was dismantled after attacks on about 1,000 victims. Law enforcement seized control of KillSec ‘s dark web leak site, the Tor website the group used to threaten victims with publishing stolen files unless they paid up. That single action locked down more […]

CybercrimeLaw EnforcementNetwork SecurityRansomware
P15
2026-10-01 16:55 UTC
Security Journalism

Police Arrest 16-Year-Old Suspected of Running KillSec, Seize Ransomware Leak Site and Servers

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-01 17:15 UTC

Police in Spain have arrested a 16-year-old whom investigators suspect of running the KillSec ransomware group. KillSec is accused of stealing data from organizations and threatening to publish it on its leak site unless they paid. The 16-year-old was one of 3 people arrested on September 30, when police also took control of that site. Investigators identified him as KillSec's suspected

Law EnforcementRansomware
P15
1 2 3