IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 1,456 matching records.
AUTO-POLL // 2026-10-09 21:25 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P5 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 9

RANSOMWARE
P5
P5
COOL // 60 ARTICLES
THU
Oct 8

RANSOMWARE
P3
P3
COOL // 62 ARTICLES
WED
Oct 7

RANSOMWARE
P5
P5
COOL // 86 ARTICLES
TUE
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
RESET
2026-10-09 18:13 UTC
Vendor Research

CVE-2026-108096: Improper authorization in query resolvers for SQL-backed models in AWS Amplify API Category

AWS Security Bulletins · aws@amazon.com · indexed 2026-10-09 18:30 UTC

Bulletin ID: 2026-133-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 10/09/2026 11:00 AM PDT Description: AWS Amplify API Category is a CDK Construct library for defining GraphQL data models with authorization rules as AWS AppSync APIs. We identified CVE-2026-108096, where improper authorization in the query resolvers generated by @aws-amplify/graphql-index-transformer might allow an authenticated remote user to read records owned by other users of the same applic…

Cloud SecurityVulnerabilitiesCVE-2026-108096
P5
2026-10-09 15:56 UTC
Vendor Research

CVE-2026-107783 - Insertion of sensitive information into log file in AWS Tools for PowerShell

AWS Security Bulletins · aws@amazon.com · indexed 2026-10-09 16:30 UTC

Bulletin ID: 2026-132-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 10/09/2026 08:30 AM PDT Description: AWS Tools for PowerShell V5 lets developers and administrators manage their AWS services from the PowerShell scripting environment. We identified CVE-2026-107783, where insertion of sensitive information into log file in AWS Tools for PowerShell before 5.0.306 might allow local users to recover an IAM user's cleartext AWS Management Console password from comma…

Cloud SecurityVulnerabilitiesCVE-2026-107783
P5
2026-10-09 15:15 UTC
Vendor Research

Hermes Agent - PKCE Session Takeover via Redirect-URI Parser Confusion

Tenable Research Advisories · Joshua Martinelle · indexed 2026-10-09 15:25 UTC

Hermes Agent - PKCE Session Takeover via Redirect-URI Parser Confusion Note: Another researcher identified the same vulnerability during the disclosure process with the Nous Researcher team.In Hermes Agent, the public GET /auth/native/authorize flow validates the redirect_uri with Python's urllib.parse.urlparse, then hands the raw, unnormalized value back to the browser after authentication.The two parsers treat backslashes differently. Python's parser and the browser's WHATWG parser therefore …

MicrosoftVulnerabilities
P0
2026-10-09 13:56 UTC
Other

Claude Helps Secure Open Source as Anthropic Offers Free Vulnerability Scanning

Security Affairs · Pierluigi Paganini · indexed 2026-10-09 14:20 UTC

Anthropic launches free OSS Scanner, using AI to find open-source vulnerabilities and help maintainers fix bugs before attackers exploit them. Anthropic is launching OSS Scanner, a vulnerability scanner for open-source code that costs nothing for projects to join. It grew directly out of lessons learned running Claude against real-world targets during Project Glasswing. The backdrop […]

Vulnerabilities
P0
2026-10-09 12:59 UTC
Security Journalism

Researchers Publish Working Exploit for Pre-Auth AnyDesk Linux Flaw That Gives Root Access

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-09 14:35 UTC

Security researchers have published a full working exploit for a pre-authentication remote code execution flaw in AnyDesk Linux that gives attackers root access before anyone approves the connection. AnyDesk patched the flaw in version 8.0.3 in June, but its changelog described the fix only as "fixed a bug that could lead to a crash," with no CVE assigned and no security

LinuxSecurity ResearchVulnerabilities
P15
2026-10-09 12:47 UTC
Security Journalism

Anthropic Launches Free AI Vulnerability Scanner for Open-Source Projects

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-09 14:35 UTC

Anthropic on Thursday unveiled OSS Scanner as an opt-in vulnerability scanner to help secure the open-source ecosystem using artificial intelligence (AI). "It's an opt-in service informed by our experience using Claude to find vulnerabilities during Project Glasswing," Anthropic said. "Projects that join will receive thorough, periodic security scans by our strongest models at no cost."

AI SecurityVulnerabilities
P0
2026-10-09 12:47 UTC
Security Journalism

Attackers Exploit AhsayCBS Flaws to Deploy XMRig Miners Disguised as Microsoft Edge

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-09 14:35 UTC

Threat actors have been observed exploiting two recently disclosed flaws in the AhsayCBS backup utility to seize control of affected devices and deploy web shells and XMRig cryptocurrency miners. Details of the flaws are below - CVE-2026-105133 (CVSS v4 score: 5.5) - An improper authentication vulnerability in the checkSysPwd() function in the "com/ahsay/obs/api/ApiStructsAction.java"

Cloud SecurityMicrosoftThreat ActorsVulnerabilitiesCVE-2026-105133
P5
2026-10-09 12:21 UTC
Security Journalism

Flax Typhoon Exploits Five Flaws as CISA Sets October 11 Deadline for Federal Agencies

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-09 12:55 UTC

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added five security flaws to its Known Exploited Vulnerabilities (KEV) catalog, following their abuse by a China-linked threat actor known as Flax Typhoon. The vulnerabilities in question are listed below - CVE-2015-3306 (CVSS score: 10.0) - An improper access control vulnerability in ProFTPD that could allow

Cloud SecurityThreat ActorsVulnerabilitiesCVE-2015-3306
P35
2026-10-09 10:04 UTC
Other

CVE-2026-107406: Citrix Fixes Critical NetScaler ADC and Gateway Vulnerability

Security Affairs · Pierluigi Paganini · indexed 2026-10-09 10:50 UTC

Citrix patched CVE-2026-107406, a critical NetScaler ADC and Gateway flaw that could allow remote code execution or denial-of-service attacks. Citrix has released security updates to fix CVE-2026-107406 (CVSS score of 9.5), a critical flaw affecting NetScaler ADC and NetScaler Gateway that could allow remote code execution or denial-of-service (DoS) under certain conditions. The vulnerability is […]

VulnerabilitiesCVE-2026-107406
P30
2026-10-09 08:27 UTC
Security Journalism

Citrix warns admins to patch new NetScaler RCE flaw immediately

BleepingComputer · Sergiu Gatlan · indexed 2026-10-09 08:40 UTC

Citrix has warned IT administrators to patch systems immediately against a new critical vulnerability affecting NetScaler ADC networking appliances and NetScaler Gateway secure remote access solutions. [...]

Vulnerabilities
P25
2026-10-09 08:11 UTC
Security Journalism

Citrix Patches Critical NetScaler Flaw That Could Enable RCE in SAML Deployments

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-09 09:55 UTC

Citrix has released patches for yet another critical security flaw impacting NetScaler ADC and NetScaler Gateway that could result in remote code execution or denial-of-service (DoS) under certain conditions. "CVE-2026-107406 is a memory overflow vulnerability that may lead to remote code execution or denial-of-service under specific configuration conditions," Citrix said. The vulnerability

VulnerabilitiesCVE-2026-107406
P20
2026-10-08 19:44 UTC
Vendor Research

CVE-2026-107608: Improper link resolution in asset bundling output handling in aws-cdk-lib

AWS Security Bulletins · aws@amazon.com · indexed 2026-10-08 20:10 UTC

Bulletin ID: 2026-131-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 10/08/2026 12:30 PM PDT Description: AWS CDK is an open source framework that allows customers to build cloud infrastructure using their favorite programming language (Python, Typescript, C#, Go). That infrastructure is then able to be deployed with AWS CDK command line commands to AWS CloudFormation. We identified CVE-2026-107608, which is an issue where Docker files could be configured to inser…

Cloud SecurityVulnerabilitiesCVE-2026-107608
P5
1 2 3