IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 1,456 matching records.
AUTO-POLL // 2026-10-10 06:40 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
WARM
COOL WARM ELEVATED HOT CRITICAL
P15 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 10

RANSOMWARE
P15
P15
WARM // 1 ARTICLE
FRI
Oct 9

RANSOMWARE
P4
P4
COOL // 67 ARTICLES
THU
Oct 8

RANSOMWARE
P3
P3
COOL // 62 ARTICLES
WED
Oct 7

RANSOMWARE
P5
P5
COOL // 86 ARTICLES
TUE
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
RESET
2026-08-28 14:00 UTC
Security Journalism

AI Is Accelerating Vulnerability Discovery. Can Defenders Keep Up?

BleepingComputer · Sponsored by Action1 · indexed 2026-08-28 14:20 UTC

AI is accelerating vulnerability discovery, putting pressure on systems built to enrich, prioritize, and remediate flaws at a slower pace. Action1 explains why defenders increasingly need to correlate multiple intelligence sources and turn vulnerability data into faster remediation. [...]

Cloud SecurityMicrosoftVulnerabilities
P0
2026-08-28 13:54 UTC
Other

U.S. CISA adds ownCloud, Linux Kernel, and JFrog Artifactory flaws to its Known Exploited Vulnerabilities catalog

Security Affairs · Pierluigi Paganini · indexed 2026-08-28 14:40 UTC

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds ownCloud, Linux Kernel, and JFrog Artifactory flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2023-49105 (CVSS score of 9.8) is an improper-authentication flaw in ownCloud Server’s WebDAV functionality. An unauthenticated attacker who […]

Cloud SecurityLinuxVulnerabilitiesCVE-2023-49105
P35
2026-08-28 12:58 UTC
Security Journalism

Over 8,300 Gitea servers vulnerable to code execution attacks

BleepingComputer · Sergiu Gatlan · indexed 2026-08-28 13:00 UTC

Over 8,300 Internet-exposed Gitea instances are still unpatched against a critical security flaw exploited in ongoing remote code execution attacks, according to cybersecurity watchdog Shadowserver. [...]

Vulnerabilities
P15
2026-08-28 12:07 UTC
Security Journalism

Two Unitree G1 EDU Humanoid Robot Flaws Enable Root RCE, One Starts Over Bluetooth

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-28 13:15 UTC

Security researcher Olivier Laflamme has disclosed two independent root remote code execution (RCE) chains affecting the Unitree G1 EDU, including a Bluetooth Low Energy (BLE) path that can reach root on the robot's Locomotion PC. The flaws are tracked as CVE-2026-76639 and CVE-2026-76640, with the first involving a network-adjacent path through chat_go and bashrunner and the

Cloud SecuritySecurity ResearchVulnerabilitiesCVE-2026-76639CVE-2026-76640
P20
2026-08-28 11:20 UTC
Security Journalism

Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-28 11:40 UTC

ServiceNow has released patches for four security flaws impacting the ServiceNow AI Platform, three of them rated 10.0 on the CVSS scoring system and exploitable, in certain circumstances, by an unauthenticated attacker. The company said it deployed a security update to hosted instances and provided the update to its partners and self-hosted customers, which leaves organizations that run their

Cloud SecurityVulnerabilities
P5
2026-08-28 10:58 UTC
Security Journalism

China-Made ZBT Routers Ship With Two Implants Giving Unauthenticated Attackers Root Access

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-28 11:40 UTC

VulnCheck has disclosed two previously undocumented factory implants in firmware for routers built by Shenzhen Zhibotong Electronics (ZBT), each of which gives an unauthenticated remote attacker the ability to run commands as root on affected devices. The implants, named SPEAKINGSTONE and DARKLANTERN by the company's zero-day research team, are tracked as CVE-2026-74232 and CVE-2026-74233.

Network SecurityVulnerabilitiesCVE-2026-74232CVE-2026-74233
P30
2026-08-28 10:09 UTC
Vendor Research

PaperCut NG/MF Critical Zero-Day Exploited in the Wild

Rapid7 · Rapid7 · indexed 2026-08-28 10:30 UTC

Overview On August 27, 2026, PaperCut Software published an urgent security advisory stating that it is investigating active exploitation of a vulnerability affecting PaperCut NG and PaperCut MF. PaperCut has confirmed customer incidents and is treating the issue as a security emergency. At the initial time of disclosure, the vulnerability had not been assigned a CVE identifier, and PaperCut had not publicly disclosed a CVSS score, vulnerability class, authentication requirements, or the techni…

DFIRNetwork SecurityRansomwareThreat IntelligenceVulnerabilitiesCVE-2023-27350CVE-2026-81578CVE-2026-82078
P100
2026-08-28 09:45 UTC
Security Journalism

Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-28 10:25 UTC

cPanel has released patches for a security flaw affecting domain parking and addon domain functionality in cPanel and WebHost Manager (WHM), which could allow code execution as the root user. The vulnerability, assigned the CVE identifier CVE-2026-65643, impacts all supported versions of cPanel & WHM. cPanel described the issue as a critical security vulnerability and said that an

VulnerabilitiesCVE-2026-65643
P5
2026-08-28 09:43 UTC
Other

PaperCut Zero-Day Under Active Attack: Emergency Patch Released

Security Affairs · Pierluigi Paganini · indexed 2026-08-29 21:40 UTC

PaperCut warns that a zero-day in NG and MF is being exploited. The company already release emergency patches to address it. PaperCut Software warns that attackers are actively exploiting a zero-day in its NG and MF print management products. The flaw has no CVE yet, and the company has not released technical details. PaperCut issued […]

Vulnerabilities
P25
2026-08-28 09:43 UTC
Other

PaperCut Zero-Day Under Active Attack: Emergency Patch Released

Security Affairs · Pierluigi Paganini · indexed 2026-08-28 10:30 UTC

PaperCut warns that a zero-day in NG and MF is being exploited. The company already release emergency patches to address it. PaperCut Software warns that attackers are actively exploiting a zero-day in its NG and MF print management products. The flaw has no CVE yet, and the company has not released technical details. PaperCut issued […]

Vulnerabilities
P25
2026-08-28 09:07 UTC
Other

U.S. CISA adds Red Hat, Linux Kernel, Ajax.NET Professional, Microsoft SQL Server, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog

Security Affairs · Pierluigi Paganini · indexed 2026-08-28 09:30 UTC

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Red Hat, Linux Kernel, Ajax.NET Professional, Microsoft SQL Server, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2015-3246 is a race condition in Red Hat libuser that could let […]

Cloud SecurityLinuxMicrosoftVulnerabilitiesCVE-2015-3246
P35
2026-08-28 08:25 UTC
Security Journalism

PaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF Versions

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-28 08:40 UTC

PaperCut has alerted customers that bad actors are actively exploiting a vulnerability impacting all versions of its PaperCut NG and PaperCut MF print management software in zero-day attacks. The company has released an emergency patch for v25 and v26 to address the issue. It said it's "aware of confirmed customer incidents and is treating this matter with the highest priority." An

Vulnerabilities
P45
2026-08-28 06:39 UTC
Vendor Research

WordPress Loops & Logic - Reflected XSS

Tenable Research Advisories · Joshua Martinelle · indexed 2026-08-28 07:15 UTC

WordPress Loops & Logic - Reflected XSS A Reflected Cross-Site Scripting vulnerability exists in the Wordpress plugin 'Loops & Logic' The ‘name’ parameter of the ‘tangible_fields_fetch’ and ‘tangible_fields_store’ actions is used in the response without any filtering, resulting in a reflected XSS vulnerability. curl http://WORDPRESS/wp-admin/admin-ajax.php?action=tangible_fields_fetch&name=%3cimg+src%3dx+onerror%3dalert%28document.domain%29%3eAll of the vulnerable code is located in 'vendor/tan…

Vulnerabilities
P0
2026-08-27 18:36 UTC
Security Journalism

OpenAI Says Reward Hacking Drove AI Agents to Exploit Zero-Days and Breach Hugging Face

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-27 20:30 UTC

OpenAI on Wednesday revealed that reward hacking was a key driver behind the artificial intelligence (AI)-powered hack of Hugging Face last month, adding that it found evidence of misaligned behavior as early as late May. The incident, the company said, took place during cybersecurity evaluations of several OpenAI models, and that it was mainly fueled by what it described as a "highly capable

AI SecurityVulnerabilities
P25
2026-08-27 15:13 UTC
Security Journalism

Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-27 17:00 UTC

Credit: Hacktron Vercel has released security patches for two critical-severity vulnerabilities in the Next.js web framework, both of which allow unauthenticated remote code execution, one exploitable via specially crafted AVIF image files and the other through a path traversal flaw affecting servers that use a Windows filesystem. The Windows path traversal, tracked as CVE-2026-75604&

Cloud SecurityMicrosoftVulnerabilitiesCVE-2026-75604
P20
2026-08-27 15:12 UTC
Security Journalism

ThreatsDay: 296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New Stories

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-27 17:00 UTC

A fake login page. A fake security scan. A fake productivity app. Apparently, pretending to be useful is still one of the easier ways into a machine. The rest of the week gets stranger: botnets borrowing AI, command traffic hiding in public infrastructure, malicious tools waiting before showing their real behavior, exposed systems getting scanned, and exploit windows shrinking again. Different

MalwareMicrosoftVulnerabilities
P15
2026-08-27 14:30 UTC
Vendor Research

How to build an exposure management program the business trusts: Lessons from Tenable’s CSO

Tenable Blog · Robert Huber · indexed 2026-08-27 14:40 UTC

Discover how Tenable’s shift to an AI-driven exposure management program helped Tenable’s CSO, Robert Huber, overcome tool sprawl, unify data silos, mitigate the risk of rapid AI adoption, and shift from presenting granular, technical metrics to communicating business risk that the C-suite and the board can understand.Key takeawaysSecurity tool sprawl and data silos make it difficult for CISOs to holistically and accurately assess their organizations’ cyber risk.An exposure management program c…

AI SecurityAppleCloud SecurityMicrosoftVulnerabilities
P0
2026-08-27 13:39 UTC
Security Journalism

Amazon Kiro Prompt Injection Can Exfiltrate Sensitive Data Through Kiro Powers

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-27 15:05 UTC

Cybersecurity researchers have disclosed details of a vulnerability in Amazon Kiro, an artificial intelligence (AI)-powered, agentic integrated development environment (IDE), that could facilitate data exfiltration via prompt injection and Kiro Powers. The security flaw, which does not have a CVE identifier, works against Kiro IDE 0.7.45 on Windows, according to Mindgard. The latest version of

AI SecurityMicrosoftSecurity ResearchVulnerabilities
P0
2026-08-27 11:56 UTC
Security Journalism

Learn How to Build Security Operations Ready for AI-Powered Attacks

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-27 12:55 UTC

Security teams have spent years trying to detect threats faster. AI is changing the harder part: how much time defenders have left to act. Advanced AI models can now help attackers discover vulnerabilities, generate exploit code, and move through weaknesses faster than traditional security processes were built to handle. The challenge is no longer just finding another vulnerability or

MicrosoftVulnerabilities
P0
2026-08-27 08:13 UTC
Security Journalism

New GPUThor Rowhammer Defeats ECC on NVIDIA RTX A6000 to Gain Host Root Access

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-27 08:50 UTC

Academic researchers have disclosed a Rowhammer attack impacting NVIDIA workstation GPUs with GDDR6 memory that defeats error correction codes (ECC), the mitigation NVIDIA recommends against GPU Rowhammer, and enables denial-of-service (DoS) and privilege escalation to a root shell. Dubbed GPUThor, the attack was developed by researchers at the University of Toronto, who hammered four DRAM

Vulnerabilities
P10
2026-08-27 07:05 UTC
Security Journalism

CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-27 07:15 UTC

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added six flaws to its Known Exploited Vulnerabilities (KEV) catalog, including a high-severity security vulnerability impacting Citrix NetScaler ADC and NetScaler Gateway, citing evidence of active exploitation. The vulnerabilities are listed below - CVE-2019-1068 - A remote code execution vulnerability in

Cloud SecurityLinuxVulnerabilitiesCVE-2019-1068
P50
24 25 26 27 28