IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 1,456 matching records.
AUTO-POLL // 2026-10-09 23:00 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P5 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 9

RANSOMWARE
P5
P5
COOL // 62 ARTICLES
THU
Oct 8

RANSOMWARE
P3
P3
COOL // 62 ARTICLES
WED
Oct 7

RANSOMWARE
P5
P5
COOL // 86 ARTICLES
TUE
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
RESET
2026-09-30 16:46 UTC
Security Journalism

Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-30 17:55 UTC

Threat actors have weaponized a now-patched security flaw in Zimbra Collaboration Suite (ZCS) to deploy web shells and access mailbox data, according to findings from the Microsoft Security Research team. The attack exploits CVE-2026-73570 (CVSS score: 8.9), an unauthenticated operating system command injection flaw that can lead to remote code execution when Simple Network Management Protocol

MicrosoftSecurity ResearchThreat ActorsVulnerabilitiesCVE-2026-73570
P20
2026-09-30 15:24 UTC
Security Journalism

Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-30 15:30 UTC

Attackers are exploiting a new critical zero-day flaw in Cisco Catalyst SD-WAN Manager, the system companies use to manage their Cisco SD-WAN networks, Cisco said in an advisory on September 30. The flaw, CVE-2026-76504, could allow a remote attacker with no login access to use the Manager's API as the admin user. Fixed releases are available, and there is no workaround. It carries a

VulnerabilitiesCVE-2026-76504
P40
2026-09-30 15:09 UTC
Vendor Research

Critical Cisco Catalyst SD-WAN Manager API authentication bypass exploited in the wild (CVE-2026-76504)

Rapid7 · Rapid7 · indexed 2026-09-30 15:25 UTC

OverviewOn September 30, 2026, Cisco published a security advisory for CVE-2026-76504, a critical API authentication bypass vulnerability affecting Cisco Catalyst SD-WAN Manager. The vulnerability has a CVSSv3.1 score of 9.8 and results from improper handling of URL encoding (CWE-177). An unauthenticated, remote attacker can send a crafted HTTP request that bypasses an authentication rule for a specific API endpoint, gaining access to the API with the privileges of the admin user.According to C…

Cloud SecurityVulnerabilitiesCVE-2026-20127CVE-2026-20182CVE-2026-76504
P90
2026-09-30 14:16 UTC
Vendor Research

Higher education is under siege, and fragmented security is making it harder to respond

Rapid7 · Rapid7 · indexed 2026-09-30 15:05 UTC

Higher education faces a difficult security equation. Universities hold large volumes of sensitive student, financial, health, and research data while supporting open networks, distributed users, legacy infrastructure, and increasingly complex cloud environments. Attackers have taken notice, and the pressure on security teams continues to grow.In Q2 2025, universities faced an average of 4,388 cyberattacks per organization per week, up 24% from the same period in 2024. Nine in ten universities …

Data BreachesDFIRMalwareMicrosoftRansomwareThreat IntelligenceVulnerabilities
P40
2026-09-30 14:00 UTC
Vendor Research

Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570

Microsoft Security Blog · Microsoft Security Research, Mahesh Mandava and Rajesh Kumar Natarajan · indexed 2026-09-30 15:00 UTC

Microsoft Threat Intelligence examines CVE-2026-73570 exploitation in Zimbra, including observed attack paths, detection opportunities, and mitigation guidance. The post Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570 appeared first on Microsoft Security Blog.

MicrosoftThreat IntelligenceVulnerabilitiesCVE-2026-73570
P5
2026-09-30 14:00 UTC
Vendor Research

Vulnerability Discovery and Exploitation Trends in the AI Era

Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-09-30 14:45 UTC

Written by: Robin Grunewald, Supriya Mazumdar, Kelli Vanderlee Introduction Google Threat Intelligence Group (GTIG) examines vulnerability disclosure and exploitation statistics to evaluate the impact of artificial intelligence (AI) on the vulnerability threat landscape. We found that AI is measurably changing not just the pace of vulnerability discovery and exploitation, but also the types and typical risk profiles of vulnerabilities that are being discovered. Key findings: Vulnerability discl…

AI SecurityCloud SecurityLinuxMicrosoftNetwork SecurityThreat ActorsThreat IntelligenceVulnerabilities
P60
2026-09-30 13:16 UTC
Security Journalism

WatchGuard Patches Critical Fireware OS Code Injection Vulnerability

Security Week · Ionut Arghire · indexed 2026-09-30 13:30 UTC

WatchGuard has rolled out patches for 15 code execution, DoS, authorization, and path traversal bugs in Fireware OS. The post WatchGuard Patches Critical Fireware OS Code Injection Vulnerability appeared first on SecurityWeek.

Vulnerabilities
P0
2026-09-30 08:04 UTC
Other

U.S. CISA adds Apple Multiple Products flaw to its Known Exploited Vulnerabilities catalog

Security Affairs · Pierluigi Paganini · indexed 2026-09-30 09:10 UTC

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Apple Multiple Products flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added an Apple Multiple Products flaw, tracked as CVE-2026-86950 (CVSS score of 8.8), to its Known Exploited Vulnerabilities (KEV) catalog. This week, Apple has released security updates for iOS, iPadOS […]

AppleVulnerabilitiesCVE-2026-86950
P35
2026-09-30 07:25 UTC
Other

WHIPSHOT and SLAPSHOT: the tools behind an active Citrix NetScaler campaign

Security Affairs · Pierluigi Paganini · indexed 2026-09-30 07:50 UTC

Mandiant and GTIG detail active exploitation of a Citrix NetScaler zero-day, deploying custom web shells WHIPSHOT and SLAPSHOT for root access. Mandiant and Google Threat Intelligence Group caught active exploitation of a zero-day in Citrix NetScaler ADC and Gateway appliances in late September 2026. The bug, tracked as CVE-2026-88772 (CVSS score of 9.5), has been […]

Threat IntelligenceVulnerabilitiesCVE-2026-88772
P30
2026-09-30 05:30 UTC
Security Journalism

Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-30 07:00 UTC

Cybersecurity researchers have disclosed technical details of a recently patched critical security flaw in Citrix NetScaler ADC and Gateway that has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-88772 (CVSS score: 9.5), has been described as a memory overflow bug in the Datagram Transport Layer Security (DTLS) protocol handling that's rooted in the NetScaler

Security ResearchVulnerabilitiesCVE-2026-88772
P25
2026-09-30 05:00 UTC
Other

ZDI-26-750: WatchGuard FireWare OS spamd statushdlr Stack-based Buffer Overflow Remote Code Execution Vulnerability

Zero Day Initiative · indexed 2026-09-30 21:10 UTC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of WatchGuard FireWare OS. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-18145.

VulnerabilitiesCVE-2026-18145
P20
2026-09-30 05:00 UTC
Other

ZDI-26-749: WatchGuard FireWare OS samld SAMLSession Deserialization of Untrusted Data Remote Code Execution Vulnerability

Zero Day Initiative · indexed 2026-09-30 21:10 UTC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of WatchGuard FireWare OS. An attacker must first obtain the ability to write to the samld session directory on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-13046.

VulnerabilitiesCVE-2026-13046
P20
2026-09-29 17:20 UTC
Security Journalism

New Spectre-v2 BTR Attack Leaks Linux Memory Despite Existing Defenses

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-29 17:20 UTC

A group of academics from VUSec and Scuola Superiore Sant'Anna have disclosed details of a new Spectre CPU vulnerability variant that affects Just-In-Time (JIT) engines present in web browsers, language runtimes, and the operating system kernel, across multiple CPU vendors. The new Spectre v2 variant has been codenamed Branch Target Reuse (BTR). "The key insight is that, while modern CPUs

LinuxVulnerabilities
P0
2026-09-29 15:17 UTC
Vendor Research

CVE-2026-100308 - GluonTS arbitrary command execution during model deserialization

AWS Security Bulletins · aws@amazon.com · indexed 2026-09-29 15:35 UTC

Bulletin ID: 2026-119-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/29/2026 08:00 AM PDT Description: GluonTS is an open source library for deep learning based time series models. We identified CVE-2026-100308 that allows arbitrary command execution upon deserialization of untrusted model artifacts. Deserialization of untrusted data in the model loading component in Amazon GluonTS before 0.17.0 might allow context-dependent attackers to execute arbitrary opera…

Cloud SecurityVulnerabilitiesCVE-2026-100308
P5
2026-09-29 14:13 UTC
Security Journalism

Kiteworks Fixes Critical Flaw Found During Nine-Hour Precautionary Shutdown

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-29 15:25 UTC

Kiteworks on Monday said it worked with federal intelligence authorities over the weekend as it identified and addressed a critical security vulnerability during the scheduled precautionary shutdown. "During the shutdown, this activity led to the discovery of a previously unknown critical vulnerability confined to a capability that is enabled for less than 1% of the customer base," the company

Vulnerabilities
P10
2026-09-29 14:00 UTC
Vendor Research

Defending Against Active Exploitation of Citrix NetScaler ADC and Gateway Appliances

Google Threat Intelligence / Mandiant · Mandiant · indexed 2026-09-29 14:00 UTC

Introduction In late September 2026, Mandiant Consulting and Google Threat Intelligence Group (GTIG) identified active, in-the-wild exploitation of a zero-day vulnerability (CVE-2026-88772) affecting Citrix NetScaler ADC and NetScaler Gateway appliances. We have observed evidence that organizations in North America and Europe in the government, financial services, technology, education, and legal and professional services sectors were likely impacted by this exploitation campaign, which has bee…

LinuxMalwareMicrosoftNetwork SecurityPhishingThreat ActorsThreat IntelligenceVulnerabilitiesCVE-2026-88771CVE-2026-88772
P30
2026-09-29 13:28 UTC
Other

Apple Patches CoreGraphics Zero-Day Linked to Sophisticated Targeted Attacks

Security Affairs · Pierluigi Paganini · indexed 2026-09-29 13:40 UTC

Apple patched zero-day CVE-2026-86950 in CoreGraphics, exploited in sophisticated targeted attacks against specific iOS users. Apple has released security updates for iOS, iPadOS and macOS to fix a zero-day vulnerability, tracked as CVE-2026-86950, in CoreGraphics that may have been exploited in attacks against specific individuals. The flaw is an out-of-bounds write that can lead to […]

AppleVulnerabilitiesCVE-2026-86950
P50
4 5 6 7 8