IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 137 matching records.
AUTO-POLL // 2026-10-09 21:25 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P5 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 9

RANSOMWARE
P5
P5
COOL // 60 ARTICLES
THU
Oct 8

RANSOMWARE
P3
P3
COOL // 62 ARTICLES
WED
Oct 7

RANSOMWARE
P5
P5
COOL // 86 ARTICLES
TUE
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
RESET
2026-10-08 17:47 UTC
Other

Hunt.io Finds New Infrastructure Of BraZetsu Access Broker Months Before Disclosure

Security Affairs · Pierluigi Paganini · indexed 2026-10-08 18:10 UTC

Hunt.io traced BraZetsu ‘s infrastructure and found that hosting patterns and certificate data remained useful after published IOCs became outdated. Group-IB researchers published a detailed writeup on BraZetsu back on August 31, naming it a Python framework compiled with Nuitka and tying it to a Brazilian actor called Exilware with high confidence. Hunt.io checked whether […]

Threat Intelligence
P0
2026-10-08 12:50 UTC
Vendor Research

Inside the Exchange Inspector: How Tenable uses OpenAI GPT cyber models to review open-source AI agents

Tenable Blog · Robert McSulla · indexed 2026-10-08 13:10 UTC

Community-built AI agents, skills, and MCP servers are landing in SOC workflows fast. Here’s what the Exchange Inspector tests before a listing earns its vetted tag on the CyberAgents Exchange. Three tools have already passed.Key takeawaysEvery Inspector-vetted listing clears three gates: an automated check, a frontier model assessment, and human verification. Tenable uses Tenable One AI Exposure to screen for prompt injection and exposed secrets, and OpenAI GPT Cyber models to assess the code …

AI SecurityCloud SecurityDFIRICS / OTMalwareMicrosoftNetwork SecurityPhishingSecurity ResearchThreat IntelligenceVulnerabilities
P0
2026-10-08 07:46 UTC
Vendor Research

Making Threat Intelligence Work for SOC Teams: ANY.RUN & Elastic Webinar Insights

ANY.RUN Blog · ANY.RUN · indexed 2026-10-08 07:50 UTC

Threat intelligence on its own is only data. Its value depends on how effectively SOC teams can turn it into action. Simply put, this was the premise of our recent webinar. The SOC and business impact of threat intelligence depends largely on how quickly analysts can use it to validate threats, make confident decisions, and […] The post Making Threat Intelligence Work for SOC Teams: ANY.RUN & Elastic Webinar Insights appeared first on ANY.RUN's Cybersecurity Blog.

Threat Intelligence
P0
2026-10-06 05:22 UTC
Security Journalism

ClickFix Smuggles Payloads Through Browser Cache to Bypass Windows Run Limits

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-06 06:15 UTC

A new type of ClickFix attack is using compromised websites to trick users into executing a malicious payload cached in a web browser's cache. "Instead of downloading and executing remote payloads like the typical attack pattern, in this attack, the websites pre-fetch a script payload into the browser cache disguised as a PNG file," the Microsoft Threat Intelligence team said in a post on X.

MicrosoftThreat Intelligence
P0
2026-10-05 13:57 UTC
Other

5th October – Threat Intelligence Report

Check Point Research · urias@checkpoint.com · indexed 2026-10-05 14:15 UTC

For the latest discoveries in cyber research for the week of 5th October, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Arizona’s state court system has suffered a phishing-led cyberattack after an employee clicked a malicious link. Attackers copied backup files containing protective-order records and more than 150,000 Foster Care Review Board reports […] The post 5th October – Threat Intelligence Report appeared first on Check Point Research.

PhishingThreat Intelligence
P0
2026-09-30 14:16 UTC
Vendor Research

Higher education is under siege, and fragmented security is making it harder to respond

Rapid7 · Rapid7 · indexed 2026-09-30 15:05 UTC

Higher education faces a difficult security equation. Universities hold large volumes of sensitive student, financial, health, and research data while supporting open networks, distributed users, legacy infrastructure, and increasingly complex cloud environments. Attackers have taken notice, and the pressure on security teams continues to grow.In Q2 2025, universities faced an average of 4,388 cyberattacks per organization per week, up 24% from the same period in 2024. Nine in ten universities …

Data BreachesDFIRMalwareMicrosoftRansomwareThreat IntelligenceVulnerabilities
P40
2026-09-30 14:00 UTC
Vendor Research

Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570

Microsoft Security Blog · Microsoft Security Research, Mahesh Mandava and Rajesh Kumar Natarajan · indexed 2026-09-30 15:00 UTC

Microsoft Threat Intelligence examines CVE-2026-73570 exploitation in Zimbra, including observed attack paths, detection opportunities, and mitigation guidance. The post Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570 appeared first on Microsoft Security Blog.

MicrosoftThreat IntelligenceVulnerabilitiesCVE-2026-73570
P5
2026-09-30 14:00 UTC
Vendor Research

Vulnerability Discovery and Exploitation Trends in the AI Era

Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-09-30 14:45 UTC

Written by: Robin Grunewald, Supriya Mazumdar, Kelli Vanderlee Introduction Google Threat Intelligence Group (GTIG) examines vulnerability disclosure and exploitation statistics to evaluate the impact of artificial intelligence (AI) on the vulnerability threat landscape. We found that AI is measurably changing not just the pace of vulnerability discovery and exploitation, but also the types and typical risk profiles of vulnerabilities that are being discovered. Key findings: Vulnerability discl…

AI SecurityCloud SecurityLinuxMicrosoftNetwork SecurityThreat ActorsThreat IntelligenceVulnerabilities
P60
2026-09-30 08:24 UTC
Security Journalism

Attackers Exploit NetScaler Flaw for Root Access, Deploy WHIPSHOT and SLAPSHOT

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-30 09:55 UTC

Unknown threat actors have been observed exploiting a newly patched security flaw in Citrix NetScaler ADC and NetScaler Gateway appliances to target organizations in North America and Europe. The activity, observed by Mandiant Consulting and Google Threat Intelligence Group (GTIG) in September 2026, has targeted government, financial services, technology, education, and legal and professional

Threat ActorsThreat Intelligence
P0
2026-09-30 07:25 UTC
Other

WHIPSHOT and SLAPSHOT: the tools behind an active Citrix NetScaler campaign

Security Affairs · Pierluigi Paganini · indexed 2026-09-30 07:50 UTC

Mandiant and GTIG detail active exploitation of a Citrix NetScaler zero-day, deploying custom web shells WHIPSHOT and SLAPSHOT for root access. Mandiant and Google Threat Intelligence Group caught active exploitation of a zero-day in Citrix NetScaler ADC and Gateway appliances in late September 2026. The bug, tracked as CVE-2026-88772 (CVSS score of 9.5), has been […]

Threat IntelligenceVulnerabilitiesCVE-2026-88772
P30
2026-09-29 14:00 UTC
Vendor Research

Defending Against Active Exploitation of Citrix NetScaler ADC and Gateway Appliances

Google Threat Intelligence / Mandiant · Mandiant · indexed 2026-09-29 14:00 UTC

Introduction In late September 2026, Mandiant Consulting and Google Threat Intelligence Group (GTIG) identified active, in-the-wild exploitation of a zero-day vulnerability (CVE-2026-88772) affecting Citrix NetScaler ADC and NetScaler Gateway appliances. We have observed evidence that organizations in North America and Europe in the government, financial services, technology, education, and legal and professional services sectors were likely impacted by this exploitation campaign, which has bee…

LinuxMalwareMicrosoftNetwork SecurityPhishingThreat ActorsThreat IntelligenceVulnerabilitiesCVE-2026-88771CVE-2026-88772
P30
2026-09-29 13:00 UTC
Vendor Research

Introducing Threat Signals: agentic skills for open-source threat intelligence, free for every Cloudflare account

Cloudflare Security · Emilia Yoffie · indexed 2026-09-29 13:20 UTC

We are expanding access to Cloudforce One's Threat Events Platform to every Cloudflare account and introducing Threat Signals. Threat Signals automatically parses open-source threat reporting, extracts structured indicators, and connects threat context directly to your WAF rules.

Threat Intelligence
P0
2026-09-28 15:00 UTC
Vendor Research

NeedyMantis: Unpacking a post-compromise malware family used in targeted operations

Microsoft Security Blog · Microsoft Threat Intelligence · indexed 2026-09-28 16:30 UTC

Microsoft Threat Intelligence identified NeedyMantis, a modular post-compromise malware framework used in targeted intrusions that combines custom loaders, encrypted archives, and extensible components to maintain long-term access and support follow-on operations. The post NeedyMantis: Unpacking a post-compromise malware family used in targeted operations appeared first on Microsoft Security Blog.

MalwareMicrosoftThreat Intelligence
P0
2026-09-28 13:55 UTC
Other

28th September – Threat Intelligence Report

Check Point Research · urias@checkpoint.com · indexed 2026-09-28 14:15 UTC

For the latest discoveries in cyber research for the week of 28th September, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES The FBI has confirmed unauthorized activity affecting FBIjobs.gov after the ShinyHunters group defaced the website. The group claimed to have stolen employee and applicant information and shared samples of purported FBI personnel […] The post 28th September – Threat Intelligence Report appeared first on Check Point Research.

Law EnforcementThreat Intelligence
P0
2026-09-28 10:05 UTC
Vendor Research

Zero-Day Exploitation of Citrix NetScaler ADC and Gateway: CVE-2026-88771 and CVE-2026-88772

Rapid7 · Rapid7 · indexed 2026-09-28 10:25 UTC

OverviewOn September 27, 2026, Citrix disclosed eight new vulnerabilities affecting NetScaler ADC and NetScaler Gateway, including two critical remote code execution (RCE) vulnerabilities: CVE-2026-88771 and CVE-2026-88772. Both of these RCE vulnerabilities carry a critical CVSSv4 score of 9.5, and both have been confirmed as being actively exploited in the wild as zero-days prior to the vendor disclosure. CVE-2026-88771 affects vulnerable NetScaler deployments in their default configuration, w…

Network SecurityThreat IntelligenceVulnerabilitiesCVE-2026-88771CVE-2026-88772CVE-2026-887729CVE-2026-887739CVE-2026-88779
P95
2026-09-27 05:35 UTC
Vendor Research

Frequently asked questions about reported Citrix NetScaler zero-day vulnerabilities

Tenable Blog · Satnam Narang · indexed 2026-09-27 10:00 UTC

CVE-2026-88771 and CVE-2026-88772, two zero-day vulnerabilities in Citrix NetScaler, have been confirmed as exploited in the wild. Citrix released patches on September 27, 2026. On October 3, Citrix disclosed CVE-2026-88779, an exploited denial of service flaw affecting SAML deployments. Fixing it requires newer builds.Change logUpdate October 4: On October 3, Citrix published security bulletin CTX697174 with fixed versions for CVE-2026-88779, an exploited denial of service vulnerability affect…

Cloud SecurityNetwork SecuritySecurity ResearchThreat IntelligenceVulnerabilitiesCVE-2026-19489CVE-2026-19490CVE-2026-88771CVE-2026-88772CVE-2026-88779
P95
2026-09-26 07:48 UTC
Security Journalism

Kiteworks Urges Customers to Shut Down Systems for 9 Hours Over Possible Cyber Attack

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-26 10:05 UTC

Kiteworks (formerly Accellion) is urging customers to shut down their systems as a precautionary measure for nine hours over the weekend after it received threat intelligence about an imminent cyber attack. "Kiteworks received credible threat intelligence from federal intelligence authorities indicating that a threat actor may attempt to target some Kiteworks systems," said Frank Balonis, Chief

Threat ActorsThreat Intelligence
P0
2026-09-25 14:00 UTC
Vendor Research

ShinyHunters Renewed Mass Exploitation Campaign Targeting Oracle PeopleSoft

Google Threat Intelligence / Mandiant · Mandiant · indexed 2026-09-26 06:55 UTC

Introduction As an update to the June 2026 post, ShinyHunters Targets Education Sector with Oracle PeopleSoft Exploit, Mandiant and Google Threat Intelligence Group (GTIG) have identified renewed mass exploitation of CVE-2026-35273 by UNC6240 (ShinyHunters), along with expanded global targeting across multiple sectors. In June, the threat actor exploited this vulnerability as a zero-day predominantly against academic institutions. This new wave of activity stems from UNC6240 modifying its explo…

LinuxMicrosoftNetwork SecurityThreat ActorsThreat IntelligenceVulnerabilitiesCVE-2026-35273
P50
2026-09-24 06:24 UTC
Other

No One Gets Phished: The New Group-IB Browser Agent Applies Predictive Intelligence At The Click

Group-IB · indexed 2026-09-24 09:10 UTC

One employee reaches a phishing page. The tab closes, the domain is blocked for every browser in the company, and the targeted password is already being reset. The new Group-IB Browser Agent brings the corporate browser under XDR coverage, checking every page against predictive Threat Intelligence in real time.

PhishingThreat Intelligence
P0
2026-09-21 23:13 UTC
Other

21st September – Threat Intelligence Report

Check Point Research · urias@checkpoint.com · indexed 2026-09-21 23:20 UTC

For the latest discoveries in cyber research for the week of 21st September, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Japan’s Digital Agency, which operates the Government Solution Service used by multiple ministries, has confirmed a data breach after attackers exploited a vulnerability in a VPN appliance. Approximately 246,000 records were exposed, […] The post 21st September – Threat Intelligence Report appeared first on Check Point Research.

Data BreachesNetwork SecurityThreat IntelligenceVulnerabilities
P0
2026-09-21 10:33 UTC
Community

TerminalFix: PNG Steganography, (Mon, Sep 21st)

SANS Internet Storm Center · indexed 2026-09-21 10:30 UTC

Microsoft Security Research published an interesting blog post "TerminalFix campaign deploys a reverse tunnel through multistage intrusion" about a malware campaign. The aspect that I want to take a closer look at, is the fact that the threat actors used PNG files with steganography. I reached out to the researchers and they kindly shared the IOCs for the PNG files with me.

MalwareMicrosoftSecurity ResearchThreat ActorsThreat Intelligence
P0
2026-09-17 07:44 UTC
Vendor Research

Enterprise Threat Intelligence Buying Guide: How to Choose the Right Solution

ANY.RUN Blog · ANY.RUN · indexed 2026-10-06 14:56 UTC

Choosing an enterprise threat intelligence solution is about more than just data volume or integrations. The right provider should deliver relevant intelligence, fit existing workflows, and help security teams investigate threats faster. While SOCs may prioritize rapid investigation and enrichment at scale, MSSPs may focus more on multi-tenancy and customer separation. This enterprise threat intelligence […] The post Enterprise Threat Intelligence Buying Guide: How to Choose the Right Solution …

DFIRThreat Intelligence
P0
2026-09-17 07:20 UTC
Other

HEAVYGRAM: A Telegram-based Surveillance Backdoor Linked to Handala Hack

Group-IB · indexed 2026-09-17 08:35 UTC

Group-IB Threat Intelligence analyzes HEAVYGRAM, a Telegram-based Windows backdoor attributed with moderate confidence to the Iran-linked threat actor Handala Hack. Active since Fall 2023, it has been used to surveil Iranian dissidents, journalists and government opponents, enabling remote command execution, data exfiltration, and persistence over Telegram command-and-control.

MalwareMicrosoftThreat ActorsThreat Intelligence
P0
2026-09-16 11:15 UTC
Security Journalism

Threat Intelligence Alone Won't Close the Exploitation Gap

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-16 11:45 UTC

A leaked credential shows up in a criminal marketplace, or a vulnerability gets a disclosure advisory, and either one can be weaponized against a real target before most security teams have triaged the alert. Attackers are combining that kind of intelligence with AI-assisted exploitation to accelerate the path from exposure to breach faster than most security programs are built to react.

Threat IntelligenceVulnerabilities
P0
2026-09-16 06:40 UTC
Vendor Research

ANY.RUN & SentinelOne: One Workspace, Instant Context for Rapid Response

ANY.RUN Blog · ANY.RUN · indexed 2026-10-06 14:56 UTC

Speed and clarity are the ultimate advantages for modern SOC teams. The integration of ANY.RUN into SentinelOne delivers exactly that. Instant threat intelligence and interactive sandbox capabilities embedded right where your analysts already work. Let’s look at how this unified workflow eliminates context switching, accelerates incident response, and drives higher ROI by transforming alerts into […] The post ANY.RUN & SentinelOne: One Workspace, Instant Context for Rapid Response appeared firs…

DFIRNetwork SecurityThreat Intelligence
P0
2026-09-14 18:01 UTC
Security Journalism

3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-14 19:45 UTC

An attacker was operating inside the network of 3BB, one of Thailand's largest broadband providers, and maintained remote control of internal machines using a legitimate management tool called MeshCentral, threat intelligence firm Hunt.io said. The company uncovered the intrusion by examining a server the attacker had left open on the internet, which held the attacker's own tools and a list of

MalwareMicrosoftThreat Intelligence
P0
2026-09-14 12:22 UTC
Other

14th September – Threat Intelligence Report

Check Point Research · urias@checkpoint.com · indexed 2026-09-14 12:30 UTC

For the latest discoveries in cyber research for the week of 14th Setpember, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES IDScan.net, a US identity verification provider, has disclosed a data breach after detecting unauthorized access on September 1. Exposed data included names and government identification numbers, while a criminal marketplace advertised a […] The post 14th September – Threat Intelligence Report appeared first on Check Point Research.

Data BreachesThreat Intelligence
P0
2026-09-11 13:33 UTC
Vendor Research

The Fraud Ecosystem: A Transition From Known Marketplaces to a Fragmented Environment

Rapid7 · Gal Givon · indexed 2026-09-11 15:05 UTC

IntroductionThe surge in emerging threat actors directly correlates with the rapid escalation of victim counts and stolen financial resources. Simultaneously, this growth has spurred the proliferation of specialized supply storefronts across social media platforms, dark web channels, and various smaller niche marketplaces. Security teams today face evolving challenges, requiring them to continuously refine monitoring channels, adjust operational strategies, and foster cross-functional internal …

CybercrimeMalwarePhishingThreat ActorsThreat Intelligence
P0
1 2 3