IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 1,456 matching records.
AUTO-POLL // 2026-10-09 22:15 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P5 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 9

RANSOMWARE
P5
P5
COOL // 62 ARTICLES
THU
Oct 8

RANSOMWARE
P3
P3
COOL // 62 ARTICLES
WED
Oct 7

RANSOMWARE
P5
P5
COOL // 86 ARTICLES
TUE
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
RESET
2026-10-06 14:09 UTC
Other

CVE-2026-96940: Microsoft Fixes Exchange Server Flaw For Which Exploitation Is More Likely

Security Affairs · Pierluigi Paganini · indexed 2026-10-06 15:20 UTC

Microsoft released emergency updates for Exchange Server to fix CVE-2026-96940, a high-severity flaw that can let attackers gain higher privileges. Microsoft has released out-of-band security updates for Exchange Server to fix a high-severity vulnerability tracked as CVE-2026-96940 (CVSS score of 8.8). The flaw is caused by weak authorization and can allow an authenticated attacker to […]

MicrosoftVulnerabilitiesCVE-2026-96940
P5
2026-10-06 09:21 UTC
Security Journalism

Google Pauses OSS Product Bug Bounty Rewards After Surge in Invalid Automated Reports

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-06 09:50 UTC

Google has stopped accepting product vulnerability reports through its bug bounty program for its open-source software. The change, in effect since October 1, means researchers can no longer submit security flaws in the code of projects such as Go, Angular, and Protocol Buffers there for a reward. Reports about supply chain compromises are still accepted, and reports filed before October 1 are

Cloud SecurityVulnerabilities
P0
2026-10-06 07:01 UTC
Other

Dell Urges Customers to Patch Critical DSU Flaw That Can Give Attackers Root Access

Security Affairs · Pierluigi Paganini · indexed 2026-10-06 07:10 UTC

Dell warns that a critical DSU flaw lets attackers run code as root. Customers should patch affected PowerEdge systems as soon as possible. Dell urged customers to patch a critical flaw, tracked as CVE-2026-86360 (CVSS score of 9.6), in its System Update (DSU) tool. The vulnerability is a path traversal issue that can let attackers […]

VulnerabilitiesCVE-2026-86360
P15
2026-10-06 06:58 UTC
Security Journalism

Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 Products

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-06 07:40 UTC

A critical flaw in 8 Atlassian Data Center products, which customers host themselves, allows an attacker with no login access to read specific files in each product's web application root directory. The attacker must already know a file's exact name and path and cannot list what the directory holds. Atlassian disclosed the flaw, CVE-2026-21589, on October 5, rated it 9.3 out of 10, and

VulnerabilitiesCVE-2026-21589
P15
2026-10-05 18:15 UTC
Other

Anthropic Mythos Found A Bug in Rejetto HFS. Attackers Are Now Exploiting It.

Security Affairs · Pierluigi Paganini · indexed 2026-10-05 19:10 UTC

AI-assisted research uncovered a critical Rejetto HFS flaw that enables authentication bypass and remote code execution, now exploited in the wild. A Rejetto HFS vulnerability, tracked as CVE-2026-61500 (CVSS score of 9.3), discovered with the help of the Anthropic Mythos AI model is now being exploited in the wild, turning an interesting security research experiment […]

Security ResearchVulnerabilitiesCVE-2026-61500
P50
2026-10-05 17:22 UTC
Security Journalism

US, Australia warn of latest Citrix vulnerability after NetScaler advisory

The Record · indexed 2026-10-05 17:30 UTC

Citrix confirmed late on Friday that it was “tracking a newly observed issue” related to some customer-managed NetScaler deployments but claimed the problem was not connected to vulnerabilities reported last week that also caused alarm among cybersecurity experts.

Vulnerabilities
P0
2026-10-05 16:21 UTC
Security Journalism

Microsoft Exchange Flaw Lets Authenticated Attackers Read Other Users' Mailboxes

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-05 17:30 UTC

Microsoft has released out-of-band security updates to address a high-severity flaw in Microsoft Exchange Server that could allow an attacker to escalate privileges under certain conditions. The vulnerability, tracked as CVE-2026-96940, is rated 8.8 on the CVSS scoring system. "Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a

MicrosoftVulnerabilitiesCVE-2026-96940
P5
2026-10-05 14:26 UTC
Security Journalism

Google Narrows Open Source Bug Bounty Amid Wave of Invalid Automated Reports

Security Week · Eduard Kovacs · indexed 2026-10-05 14:35 UTC

Google has temporarily stopped accepting product vulnerability reports through its Open Source Software Vulnerability Reward Program (OSS VRP). The post Google Narrows Open Source Bug Bounty Amid Wave of Invalid Automated Reports appeared first on SecurityWeek.

Vulnerabilities
P0
2026-10-05 14:20 UTC
Security Journalism

⚡ Weekly Recap: NetScaler and FortiMail 0-Days, AI Coding Leaks, Spectre v2 and Ransomware Arrests

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-05 15:15 UTC

A blank field. A public repo. One reply to an email. A box left exposed. None of this sounds dramatic, which is partly the problem. This week’s threats keep finding leverage in small things that were easy to overlook. There are actively exploited bugs in the mix, cleaner intrusion paths, smarter automation, and a long patch list waiting behind them. Some attacks are getting more capable. Others

RansomwareVulnerabilities
P40
2026-10-05 13:10 UTC
Other

U.S. CISA adds Citrix NetScaler flaw to its Known Exploited Vulnerabilities catalog

Security Affairs · Pierluigi Paganini · indexed 2026-10-05 13:55 UTC

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Citrix NetScaler flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Citrix NetScaler flaw tracked as CVE-2026-88779 (CVSS score of 8.7), to its Known Exploited Vulnerabilities (KEV) catalog. CVE-2026-88779 is a memory overflow vulnerability in Citrix NetScaler ADC and Gateway […]

VulnerabilitiesCVE-2026-88779
P35
2026-10-05 08:09 UTC
Security Journalism

Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-05 09:30 UTC

A critical security flaw impacting Rejetto HTTP File Server (HFS) is witnessing active exploitation attempts, according to VulnCheck. The vulnerability in question is CVE-2026-61500 (CVSS score: 9.3), a case of session forgery stemming from the use of a weak pseudo-random number generator (PRNG) that can lead to a predictable key, which an attacker can then use to gain unauthorized access and

VulnerabilitiesCVE-2026-61500
P20
2026-10-05 06:40 UTC
Security Journalism

New NetScaler Zero-Day Exploited in Targeted Attacks Can Knock SAML Deployments Offline

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-05 08:00 UTC

Citrix has released security updates for a high-severity security flaw in NetScaler ADC and NetScaler Gateway that has been exploited as part of targeted zero-day attacks. The vulnerability, tracked as CVE-2026-88779, carries a CVSS score of 8.7 out of 10.0. "CVE-2026-88779 is a memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway that can lead to

VulnerabilitiesCVE-2026-88779
P30
2026-10-04 21:58 UTC
Security Journalism

Citrix patches NetScaler SAML zero-day exploited in attacks

BleepingComputer · Lawrence Abrams · indexed 2026-10-04 22:00 UTC

Citrix has released emergency updates for a new NetScaler denial-of-service vulnerability tracked as CVE-2026-88779 that has been exploited in zero-day attacks, with researchers investigating whether it can also be exploited for remote code execution. [...]

VulnerabilitiesCVE-2026-88779
P65
2026-10-04 07:58 UTC
Other

Security Affairs newsletter Round 598 by Pierluigi Paganini – INTERNATIONAL EDITION

Security Affairs · Pierluigi Paganini · indexed 2026-10-04 09:00 UTC

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. Fake Zoom installer hides macOS backdoor CloudSyncD CVE-2026-90970: Critical GitLab AI Gateway Flaw Fixed Antino Backdoor Lets […]

AppleMalwareVulnerabilitiesCVE-2026-90970
P5
2026-10-04 07:49 UTC
Other

Warlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical Infrastructure

Security Affairs · Pierluigi Paganini · indexed 2026-10-04 08:00 UTC

Warlock ransomware continues to exploit unpatched SharePoint flaws to breach water utilities, telecoms, governments, and universities worldwide. Warlock ransomware made headlines back in mid-2025 for exploiting a chain of SharePoint zero-days collectively dubbed ToolShell. More than a year later, the same group is still using that door, and it’s still getting in. Symantec tracks the […]

Cloud SecurityMicrosoftRansomwareVulnerabilities
P40
2026-10-03 10:43 UTC
Other

CVE-2026-90970: Critical GitLab AI Gateway Flaw Fixed

Security Affairs · Pierluigi Paganini · indexed 2026-10-03 11:00 UTC

GitLab fixes critical AI Gateway flaw that could let authenticated Duo users escape a prompt sandbox and execute commands on self-hosted gateways. GitLab has released patches for a critical vulnerability in its AI Gateway, tracked as CVE-2026-90970 (CVSS score of 9.9), that could allow an authenticated user with access to the Duo Agent Platform to […]

VulnerabilitiesCVE-2026-90970
P15
2026-10-02 23:18 UTC
Vendor Research

Cisco Catalyst SD-WAN Manager API Authentication Bypass Vulnerability

Cisco Security Advisories · indexed 2026-09-30 13:10 UTC

A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user. This vulnerability is due to improper handling of URI encoding in an HTTP request, which allows the request to bypass an authentication rule that is intended to restrict access to a specific API endpoint. An attacker could exploit this vulnerability by sending a crafted HTTP request to …

Network SecurityVulnerabilitiesCVE-2026-76504
P15
2026-10-02 22:46 UTC
Other

U.S. CISA adds Zammad GmbH Zammad flaws to its Known Exploited Vulnerabilities catalog

Security Affairs · Pierluigi Paganini · indexed 2026-10-02 23:35 UTC

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Zammad GmbH Zammad flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: The first flaw, CVE-2026-102489, is a session hijacking vulnerability in Zammad that can lead to remote code execution as the […]

Cloud SecurityVulnerabilitiesCVE-2026-102489
P50
2026-10-02 20:25 UTC
Vendor Research

CVE-2026-104019 - OS command injection in the Studio Space startup script in Amazon SageMaker Distribution

AWS Security Bulletins · aws@amazon.com · indexed 2026-10-02 20:40 UTC

Bulletin ID: 2026-125-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 10/02/2026 13:00 PM PDT Description: Amazon SageMaker Unified Studio is an AWS service that unifies data, analytics, and AI development. It lets you find and access your organization's data and act on it with integrated, purpose-built tools. We identified CVE-2026-104019, an issue with the startup of SageMaker Spaces in SageMaker Unified Studio. The startup script in a SageMaker Space performs a …

Cloud SecurityVulnerabilitiesCVE-2026-104019
P5
2026-10-02 19:21 UTC
Vendor Research

CVE-2026-103956, CVE-2026-103957, and CVE-2026-103958 - Issues in Loom for AWS

AWS Security Bulletins · aws@amazon.com · indexed 2026-10-02 19:25 UTC

Bulletin ID: 2026-124-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 10/02/2026 12:00 PM PDT Description: Loom is an AWS Labs open-source AI agent orchestration platform. We have identified and addressed three issues in Loom for AWS, described below. We recommend upgrading to the latest version (1.7.0) and ensuring any forked or derivative code is patched to incorporate the new fixes. - CVE-2026-103956 ‐ Authentication bypass in Loom for AWS (CWE-306, CWE-1188) An…

AI SecurityCloud SecurityVulnerabilitiesCVE-2026-103956CVE-2026-103957CVE-2026-103958
P15
2026-10-02 19:21 UTC
Vendor Research

Cisco IOS XE Software Security Hardening Release: August 2026

Cisco Security Advisories · indexed 2026-08-15 14:33 UTC

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. These vulnerabilities were found during internal testing and are not known to be actively exploited. To assist customers in patching and streamline the disclosure process, Cisco has grouped these issues by …

AppleVulnerabilitiesCVE-2026-20267CVE-2026-20268CVE-2026-20269CVE-2026-20270CVE-2026-20271CVE-2026-20272CVE-2026-20273
P30
2026-10-02 17:02 UTC
Security Journalism

Dell CSM Flaws Enable Unauthenticated Admin Access and Root on Kubernetes Nodes

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-02 17:45 UTC

Dell has released security updates to address multiple critical security flaws in Dell Container Storage Modules (CSM) that could be exploited by bad actors to take over susceptible systems. The vulnerabilities are listed below - CVE-2026-63688 (CVSS score: 10.0) - A missing authentication for critical function vulnerability in the csm-authorization-storage gRPC server that an

Cloud SecurityVulnerabilitiesCVE-2026-63688
P5
2026-10-02 16:38 UTC
Vendor Research

CVE-2026-103505 - Mount Option Injection in Amazon EFS CSI Driver

AWS Security Bulletins · aws@amazon.com · indexed 2026-10-02 16:50 UTC

Bulletin ID: 2026-120-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 10/01/2026 08:30 AM PDT Description: The Amazon EFS CSI Driver is a Container Storage Interface driver that allows Kubernetes clusters to use Amazon Elastic File System. We identified CVE-2026-103505, where an actor with PersistentVolume creation privileges can inject additional mount options through the mounttargetipmap volumeAttribute. Appending comma-separated values to a value inside that JSO…

Cloud SecurityVulnerabilitiesCVE-2026-103505
P5
2 3 4 5 6