IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 4,784 matching records.
AUTO-POLL // 2026-10-11 16:30 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P6 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 11

ACTIVE EXPLOITATION
P6
P6
COOL // 5 ARTICLES
SAT
Oct 10

RANSOMWARE
P1
P1
COOL // 11 ARTICLES
FRI
Oct 9

RANSOMWARE
P4
P4
COOL // 67 ARTICLES
THU
Oct 8

RANSOMWARE
P3
P3
COOL // 62 ARTICLES
WED
Oct 7

RANSOMWARE
P5
P5
COOL // 86 ARTICLES
TUE
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
RESET
2026-05-20 16:00 UTC
Vendor Research

Cisco Nexus 3000 and 9000 Series Switches Border Gateway Protocol Denial of Service Vulnerability

Cisco Security Advisories · indexed 2026-08-15 14:33 UTC

A vulnerability in the Border Gateway Protocol (BGP) enforce-first-as feature of Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode could allow an unauthenticated, remote attacker to trigger BGP peer flaps, resulting in a denial of service (DoS) condition. This vulnerability is due to incorrect parsing of a transitive BGP attribute. An attacker could exploit this vulnerability by sending a crafted BGP update through an established BGP peer session. If…

Network SecurityVulnerabilitiesCVE-2026-20171
P5
2026-05-20 16:00 UTC
Vendor Research

Cisco Secure Workload Unauthorized API Access Vulnerability

Cisco Security Advisories · indexed 2026-08-15 14:33 UTC

A vulnerability in the access validation of internal REST APIs of Cisco Secure Workload could allow an unauthenticated, remote attacker to access site resources with the privileges of the Site Admin role. This vulnerability is due to insufficient validation and authentication when accessing REST API endpoints. An attacker could exploit this vulnerability if they are able to send a crafted API request to an affected endpoint. A successful exploit could allow the attacker to read sensitive inform…

VulnerabilitiesCVE-2026-20223
P5
2026-05-20 16:00 UTC
Vendor Research

Cisco ThousandEyes Virtual Appliance Authenticated Remote Code Execution Vulnerability

Cisco Security Advisories · indexed 2026-08-15 14:33 UTC

A vulnerability in the SSL certificate handling of Cisco ThousandEyes Virtual Appliance could allow an authenticated, remote attacker to execute commands on the underlying operating system as the root user. This vulnerability is due to insufficient validation of user-supplied input. An authenticated attacker could exploit this vulnerability by uploading a crafted certificate to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the un…

VulnerabilitiesCVE-2026-20199
P20
2026-05-20 16:00 UTC
Vendor Research

Cisco ThousandEyes Enterprise Agent BrowserBot Command Injection Vulnerability

Cisco Security Advisories · indexed 2026-08-15 14:33 UTC

A vulnerability in the BrowserBot component of Cisco ThousandEyes Enterprise Agent could have allowed an authenticated, remote attacker to execute arbitrary commands on Agents on behalf of the BrowserBot synthetics orchestration process. Cisco has addressed this vulnerability in the Cisco ThousandEyes Enterprise Agent, and no customer action is needed. This vulnerability was due to insufficient input validation of command arguments that are supplied by the user. Prior to this vulnerability bein…

VulnerabilitiesCVE-2026-20206
P5
2026-05-19 17:49 UTC
Vendor Research

Continued Evolution of Persistence Mechanism Against Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense

Cisco Security Advisories · indexed 2026-08-15 14:33 UTC

On April 23, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued an update to V1: Emergency Directive (ED) 25-03: Identify and Mitigate Potential Compromise of Cisco Devices related to Cisco Secure Firewall Adaptive Security Appliance (ASA) and Cisco Secure Firewall Threat Defense (FTD) products. According to the update, the ArcaneDoor threat actor has developed a previously unknown persistence mechanism that is preserved across upgrading to the fixed releases that wer…

Network SecurityThreat ActorsVulnerabilitiesCVE-2025-20333CVE-2025-20362
P20
2026-05-19 08:50 UTC
Other

The quest for greater tech independence

ESET · indexed 2026-09-07 17:30 UTC

A complete decoupling from US technology is neither realistic nor necessary, but the changing environment does require nations and companies to reassess their relationships and dependencies

P0
2026-05-19 07:00 UTC
Security Journalism

Exposed RDP: The Misconfiguration Attackers Keep Exploiting

Huntress · indexed 2026-09-07 17:30 UTC

Exposed RDP is still one of the most reliable ways attackers get in and most teams don't know it's open. See real cases where it was caught before it became a catastrophe.

P0
2026-05-18 09:21 UTC
Other

Introducing Group-IB Prevyn AI

Group-IB · indexed 2026-09-07 17:30 UTC

How Group-IB is building a cognitive core that anticipates threats before they happen

P0
2026-05-18 06:00 UTC
Vendor Research

Project Glasswing: what Mythos showed us

Cloudflare Security · Grant Bourzikas · indexed 2026-08-15 18:58 UTC

In recent weeks, we pointed Mythos and other security-focused LLMs at live code across critical parts of our infrastructure. We share what we observed, the models’ strengths and weaknesses, and what the work around them needs to look like before any of it can scale.

AI Security
P0
2026-05-15 14:00 UTC
Vendor Research

Welcome to BlackFile: Inside a Vishing Extortion Operation

Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-08-15 18:55 UTC

Written by: Austin Larsen, Tyler McLellan, Genevieve Stark, Dan Ebreo Introduction Google Threat Intelligence Group (GTIG) has continued to track an expansive extortion campaign by UNC6671, a threat actor operating under the "BlackFile" brand, that targets organizations via sophisticated voice phishing (vishing) and single sign-on (SSO) compromise. By leveraging adversary-in-the-middle (AiTM) techniques to bypass traditional perimeter defenses and multi-factor authentication (MFA), UNC6671 gain…

Data BreachesMicrosoftNetwork SecurityPhishingThreat ActorsThreat IntelligenceVulnerabilities
P0
2026-05-15 11:58 UTC
Other

What Is an Incident Response Retainer? (And Why Waiting Until a Breach Is Too Late)

Group-IB · indexed 2026-09-07 17:30 UTC

An incident response retainer gives organizations immediate access to cybersecurity experts when a breach occurs, without losing critical time to legal, procurement, or onboarding delays. This article explains how IR retainers work, the different retainer models available, and why they can significantly reduce downtime, damage, and uncertainty during a cyber incident.

DFIR
P0
2026-05-15 04:00 UTC
Security Journalism

What Is Single Sign-On? The Practical Guide | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

Learn what single sign-on (SSO) login is, how it’s used in role management and cybersecurity, and how to set it up at your organization.

P0
2026-05-15 00:00 UTC
Security Journalism

Strong Stack. Strong Team. Real Security Resilience.

Huntress · indexed 2026-09-07 17:30 UTC

Learn how to build a resilient security stack and program that cuts alert noise, strengthens identity defense, and helps teams respond faster.

P0
2026-05-14 16:00 UTC
Vendor Research

Cisco Catalyst SD-WAN Manager Vulnerabilities

Cisco Security Advisories · indexed 2026-08-15 14:33 UTC

Multiple vulnerabilities in Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow a remote attacker to gain access to sensitive information, elevate privileges, or gain unauthorized access to the application. For more information about these vulnerabilities, see the Details section of this advisory. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities. Cisco strongly recommends that customers upgrade to…

VulnerabilitiesCVE-2026-20209CVE-2026-20210CVE-2026-20224
P5
2026-05-14 15:56 UTC
Vendor Research

Cisco Crosswork Network Controller and Cisco Network Services Orchestrator Advisory

Cisco Security Advisories · indexed 2026-08-15 14:33 UTC

Following the initial publication of the Security Advisory about a denial of service (DoS) condition in Cisco Crosswork Network Controller and Cisco Network Services Orchestrator (NSO), additional information has been made available to the Cisco Product Security Incident Response Team (PSIRT). Upon further analysis, the Cisco PSIRT has reclassified this issue as a customer-configurable, resource management issue rather than a security vulnerability. This advisory is available at the following l…

DFIRVulnerabilitiesCVE-2026-20188
P5
2026-05-14 11:00 UTC
Security Journalism

Panic at the Distro

Huntress · indexed 2026-09-07 17:30 UTC

Learn how critical Linux kernel flaws in CopyFail, Dirty Frag, and Fragnesia let unprivileged users escalate to root access. See what security teams can do to remediate.

Cloud SecurityLinux
P0
2026-05-14 09:38 UTC
Other

The Mythos Effect: Why Exposure Intelligence Matters More Than Ever

Red Hunt Labs · Sudhanshu Chauhan · indexed 2026-09-07 17:30 UTC

Why Mythos (and other AI models) Make Continuous Exposure Visibility Critical For years, vulnerability discovery was naturally constrained by expertise, time, and scale. Finding meaningful security issues often required experienced researchers spending days or weeks understanding codebases, testing assumptions, reviewing implementations, and validating exploitability. That dynamic is changing rapidly. Recent developments around systems like Anthropic’s Project Glasswing 🔗 and Mythos, OpenAI’s …

AppleMicrosoftSecurity ResearchVulnerabilities
P50
2026-05-14 04:00 UTC
Security Journalism

CMMC Final Rule: A Guide for DoD Subcontractors

Huntress · indexed 2026-09-07 17:30 UTC

CMMC final rule requires DoD subs meet Level 2 by Nov 2026. Huntress Managed SIEM provides vendor docs and 24/7 monitoring for compliance.

P0
110 111 112 113 114