IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 229 matching records.
AUTO-POLL // 2026-10-09 22:50 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P5 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 9

RANSOMWARE
P5
P5
COOL // 62 ARTICLES
THU
Oct 8

RANSOMWARE
P3
P3
COOL // 62 ARTICLES
WED
Oct 7

RANSOMWARE
P5
P5
COOL // 86 ARTICLES
TUE
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
RESET
2026-01-15 06:07 UTC
Other

DeadLock Ransomware: Smart Contracts for Malicious Purposes

Group-IB · indexed 2026-09-07 17:30 UTC

This blog uncovers DeadLock’s stealthy usage of Polygon smart contracts for proxy address storage, a poorly-documented and under-reported technique that Group-IB analysts have observed increased usage in the wild. Variants of this technique are very wide and offer great alternatives to threat actors for bypassing traditional defenses by abusing decentralized blockchains available worldwide.

MicrosoftRansomwareThreat Actors
P35
2025-12-08 06:00 UTC
Security Journalism

Hardening the Hypervisor | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

Hypervisors are a major target for ransomware attacks. Get expert guidance from Huntress on how to protect your virtualized infrastructure. Learn how to secure access, put runtime controls in place, simplify patching, and improve your recovery plans.

Ransomware
P15
2025-11-05 15:00 UTC
Security Journalism

Gootloader | Threat Detection Overview

Huntress · indexed 2026-09-07 17:30 UTC

Gootloader returns with new obfuscation techniques, including custom WOFF2 fonts and updated persistence mechanisms, while continuing its partnership with Vanilla Tempest for ransomware deployment. Dive in and discover what Huntress is seeing.

Ransomware
P15
2025-10-22 05:00 UTC
Security Journalism

Looking Through a Pinhole at a Qilin Ransomware Attack

Huntress · indexed 2026-09-07 17:30 UTC

Incident analysis is critical, but for newcomers, it can be daunting. Learn how to confirm commands, validate findings, and spot real impact during a Qilin ransomware event.

Ransomware
P15
2025-10-16 05:00 UTC
Security Journalism

Dispelling Ransomware Deployment Myths

Huntress · indexed 2026-09-07 17:30 UTC

Huntress analyzes ransomware activity, uncovering attack patterns and key detection opportunities while dispelling ransomware myths.

Ransomware
P15
2025-08-21 21:00 UTC
Security Journalism

Cephalus Ransomware: Don’t Lose Your Head

Huntress · indexed 2026-09-07 17:30 UTC

In mid-August, Huntress saw two incidents that linked back to a ransomware variant called Cephalus, which included DLL sideloading via a legitimate SentinelOne executable.

Ransomware
P15
2025-08-19 14:00 UTC
Security Journalism

Exposing Data Exfiltration | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

Threat actors often steal data during the course of their attacks. This is particularly true for ransomware threat actors, who do it before deploying file encryption in order to engage in “double extortion” activities. This activity can be difficult to detect, particularly if it’s not dissimilar to legitimate actions taken by system administrators.

RansomwareThreat Actors
P15
2025-08-14 05:00 UTC
Security Journalism

Kawabunga, Dude, You’ve Been Ransomed!

Huntress · indexed 2026-09-07 17:30 UTC

Thanks in large part to our customer base, Huntress sees a great deal of interesting activity, particularly from threat actors (but also from admins). Part of that activity includes not just ransomware variants that Huntress hasn’t seen before, but also variants that may not have been documented via any public means. Further, when these incidents occur, Huntress very often gets a detailed look at the threat actor’s activity, including commands and their timing.

RansomwareThreat Actors
P15
2025-08-13 22:00 UTC
Security Journalism

Active Exploitation of SonicWall VPNs

Huntress · indexed 2026-09-07 17:30 UTC

A likely zero-day vulnerability in SonicWall VPNs is being actively exploited to bypass MFA and deploy ransomware. Huntress advises disabling the VPN service immediately or severely restricting access via IP allow-listing. We're seeing threat actors pivot directly to domain controllers within hours of the initial breach.

Network SecurityRansomwareThreat ActorsVulnerabilities
P40
2025-05-13 05:00 UTC
Security Journalism

Time to Ransom is Money

Huntress · indexed 2026-09-07 17:30 UTC

During ransomware attacks, the average time-to-ransom for attackers is almost 17 hours. Learn more about what this means for businesses.

Ransomware
P15
2025-04-30 06:00 UTC
Other

Ransomware debris: an analysis of the RansomHub operation

Group-IB · indexed 2026-09-07 17:30 UTC

This blog on RansomHub provides an overview into how this Ransomware-as-a-Service (RaaS) group operates, including its extortion tactics, affiliate recruitment strategies, and the features of its affiliate panel.

Ransomware
P15
2025-04-10 05:00 UTC
Security Journalism

Ransomware Initial Access Brokers Exposed

Huntress · indexed 2026-09-07 17:30 UTC

Discover how a seemingly simple brute force attack led to the uncovering of a suspected ransomware-as-a-service operation. This ecosystem appears to be leveraged by initial access brokers, driving an illicit and complex network of cybercrime.

CybercrimeRansomware
P15
2025-04-02 06:02 UTC
Other

The beginning of the end: the story of Hunters International

Group-IB · indexed 2026-09-07 17:30 UTC

Learn about technical details on the ransomware and Storage Software tool, how the criminals use the affiliate panel as well as information on the Hunters International ransomware group from its emergence to the end of the operation.

Ransomware
P15
2025-02-11 00:00 UTC
Security Journalism

2025 Cybersecurity Threat Report | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

Huntress’ 2025 Cyber Threat Report is here! Explore the year's biggest threats—RATs, phishing, ransomware—and how evolving tactics demand smarter defense.

PhishingRansomware
P15
2025-01-28 06:43 UTC
Other

Cat’s out of the bag: Lynx Ransomware-as-a-Service

Group-IB · indexed 2026-09-07 17:30 UTC

In this blog, we observed how the Lynx Ransomware-as-a-Service (RaaS) group operates, detailing the workflow of their affiliates within the panel, their cross-platform ransomware arsenal, customizable encryption modes, and advanced technical capabilities.

Ransomware
P15
4 5 6 7 8