IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 1,456 matching records.
AUTO-POLL // 2026-10-10 05:20 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
WARM
COOL WARM ELEVATED HOT CRITICAL
P15 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 10

RANSOMWARE
P15
P15
WARM // 1 ARTICLE
FRI
Oct 9

RANSOMWARE
P4
P4
COOL // 67 ARTICLES
THU
Oct 8

RANSOMWARE
P3
P3
COOL // 62 ARTICLES
WED
Oct 7

RANSOMWARE
P5
P5
COOL // 86 ARTICLES
TUE
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
RESET
2026-09-09 05:00 UTC
Other

ZDI-26-630: NI LabVIEW VI File Parsing Integer Overflow Information Disclosure Vulnerability

Zero Day Initiative · indexed 2026-09-09 22:30 UTC

This vulnerability allows remote attackers to disclose sensitive information on affected installations of NI LabVIEW. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-18445.

VulnerabilitiesCVE-2026-18445
P5
2026-09-09 05:00 UTC
Other

ZDI-26-628: Backblaze Personal Computer Backup bzreports Link Following Denial-of-Service Vulnerability

Zero Day Initiative · indexed 2026-09-09 21:50 UTC

This vulnerability allows local attackers to create a denial-of-service condition on affected installations of Backblaze Personal Computer Backup. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.1. The following CVEs are assigned: CVE-2026-19820.

VulnerabilitiesCVE-2026-19820
P5
2026-09-09 05:00 UTC
Other

ZDI-26-627: Backblaze Personal Computer Backup bztransmit Link Following Denial-of-Service Vulnerability

Zero Day Initiative · indexed 2026-09-09 21:50 UTC

This vulnerability allows local attackers to create a denial-of-service condition on affected installations of Backblaze Personal Computer Backup. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.1. The following CVEs are assigned: CVE-2026-19820.

VulnerabilitiesCVE-2026-19820
P5
2026-09-09 05:00 UTC
Other

ZDI-26-626: Backblaze Personal Computer Backup bzfilelist Link Following Denial-of-Service Vulnerability

Zero Day Initiative · indexed 2026-09-09 21:50 UTC

This vulnerability allows local attackers to create a denial-of-service condition on affected installations of Backblaze Personal Computer Backup. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.1. The following CVEs are assigned: CVE-2026-19820.

VulnerabilitiesCVE-2026-19820
P5
2026-09-09 05:00 UTC
Other

ZDI-26-625: Backblaze Personal Computer Backup bzserv Link Following Denial-of-Service Vulnerability

Zero Day Initiative · indexed 2026-09-09 21:50 UTC

This vulnerability allows local attackers to create a denial-of-service condition on affected installations of Backblaze Personal Computer Backup. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.1. The following CVEs are assigned: CVE-2026-19820.

VulnerabilitiesCVE-2026-19820
P5
2026-09-09 05:00 UTC
Other

ZDI-26-624: Backblaze Personal Computer Backup bzbackup Link Following Denial-of-Service Vulnerability

Zero Day Initiative · indexed 2026-09-09 21:50 UTC

This vulnerability allows local attackers to create a denial-of-service condition on affected installations of Backblaze Personal Computer Backup. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.1. The following CVEs are assigned: CVE-2026-19820.

VulnerabilitiesCVE-2026-19820
P5
2026-09-09 04:41 UTC
Security Journalism

Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-09 06:20 UTC

Microsoft on Tuesday broke Patch Tuesday records by addressing an earth-shattering 974 vulnerabilities spanning its software portfolio, including two flaws that it said have been actively exploited in the wild. These include 723 flaws in Windows, 111 in Office and Office 2016, 62 in SQL, and 22 in Developer Tools. Of these, over 110 shortcomings have been assigned a critical severity rating.

Cloud SecurityMicrosoftVulnerabilities
P45
2026-09-09 04:27 UTC
Security Journalism

N-able N-central Pre-Auth RCE Flaw Exploited in the Wild

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-09 04:40 UTC

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a maximum-severity security flaw impacting N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by September 11, 2026. The vulnerability in question is CVE-2026-86218 (CVSS score: 10.0), which has been described as a

MicrosoftVulnerabilitiesCVE-2026-86218
P70
2026-09-08 21:44 UTC
Vendor Research

Patch Tuesday - September 2026

Rapid7 · Rapid7 · indexed 2026-09-09 00:10 UTC

Microsoft is publishing 974 own-product vulnerabilities on September 2026 Patch Tuesday, including 723 vulnerabilities in Windows. Along with Microsoft fixes for 25 non-Microsoft CVEs, that brings the total number of vulnerabilities on the table today to 999. Whether this is the biggest Patch Tuesday ever depends on how we count, but this is by far the most CVEs that Microsoft has ever published in a single day. As Rapid7 noted last month, there is no reason to suppose that Patch Tuesday will e…

Cloud SecurityLinuxMicrosoftRansomwareVulnerabilitiesCVE-2026-81963CVE-2026-84323CVE-2026-84324CVE-2026-84325CVE-2026-84326CVE-2026-84327CVE-2026-84328CVE-2026-84329CVE-2026-84331CVE-2026-84332CVE-2026-84334CVE-2026-84335CVE-2026-84347CVE-2026-84348CVE-2026-84349CVE-2026-84350CVE-2026-84351CVE-2026-84353CVE-2026-84354CVE-2026-84355CVE-2026-85045CVE-2026-85046CVE-2026-85880
P65
2026-09-08 20:24 UTC
Security Journalism

The EU CRA's Real Question: What Shipped, and When Did You Know?

BleepingComputer · Sponsored by ActiveState · indexed 2026-09-08 20:25 UTC

The EU Cyber Resilience Act's vulnerability reporting requirements take effect September 11, giving software vendors as little as 24 hours to report actively exploited flaws. ActiveState explains why knowing exactly what shipped and when vulnerabilities were discovered will be critical to meeting the new requirements. [...]

Cloud SecurityVulnerabilities
P25
2026-09-08 19:20 UTC
Community

September 2026 Microsoft Patch Tuesday, (Tue, Sep 8th)

SANS Internet Storm Center · indexed 2026-09-08 19:35 UTC

This month, Microsoft released patches for a record-breaking 973 vulnerabilities, including 113 rated critical. It is by far the largest Patch Tuesday to date, well ahead of the previous high of 664 set in July 2026. Two vulnerabilities are listed as exploited in the wild, while none were publicly disclosed before Patch Tuesday. Notable fixes include Windows privilege escalation and critical RCEs in Skype for Business, MSMQ and RRAS.

MicrosoftVulnerabilities
P30
2026-09-08 17:21 UTC
Vendor Research

Claude Mythos 5 is coming to Tenable One, powering the new “Adversary View”

Tenable Blog · Eric Doerr · indexed 2026-09-08 17:30 UTC

Tenable is bringing Anthropic’s Claude Mythos 5 into our enterprise security offerings. Adding frontier adversarial reasoning to the Tenable One Exposure Management Platform will help customers better anticipate how attackers could breach their environments and stay ahead of AI-fueled risk. Tenable One Adversary View, the first innovation planned from this work, will debut in the coming weeks.Key takeawaysClaude Mythos 5 is coming to Tenable One. In addition to using Claude Mythos 5 for researc…

AI SecurityICS / OTMicrosoftVulnerabilities
P0
2026-09-08 14:55 UTC
Security Journalism

SAP Patches Critical Extended Passport Processing Vulnerability

Security Week · Ionut Arghire · indexed 2026-09-08 15:05 UTC

Affecting the SAP kernel code, the flaw allows unauthenticated, remote attackers to run arbitrary commands, recover secrets, and modify data. The post SAP Patches Critical Extended Passport Processing Vulnerability appeared first on SecurityWeek.

LinuxVulnerabilities
P0
2026-09-08 14:07 UTC
Vendor Research

Microsoft’s September 2026 Patch Tuesday addresses 964 CVEs (CVE-2026-81963, CVE-2026-85880)

Tenable Cyber Exposure Alerts · Research Special Operations · indexed 2026-09-08 18:20 UTC

104Critical860Important0Moderate0LowMicrosoft addresses 964 CVEs, smashing July’s release as the largest Patch Tuesday release. This month’s updates include patches for two zero-days that were exploited in the wild.Microsoft patched a record 964 CVEs in its September 2026 Patch Tuesday release, with 104 rated critical and 860 rated as important.This month’s update includes patches for:.NET.NET and Visual StudioASP.NET CoreActive Directory Certificate Services (AD CS)Active Directory Domain Serv…

Cloud SecurityLinuxMicrosoftMobile SecurityNetwork SecurityVulnerabilitiesCVE-2023-21674CVE-2026-81963CVE-2026-85880
P65
2026-09-08 14:00 UTC
Vendor Research

GTIG AI Threat Tracker: From Prompting to Autonomy – The Evolution of Adversarial AI

Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-09-08 13:45 UTC

Executive Summary Since the release of our May 2026 report detailing adversarial misuse of artificial intelligence (AI), Google Threat Intelligence Group (GTIG) has observed forward leaning adversaries transition from basic prompting to agentic AI workflows and AI-enabled automation. In these operations, human-in-the-loop latency is dramatically reduced, compressing the traditional window for defenders to respond. In Q2 2026, GTIG observed threat actors compromise a cloud resource, then plan, b…

AI SecurityAPT / Nation-StateCloud SecurityData BreachesDFIRMalwareMicrosoftPhishingRansomwareThreat ActorsThreat IntelligenceVulnerabilities
P35
2026-09-08 11:22 UTC
Vendor Research

Cisco Secure Email Secure/Multipurpose Internet Mail Extensions Ciphertext Decryption Vulnerabilities

Cisco Security Advisories · indexed 2026-09-02 16:10 UTC

Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption functionality of Cisco Secure Email could allow an unauthenticated, remote attacker to recover plain text from encrypted email messages. These vulnerabilities are due to insufficient validation of message integrity. An attacker could exploit these vulnerabilities by using a machine-in-the-middle technique to intercept and modify traffic between email gateways. A successful exploit could allow the at…

VulnerabilitiesCVE-2026-20354CVE-2026-20355
P5
2026-09-08 11:01 UTC
Vendor Research

CVE-2026-86206, CVE-2026-86207: N-able N-central Authentication Bypass (FIXED)

Rapid7 · Stephen Fewer · indexed 2026-09-08 12:25 UTC

OverviewWhile conducting research into a recent N-able N-central authentication bypass vulnerability (CVE-2026-18577), Rapid7 Labs discovered two new vulnerabilities affecting the latest version of N-central. When chained together, these two vulnerabilities allow a remote unauthenticated attacker to bypass authentication and create a new attacker-controlled System administrator account on an affected server.CVE IDDescriptionCWECVSSv4CVE-2026-86206Semicolon/Forwarded access-control bypassCWE-791…

MicrosoftSecurity ResearchVulnerabilitiesCVE-2026-18577CVE-2026-86206CVE-2026-86207
P15
2026-09-08 10:37 UTC
Security Journalism

N-able Patches Critical Zero-Day in N-central

Security Week · Ionut Arghire · indexed 2026-09-08 10:50 UTC

Administrators are advised to check their deployments for newly created user accounts they don’t recognize. The post N-able Patches Critical Zero-Day in N-central appeared first on SecurityWeek.

MicrosoftVulnerabilities
P25
2026-09-08 10:00 UTC
Vendor Research

StyleSmuggler (CVE-2026-75650): Frequently asked questions about Adobe Commerce and Magento zero-day

Tenable Cyber Exposure Alerts · Satnam Narang · indexed 2026-09-08 14:20 UTC

A critical unauthenticated remote code execution (RCE) zero-day in Adobe Commerce and Magento Open Source, dubbed StyleSmuggler, has been actively exploited since September 4 with attacks observed three days before a vendor patch became available.Key takeawaysCVE-2026-75650 is a critical remote code execution vulnerability in Adobe Commerce, Adobe Commerce B2B and Magento Open Source that can be triggered without authentication.Active exploitation of CVE-2026-75650 began on September 4, 2026, t…

DFIRLinuxMalwareThreat ActorsThreat IntelligenceVulnerabilitiesCVE-2026-75650
P95
2026-09-08 09:13 UTC
Security Journalism

Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-08 10:00 UTC

Adobe on Monday released security patches to address a maximum-severity flaw impacting Adobe Commerce and Magento Open Source that has come under active exploitation in the wild. The vulnerability, now tracked as CVE-2026-75650 (CVSS score: 10.0), has been codenamed StyleSmuggler by Sansec, which discovered zero-day exploitation starting September 4, 2026. "This update resolves a critical

MalwareVulnerabilitiesCVE-2026-75650
P50
2026-09-08 05:00 UTC
Other

ZDI-26-622: Microsoft Windows IKEv2 AES-GCM Decryption Integer Underflow Remote Code Execution Vulnerability

Zero Day Initiative · indexed 2026-09-08 21:50 UTC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Windows. Authentication is not required to exploit this vulnerability, but only systems with specific IPsec configurations are vulnerable. The ZDI has assigned a CVSS rating of 8.1. The following CVEs are assigned: CVE-2026-50696.

MicrosoftVulnerabilitiesCVE-2026-50696
P20
2026-09-08 05:00 UTC
Other

ZDI-26-621: Microsoft Windows UMPDDrvRealizeBrush Improper Object Management Local Privilege Escalation Vulnerability

Zero Day Initiative · indexed 2026-09-08 21:50 UTC

This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-62712.

MicrosoftVulnerabilitiesCVE-2026-62712
P15
20 21 22 23 24