IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 1,456 matching records.
AUTO-POLL // 2026-10-10 01:25 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
WARM
COOL WARM ELEVATED HOT CRITICAL
P15 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 10

RANSOMWARE
P15
P15
WARM // 1 ARTICLE
FRI
Oct 9

RANSOMWARE
P4
P4
COOL // 67 ARTICLES
THU
Oct 8

RANSOMWARE
P3
P3
COOL // 62 ARTICLES
WED
Oct 7

RANSOMWARE
P5
P5
COOL // 86 ARTICLES
TUE
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
RESET
2026-09-18 05:00 UTC
Other

ZDI-26-715: Linux Mint Xreader PDF File Parsing Type Confusion Remote Code Execution Vulnerability

Zero Day Initiative · indexed 2026-09-18 14:35 UTC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Linux Mint Xreader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-19772.

LinuxVulnerabilitiesCVE-2026-19772
P20
2026-09-17 21:13 UTC
Vendor Research

Cisco IOS XR Software Security Hardening Release: September 2026

Cisco Security Advisories · indexed 2026-09-02 16:10 UTC

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. These vulnerabilities were found during internal testing and are not known to be actively exploited. To assist customers in patching and streamline the disclosure process, Cisco has grouped these issues by …

AppleVulnerabilitiesCVE-2026-20274CVE-2026-20275CVE-2026-20276CVE-2026-20277CVE-2026-20278CVE-2026-20279CVE-2026-20280
P30
2026-09-17 19:18 UTC
Vendor Research

CVE-2026-92943 - Improper validation of certificate with host mismatch in AWS IoT Device SDK for Python

AWS Security Bulletins · aws@amazon.com · indexed 2026-09-17 19:25 UTC

Bulletin ID: 2026-115-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/17/2026 12:00 PM PDT Description: AWS IoT Device SDK for Python (AWSIoTPythonSDK) is an open source SDK that lets IoT devices and gateways connect to AWS IoT Core over MQTT. We identified CVE-2026-92943 in the MQTT client TLS connection layer, where the client did not validate that the server certificate matched the AWS IoT Core endpoint hostname. On Python 3.7 and later, an adversary-in-the-m…

Cloud SecurityVulnerabilitiesCVE-2026-92943
P5
2026-09-17 18:08 UTC
Security Journalism

Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-18 03:55 UTC

A critical vulnerability in Check Point's Security Management and Log Servers could allow an attacker without login credentials to run code as root on those servers over the network. The Security Management Server is the system that controls firewall policy and administrator access. Check Point has released a fix through its LivePatch update channel and says it has no indication that the flaw

Network SecurityVulnerabilities
P10
2026-09-17 16:47 UTC
Vendor Research

Cisco Secure Email Gateway SQL Injection Vulnerability

Cisco Security Advisories · indexed 2026-09-14 16:20 UTC

A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. This vulnerability is due to insufficient validation in the email parsing logic. An attacker could exploit this vulnerability by sending a crafted email message that contains malicious SQL statements through an affected device. A successful exploit could allow the attac…

VulnerabilitiesCVE-2026-76461
P5
2026-09-17 15:37 UTC
Security Journalism

Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-18 03:55 UTC

Malicious code running inside a Docker Sandboxes virtual machine on macOS could escape the project directory shared into it and read or change files anywhere else on the host, Docker warns in a security announcement on September 15. The escape runs with the rights of the host account that runs the virtual machine. The flaw, CVE-2026-77179, is rated Critical, affects versions

AppleVulnerabilitiesCVE-2026-77179
P5
2026-09-17 14:28 UTC
Security Journalism

CISA Retires Weekly Vulnerability Bulletin in Risk-Based Pivot

Security Week · Eduard Kovacs · indexed 2026-09-17 14:30 UTC

The decision follows BOD 26-04, which directs federal organizations to prioritize vulnerabilities based on real-world risk. The post CISA Retires Weekly Vulnerability Bulletin in Risk-Based Pivot appeared first on SecurityWeek.

Vulnerabilities
P0
2026-09-17 12:30 UTC
Security Journalism

Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-17 13:45 UTC

Every release of the Unbound DNS resolver before 1.26.1 has a critical heap overflow in its DNSSEC validator, maintainer NLnet Labs said in an advisory on Wednesday. An attacker who controls a malicious zone and queries a vulnerable resolver can trigger it, enabling remote code execution. Unbound 1.26.1, released the same day, fixes the bug, tracked as CVE-2026-81642, along with

VulnerabilitiesCVE-2026-81642
P20
2026-09-17 09:26 UTC
Other

U.S. CISA adds Acronis Backup, Cisco ISE, and Google Pixel flaws to its Known Exploited Vulnerabilities catalog

Security Affairs · Pierluigi Paganini · indexed 2026-09-17 10:20 UTC

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Acronis Backup, Cisco ISE, and Google Pixel flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added [1, 2] the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2026-76460 is an authentication bypass vulnerability affecting an API in Cisco Identity Services Engine (ISE). The flaw […]

Cloud SecurityVulnerabilitiesCVE-2026-76460
P45
2026-09-17 06:39 UTC
Security Journalism

Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-17 13:45 UTC

Cisco has warned of a fresh maximum-severity security flaw impacting Identity Services Engine (ISE) that has come under active exploitation. The vulnerability, tracked as CVE-2026-76460 (CVSS score: 10.0), could allow an unauthenticated, remote attacker to bypass authentication. "This vulnerability is due to insufficient authentication control on an API endpoint," Cisco said. "An attacker

VulnerabilitiesCVE-2026-76460
P30
2026-09-17 06:19 UTC
Security Journalism

Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day

Security Week · Ionut Arghire · indexed 2026-09-17 06:35 UTC

Remote, unauthenticated attackers can exploit the vulnerability to bypass authentication via crafted requests. The post Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day appeared first on SecurityWeek.

Vulnerabilities
P25
2026-09-17 05:00 UTC
Other

ZDI-26-714: Samsung rlottie Stack-based Buffer Overflow Remote Code Execution Vulnerability

Zero Day Initiative · indexed 2026-09-17 14:55 UTC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Samsung rlottie. Interaction with the rlottie library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-91826.

VulnerabilitiesCVE-2026-91826
P20
2026-09-16 20:16 UTC
Vendor Research

CVE-2026-86831: Improper validation of pod identifier uniqueness in aws-network-policy-agent in Amazon EKS

AWS Security Bulletins · aws@amazon.com · indexed 2026-09-16 20:20 UTC

Bulletin ID: 2026-113-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/16/2026 12:30 PM PDT Description: Network Policy Agent is an EKS Policy management feature. We identified CVE-2026-86831, a cross-namespace NetworkPolicy bypass in Amazon EKS Network Policy Agent (aws-network-policy-agent) before v1.4.0. Pod identifiers are constructed by concatenating the pod name and namespace with a hyphen delimiter, which is a legal character in both Kubernetes pod names a…

Cloud SecurityVulnerabilitiesCVE-2026-86831
P5
2026-09-16 16:39 UTC
Security Journalism

First Agentic AI Data Breach Reported to Spanish Regulator

Security Week · Kevin Townsend · indexed 2026-09-16 16:50 UTC

Spanish regulators say an AI agent chained together a successful login, vulnerability discovery, and access to personal data in a potential milestone for autonomous cyberattacks. The post First Agentic AI Data Breach Reported to Spanish Regulator appeared first on SecurityWeek.

AI SecurityData BreachesVulnerabilities
P0
2026-09-16 16:07 UTC
Vendor Research

Cisco Advance Notification for Publication of September 16, 2026, Security Advisories

Cisco Security Advisories · indexed 2026-09-09 16:30 UTC

On September 16, 2026, the Cisco Product Security Incident Response Team (PSIRT) published the advisories that are listed in the following tables. To remediate these vulnerabilities, Cisco strongly recommends that customers upgrade to the fixed software that is indicated in the advisories. For more information about changes in Cisco PSIRT vulnerability disclosure, see Strengthening the Foundation: A Predictable, Customer-Focused Response to AI-Accelerated Vulnerability Discovery. Cisco Identity…

DFIRVulnerabilitiesCVE-2026-20352CVE-2026-76460
P30
2026-09-16 16:05 UTC
Vendor Research

Cisco Secure Firewall Management Center Software Static Credential Vulnerability

Cisco Security Advisories · indexed 2026-08-15 14:33 UTC

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems. This vulnerability is due to the presence of static user credentials for a low-privileged account. An attacker could exploit this vulnerability by using the account to log in to an affected system. A successful exploit could allow the atta…

Network SecurityVulnerabilitiesCVE-2026-20316
P5
2026-09-16 16:05 UTC
Vendor Research

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access SSL VPN Denial of Service Vulnerability

Cisco Security Advisories · indexed 2026-08-15 14:33 UTC

A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to insufficient error checking when processing HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to the Remot…

Network SecurityVulnerabilitiesCVE-2026-20349
P5
2026-09-16 16:03 UTC
Vendor Research

Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability

Cisco Security Advisories · indexed 2026-08-15 14:33 UTC

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system. This vulnerability is due to an improper system process that is created at boot time. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the at…

Network SecurityVulnerabilitiesCVE-2026-20079
P15
2026-09-16 16:00 UTC
Vendor Research

Cisco Identity Services Engine Cross-Site Scripting Vulnerability

Cisco Security Advisories · indexed 2026-09-16 16:40 UTC

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attac…

VulnerabilitiesCVE-2026-20309
P5
2026-09-16 16:00 UTC
Vendor Research

Cisco Identity Services Engine Authorization Bypass Vulnerabilities

Cisco Security Advisories · indexed 2026-09-16 16:40 UTC

Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to modify parts of the configuration on an affected device. These vulnerabilities are due to the lack of server-side validation of Administrator permissions. An attacker could exploit these vulnerabilities by submitting a crafted HTTP request to an affected system. A successful exploit could allow …

VulnerabilitiesCVE-2026-20285CVE-2026-20286
P5
2026-09-16 16:00 UTC
Vendor Research

Cisco BroadWorks CommPilot Application Software Authorization Bypass Vulnerability

Cisco Security Advisories · indexed 2026-09-16 16:40 UTC

A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot Application Software could allow an authenticated, remote attacker with low privileges to alter configurations on an affected device. This vulnerability is due to missing authorization checks. An attacker could exploit this vulnerability by sending a crafted HTTP request. A successful exploit could allow the attacker to alter configurations on select pages. Cisco has released software updates that address this v…

VulnerabilitiesCVE-2026-76438
P5
2026-09-16 16:00 UTC
Vendor Research

Cisco Identity Services Engine SQL and HQL Injection Vulnerabilities

Cisco Security Advisories · indexed 2026-09-16 16:40 UTC

Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to conduct SQL or HQL injection attacks on an affected device. These vulnerabilities are due to insufficient validation of user-supplied input to the affected APIs before it is used to build database queries. An attacker could exploit these vulnerabilities by sending a crafted request to an affected device. A successful exploit could a…

VulnerabilitiesCVE-2026-76448CVE-2026-76449CVE-2026-76450CVE-2026-76451
P5
2026-09-16 16:00 UTC
Vendor Research

Cisco Identity Services Engine SQL Injection Vulnerabilities

Cisco Security Advisories · indexed 2026-09-16 16:40 UTC

Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow a remote attacker to conduct SQL injection attacks on an affected device. For more information about these vulnerabilities, see the Details section of this advisory. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities. This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvis…

VulnerabilitiesCVE-2026-20247CVE-2026-20300
P5
2026-09-16 16:00 UTC
Vendor Research

Cisco Identity Services Engine Information Disclosure Vulnerability

Cisco Security Advisories · indexed 2026-09-16 16:40 UTC

A vulnerability in the API of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to view sensitive information on an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to insufficient validation of user-supplied parameters in API requests. An attacker could exploit this vulnerability by sending a crafted API request to an affected device. A successful exploit could allow the attacker …

VulnerabilitiesCVE-2026-20235
P5
2026-09-16 16:00 UTC
Vendor Research

Cisco Identity Services Engine RADIUS Denial of Service Vulnerability

Cisco Security Advisories · indexed 2026-09-16 16:40 UTC

A vulnerability in the RADIUS feature of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of certain RADIUS requests. An attacker could exploit this vulnerability by sending a crafted RADIUS request directly to an affected device. A successful exploit could allow the attacker to cause the ISE node to become unavailable. For single node deployment…

VulnerabilitiesCVE-2026-20352
P5
2026-09-16 16:00 UTC
Vendor Research

Cisco Secure Firewall Management Center and Secure Firewall Threat Defense Software sftunnel Vulnerabilities

Cisco Security Advisories · indexed 2026-09-16 16:40 UTC

Multiple vulnerabilities in Cisco Secure Firewall Management Center (FMC) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated attacker to perform an sftunnel authentication bypass or sftunnel denial of service (DoS) attack. For more information about these vulnerabilities, see the Details section of this advisory. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities. This a…

Network SecurityVulnerabilitiesCVE-2026-20295CVE-2026-20323
P15
2026-09-16 16:00 UTC
Vendor Research

Cisco Secure Firewall Threat Defense Software TLS 1.3 Denial of Service Vulnerability

Cisco Security Advisories · indexed 2026-09-16 16:40 UTC

A vulnerability in the TLS 1.3 implementation in Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to improper buffer management during the TLS 1.3 connection. An attacker could exploit this vulnerability by sending a crafted TLS 1.3 packet to an affected system through a TLS 1.3-enabled listening socket. A successful e…

Network SecurityVulnerabilitiesCVE-2026-20135
P5
11 12 13 14 15