IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 305 matching records.
AUTO-POLL // 2026-10-10 00:35 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
NO DATA
NO INTELLIGENCE AGGREGATED TODAY
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 10
NO DATA
--
NO INTEL
FRI
Oct 9

RANSOMWARE
P4
P4
COOL // 67 ARTICLES
THU
Oct 8

RANSOMWARE
P3
P3
COOL // 62 ARTICLES
WED
Oct 7

RANSOMWARE
P5
P5
COOL // 86 ARTICLES
TUE
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
RESET
2024-11-21 09:33 UTC
Other

Tracing the Path of VietCredCare and DuckTail: Vietnamese dark market of infostealers’ data

Group-IB · indexed 2026-09-07 17:30 UTC

Following the arrest in May 2024 of more than 20 individuals behind Facebook infostealers campaigns in Vietnam, we have compared the tactics of operators behind VietCredCare and DuckTail stealers. These 2 malware families have been active before the arrest in Vietnam and are believed to be controlled by Vietnamese threat actors. Based on the research, we decided that the groups operate in a different way and the arrest probably affected the VietCredCare operators.

MalwareThreat Actors
P0
2024-10-17 00:00 UTC
Security Journalism

Detecting Malicious Use of LOLBins, Pt. II | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

Rhetoric within the cybersecurity community has leaned heavily towards threat actor use of LOLBins as a means of “hiding amongst the noise” of normal, administrative and operational activity. However, as Huntress SOC analysts can attest, this is often far from the case.

Threat Actors
P0
2024-09-20 00:00 UTC
Security Journalism

Akira Ransomware Indicators | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

Tracking various indicators associated with different attacks, Huntress analysts have been able to identify specific indicators (threat actor workstation names, passwords associated with new user account creation or current account modification, CloudFlare tunnel tokens) that are associated with Akira ransomware infections. By detecting these indicators much earlier in the attack chain, organizations can inhibit or even obviate file encryption malware deployment.

MalwareRansomwareThreat Actors
P15
2024-05-30 00:00 UTC
Security Journalism

Attack Behaviors | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

In the cybersecurity community, we may hear analysts say, “Oh, threat actors change their tactics…”, and at times, they may include the word “always” as part of that statement. However, the question at hand is, “Does the data really show that to be the case?” What are we truly seeing in real-world incidents?

Threat Actors
P0
2024-05-01 00:00 UTC
Security Journalism

LOLBin to INC Ransomware

Huntress · indexed 2026-09-07 17:30 UTC

Huntress has observed INC ransomware deployed in the past but recent activity indicates a possible continued shift in/or improvement of tactics employed by these threat actors.

RansomwareThreat Actors
P15
2024-03-28 00:00 UTC
Security Journalism

MSSQL to ScreenConnect | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

Huntress continues to see MSSQL server systems being attacked, and in recent incidents have seen overlap with previous incidents, not only in the use of LOLBins, but also in IP addresses used by the threat actor.

Threat Actors
P0
2024-03-20 00:00 UTC
Security Journalism

Managing Attack Surface | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

Huntress recently detected interesting activity on an endpoint; a threat actor was attempting to establish a foothold on an endpoint by using commands issued via MSSQL to upload a reverse shell accessible from the web server. All attempts were obviated by MAV and process detections, but boy-howdy, did they try!

Threat Actors
P0
2024-03-13 00:00 UTC
Security Journalism

Using Backup Utilities for Data Exfiltration | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

“Double extortion” attacks, often perpetrated by ransomware threat actors, include data exfiltration prior to file encryption. Huntress analysts have observed various means of data exfiltration, but recently observed the use of a legitimate backup application seen by others to be associated with a Noberus/ALPHV ransomware affiliate.

RansomwareThreat Actors
P15
2024-03-04 00:00 UTC
Security Journalism

Insights: RMM Tools | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

Over the past year, the Huntress team has posted a number of blog posts related to remote monitoring and management (RMM) tools being installed or abused by threat actors.

Threat Actors
P0
2024-02-08 00:00 UTC
Security Journalism

Attacking MSSQL Servers | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

In addition to social engineering attacks, threat actors target organizations' attack surface, looking for exposed services and applications to gain access into an infrastructure. Microsoft SQL database servers have long been a target for attackers.

MicrosoftThreat Actors
P0
2023-11-09 00:00 UTC
Security Journalism

Bitter Pill | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

Huntress has uncovered a series of unauthorized access, revealing a threat actor using ScreenConnect to infiltrate multiple healthcare organizations.

Threat Actors
P0
2023-11-02 00:00 UTC
Other

ApatchMe

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Amazon Managed Workflows for Apache Airflow (MWAA) and the Task instance details page in the Google Composer UI were not patched against CVE-2023-29247 (Stored XSS). This meant that post-authentication, a threat actor could have exploited this to store their JavaScript payload in the victim's managed Apache Airflow instance and run JavaScript on behalf of the victim (who could be an admin or another user with higher permissions than the threat actor, thereby leading to privilege escalation). Wi…

Threat ActorsVulnerabilitiesCVE-2023-29247
P15
2023-06-08 00:00 UTC
Security Journalism

Calm In The Storm: Reviewing Volt Typhoon

Huntress · indexed 2026-09-07 17:30 UTC

Explore the recent disclosures concerning Volt Typhoon, a threat actor engaged in the widespread exploitation of external-facing services and network appliances.

Threat Actors
P0
2023-05-18 00:00 UTC
Other

GuardDuty bypass via S3 permission modification

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Threat actors in possession of IAM active credentials that had the power to update S3 bucket policies could have bypassed GuardDuty’s S3 detections and silently updated permissions for S3 resources, resulting in a bucket configuration that allowed anonymous data access. This gap in GuardDuty’s alert coverage occurred only when S3’s Block Public Access was not enabled on the account or the bucket, and when KMS-based server-side bucket encryption was not in use. In order to trigger on opening pub…

Cloud SecurityThreat Actors
P0
2023-04-21 00:00 UTC
Other

GhostToken

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Google users can find and install third-party OAuth applications from Google Marketplace that are integrated with Google Workspace. Each OAuth application client in Google is associated with a GCP project. A bug in the way a GCP project enters a "pending deletion" state when deleted, could have allowed threat actors to make a malicious application invisible and unremovable from the user's account. If an attacker had managed to install an application in an account (e.g., through a phishing attac…

PhishingThreat ActorsVulnerabilities
P0
8 9 10 11