IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 4,768 matching records.
AUTO-POLL // 2026-10-09 23:40 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P4 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 9

RANSOMWARE
P4
P4
COOL // 67 ARTICLES
THU
Oct 8

RANSOMWARE
P3
P3
COOL // 62 ARTICLES
WED
Oct 7

RANSOMWARE
P5
P5
COOL // 86 ARTICLES
TUE
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
RESET
2026-10-06 11:27 UTC
Vendor Research

IronChain Ransomware Threatens Businesses with Permanent Data Loss and Costly Downtime

ANY.RUN Blog · Himanshu Anand · indexed 2026-10-06 14:56 UTC

Editor’s note: This research was conducted by Himanshu Anand, an independent cybersecurity researcher (follow Himanshu on X). During Cybersecurity Awareness Month, ransomware remains one of the clearest examples of how a cyber incident can become a business continuity issue. IronChain shows why. It puts business-critical data at risk of permanent loss and can bring operations […] The post IronChain Ransomware Threatens Businesses with Permanent Data Loss and Costly Downtime appeared first on AN…

RansomwareSecurity Research
P15
2026-10-06 11:26 UTC
Security Journalism

Wikimedia Says OpenAI Agents Tried to Compromise Etherpad and Use Wiki Tools as Proxies

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-06 12:00 UTC

The Wikimedia Foundation, which hosts Wikipedia, has confirmed that it has discovered activity by rogue OpenAI agents on its platforms, including unsuccessful efforts to compromise Etherpad, a public note-taking tool, and edit Wikipedia pages. "The unauthorized bot activities included edits to our wikis, some unsuccessful attempts to exploit a public note-taking tool we host, and heavy traffic,

AI Security
P0
2026-10-06 11:02 UTC
Security Journalism

Welcome to the Jungle: What We Found Inside 15,465 Public MCP Servers

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-06 12:00 UTC

In 2024, MCP (Model Context Protocol) set out to become the USB-C of AI: one standard for connecting models, agents, and IDEs to tools and data. The protocol delivered. Thousands of developers built servers, and enterprises plugged them into agent workflows. The ecosystem around it fell short. Earlier this year, our team at OX Security, traced critical vulnerabilities in Anthropic's MCP

P0
2026-10-06 11:01 UTC
Security Journalism

Cybersecurity M&A Roundup: 39 Deals Announced in September 2026

Security Week · Eduard Kovacs · indexed 2026-10-06 11:20 UTC

Significant cybersecurity M&A deals announced by Dragos, IBM, Palo Alto Networks, Kiteworks, and Upwind. The post Cybersecurity M&A Roundup: 39 Deals Announced in September 2026 appeared first on SecurityWeek.

Network Security
P0
2026-10-06 10:34 UTC
Security Journalism

Long-Running NPM Malware Campaign Accumulates 40,000 Downloads

Security Week · Ionut Arghire · indexed 2026-10-06 10:40 UTC

Since August 2023, attackers have published eight malicious packages as part of the MALFEX supply chain campaign. The post Long-Running NPM Malware Campaign Accumulates 40,000 Downloads appeared first on SecurityWeek.

Malware
P0
2026-10-06 10:00 UTC
Vendor Research

Blinder Tunnel Campaign Targets Iraqi Infrastructure

Palo Alto Networks Unit 42 · Unit 42 · indexed 2026-10-06 10:20 UTC

Analysis of Blinder Tunnel, an Iran-nexus campaign using fake Dubai Airports recruitment lures and GitHub C2 malware to target critical infrastructure. The post Blinder Tunnel Campaign Targets Iraqi Infrastructure appeared first on Unit 42.

Malware
P0
2026-10-06 09:27 UTC
Other

FBI Drops Accenture Contractor After Sensitive Data Breach

Security Affairs · Pierluigi Paganini · indexed 2026-10-06 09:40 UTC

Accenture lost an FBI contract after a missed security patch exposed sensitive employee data, raising serious concerns over operational security. The FBI pulled an Accenture contractor off its account on Monday, and the reason is almost mundane compared to the damage it caused. One update didn’t get installed on time. “The ‌Federal Bureau of Investigation […]

Data BreachesDFIRLaw Enforcement
P0
2026-10-06 09:21 UTC
Security Journalism

Google Pauses OSS Product Bug Bounty Rewards After Surge in Invalid Automated Reports

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-06 09:50 UTC

Google has stopped accepting product vulnerability reports through its bug bounty program for its open-source software. The change, in effect since October 1, means researchers can no longer submit security flaws in the code of projects such as Go, Angular, and Protocol Buffers there for a reward. Reports about supply chain compromises are still accepted, and reports filed before October 1 are

Cloud SecurityVulnerabilities
P0
2026-10-06 08:38 UTC
Security Journalism

Social Engineering Detection Moves Into the Live Conversation

Security Week · Kevin Townsend · indexed 2026-10-06 08:45 UTC

Companies are pouring time and dollars into security awareness training, but little evidence shows it actually works against social engineering. The post Social Engineering Detection Moves Into the Live Conversation appeared first on SecurityWeek.

P0
2026-10-06 08:19 UTC
Security Journalism

Engineer sentenced for locking over 3,000 devices on employer network

BleepingComputer · Sergiu Gatlan · indexed 2026-10-06 08:20 UTC

A former core infrastructure engineer at an industrial company headquartered in New Jersey was sentenced to 32 months in prison for locking thousands of devices on his employer's network in a ransomware-style attack. [...]

Ransomware
P15
2026-10-06 08:15 UTC
Other

From Detonation to Detection: The Sandbox Now Writes the Rules

Group-IB · indexed 2026-10-06 09:25 UTC

Understanding what a malware sample does and being able to detect it are two different jobs, and the second one needs a skill many teams are short of. The Group-IB Malware Detonation Platform now produces indicators, Sigma rules, and hunting queries from the behavior it observes.

Malware
P0
2026-10-06 07:01 UTC
Other

Dell Urges Customers to Patch Critical DSU Flaw That Can Give Attackers Root Access

Security Affairs · Pierluigi Paganini · indexed 2026-10-06 07:10 UTC

Dell warns that a critical DSU flaw lets attackers run code as root. Customers should patch affected PowerEdge systems as soon as possible. Dell urged customers to patch a critical flaw, tracked as CVE-2026-86360 (CVSS score of 9.6), in its System Update (DSU) tool. The vulnerability is a path traversal issue that can let attackers […]

VulnerabilitiesCVE-2026-86360
P15
2026-10-06 06:58 UTC
Security Journalism

Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 Products

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-06 07:40 UTC

A critical flaw in 8 Atlassian Data Center products, which customers host themselves, allows an attacker with no login access to read specific files in each product's web application root directory. The attacker must already know a file's exact name and path and cannot list what the directory holds. Atlassian disclosed the flaw, CVE-2026-21589, on October 5, rated it 9.3 out of 10, and

VulnerabilitiesCVE-2026-21589
P15
2026-10-06 06:56 UTC
Security Journalism

FBI Removes Accenture Contractor After Patch Failure Led to ShinyHunters Breach

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-06 07:40 UTC

The U.S. Federal Bureau of Investigation (FBI) has removed an Accenture contractor for their alleged role in a ShinyHunters-breach that led to the theft of personal details of thousands of bureau employees. That's according to a report from Reuters, citing two sources familiar with the matter. "To date, our review has determined that the incident occurred as the result of a security failure ​

DFIRLaw Enforcement
P0
2026-10-06 06:31 UTC
Other

ClingSTUN Linux Backdoor Abuses Public STUN Infrastructure

Security Affairs · Pierluigi Paganini · indexed 2026-10-06 07:10 UTC

Fortinet details ClingSTUN, a Linux backdoor exploiting unpatched IoT devices and abusing public STUN servers to route traffic past NAT. FortiGuard Labs researchers spotted a Linux malware family they call ClingSTUN, and the name gives away its trick immediately. Instead of relying on a dedicated command server, the malicious code leans on STUN, the protocol […]

LinuxMalwareNetwork Security
P0
2026-10-06 06:00 UTC
Security Journalism

Denmark Says Attackers Accessed CPR Data for 8.8 Million People via Company Account

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-06 06:15 UTC

Unauthorized parties have gained access to the names, addresses, and personal identification numbers of about 8.8 million people, living and dead, in Denmark's national population register, the country's digitalization ministry said on October 5. They used a private Danish company's lawful right to look up records in the Central Person Register (CPR). The ministry has told people never to

Microsoft
P0
2026-10-06 05:22 UTC
Security Journalism

ClickFix Smuggles Payloads Through Browser Cache to Bypass Windows Run Limits

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-06 06:15 UTC

A new type of ClickFix attack is using compromised websites to trick users into executing a malicious payload cached in a web browser's cache. "Instead of downloading and executing remote payloads like the typical attack pattern, in this attack, the websites pre-fetch a script payload into the browser cache disguised as a PNG file," the Microsoft Threat Intelligence team said in a post on X.

MicrosoftThreat Intelligence
P0
2026-10-05 21:41 UTC
Vendor Research

AWS Continuum sets a new standard in autonomous code security

AWS Security Blog · Alexander Greaves-Tunnell · indexed 2026-10-05 21:50 UTC

As AI models become more capable, they uncover more security vulnerabilities and identify increasingly sophisticated paths to exploit them, raising the bar for how quickly defenders must respond. Security teams now face more potential vulnerabilities than their existing processes were designed to handle — each requiring investigation, reproduction, and a repair that must be tested […]

Cloud SecurityDFIRMicrosoft
P0
2026-10-05 18:15 UTC
Other

Anthropic Mythos Found A Bug in Rejetto HFS. Attackers Are Now Exploiting It.

Security Affairs · Pierluigi Paganini · indexed 2026-10-05 19:10 UTC

AI-assisted research uncovered a critical Rejetto HFS flaw that enables authentication bypass and remote code execution, now exploited in the wild. A Rejetto HFS vulnerability, tracked as CVE-2026-61500 (CVSS score of 9.3), discovered with the help of the Anthropic Mythos AI model is now being exploited in the wild, turning an interesting security research experiment […]

Security ResearchVulnerabilitiesCVE-2026-61500
P50
8 9 10 11 12