IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 229 matching records.
AUTO-POLL // 2026-10-09 21:25 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P5 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 9

RANSOMWARE
P5
P5
COOL // 60 ARTICLES
THU
Oct 8

RANSOMWARE
P3
P3
COOL // 62 ARTICLES
WED
Oct 7

RANSOMWARE
P5
P5
COOL // 86 ARTICLES
TUE
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
RESET
2026-09-17 08:15 UTC
Vendor Research

How MSSPs Can Prove Their Value When “Nothing Happened”

ANY.RUN Blog · ANY.RUN · indexed 2026-10-06 14:56 UTC

For an MSSP, a quiet month can be a good month. No ransomware outbreak. No major account compromise. No business disruption. But it can also create an awkward conversation with the client: What exactly did we pay for this month? The problem is not that the SOC did nothing. Quite the opposite. Analysts may have […] The post How MSSPs Can Prove Their Value When “Nothing Happened” appeared first on ANY.RUN's Cybersecurity Blog.

Ransomware
P15
2026-09-16 15:27 UTC
Security Journalism

Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-16 16:25 UTC

Enterprises in Russia have emerged as the target of three threat activity clusters tracked as NightEagle, Hacking Cat, and Toy Ghouls, according to multiple reports from Kaspersky. The cybersecurity vendor said it has identified attacks mounted by NightEagle (aka APT-Q-95), a threat actor known to be active since at least 2023, that involve new techniques for persistence and lateral movement.

APT / Nation-StateMalwareRansomwareThreat Actors
P15
2026-09-16 14:00 UTC
Security Journalism

The true cost of a ransomware attack, with and without BCDR

BleepingComputer · Sponsored by Datto · indexed 2026-09-16 14:20 UTC

The ransom itself can be only a fraction of the total cost of a ransomware attack, with downtime, recovery, remediation, and legal obligations adding millions to the bill. Datto explains how a mature BCDR strategy can reduce downtime and provide a faster, more predictable path to recovery. [...]

Ransomware
P15
2026-09-13 09:19 UTC
Other

Conti Hacker Who Built Malware and Attacked Victims Gets Four-Year Sentence

Security Affairs · Pierluigi Paganini · indexed 2026-09-13 10:15 UTC

Ukrainian lawyer and Conti malware developer Oleksii Lytvynenko was sentenced to four years in U.S. prison for ransomware attacks. Oleksii Oleksiyovych Lytvynenko had, by most accounts, a fairly ordinary legal career in Ukraine before he switched to writing malware. A US federal court sentenced the 44-year-old to four years in prison this week for conspiracy […]

MalwareNetwork SecurityRansomware
P15
2026-09-11 10:14 UTC
Other

Attackers Exploit Critical Cisco FMC Flaw to deploy Qilin ransomware

Security Affairs · Pierluigi Paganini · indexed 2026-09-11 10:55 UTC

Three threat groups are exploiting two Cisco FMC flaws to steal credentials, gain root access and deploy Qilin ransomware. Cisco Talos says three separate threat groups are exploiting two recently patched Secure Firewall Management Center (FMC) flaws. The main target is CVE-2026-20079, a critical authentication bypass that lets unauthenticated attackers remotely bypass security controls, run […]

Cloud SecurityNetwork SecurityRansomwareVulnerabilitiesCVE-2026-20079
P30
2026-09-11 06:19 UTC
Security Journalism

Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-11 07:40 UTC

Cisco has revealed that three distinct threat clusters linked to ransomware and state-sponsored attacks have been exploiting two recently patched Secure Firewall Management Center (FMC) vulnerabilities. The attacks leverage CVE-2026-20079 (CVSS score: 10.0), an authentication bypass vulnerability in the web interface of FMC software that could allow an unauthenticated, remote attacker to bypass

APT / Nation-StateCloud SecurityNetwork SecurityRansomwareVulnerabilitiesCVE-2026-20079
P30
2026-09-08 21:44 UTC
Vendor Research

Patch Tuesday - September 2026

Rapid7 · Rapid7 · indexed 2026-09-09 00:10 UTC

Microsoft is publishing 974 own-product vulnerabilities on September 2026 Patch Tuesday, including 723 vulnerabilities in Windows. Along with Microsoft fixes for 25 non-Microsoft CVEs, that brings the total number of vulnerabilities on the table today to 999. Whether this is the biggest Patch Tuesday ever depends on how we count, but this is by far the most CVEs that Microsoft has ever published in a single day. As Rapid7 noted last month, there is no reason to suppose that Patch Tuesday will e…

Cloud SecurityLinuxMicrosoftRansomwareVulnerabilitiesCVE-2026-81963CVE-2026-84323CVE-2026-84324CVE-2026-84325CVE-2026-84326CVE-2026-84327CVE-2026-84328CVE-2026-84329CVE-2026-84331CVE-2026-84332CVE-2026-84334CVE-2026-84335CVE-2026-84347CVE-2026-84348CVE-2026-84349CVE-2026-84350CVE-2026-84351CVE-2026-84353CVE-2026-84354CVE-2026-84355CVE-2026-85045CVE-2026-85046CVE-2026-85880
P65
2026-09-08 14:00 UTC
Vendor Research

GTIG AI Threat Tracker: From Prompting to Autonomy – The Evolution of Adversarial AI

Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-09-08 13:45 UTC

Executive Summary Since the release of our May 2026 report detailing adversarial misuse of artificial intelligence (AI), Google Threat Intelligence Group (GTIG) has observed forward leaning adversaries transition from basic prompting to agentic AI workflows and AI-enabled automation. In these operations, human-in-the-loop latency is dramatically reduced, compressing the traditional window for defenders to respond. In Q2 2026, GTIG observed threat actors compromise a cloud resource, then plan, b…

AI SecurityAPT / Nation-StateCloud SecurityData BreachesDFIRMalwareMicrosoftPhishingRansomwareThreat ActorsThreat IntelligenceVulnerabilities
P35
2026-09-07 07:19 UTC
Other

Berlin Ransomware Leak Exposes State Secrets

Security Affairs · Pierluigi Paganini · indexed 2026-09-07 08:30 UTC

Berlin refused a 30 Bitcoin ransom, leading hackers to leak 6TB of sensitive state administration and national defense data on the dark web. When a ransomware gang dumps nearly six terabytes of state administration files onto the dark web, ignoring them does not make the problem go away. The Rhysida ransomware group recently carried out […]

CybercrimeRansomware
P15
2026-09-03 21:15 UTC
Vendor Research

Incident response guide for AWS CloudTrail investigations – Part 2

AWS Security Blog · Oscar Diaz · indexed 2026-09-03 21:35 UTC

In Part 1 of this guide, we examined two common incident scenarios: cross-account Amazon Simple Storage Service (Amazon S3) data deletion with ransomware implications, and cryptocurrency mining deployed through AWS CloudFormation using exposed AWS Management Console credentials. We also introduced key incident response terminology and investigative frameworks for analyzing AWS CloudTrail events. In this second […]

AppleCloud SecurityDFIRRansomware
P15
2026-09-02 14:02 UTC
Security Journalism

Ransomware protection for MSPs: A 6-point checklist for faster recovery

BleepingComputer · Sponsored by Acronis · indexed 2026-09-02 14:15 UTC

Ransomware resilience requires more than backups or endpoint detection alone. Acronis outlines six capabilities MSPs should test across client environments, from reducing exposure and detecting attacks to preserving recovery points and restoring operations quickly. [...]

Ransomware
P15
2026-08-31 11:47 UTC
Security Journalism

Aurora Ransomware Operators Use Cursor AI in Attacks Against 10 Targets

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-31 12:30 UTC

Threat actors associated with Aurora (aka Aur0ra) ransomware have been observed using SpaceX's artificial intelligence (AI)-powered coding assistant Cursor to break into target networks, according to findings from CloudSEK and Gambit Security. The two independent analyses are based on exposed infrastructure associated with the Russian-speaking cybercrime group, leading to the discovery of its

AI SecurityCybercrimeRansomwareThreat Actors
P15
2026-08-30 08:38 UTC
Other

Security Affairs newsletter Round 592 by Pierluigi Paganini – INTERNATIONAL EDITION

Security Affairs · Pierluigi Paganini · indexed 2026-08-30 09:40 UTC

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. Hack One Robot, Reach the Next: Unitree G1 Security Flaws Rhysida Ransomware Group Targets Berlin Government Ahead […]

Cloud SecurityRansomware
P15
2026-08-29 10:55 UTC
Other

Rhysida Ransomware Group Targets Berlin Government Ahead of Vote

Security Affairs · Pierluigi Paganini · indexed 2026-08-29 11:35 UTC

Berlin ‘s government faces a Rhysida ransomware attack weeks before elections, with officials refusing to pay despite a claimed 5.79 TB data theft. Berlin’s state government confirmed this week it’s dealing with an extortion attempt following an August cyberattack on the city-state’s administrative network, and officials have already refused the requested ransom. The ransomware group […]

Ransomware
P15
2026-08-28 10:09 UTC
Vendor Research

PaperCut NG/MF Critical Zero-Day Exploited in the Wild

Rapid7 · Rapid7 · indexed 2026-08-28 10:30 UTC

Overview On August 27, 2026, PaperCut Software published an urgent security advisory stating that it is investigating active exploitation of a vulnerability affecting PaperCut NG and PaperCut MF. PaperCut has confirmed customer incidents and is treating the issue as a security emergency. At the initial time of disclosure, the vulnerability had not been assigned a CVE identifier, and PaperCut had not publicly disclosed a CVSS score, vulnerability class, authentication requirements, or the techni…

DFIRNetwork SecurityRansomwareThreat IntelligenceVulnerabilitiesCVE-2023-27350CVE-2026-81578CVE-2026-82078
P100
2026-08-27 13:00 UTC
Security Journalism

Retail Cybersecurity in ANZ: Five Decisions That Keep Trading

Huntress · indexed 2026-09-07 17:30 UTC

Protect your Australia- and New Zealand-based retail business from cyber threats. Learn five key decisions to secure identities, manage dependencies and ensure trading continuity against ransomware

Ransomware
P15
1 2 3 4 5