IntelFreed Cybersecurity Intelligence Weather Report

HIGH PRIORITY

Aggregated cybersecurity reporting, advisories and research. 351 matching records.
AUTO-POLL // 2026-10-10 00:35 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
NO DATA
NO INTELLIGENCE AGGREGATED TODAY
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 10
NO DATA
--
NO INTEL
FRI
Oct 9

RANSOMWARE
P4
P4
COOL // 67 ARTICLES
THU
Oct 8

RANSOMWARE
P3
P3
COOL // 62 ARTICLES
WED
Oct 7

RANSOMWARE
P5
P5
COOL // 86 ARTICLES
TUE
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
RESET
2026-09-21 14:24 UTC
Security Journalism

⚡ Weekly Recap: Cisco 0-Day, AI Agent RCE, ClickFix Attacks, ClickFix Surge, and Browser Hijacks

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-21 14:45 UTC

A browser. A plugin. A package. A login screen. Normal stuff. That is basically the problem this week. The trouble keeps showing up inside things people already trust: code that takes a bad turn, old payloads coming back, exposed systems, weak checks, fake fixes, and attack paths that look almost too easy. Even the research side is getting messy, with more findings, more automation, and not

AI SecurityVulnerabilities
P25
2026-09-18 07:14 UTC
Security Journalism

Check Point, Kaspersky, Tanium Patch Product Vulnerabilities

Security Week · Eduard Kovacs · indexed 2026-09-18 07:30 UTC

Check Point Security Management and Log Servers are affected by a critical vulnerability that can allow remote code execution with root privileges. The post Check Point, Kaspersky, Tanium Patch Product Vulnerabilities appeared first on SecurityWeek.

Vulnerabilities
P25
2026-09-17 06:19 UTC
Security Journalism

Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day

Security Week · Ionut Arghire · indexed 2026-09-17 06:35 UTC

Remote, unauthenticated attackers can exploit the vulnerability to bypass authentication via crafted requests. The post Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day appeared first on SecurityWeek.

Vulnerabilities
P25
2026-09-16 05:18 UTC
Security Journalism

Active Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-16 06:40 UTC

A critical security flaw in WSO2 API Manager has come under active exploitation in the wild, according to findings from watchTowr. The vulnerability, tracked as CVE-2026-5430 (CVSS score: 9.8/10.0), is a case of improper verification of a cryptographic signature that could result in account takeover. Hacktron Team has been credited with discovering and reporting the flaw. "JWT authentication

VulnerabilitiesCVE-2026-5430
P25
2026-09-15 13:45 UTC
Security Journalism

What Zero-Day Response Should Be in the Post-Mythos Era

BleepingComputer · Sponsored by Picus Security · indexed 2026-09-15 14:05 UTC

AI is shrinking the time between vulnerability disclosure and exploitation, leaving defenders less time to wait for patches or public exploits. Picus Security explains how exploitability validation, security control testing, and autonomous pentesting can help teams close exposure gaps before attackers arrive. [...]

MicrosoftVulnerabilities
P25
2026-09-15 10:17 UTC
Other

One Exploit Chain, Two Espionage Campaigns: Chrome and Windows Under Fire

Security Affairs · Pierluigi Paganini · indexed 2026-09-15 11:30 UTC

Two China-linked groups ran identical Chrome/Windows zero-day exploits against NGOs, before Chrome’s patch shipped, deploying different backdoors each. Two China-linked threat actors used the same Chrome/Windows zero-day against NGOs starting September 1, 2026, Volexity’s new report lays out the whole chain in detail. On September 1, Volexity detected a spear-phishing campaign by UTA0560 targeting several […]

APT / Nation-StateMalwareMicrosoftPhishingThreat ActorsVulnerabilities
P25
2026-09-15 07:19 UTC
Other

Non-Zero-Day VPN Flaw Left Japan ‘s Government Shared Network Platform Exposed: 246,000 Records at Risk

Security Affairs · Pierluigi Paganini · indexed 2026-09-15 08:00 UTC

Japan ‘s Digital Agency disclosed a VPN breach exposing 246,000 government employee records across 23 ministries. Detected June 25, publicly disclosed September 11. Japan ‘s Digital Agency disclosed that attackers exploited a vulnerability in a VPN device to access its Government Solution Service (GSS), potentially leaking personal information belonging to approximately 246,000 government employees, public […]

Network SecurityVulnerabilities
P25
2026-09-15 05:31 UTC
Security Journalism

China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-15 06:25 UTC

A Chinese threat actor has been attributed to a spear-phishing campaign that exploits recently patched security flaws in Google Chrome and Microsoft Windows to deliver a malicious JavaScript backdoor called GRIMWEDGE. Volexity, which is tracking the threat cluster under the moniker UTA0560, said the activity targeted multiple non-governmental organizations (NGOs) on September 1, 2026. "The

Cloud SecurityMalwareMicrosoftPhishingThreat ActorsVulnerabilities
P25
2026-09-11 06:46 UTC
Security Journalism

PaperCut Replaces Emergency Patches With Fixes for Two Actively Exploited Flaws

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-11 07:40 UTC

PaperCut on Thursday released a new security maintenance release that replaces all previously published emergency patches that were pushed to address two security flaws that have come under active exploitation. The software development company said PaperCut NG/MF versions 26.0.5, 25.0.13 and 24.1.10 are now available for customers to download. "These are Regular Maintenance Releases (MR) that

Cloud Security
P25
2026-09-10 13:00 UTC
Vendor Research

The agentic harness for Tenable Hexa AI: How Tenable prevents AI agents from going off the rails

Tenable Blog · Raj Agrawal · indexed 2026-09-10 13:05 UTC

Learn why Tenable treats agentic LLMs as untrusted insiders, and how we’ve made sure you can control and monitor the AI agents making changes in your production security environmentKey takeawaysAI models can quickly understand data, but not your business. While modern AI models are great at reasoning, they don’t automatically understand your unique environment or who is allowed to do what. The “harness” is the custom-built layer that translates AI intelligence into safe, controlled actions spec…

AI SecurityVulnerabilities
P25
2026-09-10 05:35 UTC
Other

Four Nation-State Actors Used the Same Chrome Zero-Day Exploit Kit Within 12 Days

Security Affairs · Pierluigi Paganini · indexed 2026-09-10 06:35 UTC

Four espionage groups used the BlueMoon Chrome+Windows exploit kit within 12 days. Researchers suspect AI development. Proofpoint published a detailed analysis of a Chrome-and-Windows exploit kit it tracks as BlueMoon that four nation-state actors adopted within roughly two weeks of the first observed use. Google’s Threat Intelligence Group, Microsoft’s MSTIC, and Volexity all contributed to […]

APT / Nation-StateMicrosoftThreat IntelligenceVulnerabilities
P25
2026-09-09 09:45 UTC
Security Journalism

Chrome 153 Patches Seventh Zero-Day of 2026

Security Week · Ionut Arghire · indexed 2026-09-09 09:50 UTC

The Chrome update includes 230 security fixes, and users are advised to update their browsers as soon as possible. The post Chrome 153 Patches Seventh Zero-Day of 2026 appeared first on SecurityWeek.

Vulnerabilities
P25
2026-09-09 07:53 UTC
Other

Chaotic Eclipse Released ShieldCrash, A PoC For Microsoft Defender Zero-Day

Security Affairs · Pierluigi Paganini · indexed 2026-09-09 08:30 UTC

The researcher Chaotic Eclipse released ShieldCrash, a PoC exploit for a Microsoft Defender Zero-Day vulnerability. Security researcher Chaotic Eclipse, also known as INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse, released a new zero-day exploit targeting Microsoft Defender. The researcher named the exploit ShieldCrash, it triggers an arbitrary file read as SYSTEM. The researcher claims that Microsoft has not fully […]

MicrosoftSecurity ResearchVulnerabilities
P25
2026-09-08 20:24 UTC
Security Journalism

The EU CRA's Real Question: What Shipped, and When Did You Know?

BleepingComputer · Sponsored by ActiveState · indexed 2026-09-08 20:25 UTC

The EU Cyber Resilience Act's vulnerability reporting requirements take effect September 11, giving software vendors as little as 24 hours to report actively exploited flaws. ActiveState explains why knowing exactly what shipped and when vulnerabilities were discovered will be critical to meeting the new requirements. [...]

Cloud SecurityVulnerabilities
P25
2026-09-08 10:37 UTC
Security Journalism

N-able Patches Critical Zero-Day in N-central

Security Week · Ionut Arghire · indexed 2026-09-08 10:50 UTC

Administrators are advised to check their deployments for newly created user accounts they don’t recognize. The post N-able Patches Critical Zero-Day in N-central appeared first on SecurityWeek.

MicrosoftVulnerabilities
P25
2026-09-07 17:49 UTC
Other

StyleSmuggler: The Magento Zero-Day Behind New Store Attacks

Security Affairs · Pierluigi Paganini · indexed 2026-09-07 18:00 UTC

StyleSmuggler Magento zero-day is under active attack, letting unauthenticated attackers execute code and install backdoors on stores that may already be patched. A new zero-day flaw, dubbed StyleSmuggler, in Magento and Adobe Commerce is under active attack, giving unauthenticated attackers a path to run code on vulnerable online stores. Sansec researchers say it affects current […]

MalwareVulnerabilities
P25
2026-09-07 14:36 UTC
Security Journalism

⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-07 16:10 UTC

Turning off email images should at least stop the pictures. This week, attackers had a workaround: a scannable QR code built out of text. It still appears, even with images blocked. A small detail, but an annoying one if that was a precaution you were counting on. Elsewhere, a trusted software source delivered code that stole credentials, and a protocol designed for secure network management

Network SecurityVulnerabilities
P25
2026-09-07 13:42 UTC
Other

Chaotic Eclipse Released GreenSection, A PoC For NVIDIA Memory Corruption Zero-Day

Security Affairs · Pierluigi Paganini · indexed 2026-09-09 08:30 UTC

Chaotic Eclipse released GreenSection, a PoC exploit for an Nvidia Memory Corruption Zero-Day Security researcher Chaotic Eclipse, also known as INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse, released a new zero-day exploit targeting Nvidia. The researcher named the exploit GreenSection, it triggers a Memory Corruption flaw. The researcher disclosed a potential security vulnerability in NVIDIA’s Windows user-mode components. […]

MicrosoftSecurity ResearchVulnerabilities
P25
2026-09-07 13:42 UTC
Other

Chaotic Eclipse Released A PoC For NVIDIA GreenSection Memory Corruption Zero-Day

Security Affairs · Pierluigi Paganini · indexed 2026-09-07 14:40 UTC

Chaotic Eclipse released GreenSection, a PoC exploit for an Nvidia GreenSection Memory Corruption Zero-Day Security researcher Chaotic Eclipse, also known as INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse, released a new zero-day exploit targeting Nvidia. The researcher named the exploit GreenSection, it triggers a Memory Corruption flaw. The researcher disclosed a potential security vulnerability in NVIDIA’s Windows user-mode […]

MicrosoftSecurity ResearchVulnerabilities
P25
2026-09-07 11:58 UTC
Security Journalism

Adobe Commerce Zero-Day Exploited to Backdoor Online Stores

Security Week · Ionut Arghire · indexed 2026-09-07 17:25 UTC

The StyleSmuggler zero-day allows attackers to execute code and deploy a stealthy backdoor on Adobe Commerce and Magento stores. The post Adobe Commerce Zero-Day Exploited to Backdoor Online Stores appeared first on SecurityWeek.

MalwareVulnerabilities
P25
8 9 10 11 12