IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 163 matching records.
AUTO-POLL // 2026-10-09 21:30 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P5 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 9

RANSOMWARE
P5
P5
COOL // 62 ARTICLES
THU
Oct 8

RANSOMWARE
P3
P3
COOL // 62 ARTICLES
WED
Oct 7

RANSOMWARE
P5
P5
COOL // 86 ARTICLES
TUE
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
RESET
2026-09-22 16:14 UTC
Security Journalism

Researcher Drops BigDiskBuster Zero-Day PoC That Blocks Microsoft Defender Updates

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-22 17:55 UTC

A zero-day proof-of-concept tool that stops Microsoft Defender from installing platform and signature updates by filling all available disk space was published on GitHub on September 19. The tool, called BigDiskBuster, has no patch, no CVE, and no Microsoft advisory. Its author, Abdelhamid Naceri, is a former Microsoft security researcher whose earlier Defender exploits were used in

MicrosoftSecurity ResearchVulnerabilities
P25
2026-09-22 14:04 UTC
Other

Chaotic Eclipse Released BigDiskBuster, A PoC For Windows Defender Update DoS Zero-Day

Security Affairs · Pierluigi Paganini · indexed 2026-09-22 14:10 UTC

The researcher Chaotic Eclipse released BigDiskBuster, a PoC exploit for a Windows Defender Update DoS Zero-Day vulnerability. Security researcher Chaotic Eclipse, also known as INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse, released a new zero-day exploit targeting Microsoft Defender. The researcher named the exploit BigDiskBuster, it triggers a Denial of Service Vulnerability in Windows Defender Update. The security researcher […]

MicrosoftSecurity ResearchVulnerabilities
P25
2026-09-22 11:17 UTC
Security Journalism

SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-22 12:10 UTC

A SharePoint Server vulnerability that Microsoft initially classified as a spoofing flaw with a CVSS score of 6.5 actually enables authenticated remote code execution, according to full technical details published today by Viettel Cyber Security researcher Dinh Ho Anh Khoa. The flaw, CVE-2026-65660, affects SharePoint Server 2016, 2019, and Subscription Edition. Patches have been

MicrosoftSecurity ResearchVulnerabilitiesCVE-2026-65660
P20
2026-09-22 06:33 UTC
Security Journalism

One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-22 06:55 UTC

Malware already running on a Mac can quietly take over Meta's Muse assistant and use the broad access its owner granted the app, security researcher Patrick Wardle has shown in a proof-of-concept released on September 21. It works by changing a hidden setting so that when the user taps the microphone and dictates a prompt, the words go to the attacker instead of Meta. The flaw is in

MalwareSecurity Research
P0
2026-09-21 14:15 UTC
Security Journalism

TASK#STOMP PowerShell Backdoor Steals Documents, Wi-Fi Passwords, and Clipboard Data

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-21 14:45 UTC

Cybersecurity researchers have disclosed details of a new campaign dubbed TASK#STOMP that delivers a PowerShell backdoor designed to harvest sensitive data from compromised hosts. The backdoor "automatically harvests and exfiltrates business documents, watches the filesystem for new files in real time, steals Wi-Fi passwords and clipboard contents, takes screenshots, and accepts arbitrary

MalwareSecurity Research
P0
2026-09-21 10:33 UTC
Community

TerminalFix: PNG Steganography, (Mon, Sep 21st)

SANS Internet Storm Center · indexed 2026-09-21 10:30 UTC

Microsoft Security Research published an interesting blog post "TerminalFix campaign deploys a reverse tunnel through multistage intrusion" about a malware campaign. The aspect that I want to take a closer look at, is the fact that the threat actors used PNG files with steganography. I reached out to the researchers and they kindly shared the IOCs for the PNG files with me.

MalwareMicrosoftSecurity ResearchThreat ActorsThreat Intelligence
P0
2026-09-21 08:27 UTC
Other

The Target Is No Longer the Model. It’s the Agent.

Security Affairs · Pierluigi Paganini · indexed 2026-09-21 09:25 UTC

AI agents are becoming the new attack surface, exposed to poisoned skills, prompt injection, jailbreaks and attacks through connected tools. I read the AI security research published in a single month, February 2026, and when you put it all together, it’s not a list of curiosities. It’s a field guide to a new attack surface. […]

AI SecurityAppleSecurity Research
P0
2026-09-19 18:36 UTC
Security Journalism

Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-19 11:30 UTC

Three researchers at the security firm Hacktron used Anthropic's Claude Opus 5 to chain two flaws and take over the ChatGPT and Codex accounts of several OpenAI employees, then reach an internal OpenAI code repository. The chain began with a bug in the software that runs OpenAI's public help forum and moved through a weakness in OpenAI's own login system. This was security research,

Cloud SecuritySecurity Research
P0
2026-09-18 18:02 UTC
Security Journalism

Public Exploits Released for Four Linux Kernel Flaws That Enable Local Root

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-18 20:25 UTC

A security researcher has released working exploit code for four Linux kernel flaws that each let a local user gain root, the highest level of access on a machine. Kernel maintainers have fixed all four over the past few weeks, so a system running an up-to-date kernel is not affected. But the exploit code is now public, and any machine still running an older kernel should be updated. The flaws

Cloud SecurityLinuxSecurity Research
P0
2026-09-18 10:40 UTC
Security Journalism

WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storage

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-18 11:00 UTC

Cybersecurity researchers have discovered a cluster of 13 npm packages that have been found to deliver a previously undocumented JavaScript stealer codenamed WeaselBiscuit. The new malware family, per OpenSourceMalware, exhibits functional overlaps with two malware strains associated with the Democratic People's Republic of Korea's (DPRK) Contagious Interview campaign: BeaverTail and

MalwareSecurity Research
P0
2026-09-18 06:17 UTC
Security Journalism

RatHat Android Malware Abuses ADB to Retain Shell Access After Uninstall

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-18 06:30 UTC

Cybersecurity researchers have flagged a new Android malware called RatHat that's assessed to be operated by China-based threat actors and features an artificial intelligence (AI)-powered system to navigate and control compromised devices. "Distributed primarily via targeted smishing (SMS/text phishing) and malvertising campaigns leading to deceptive third-party download portals, RatHat uses

AI SecurityMalwareMobile SecurityPhishingSecurity ResearchThreat Actors
P0
2026-09-17 10:05 UTC
Security Journalism

China-Aligned FamousSparrow Deploys SparroWocky Backdoor Across Latin America

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-17 13:45 UTC

The China-aligned state-sponsored threat actor known as FamousSparrow has been observed deploying a previously unreported backdoor called SparroWocky in attacks targeting multiple countries in Latin America since at least August 2025. "SparroWocky is a modular, C++ backdoor," ESET security researchers Alexandre Côté Cyr and Romain Dumont said in a technical report shared with The Hacker News

APT / Nation-StateMalwareSecurity ResearchThreat Actors
P0
2026-09-16 14:36 UTC
Security Journalism

One Extension Could Hijack AI Assistants Across Chrome, Comet, Edge, Opera Neon and Claude

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-16 16:25 UTC

Security researchers at Forever Security have shown that one ordinary browser extension could take control of the AI assistants built into five Chromium-based products: Gemini Live in Chrome, Perplexity Comet, Microsoft Edge, Opera Neon and the Claude in Chrome extension. Once the extension was installed, it could access each product's built-in AI with a single click. On Comet, Edge,

MicrosoftSecurity Research
P0
2026-09-15 18:54 UTC
Security Journalism

KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-15 19:10 UTC

Cybersecurity researchers have shed light on a previously undocumented Brazilian banking malware operation that delivers a toolkit called KREMLIN. Elastic Security Labs is tracking the activity under the moniker REF9334. Active since at least May 2025, the threat actor has used lures that impersonate a dozen Brazilian banks and install a malicious browser extension on Google Chrome and

MalwareSecurity ResearchThreat Actors
P0
2026-09-15 15:23 UTC
Security Journalism

BambooToken Malware Uses MQTT to Control Windows and Linux Systems

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-15 15:50 UTC

Cybersecurity researchers have disclosed details of a multi-platform campaign that uses the Message Queueing Telemetry Transport (MQTT) protocol as a communication channel to control Windows and Linux systems. The emerging malware family, codenamed BambooToken, is assessed to be active since at least February 2023 and put to use in attacks targeting organizations across Asia and South America.

LinuxMalwareMicrosoftSecurity Research
P0
2026-09-15 11:12 UTC
Security Journalism

Mass-Scanning Campaign Exploits Vite Flaw to Extract Cloud Credentials From Exposed Dev Servers

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-15 12:25 UTC

Cybersecurity researchers have disclosed details of a mass-scanning campaign that has targeted Vite deployments siphon sensitive data. The first is an automated effort aimed at internet-exposed Vite development servers that's designed to steal cloud credentials, configurations from Amazon Web Services (AWS) and Microsoft Azure instances, and infrastructure state files, per F5 Labs. The

Cloud SecurityMicrosoftSecurity Research
P0
2026-09-15 07:48 UTC
Other

Telegram Desktop Flaw Could Turn Old Chat Exports Into Data Theft Traps

Security Affairs · Pierluigi Paganini · indexed 2026-09-15 09:00 UTC

A Telegram Desktop flaw let bots inject JavaScript into exported chats, enabling data theft and page manipulation. Old HTML exports remain unsafe. A vulnerability in Telegram Desktop could have turned an ordinary chat export into a serious data leak. Security researchers Denis and Aleksander Rostilov of ExPatch found a stored cross-site scripting flaw in the […]

Data BreachesSecurity ResearchVulnerabilities
P0
2026-09-14 17:58 UTC
Security Journalism

Telegram Desktop Flaw Lets Hidden JavaScript Exfiltrate Messages From HTML Exports

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-14 19:45 UTC

A flaw in Telegram Desktop let a bot's message plant hidden JavaScript inside chats that users exported to HTML files, security researchers at ExPatch said in a writeup published on September 12. In Telegram, the message looked ordinary, with a link button, and the script ran only when someone opened the export file in a web browser. It could then copy every message in that file to

Security Research
P0
2026-09-09 07:53 UTC
Other

Chaotic Eclipse Released ShieldCrash, A PoC For Microsoft Defender Zero-Day

Security Affairs · Pierluigi Paganini · indexed 2026-09-09 08:30 UTC

The researcher Chaotic Eclipse released ShieldCrash, a PoC exploit for a Microsoft Defender Zero-Day vulnerability. Security researcher Chaotic Eclipse, also known as INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse, released a new zero-day exploit targeting Microsoft Defender. The researcher named the exploit ShieldCrash, it triggers an arbitrary file read as SYSTEM. The researcher claims that Microsoft has not fully […]

MicrosoftSecurity ResearchVulnerabilities
P25
2026-09-09 06:47 UTC
Security Journalism

Researcher Drops New Microsoft Defender PoC Showing ShieldBreak Patch Can Be Bypassed

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-09 09:30 UTC

The security researcher known as Chaotic Eclipse has dropped a proof-of-concept (PoC) for yet another zero-day in Microsoft Defender. The vulnerability, codenamed ShieldCrash, is assessed to be a patch bypass for CVE-2026-69414 (CVSS score: 7.8), also called ShieldBreak, which the researcher reported last month. "Microsoft has failed to properly patch ShieldBreak CVE-2026-69414," Chaotic

MicrosoftSecurity ResearchVulnerabilitiesCVE-2026-69414
P30
2026-09-08 14:19 UTC
Security Journalism

ChatGPT Flaw Let a Planted Prompt Send a Victim's Gmail Data to Another Account

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-08 15:20 UTC

Check Point Research said in a report published today that a single instruction planted in a ChatGPT conversation could cause ChatGPT to quietly work for an attacker while answering the user's question as usual. In the company's proof of concept, that hidden work read data from the user's connected Gmail account and passed it to a second ChatGPT account through a hidden channel

Security Research
P0
2026-09-08 11:01 UTC
Vendor Research

CVE-2026-86206, CVE-2026-86207: N-able N-central Authentication Bypass (FIXED)

Rapid7 · Stephen Fewer · indexed 2026-09-08 12:25 UTC

OverviewWhile conducting research into a recent N-able N-central authentication bypass vulnerability (CVE-2026-18577), Rapid7 Labs discovered two new vulnerabilities affecting the latest version of N-central. When chained together, these two vulnerabilities allow a remote unauthenticated attacker to bypass authentication and create a new attacker-controlled System administrator account on an affected server.CVE IDDescriptionCWECVSSv4CVE-2026-86206Semicolon/Forwarded access-control bypassCWE-791…

MicrosoftSecurity ResearchVulnerabilitiesCVE-2026-18577CVE-2026-86206CVE-2026-86207
P15
2026-09-08 08:43 UTC
Security Journalism

BengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support Scams

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-08 10:00 UTC

Cybersecurity researchers have disclosed details of a sprawling search engine optimization (SEO) poisoning campaign that paves the way for malware deployment and tech support scams. The campaign, discovered by the DFIR Report in March 2026, has been codenamed BengalSEO. It has operated out of the Indian state of Rajasthan since at least 2015, driven by two IT service providers named WeConnect

DFIRMalwareSecurity Research
P0
2026-09-07 18:12 UTC
Security Journalism

PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-07 18:40 UTC

Cybersecurity researchers have disclosed details of a complex Chromium-based post-exploitation toolkit called PEEP that masquerades as a bookmarks extension for the web browser. "Requiring prior administrative or code execution access, its installer injects the extension directly into Chrome/Edge profiles, bypassing Web Store checks and user prompts by forging Chromium's own Secure Preferences

MalwareSecurity Research
P0
2026-09-07 13:42 UTC
Other

Chaotic Eclipse Released GreenSection, A PoC For NVIDIA Memory Corruption Zero-Day

Security Affairs · Pierluigi Paganini · indexed 2026-09-09 08:30 UTC

Chaotic Eclipse released GreenSection, a PoC exploit for an Nvidia Memory Corruption Zero-Day Security researcher Chaotic Eclipse, also known as INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse, released a new zero-day exploit targeting Nvidia. The researcher named the exploit GreenSection, it triggers a Memory Corruption flaw. The researcher disclosed a potential security vulnerability in NVIDIA’s Windows user-mode components. […]

MicrosoftSecurity ResearchVulnerabilities
P25
2026-09-07 13:42 UTC
Other

Chaotic Eclipse Released A PoC For NVIDIA GreenSection Memory Corruption Zero-Day

Security Affairs · Pierluigi Paganini · indexed 2026-09-07 14:40 UTC

Chaotic Eclipse released GreenSection, a PoC exploit for an Nvidia GreenSection Memory Corruption Zero-Day Security researcher Chaotic Eclipse, also known as INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse, released a new zero-day exploit targeting Nvidia. The researcher named the exploit GreenSection, it triggers a Memory Corruption flaw. The researcher disclosed a potential security vulnerability in NVIDIA’s Windows user-mode […]

MicrosoftSecurity ResearchVulnerabilities
P25
2026-09-07 11:36 UTC
Security Journalism

Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-07 13:00 UTC

Cybersecurity researchers have disclosed details of worm-like activity that abuses ConnectWise ScreenConnect to distribute a malicious Visual Basic Script (VBScript) payload to newly connected systems. According to Huntress, three unrelated incidents have been found to use diverse initial access methods, namely a Quick Assist tech-support scam, a phishing-delivered MSI installer, and a fake

PhishingSecurity Research
P0
2026-09-07 07:53 UTC
Security Journalism

JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-07 08:35 UTC

Cybersecurity researchers have unpacked JSCeal, a sophisticated compiled V8 JavaScript (JSC) malware with credential harvesting, surveillance, and traffic-interception capabilities. "The payloads are protected with javascript-obfuscator, using multiple techniques including RC4-protected strings, control-flow flattening, proxy functions, and operation wrappers," Check Point Research said in a

MalwarePhishingSecurity Research
P0
1 2 3 4