IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 305 matching records.
AUTO-POLL // 2026-10-10 00:05 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
NO DATA
NO INTELLIGENCE AGGREGATED TODAY
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 10
NO DATA
--
NO INTEL
FRI
Oct 9

RANSOMWARE
P4
P4
COOL // 67 ARTICLES
THU
Oct 8

RANSOMWARE
P3
P3
COOL // 62 ARTICLES
WED
Oct 7

RANSOMWARE
P5
P5
COOL // 86 ARTICLES
TUE
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
RESET
2026-01-15 06:07 UTC
Other

DeadLock Ransomware: Smart Contracts for Malicious Purposes

Group-IB · indexed 2026-09-07 17:30 UTC

This blog uncovers DeadLock’s stealthy usage of Polygon smart contracts for proxy address storage, a poorly-documented and under-reported technique that Group-IB analysts have observed increased usage in the wild. Variants of this technique are very wide and offer great alternatives to threat actors for bypassing traditional defenses by abusing decentralized blockchains available worldwide.

MicrosoftRansomwareThreat Actors
P35
2025-12-18 08:00 UTC
Security Journalism

A Series of Unfortunate (RMM) Events

Huntress · indexed 2026-09-07 17:30 UTC

Recently, the Huntress SOC has observed threat actors increasingly use PDQ and GoTo Resolve to deploy further remote monitoring and management (RMM) tools in attacks.

Threat Actors
P0
2025-11-24 06:00 UTC
Security Journalism

ClickFix Gets Creative: Malware Buried in Images

Huntress · indexed 2026-09-07 17:30 UTC

Huntress uncovered an attack utilizing a ClickFix lure to initiate a multi-stage malware execution chain. This analysis reveals how threat actors use steganography to conceal infostealers like LummaC2 and Rhadamanthys within seemingly harmless PNGs.

MalwareThreat Actors
P0
2025-11-20 15:00 UTC
Security Journalism

Velociraptor WSUS Exploitation, Pt. I: WSUS-Up?

Huntress · indexed 2026-09-07 17:30 UTC

Huntress has seen an uptick in threat actors abusing the Velociraptor open-source DFIR tool in a range of attacks, including a recent incident involving WSUS exploitation.

DFIRThreat Actors
P0
2025-10-07 05:00 UTC
Security Journalism

Ditch Lame Cybersecurity Tips | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

Tired of hearing the same old cybersecurity tips? Learn actionable, modern strategies to protect yourself and your organization from bad threat actors.

Threat Actors
P0
2025-09-29 05:58 UTC
Other

E-commerce Fraud-as-a-Service: How Scammers Exploit Brand Trust at Scale

Red Hunt Labs · Hariharan M · indexed 2026-09-07 17:30 UTC

In the rapidly evolving digital marketplace, e-commerce brands have become prime targets for cybercriminals. Beyond traditional data breaches, these brands now face sophisticated scams that exploit their reputation, deceive consumers, and erode trust. Drawing from investigations conducted by RedHunt Labs’ threat intelligence team, this blog delves into some of the most prevalent scams targeting e-commerce platforms and highlights how a Digital Risk Protection (DRP) solution can help fortify you…

CybercrimeData BreachesDFIRPhishingThreat ActorsThreat Intelligence
P0
2025-08-29 05:00 UTC
Security Journalism

From a Fake AnyDesk Installer to MetaStealer

Huntress · indexed 2026-09-07 17:30 UTC

Learn how a fake AnyDesk installer led to a unique MetaStealer attack, highlighting how threat actors evolve ClickFix techniques beyond the classic playbook to steal credentials and files.

MalwareThreat Actors
P0
2025-08-19 14:00 UTC
Security Journalism

Exposing Data Exfiltration | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

Threat actors often steal data during the course of their attacks. This is particularly true for ransomware threat actors, who do it before deploying file encryption in order to engage in “double extortion” activities. This activity can be difficult to detect, particularly if it’s not dissimilar to legitimate actions taken by system administrators.

RansomwareThreat Actors
P15
2025-08-14 05:00 UTC
Security Journalism

Kawabunga, Dude, You’ve Been Ransomed!

Huntress · indexed 2026-09-07 17:30 UTC

Thanks in large part to our customer base, Huntress sees a great deal of interesting activity, particularly from threat actors (but also from admins). Part of that activity includes not just ransomware variants that Huntress hasn’t seen before, but also variants that may not have been documented via any public means. Further, when these incidents occur, Huntress very often gets a detailed look at the threat actor’s activity, including commands and their timing.

RansomwareThreat Actors
P15
2025-08-13 22:00 UTC
Security Journalism

Active Exploitation of SonicWall VPNs

Huntress · indexed 2026-09-07 17:30 UTC

A likely zero-day vulnerability in SonicWall VPNs is being actively exploited to bypass MFA and deploy ransomware. Huntress advises disabling the VPN service immediately or severely restricting access via IP allow-listing. We're seeing threat actors pivot directly to domain controllers within hours of the initial breach.

Network SecurityRansomwareThreat ActorsVulnerabilities
P40
2025-07-17 05:00 UTC
Security Journalism

Remote Monitoring and Management Tools | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

When a threat actor exploited an MSP's RMM tool to target businesses, Huntress investigated and uncovered another eerily similar incident with key differences that reveal evolving tactics

Threat Actors
P0
2025-06-13 16:03 UTC
Vendor Research

Mitigating prompt injection attacks with a layered defense strategy

Google Online Security Blog · Kimberly Samra · indexed 2026-08-15 14:33 UTC

Posted by Adam Gavish, Google GenAI Security TeamWith the rapid adoption of generative AI, a new wave of threats is emerging across the industry with the aim of manipulating the AI systems themselves. One such emerging attack vector is indirect prompt injections. Unlike direct prompt injections, where an attacker directly inputs malicious commands into a prompt, indirect prompt injections involve hidden malicious instructions within external data sources. These may include emails, documents, or…

AI SecurityMalwarePhishingSecurity ResearchThreat ActorsThreat IntelligenceVulnerabilities
P0
2025-05-06 05:00 UTC
Security Journalism

Do Tigers Really Change Their Stripes?

Huntress · indexed 2026-09-07 17:30 UTC

Across the larger cybersecurity community, an often-used adage is that “threat actors always change their tactics.” However, when we really start to look at and track incident data, we begin to see that while some changes may be necessitated based on infrastructures and other challenges the threat actor may encounter, there are times when tactics remain consistent across incidents. Recent investigations into exploitation activity for CVE-2025-31151 and CVE-2025-30406 show similar TTPs across di…

DFIRThreat ActorsThreat IntelligenceVulnerabilitiesCVE-2025-30406CVE-2025-31151
P5
2025-04-23 07:05 UTC
Other

Toll of Deception: Where Evasion Drives Phishing Forward

Group-IB · indexed 2026-09-07 17:30 UTC

Discover the latest phishing campaign targeting a major toll road service provider, where cybercriminals use sophisticated evasion techniques to bypass security detections. This in-depth blog reveals how threat actors exploit legitimate platforms and deploy cloaking methods to disguise malicious links, allowing them to evade detection by security solutions. Discover how these sophisticated tactics create highly convincing phishing pages designed to steal victims’ card information, and how to sa…

PhishingThreat Actors
P0
2025-04-22 05:00 UTC
Security Journalism

Say Hello to Mac Malware

Huntress · indexed 2026-09-07 17:30 UTC

In this month’s Tradecraft Tuesday, we talked about how threat actors are finetuning their macOS malware in order to maintain persistent access and avoid detection by Apple’s security features.

AppleMalwareThreat Actors
P0
2025-04-09 05:00 UTC
Security Journalism

How EDR and ITDR Elevate Your Security

Huntress · indexed 2026-09-07 17:30 UTC

Threat actors are now exploiting both endpoints and identities in the latest cyberattacks. Learn about the rise of identity-based threats and why a combined EDR and ITDR approach is crucial for your cybersecurity.

Threat Actors
P0
2025-04-02 05:00 UTC
Security Journalism

The Unwanted Guest

Huntress · indexed 2026-09-07 17:30 UTC

Threat actors are enabling the built-in Windows Guest account to maintain persistence. Learn how they gain access and how to detect this activity.

MicrosoftThreat Actors
P0
7 8 9 10 11