IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 163 matching records.
AUTO-POLL // 2026-10-09 21:40 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P5 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 9

RANSOMWARE
P5
P5
COOL // 62 ARTICLES
THU
Oct 8

RANSOMWARE
P3
P3
COOL // 62 ARTICLES
WED
Oct 7

RANSOMWARE
P5
P5
COOL // 86 ARTICLES
TUE
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
RESET
2026-10-09 19:14 UTC
Security Journalism

Credential-Stealing GitHub Actions Workflows Planted in Tens of Thousands of Repositories

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-09 20:55 UTC

Cybersecurity researchers have disclosed details of an ongoing credential-theft campaign that has compromised two high-profile open-source maintainer accounts to push a malicious workflow into over 340 repositories. "Using the account of Takashi Kitao, author of the 18,400-star game engine pyxel, the attacker pushed a malicious workflow to 27 repositories starting at 13:20 UTC," StepSecurity

Security Research
P0
2026-10-09 16:29 UTC
Security Journalism

P7 DarkSword iOS Exploit Kit Adds Crypto Wallet Data Theft and Remote Commands

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-09 16:50 UTC

Cybersecurity researchers have disclosed details of a previously unseen variant of the DarkSword iOS exploit kit called P7 DarkSword. "Compared with the variants we usually observe, P7 reduces its on-device footprint, adds on-device keychain and crypto-wallet theft, and adds two way C2 communication with the attacker's infrastructure," iVerify said in a new report published Thursday. The name

AppleSecurity Research
P0
2026-10-09 12:59 UTC
Security Journalism

Researchers Publish Working Exploit for Pre-Auth AnyDesk Linux Flaw That Gives Root Access

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-09 14:35 UTC

Security researchers have published a full working exploit for a pre-authentication remote code execution flaw in AnyDesk Linux that gives attackers root access before anyone approves the connection. AnyDesk patched the flaw in version 8.0.3 in June, but its changelog described the fix only as "fixed a bug that could lead to a crash," with no CVE assigned and no security

LinuxSecurity ResearchVulnerabilities
P15
2026-10-08 14:12 UTC
Security Journalism

ARTEX AI Pentesting Tool Used in Data Theft Attacks on South Korean Financial Firms

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-08 15:40 UTC

Cybersecurity researchers have disclosed details of a targeted campaign aimed at South Korean financial organizations that used an artificial intelligence (AI) pen testing tool named ARTEX to carry out the attacks. The activity, per CrowdStrike Intelligence, was active from late September to early October 2026, and resulted in data exfiltration from various South Korea-based financial firms,

AI SecuritySecurity Research
P0
2026-10-08 12:50 UTC
Vendor Research

Inside the Exchange Inspector: How Tenable uses OpenAI GPT cyber models to review open-source AI agents

Tenable Blog · Robert McSulla · indexed 2026-10-08 13:10 UTC

Community-built AI agents, skills, and MCP servers are landing in SOC workflows fast. Here’s what the Exchange Inspector tests before a listing earns its vetted tag on the CyberAgents Exchange. Three tools have already passed.Key takeawaysEvery Inspector-vetted listing clears three gates: an automated check, a frontier model assessment, and human verification. Tenable uses Tenable One AI Exposure to screen for prompt injection and exposed secrets, and OpenAI GPT Cyber models to assess the code …

AI SecurityCloud SecurityDFIRICS / OTMalwareMicrosoftNetwork SecurityPhishingSecurity ResearchThreat IntelligenceVulnerabilities
P0
2026-10-08 09:46 UTC
Security Journalism

16 Malicious Firefox Extensions Pose as Rabby and OKX Wallets to Steal Recovery Phrases

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-08 09:55 UTC

Cybersecurity researchers have discovered a cluster of 16 malicious Mozilla Firefox extensions that are capable of stealing cryptocurrency wallet recovery phrases and private keys. "The extensions masquerade as wallet portals, desktop utilities, and browser tools, but their code intercepts recovery phrases and private keys during wallet import flows and attempts to send those secrets to

Security Research
P0
2026-10-07 17:43 UTC
Security Journalism

Eight Malicious npm Packages Downloaded 40,767 Times Deliver Overlord RAT and Stealer

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-07 17:55 UTC

Cybersecurity researchers have disclosed details of a long-running npm supply chain malware campaign that pushes information stealers and remote access trojans (RAT) to compromised hosts. The campaign has been codenamed MALFEX by CloudSEK and Checkmarx. The activity is assessed to be the work of a lone threat actor who appears to have published 12 packages since August 2023, eight of which have

MalwareSecurity ResearchThreat Actors
P0
2026-10-07 15:33 UTC
Security Journalism

PoeLLM Malware Infects 3,400+ Servers to Expand Crypto Mining Botnet

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-07 16:15 UTC

Cybersecurity researchers are calling attention to a new malware family that has been observed targeting exposed artificial intelligence (AI) and large language model (LLM) infrastructure with an aim to deploy cryptocurrency miners and further expand the scale of the botnet. The financially motivated campaign, dubbed Canto Incognito, has been found to install cryptocurrency miners, including

AI SecurityMalwareSecurity Research
P0
2026-10-06 18:38 UTC
Security Journalism

Fake ChatGPT, Gemini, and Claude Ad Portals Capture Credentials and MFA Codes

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-06 20:15 UTC

Cybersecurity researchers have disclosed details of a "human-operated phishing platform" that impersonates advertising products for artificial intelligence (AI) chatbots like Google Gemini, Anthropic Claude, OpenAI ChatGPT, Perplexity, Meta Muse, and Manus. The products, which claim to offer campaign optimization, spend audits, and business-account connections, are designed with one goal in

AI SecurityPhishingSecurity Research
P0
2026-10-06 11:57 UTC
Security Journalism

LibreOffice and OpenOffice Flaws Let Malicious Spreadsheets Run Code Without Macro Warnings

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-06 12:00 UTC

A malicious spreadsheet can make LibreOffice and Apache OpenOffice run an attacker's code as soon as the file is opened, security researchers have shown. There is no warning first, of the kind either program shows before it runs a macro. The attack works only when the program's Java support is enabled. So far, it has only been shown as a proof of concept, and there are no reports of its use in

Cloud SecuritySecurity Research
P0
2026-10-06 11:27 UTC
Vendor Research

IronChain Ransomware Threatens Businesses with Permanent Data Loss and Costly Downtime

ANY.RUN Blog · Himanshu Anand · indexed 2026-10-06 14:56 UTC

Editor’s note: This research was conducted by Himanshu Anand, an independent cybersecurity researcher (follow Himanshu on X). During Cybersecurity Awareness Month, ransomware remains one of the clearest examples of how a cyber incident can become a business continuity issue. IronChain shows why. It puts business-critical data at risk of permanent loss and can bring operations […] The post IronChain Ransomware Threatens Businesses with Permanent Data Loss and Costly Downtime appeared first on AN…

RansomwareSecurity Research
P15
2026-10-05 18:15 UTC
Other

Anthropic Mythos Found A Bug in Rejetto HFS. Attackers Are Now Exploiting It.

Security Affairs · Pierluigi Paganini · indexed 2026-10-05 19:10 UTC

AI-assisted research uncovered a critical Rejetto HFS flaw that enables authentication bypass and remote code execution, now exploited in the wild. A Rejetto HFS vulnerability, tracked as CVE-2026-61500 (CVSS score of 9.3), discovered with the help of the Anthropic Mythos AI model is now being exploited in the wild, turning an interesting security research experiment […]

Security ResearchVulnerabilitiesCVE-2026-61500
P50
2026-10-01 14:37 UTC
Security Journalism

WordPress Backdoor Rebuilds Itself After Cleanup Using Files, Database, and Shared Memory

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-01 14:50 UTC

Cybersecurity researchers have shed light on a WordPress compromise in which threat actors deployed multiple persistence mechanisms to ensure that the final payload kept returning without having to infect the site again. The backdoor has been codenamed SC after the "SC_" markers present in the injected content. Sucuri has described the malware as a "self-healing mesh" that's

MalwareSecurity ResearchThreat Actors
P0
2026-10-01 08:04 UTC
Other

AI Agent Chains Zammad Zero-Days To Take Over DIVD Systems in Seconds

Security Affairs · Pierluigi Paganini · indexed 2026-10-01 08:10 UTC

DIVD was breached through two Zammad zero-days that let an AI agent reach root in seconds, steal data and pivot to other services before being stopped. The Dutch Institute for Vulnerability Disclosure, a nonprofit organization of volunteer security researchers whose whole job is finding and responsibly disclosing vulnerabilities in other people’s software, just disclosed that […]

AI SecuritySecurity ResearchVulnerabilities
P25
2026-10-01 05:54 UTC
Security Journalism

Apple CoreGraphics PoC Emerges as WhatsApp PDF Checks Hint at Possible Delivery Path

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-01 07:20 UTC

Security researchers have published the first public proof-of-concept for CVE-2026-86950, an Apple CoreGraphics flaw Apple says may have been used in attacks against specific targeted individuals. The trigger is a malicious PDF with a crafted embedded font that crashes unpatched iPhones and Macs. The code causes a crash, not an execution error. Turning the memory corruption into a working

AppleSecurity ResearchVulnerabilitiesCVE-2026-86950
P5
2026-09-30 16:46 UTC
Security Journalism

Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-30 17:55 UTC

Threat actors have weaponized a now-patched security flaw in Zimbra Collaboration Suite (ZCS) to deploy web shells and access mailbox data, according to findings from the Microsoft Security Research team. The attack exploits CVE-2026-73570 (CVSS score: 8.9), an unauthenticated operating system command injection flaw that can lead to remote code execution when Simple Network Management Protocol

MicrosoftSecurity ResearchThreat ActorsVulnerabilitiesCVE-2026-73570
P20
2026-09-30 05:30 UTC
Security Journalism

Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-30 07:00 UTC

Cybersecurity researchers have disclosed technical details of a recently patched critical security flaw in Citrix NetScaler ADC and Gateway that has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-88772 (CVSS score: 9.5), has been described as a memory overflow bug in the Datagram Transport Layer Security (DTLS) protocol handling that's rooted in the NetScaler

Security ResearchVulnerabilitiesCVE-2026-88772
P25
2026-09-29 13:45 UTC
Security Journalism

101 Malicious npm Packages Add Developers' WhatsApp Accounts to Groups Without Consent

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-29 15:25 UTC

Cybersecurity researchers have identified a cluster of 101 npm packages that are used to trap developers into a WhatsApp group subscriber campaign dubbed PhantomSub. "The malicious packages abuse the 'Baileys' WhatsApp open source project to add the victims to groups without their consent," OX Security researchers Nir Zadok, Moshe Siman Tov Bustan, and Vitalii Chepurko said in a technical

Security Research
P0
2026-09-28 11:46 UTC
Security Journalism

Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-28 12:40 UTC

Cybersecurity researchers have disclosed details of a new botnet malware called Carbonato that's targeting exposed Docker daemons to deploy an open-source artificial intelligence (AI) agent framework called Hermes Agent. "The implant installs the framework unchanged, then overwrites its SOUL.md persona file," ThreatDown said. "The 39-line prompt directs it to execute tasks received through

AI SecurityMalwareSecurity Research
P0
2026-09-27 05:35 UTC
Vendor Research

Frequently asked questions about reported Citrix NetScaler zero-day vulnerabilities

Tenable Blog · Satnam Narang · indexed 2026-09-27 10:00 UTC

CVE-2026-88771 and CVE-2026-88772, two zero-day vulnerabilities in Citrix NetScaler, have been confirmed as exploited in the wild. Citrix released patches on September 27, 2026. On October 3, Citrix disclosed CVE-2026-88779, an exploited denial of service flaw affecting SAML deployments. Fixing it requires newer builds.Change logUpdate October 4: On October 3, Citrix published security bulletin CTX697174 with fixed versions for CVE-2026-88779, an exploited denial of service vulnerability affect…

Cloud SecurityNetwork SecuritySecurity ResearchThreat IntelligenceVulnerabilitiesCVE-2026-19489CVE-2026-19490CVE-2026-88771CVE-2026-88772CVE-2026-88779
P95
2026-09-25 13:18 UTC
Security Journalism

PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-25 16:10 UTC

Cybersecurity researchers have flagged a new version of PamStealer that ensures that the main payload can only be recovered using a server-side decryption chain. The latest artifacts, per Jamf Threat Labs, continue to rely on the same JavaScript for Automation (JXA) dropper mechanism, but modify the lure and the delivery method. "Where earlier variants embedded their payload key material

AppleMalwareSecurity Research
P0
2026-09-24 06:32 UTC
Security Journalism

TeamFiltration Campaign Compromises Seven Microsoft 365 Accounts Using Default Passwords

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-24 08:35 UTC

Cybersecurity researchers have disclosed details of an active TeamFiltration campaign codenamed UNK_CondorFiltration that has targeted over 5,700 accounts across 28 Microsoft 365 tenants. According to Proofpoint, the activity has primarily focused on Chilean retail and financial institutions. It originated from 1,487 unique AWS EC2 source IP addresses. "The campaign compromised 7 accounts –

Cloud SecurityMicrosoftSecurity Research
P0
2026-09-23 18:06 UTC
Security Journalism

Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-23 20:00 UTC

Cybersecurity researchers have disclosed Go-based malware distributed via two Go Modules and two Terraform providers, marking the first time threat actors are using the centralized repository hosted by HashiCorp as a distribution vector for malicious payloads. According to Aikido, the list of Terraform providers and Go modules is below - gocommunity-io/dockerd (222 downloads) kreuzwenker/

MalwareMicrosoftSecurity ResearchThreat Actors
P0
2026-09-23 08:43 UTC
Vendor Research

CVE-2026-94127: Critical Unauthenticated RCE in F5 BIG-IP APM

Rapid7 · Rapid7 · indexed 2026-09-23 09:30 UTC

OverviewOn September 22, 2026, F5 published a security advisory for CVE-2026-94127, a critical heap-based buffer overflow vulnerability affecting F5 BIG-IP Access Policy Manager (APM). The vulnerability has a CVSS v3.1 score of 9.8. An unauthenticated attacker with network access to an affected virtual server may be able to achieve remote code execution (RCE) by sending specifically crafted traffic.BIG-IP APM provides identity-aware access control for applications and other corporate resources …

Security ResearchVulnerabilitiesCVE-2026-94127
P50
2026-09-22 17:58 UTC
Security Journalism

Malicious npm Package Poses as Twilio Bug-Bounty Probe, Can Exfiltrate Credentials

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-22 19:25 UTC

Cybersecurity researchers have disclosed details of a malicious npm package named "tw-pkgprobe-7731" that masquerades as a security tool targeting developers integrating Twilio into their applications, while stealthily attempting to harvest sensitive data. The package, named "tw-pkgprobe-7731," was first uploaded to the npm registry in mid-August 2026 by an npm account named "twdepprobe7731."

Security Research
P0
1 2 3