IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 1,456 matching records.
AUTO-POLL // 2026-10-09 21:25 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P5 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 9

RANSOMWARE
P5
P5
COOL // 60 ARTICLES
THU
Oct 8

RANSOMWARE
P3
P3
COOL // 62 ARTICLES
WED
Oct 7

RANSOMWARE
P5
P5
COOL // 86 ARTICLES
TUE
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
RESET
2026-10-07 18:17 UTC
Other

SonicWall Fixes Max Severity Pre-Auth Flaw in SMA1000 Appliances

Security Affairs · Pierluigi Paganini · indexed 2026-10-07 18:50 UTC

SonicWall patched a CVSS 10 pre-auth SSRF flaw in SMA1000 appliances that could let unauthenticated attackers reach internal functions. SonicWall released hotfixes for four vulnerabilities in its SMA1000 remote access appliances, including a critical flaw tracked as CVE-2026-102255 (CVSS score of 10.0. The issue is a pre-authentication SSRF bug in the WorkPlace portal that could […]

VulnerabilitiesCVE-2026-102255
P15
2026-10-07 16:17 UTC
Security Journalism

SonicWall Patches CVSS 10.0 Pre-Authentication SSRF Flaw in SMA1000 Appliances

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-07 17:55 UTC

SonicWall has released hotfixes for four flaws in its SMA1000 appliances, the gateways that give remote workers access to a company's network and applications. The most serious could allow an attacker without a login to send requests through the appliance and reach internal functions. SonicWall rates it 10.0 on the CVSS scale and says it has no evidence that any of the four flaws is being

Cloud SecurityVulnerabilities
P0
2026-10-07 16:00 UTC
Vendor Research

Cisco Advance Notification for Publication of October 7, 2026, Security Advisories

Cisco Security Advisories · indexed 2026-09-30 16:25 UTC

On October 7, 2026, the Cisco Product Security Incident Response Team (PSIRT) published the advisories that are listed in the following tables. To remediate the vulnerabilities that were disclosed on October 7, 2026, Cisco strongly recommends that customers upgrade to the fixed software that is indicated in the advisories. For more information about changes in Cisco PSIRT vulnerability disclosure, see Strengthening the Foundation: A Predictable, Customer-Focused Response to AI-Accelerated Vulne…

DFIRNetwork SecurityVulnerabilitiesCVE-2026-20032CVE-2026-20038CVE-2026-20173CVE-2026-76465CVE-2026-76471
P20
2026-10-07 16:00 UTC
Vendor Research

3 lessons from frontier AI vulnerability research

Microsoft Security Blog · Taesoo Kim · indexed 2026-10-07 16:50 UTC

Read how How Microsoft Security's FORGE Lab is scaling vulnerability research from Windows to the Linux kernel. The post 3 lessons from frontier AI vulnerability research appeared first on Microsoft Security Blog.

LinuxMicrosoftVulnerabilities
P0
2026-10-07 16:00 UTC
Vendor Research

Cisco NX-OS Software Python Sandbox Escape Vulnerability

Cisco Security Advisories · indexed 2026-10-07 16:15 UTC

A vulnerability in the Python interpreter of Cisco NX-OS Software could allow an authenticated, local attacker with low privileges to escape the Python sandbox and gain unauthorized access to the underlying operating system of an affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by manipulating specific functions within the Python interpreter. A successful exploit could allow an attacker to escape the Pytho…

VulnerabilitiesCVE-2026-20032
P5
2026-10-07 16:00 UTC
Vendor Research

Cisco Finesse Server-Side Request Forgery Vulnerability

Cisco Security Advisories · indexed 2026-10-07 16:15 UTC

A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device. This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to obtain limited sensitive information for services that are assoc…

VulnerabilitiesCVE-2026-20362
P5
2026-10-07 16:00 UTC
Vendor Research

Cisco Nexus 3000 and 9000 Series Switches MPLS OAM Remote Code Execution Vulnerability

Cisco Security Advisories · indexed 2026-10-07 16:15 UTC

A vulnerability in the MPLS Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software for Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges or cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper validation when an affected device is processing an MPLS echo-request packet. An attacker could exploit this vulner…

Network SecurityVulnerabilitiesCVE-2026-76465
P20
2026-10-07 16:00 UTC
Vendor Research

Cisco Application Policy Infrastructure Controller Unauthorized File Access Vulnerability

Cisco Security Advisories · indexed 2026-10-07 16:15 UTC

A vulnerability in the export policies functionality of Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated, remote attacker to access sensitive files on an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to insufficient access control to file system resources. An attacker could exploit this vulnerability by submitting crafted values in specific UI fields. A successful exploit c…

Network SecurityVulnerabilitiesCVE-2026-76488
P5
2026-10-07 16:00 UTC
Vendor Research

Cisco Application Policy Infrastructure Controller API Command Injection Vulnerability

Cisco Security Advisories · indexed 2026-10-07 16:15 UTC

A vulnerability in the web-based management API for Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated, remote attacker to execute arbitrary commands as the root user. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to insufficient input validation of user-controlled command arguments. An attacker could exploit this vulnerability by authenticating using the API and sending crafted input. A succ…

VulnerabilitiesCVE-2026-20321
P5
2026-10-07 16:00 UTC
Vendor Research

Cisco License (Smart Software Manager) On-Prem Security Hardening Release: October 2026

Cisco Security Advisories · indexed 2026-10-07 16:15 UTC

As part of Cisco's ongoing commitment to proactive security and product quality, the engineering team for Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. These vulnerabilities were found during internal testing and are not known to be actively exploited. To assist customers in patching and str…

VulnerabilitiesCVE-2026-76480CVE-2026-76482CVE-2026-76483CVE-2026-76484
P30
2026-10-07 16:00 UTC
Vendor Research

Cisco Nexus 9000 Series Fabric Switches in ACI Mode Endpoint Group Contract Bypass Vulnerability

Cisco Security Advisories · indexed 2026-10-07 16:15 UTC

A vulnerability in the endpoint group (EPG) contract functionality of Cisco Nexus 9000 Series Fabric Switches in ACI Mode could allow an unauthenticated, remote attacker to bypass configured EPG contracts. This vulnerability is due to an improper control with EPG contracts. An attacker could exploit this vulnerability by sending IPv4 or IPv6 packets using UDP source and destination ports that are assigned to DHCP traffic through an affected device. A successful exploit could allow the attacker …

Network SecurityVulnerabilitiesCVE-2026-20038
P5
2026-10-07 16:00 UTC
Vendor Research

Cisco Nexus 3000 and 9000 Series Switches NGOAM Remote Code Execution Vulnerabilities

Cisco Security Advisories · indexed 2026-10-07 16:15 UTC

Multiple vulnerabilities in the Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software, known as Next Generation OAM (NGOAM), could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges or cause a denial of service (DoS) condition on an affected device. These vulnerabilities are due to improper input validation of IP traffic when NGOAM is enabled. An attacker could exploit these vulnerabilities by sending crafted packets to an IP inte…

Network SecurityVulnerabilitiesCVE-2026-76485CVE-2026-76486CVE-2026-76501
P20
2026-10-07 16:00 UTC
Vendor Research

Cisco Application Policy Infrastructure Controller Security Hardening Release: October 2026

Cisco Security Advisories · indexed 2026-10-07 16:15 UTC

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Application Policy Infrastructure Controller (APIC) engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. These vulnerabilities were found during internal testing and are not known to be actively exploited. To assist customers in patching and streamline the disclosure process…

VulnerabilitiesCVE-2026-76498CVE-2026-76499CVE-2026-76500
P30
2026-10-07 16:00 UTC
Vendor Research

Cisco NX-OS Software Control Plane Denial of Service Vulnerability

Cisco Security Advisories · indexed 2026-10-07 16:15 UTC

A vulnerability in Cisco NX-OS Software could allow an unauthenticated, remote attacker to exhaust system resources, causing a denial of service (DoS) condition. This vulnerability exists because rate limiting was improperly applied to some protocols. An attacker could exploit this vulnerability by sending a high rate of UDP or TCP connections to a data plane interface on an affected device. A successful exploit could allow the attacker to cause instability to various routing and control plane …

VulnerabilitiesCVE-2026-20173
P5
2026-10-07 16:00 UTC
Vendor Research

Cisco License (Smart Software Manager) On-Prem Vulnerabilities

Cisco Security Advisories · indexed 2026-10-07 16:15 UTC

Multiple vulnerabilities in the web-based management interface and API endpoints of Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), could allow a remote attacker to gain unauthorized access, access sensitive information, cause a denial of service (DoS) condition, or elevate privileges. For more information about these vulnerabilities, see the Details section of this advisory. Cisco has released software updates that address these vulnerabilities. There are no…

VulnerabilitiesCVE-2026-20328CVE-2026-76437CVE-2026-76452CVE-2026-76454
P5
2026-10-07 16:00 UTC
Vendor Research

Cisco NX-OS Software Security Hardening Release: October 2026

Cisco Security Advisories · indexed 2026-10-07 16:15 UTC

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco NX-OS Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. These vulnerabilities were found during internal testing and are not known to be actively exploited. To assist customers in patching and streamline the disclosure process, Cisco has grouped these issues by t…

VulnerabilitiesCVE-2026-76453CVE-2026-76455CVE-2026-76456CVE-2026-76457CVE-2026-76458CVE-2026-76459
P30
2026-10-07 15:34 UTC
Security Journalism

Unpatched Critical LMCache Flaw Lets Unauthenticated Attackers Run Code Remotely

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-07 16:15 UTC

A critical vulnerability in LMCache, open-source software that speeds up large language model (LLM) servers such as vLLM, lets an attacker run code on the cache server without logging in, and no fixed version is available. The flaw is in LMCache's multiprocess mode, where the cache runs as a standalone server that LLM workers reach over the ZeroMQ messaging library. A single network

AI SecurityVulnerabilities
P10
2026-10-07 14:59 UTC
Community

Scans for Atlassian vulnerablity (CVE-2026-21589), (Wed, Oct 7th)

SANS Internet Storm Center · indexed 2026-10-07 15:15 UTC

On October 5th, Atlassian published patches for multiple products to fix an "Arbitrary File Access" vulnerability [CVE-2026-21589]. An attacker can read arbitrary files in the web application's directory, potentially exposing sensitive information such as configuration files.

VulnerabilitiesCVE-2026-21589
P5
2026-10-07 12:11 UTC
Vendor Research

CVE-2026-21589: Critical unauthenticated arbitrary file access in Atlassian products

Rapid7 · Rapid7 · indexed 2026-10-07 12:30 UTC

OverviewOn October 5, 2026, Atlassian published a security advisory for CVE-2026-21589, a critical arbitrary file access vulnerability affecting eight products: Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center, Crowd Data Center, Crucible, and Fisheye. Atlassian assigned the vulnerability a CVSSv4 score of 9.3. An unauthenticated remote attacker who knows a target file's exact name and path can access it within the…

DFIRNetwork SecurityVulnerabilitiesCVE-2026-21589
P5
2026-10-07 11:49 UTC
Security Journalism

Atlassian Data Center Flaw Draws Exploitation Attempts Within Two Hours of Public Details

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-07 12:20 UTC

Threat actors have begun to exploit a newly disclosed critical security flaw impacting Atlassian Data Center products that could allow access to sensitive files under certain conditions. The arbitrary file access flaw, tracked as CVE-2026-21589 (CVSS score: 9.3) affects multiple products, including Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software

Cloud SecurityThreat ActorsVulnerabilitiesCVE-2026-21589
P5
2026-10-07 10:40 UTC
Vendor Research

The ASOS Incident: When Attackers Use the Channels Customers Trust

Rapid7 · Emma Burdett · indexed 2026-10-07 10:50 UTC

This week, ASOS customers opened their phones to find a hostile push notification delivered through the retailer’s own app. The message claimed the company’s Snowflake environment had been compromised and directed ASOS to engage with the sender through Telegram. ASOS later confirmed to Sky News that an unauthorized customer notification had been sent and said it was investigating activity involving third-party platforms used to communicate with customers. The company also said basic personal in…

CybercrimeDFIRMalwarePhishingVulnerabilities
P0
2026-10-07 07:52 UTC
Government

2026-015: Critical Vulnerability in Multiple Atlassian Products

CERT-EU Security Advisories · indexed 2026-10-07 08:00 UTC

On 5 October 2026, Atlassian published a security advisory addressing a critical arbitrary file access vulnerability. It affects Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center, Crowd Data Center, Crucible and Fisheye. CERT-EU strongly recommends upgrading all affected installations to a fixed version as soon as possible, starting with instances accessible from the internet. CERT-EU also recommends checking access…

Vulnerabilities
P10
2026-10-07 06:37 UTC
Security Journalism

Atlassian Patches Critical Vulnerability Affecting 8 Products

Security Week · Ionut Arghire · indexed 2026-10-07 06:50 UTC

Unauthenticated attackers could exploit the flaw to access specific files in the web application root directory. The post Atlassian Patches Critical Vulnerability Affecting 8 Products appeared first on SecurityWeek.

Vulnerabilities
P10
2026-10-06 20:41 UTC
Vendor Research

CVE-2026-105812 and CVE-2026-106032: Issue with Bedrock AgentCore Starter Toolkit - Import Agent Code Injection and SSRF

AWS Security Bulletins · aws@amazon.com · indexed 2026-10-06 20:55 UTC

Bulletin ID: 2026-127-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 10/06/2026 13:30 PM PDT Description: bedrock-agentcore-starter-toolkit is an AWS-maintained open-source Python package, distributed via GitHub and PyPI, that provides a command-line interface for importing Amazon Bedrock Agents into local development environments. We identified CVE-2026-105812, a code injection issue that could allow arbitrary code execution when a specially crafted agent is impo…

Cloud SecurityVulnerabilitiesCVE-2026-105812CVE-2026-106032
P5
2026-10-06 16:00 UTC
Vendor Research

CISO perspectives on managing vulnerability risks in the age of AI

Microsoft Security Blog · Freddy Dezeure and Sesha Mani · indexed 2026-10-06 16:55 UTC

Learn how CISOs can mitigate cybersecurity risks and increase resilience in the age of AI-powered vulnerability management. The post CISO perspectives on managing vulnerability risks in the age of AI appeared first on Microsoft Security Blog.

MicrosoftVulnerabilities
P0
2026-10-06 14:11 UTC
Vendor Research

Securing Agent-to-Agent Communication: The Next Identity Frontier

Rapid7 · Umair Mazhar · indexed 2026-10-06 14:20 UTC

As organizations deploy autonomous AI agents, security teams face a significant shift as non-human non-human entities making decisions, invoking tools, and delegating tasks to other agents without human intervention. Security architectures built around human users, static APIs, and distinct endpoints break down when AI agents dynamically collaborate across an environment. As these interactions become more common, securing agent-to-agent communication without blocking adoption will require secur…

AI SecurityDFIRVulnerabilities
P10
1 2 3 4 5