IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 1,456 matching records.
AUTO-POLL // 2026-10-09 21:25 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P5 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 9

RANSOMWARE
P5
P5
COOL // 60 ARTICLES
THU
Oct 8

RANSOMWARE
P3
P3
COOL // 62 ARTICLES
WED
Oct 7

RANSOMWARE
P5
P5
COOL // 86 ARTICLES
TUE
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
RESET
2026-10-08 19:29 UTC
Vendor Research

CVE-2026-107322 - OS command injection in Amazon Agent Plugins for AWS databases-on-aws

AWS Security Bulletins · aws@amazon.com · indexed 2026-10-08 19:10 UTC

Bulletin ID: 2026-130-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 10/08/2026 11:30 AM PDT Description: Amazon Agent Plugins for AWS is an open source collection of plugins that extends supported AI coding agents with AWS-focused workflows and tool integrations. The databases-on-aws plugin provides database design, development, migration, and operational guidance, including Aurora DSQL helper scripts. We identified CVE-2026-107322, where an incomplete list of di…

Cloud SecurityVulnerabilitiesCVE-2026-107322
P5
2026-10-08 17:43 UTC
Vendor Research

CVE-2026-107332 - Insecure default file permissions on cached credentials in AWS Toolkit for Visual Studio Code

AWS Security Bulletins · aws@amazon.com · indexed 2026-10-08 17:50 UTC

Bulletin ID: 2026-129-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 10/08/2026 10:30 PM PDT Description: AWS Toolkit for Visual Studio Code is an open source extension that lets developers work with AWS services, including Amazon CodeCatalyst, from within Visual Studio Code. We identified CVE-2026-107332, an issue in the CodeCatalyst connection handler. When a user connected to a CodeCatalyst Dev Environment, the extension cached the user's CodeCatalyst bearer to…

Cloud SecurityVulnerabilitiesCVE-2026-107332
P5
2026-10-08 15:28 UTC
Security Journalism

Cisco Patches a Dozen Critical Vulnerabilities

Security Week · Ionut Arghire · indexed 2026-10-08 15:30 UTC

The security defects could lead to unauthorized access, information leaks, privilege escalation, DoS attacks, and remote code execution. The post Cisco Patches a Dozen Critical Vulnerabilities appeared first on SecurityWeek.

Vulnerabilities
P25
2026-10-08 14:11 UTC
Vendor Research

Cisco NX-OS Software NX-API Remote Code Execution Vulnerability

Cisco Security Advisories · indexed 2026-10-07 16:15 UTC

A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges or cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient input validation of data that is sent to the NX-API. An attacker could exploit this vulnerability by sending a crafted HTTP request to the NX-API of an affected device. A successful exploit could allow the attacker to execute arbitra…

VulnerabilitiesCVE-2026-76471
P20
2026-10-08 12:50 UTC
Vendor Research

Inside the Exchange Inspector: How Tenable uses OpenAI GPT cyber models to review open-source AI agents

Tenable Blog · Robert McSulla · indexed 2026-10-08 13:10 UTC

Community-built AI agents, skills, and MCP servers are landing in SOC workflows fast. Here’s what the Exchange Inspector tests before a listing earns its vetted tag on the CyberAgents Exchange. Three tools have already passed.Key takeawaysEvery Inspector-vetted listing clears three gates: an automated check, a frontier model assessment, and human verification. Tenable uses Tenable One AI Exposure to screen for prompt injection and exposed secrets, and OpenAI GPT Cyber models to assess the code …

AI SecurityCloud SecurityDFIRICS / OTMalwareMicrosoftNetwork SecurityPhishingSecurity ResearchThreat IntelligenceVulnerabilities
P0
2026-10-08 07:26 UTC
Other

Atlassian Vulnerability Comes Under Attack Hours After Details Go Public

Security Affairs · Pierluigi Paganini · indexed 2026-10-08 08:10 UTC

Threat actors are exploiting CVE-2026-21589, a critical Atlassian flaw that can expose sensitive files across multiple Data Center products. Threat actors have started exploiting CVE-2026-21589 (CVSS score of 9.3), a critical arbitrary file access flaw in Atlassian Data Center products. The vulnerability could allow attackers to access sensitive files under certain conditions. Affected products include […]

Threat ActorsVulnerabilitiesCVE-2026-21589
P5
2026-10-08 00:18 UTC
Vendor Research

Cisco Meraki Security Hardening Release: October 2026

Cisco Security Advisories · indexed 2026-10-07 16:15 UTC

As part of Cisco's ongoing commitment to proactive security and product quality, engineering teams conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. These vulnerabilities were found during internal testing and are not known to be actively exploited. To assist customers in patching and streamline the disclosure process, Cisco has grouped these issues by their underlying vulnerabilit…

VulnerabilitiesCVE-2026-76463CVE-2026-76464CVE-2026-76467CVE-2026-76468CVE-2026-76469CVE-2026-76470CVE-2026-76472
P30
2026-10-07 21:49 UTC
Vendor Research

Configuring your AI vulnerability harness, Part 2: The steering file

AWS Security Blog · Justin Kontny · indexed 2026-10-07 22:20 UTC

This post shows you how to configure an AI model to perform structured, evidence-based vulnerability triage with the consistency of a seasoned security analyst. You’ll learn the design decisions behind five configuration sections that enforce structural verification, evidence-based scoring, and infrastructure-aware prioritization across every analysis session. Our companion post—Building your AI vulnerability harness—covered the architecture; […]

Vulnerabilities
P0
2026-10-07 21:49 UTC
Vendor Research

Building your AI vulnerability harness, Part 1

AWS Security Blog · Nidhi Ramakant · indexed 2026-10-07 22:20 UTC

Vulnerability scanners produce findings faster than manual triage can process them. Your developers ship more code with more dependencies, and the volume of candidate findings grows with it. Many findings a scanner produces are unlikely to be exploited. The ones that matter need to reach an engineer fast, with enough evidence that they can act […]

Vulnerabilities
P0
2026-10-07 20:19 UTC
Vendor Research

CVE-2026-107352 - Missing authorization checks in Amazon Athena engine version 3 request handling

AWS Security Bulletins · aws@amazon.com · indexed 2026-10-07 20:30 UTC

Bulletin ID: 2026-128-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 10/07/2026 13:00 PM PDT Description: Missing authorization checks in Amazon Athena engine version 3 request handling could have allowed an authenticated user to read limited query metadata (AWS account identifiers and SQL statement text) from other AWS accounts. AWS remediated the issue on September 1, 2026, and has confirmed no customer metadata was accessed. Query results, credentials, and Amaz…

Cloud SecurityVulnerabilitiesCVE-2026-107352
P5
2026-10-07 19:27 UTC
Vendor Research

Microsoft, Adobe, Apple, and Foxit vulnerabilities

Cisco Talos Intelligence Blog · Kri Dontje · indexed 2026-10-07 20:00 UTC

Cisco Talos’ Vulnerability Discovery & Research team recently disclosed vulnerabilities in Adobe, Apple, Foxit Reader, and Microsoft.The vulnerabilities mentioned in this blog post have been patched by their respective vendors, in adherence to Cisco’s third-party vulnerability disclosure policy. For Snort coverage that can detect

AppleMicrosoftVulnerabilities
P0
2026-10-07 18:25 UTC
Vendor Research

CVE-2026-105811 - Authorization bypass through a user-controlled key in the Amazon Q Business Lambda hook sample in QnABot on AWS

AWS Security Bulletins · aws@amazon.com · indexed 2026-10-07 18:30 UTC

Bulletin ID: 2026-126-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 10/06/2026 13:00 PM PDT Description: QnABot on AWS is a sample solution of a multi-channel, multi-language conversational interface (chatbot) that responds to your customer's questions, answers, and feedback. We identified CVE-2026-105811 in the optional Amazon Q Business Lambda hook sample of QnABot on AWS. The Amazon Q Business Lambda hook sample (q-business-lambda-hook) is an optional integrat…

Cloud SecurityVulnerabilitiesCVE-2026-105811
P5
1 2 3 4