IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 4,782 matching records.
AUTO-POLL // 2026-10-11 14:50 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
WARM
COOL WARM ELEVATED HOT CRITICAL
P10 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 11

ACTIVE EXPLOITATION
P10
P10
WARM // 3 ARTICLES
SAT
Oct 10

RANSOMWARE
P1
P1
COOL // 11 ARTICLES
FRI
Oct 9

RANSOMWARE
P4
P4
COOL // 67 ARTICLES
THU
Oct 8

RANSOMWARE
P3
P3
COOL // 62 ARTICLES
WED
Oct 7

RANSOMWARE
P5
P5
COOL // 86 ARTICLES
TUE
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
RESET
2026-06-30 13:00 UTC
Security Journalism

Microsoft 365 Hardening and Huntress Managed ISPM

Huntress · indexed 2026-09-07 17:30 UTC

Most Microsoft 365 environments are missing more than half of the recommended security controls, even with tooling in place. Here's why that happens and what Huntress Managed ISPM does about it.

Microsoft
P0
2026-06-30 12:00 UTC
Government

Verifiable Digital Credential Presentment

NIST Cybersecurity Insights · Bill Fisher, Ryan Galluzzo, Heather Flanagan · indexed 2026-08-15 20:45 UTC

This blog post is #4 in our series on Verifiable Digital Credentials (VDCs). Our other posts can be found via Post #1, Post #2, and Post #3. In earlier posts, we discussed how verifiable digital credentials (VDCs) are issued and compared the underlying credential formats (ISO/IEC “mdoc” vs. W3C Verifiable Credentials). In this post, we turn to the other side of the story: presentation; that is, how a holder shows their VDC to a verifier at runtime in both in-person and online contexts. We’ll ag…

P0
2026-06-29 14:00 UTC
Vendor Research

The Bear Necessities: A Look at the Drivers, Dynamics, and Applications of the Pro-Russia Influence Ecosystem

Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-08-15 18:55 UTC

Written by: James Sadowski, Alden Wahlstrom Introduction Four years into Russia’s full-scale invasion of Ukraine, the pro-Russia influence ecosystem has evolved from a tool of war back into a global strategic asset. Since the mobilization of this ecosystem to support frontline objectives, we have witnessed the expedited development of new influence assets linked to multiple, expansive, covert information operations (IO) campaigns and a revitalization of pro-Russia hacktivism at an unprecedented…

APT / Nation-StateMicrosoft
P0
2026-06-29 07:00 UTC
Security Journalism

These Recent Insider Threat Allegations

Huntress · indexed 2026-09-07 17:30 UTC

Huntress responds to recent public allegations of an insider threat, separating fact from speculation and sharing how we approach ethics, transparency, and trust.

P0
2026-06-29 07:00 UTC
Security Journalism

Defence Impairment Olympics

Huntress · indexed 2026-09-07 17:30 UTC

Huntress analyzed a credential dumping attack where threat actors disabled Defender, killed monitoring tools, and used Mimikatz to steal credentials.

MicrosoftThreat Actors
P0
2026-06-25 14:31 UTC
Vendor Research

Cisco Finesse Remote File Inclusion Vulnerability

Cisco Security Advisories · indexed 2026-08-15 14:33 UTC

A vulnerability in Cisco Finesse could allow an unauthenticated, remote attacker to load arbitrary files from remote locations into an active user session on an affected device, possibly leading to browser-based attacks. This vulnerability is due to insufficient validation of user-supplied input for HTTP requests that are sent to an affected device. An attacker who has knowledge of the address of the affected device could exploit this vulnerability by persuading a user to click a crafted link t…

VulnerabilitiesCVE-2026-20175
P5
2026-06-25 14:00 UTC
Vendor Research

STOCKSTAY Another Day: The Latest Addition to Turla’s Intelligence Gathering Apparatus

Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-08-15 18:55 UTC

Written by: Jordan Jones Introduction Google Threat Intelligence Group (GTIG) has conducted an in-depth analysis of a .NET backdoor, tracked as STOCKSTAY, that has been continually developed and deployed by the Russia-linked threat actor Turla (aka SUMMIT, Secret Blizzard, VENOMOUS BEAR, UAC-0194) since at least December 2022. Turla has deployed STOCKSTAY against government and military organizations in Ukraine, as well as entities with an interest in Italian foreign policy. Used for ongoing cy…

APT / Nation-StateMalwareMicrosoftThreat ActorsThreat Intelligence
P0
2026-06-25 09:30 UTC
Other

Millenium: A RAT Rewritten, A Threat Multiplied

Group-IB · indexed 2026-09-07 17:30 UTC

Group-IB analyzes Millenium RAT version 4.*, a remote access trojan that has undergone an architectural shift from .NET to native C++, while continuing to leverage the Telegram Bot API for command and control, requiring no dedicated server infrastructure. This blog also profiles the developer “ShinyEnigma”, and threat actor cluster “Y2K Operators” responsible for active Millenium RAT exploitation campaigns. Over 62,000 compromised endpoints across more than 160 countries have been identified, w…

MalwareThreat Actors
P0
2026-06-24 12:00 UTC
Government

Advancing Product Security: New IoT Guidance and New Engagement

NIST Cybersecurity Insights · Michael Fagan · indexed 2026-08-15 20:45 UTC

It may be summertime, but the NIST Cybersecurity for the Internet of Things (IoT) Program isn’t hitting the hammock! Organizations are managing growing device complexity, evolving threats, and pressure to turn guidance into operational decisions…so we remain focused on helping stakeholders apply security guidance in ways that are practical and actionable. What’s Been Happening Lately? An initial public draft (IPD) of NIST SP 800-213 Revision 1, IoT Product Cybersecurity Guidelines for the Feder…

P0
2026-06-24 11:00 UTC
Vendor Research

Zero-Day Exploitation of Vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN Manager

Google Threat Intelligence / Mandiant · Mandiant · indexed 2026-08-15 18:55 UTC

Written by: Chester Sng, Pete Boonyakarn, Logeswaran Nadarajan, Lukasz Lamparski Introduction In early 2026, Mandiant identified a threat actor targeting SD-WAN infrastructure at a service provider. After gaining initial access, the threat actor exploited a zero-day vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN to escalate privileges from a compromised administrative account to root-level access. The vulnerability stems from the device’s file upload feature lacking the ability to prop…

MicrosoftNetwork SecurityThreat ActorsVulnerabilitiesCVE-2026-20127CVE-2026-20182CVE-2026-20245
P40
2026-06-24 06:00 UTC
Vendor Research

Unlocking the Cloudflare app ecosystem with OAuth for all

Cloudflare Security · Sam Cabell · indexed 2026-08-15 18:58 UTC

Self-Managed OAuth is now available to all developers on Cloudflare. Here's how we executed a zero-downtime migration of our core OAuth engine to make it happen.

P0
2026-06-23 16:12 UTC
Independent Research

Scattered Spider Hackers Plead Guilty on Day 1 of Trial

Krebs on Security · BrianKrebs · indexed 2026-08-15 14:33 UTC

Two men pleaded guilty in the United Kingdom this week to criminal charges stemming from an August 2024 cyberattack that crippled Transport for London, the entity responsible for the public transport network in the Greater London area. The duo were key members of a prolific cybercrime group known as Scattered Spider, and their guilty pleas came on the first day of what was expected to be a six-week trial.

Cybercrime
P0
2026-06-23 01:16 UTC
Other

10 Cybersecurity Priorities for E-Commerce Teams This Year

Group-IB · indexed 2026-09-07 17:30 UTC

E-commerce is the second most targeted sector for cyberattacks in 2026. Get the 10 priorities every security team must act on, with Group-IB intelligence behind each.

P0
2026-06-22 15:04 UTC
Vendor Research

Cisco Packaged Contact Center Enterprise and Cisco Unified Contact Center Enterprise Cross-Site Scripting Vulnerabilities

Cisco Security Advisories · indexed 2026-08-15 14:33 UTC

Multiple vulnerabilities in the web-based management interface of Cisco Packaged Contact Center Enterprise (Packaged CCE) and Cisco Unified Contact Center Enterprise (Unified CCE) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. These vulnerabilities exist because the web-based management interface does not properly validate user-supplied input. An attacker could exploit these…

VulnerabilitiesCVE-2026-20055CVE-2026-20109
P5
106 107 108 109 110