IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 4,784 matching records.
AUTO-POLL // 2026-10-11 17:15 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P6 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 11

ACTIVE EXPLOITATION
P6
P6
COOL // 5 ARTICLES
SAT
Oct 10

RANSOMWARE
P1
P1
COOL // 11 ARTICLES
FRI
Oct 9

RANSOMWARE
P4
P4
COOL // 67 ARTICLES
THU
Oct 8

RANSOMWARE
P3
P3
COOL // 62 ARTICLES
WED
Oct 7

RANSOMWARE
P5
P5
COOL // 86 ARTICLES
TUE
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
RESET
2026-04-30 13:00 UTC
Security Journalism

ClickFix Removes Your Background but Leaves the Malware

Huntress · indexed 2026-09-07 17:30 UTC

Your background is gone, but malware is here. Huntress breaks down BackgroundFix, a new ClickFix social engineering tactic involving CastleLoader, NetSupport RAT, and CastleStealer. Read the analysis.

Malware
P0
2026-04-30 09:25 UTC
Government

2026-005: High Vulnerability in the Linux Kernel ("Copy Fail")

CERT-EU Security Advisories · indexed 2026-08-15 18:50 UTC

On 29 April 2026, a high local privilege escalation vulnerability in the Linux kernel, tracked as CVE-2026-31431 and named "Copy Fail", was publicly disclosed. The vulnerability affects every mainstream Linux distributions shipping a kernel built since 2017. A public proof-of-concept exploit has been released. As of the date of this advisory, no distribution has shipped a fixed kernel package. The mainline fix was committed on 1 April 2026, but vendor updates are still pending across all major …

Cloud SecurityLinuxVulnerabilitiesCVE-2026-31431
P15
2026-04-30 09:00 UTC
Other

This month in security with Tony Anscombe – April 2026 edition

ESET · indexed 2026-09-07 17:30 UTC

Warnings about helpdesk impersonation scams and Iran-linked hackers targeting critical sectors in the US, plus the most damaging scams of 2025 - here's some of what made the headlines this month

P0
2026-04-29 06:54 UTC
Other

Phoenix Rising: Exposing the PhaaS Kit Behind Global Mass Phishing Campaigns

Group-IB · indexed 2026-09-07 17:30 UTC

While analyzing global smishing operations spanning APAC, LATAM, Europe, and MEA, Group-IB researchers uncovered the 'Phoenix System' administrative panel, a centralized Phishing-as-a-Service (PhaaS) platform with real-time victim monitoring, geofencing, and live-phishing interventions to bypass multi-factor authentication.

MicrosoftPhishing
P0
2026-04-28 12:00 UTC
Government

From DMV to Wallet: Understanding Verifiable Digital Credential Issuance

NIST Cybersecurity Insights · Bill Fisher, Ryan Galluzzo, Heather Flanagan · indexed 2026-08-15 20:45 UTC

In our last post in this series, we compared two credential formats that shape the digital identity ecosystem: ISO/IEC 18013-5 and -7 mobile documents (mdocs) and W3C Verifiable Credentials (VCs). Both formats define how a credential is structured and shared, but neither can function without an issuance process. This blog post explores what it takes to issue verifiable digital credentials, with a focus on mobile driver’s licenses (mDLs). We’ll look at how issuance works today in practice, where…

P0
2026-04-23 21:38 UTC
Vendor Research

AI threats in the wild: The current state of prompt injections on the web

Google Online Security Blog · Kimberly Samra · indexed 2026-08-15 14:33 UTC

Posted by Thomas Brunner, Yu-Han Liu, Moni PandeAt Google, our Threat Intelligence teams are dedicated to staying ahead of real-world adversarial activity, proactively monitoring emerging threats before they can impact users. Right now, Indirect Prompt Injection (IPI) is a top priority for the security community, anticipating it as a primary attack vector for adversaries to target and compromise AI agents. But while the danger of IPI is widely discussed, are threat actors actually exploiting th…

AI SecurityMicrosoftSecurity ResearchThreat ActorsThreat Intelligence
P20
2026-04-23 14:00 UTC
Vendor Research

Snow Flurries: How UNC6692 Employed Social Engineering to Deploy a Custom Malware Suite

Google Threat Intelligence / Mandiant · Mandiant · indexed 2026-08-15 18:55 UTC

Written by: JP Glab, Tufail Ahmed, Josh Kelley, Muhammad Umair Introduction Google Threat Intelligence Group (GTIG) identified a multistage intrusion campaign by a newly tracked threat group, UNC6692, that leveraged persistent social engineering, a custom modular malware suite, and deft pivoting inside the victim’s environment to achieve deep network penetration. As with many other intrusions in recent years, UNC6692 relied heavily on impersonating IT helpdesk employees, convincing their victim…

Cloud SecurityMalwareMicrosoftPhishingThreat ActorsThreat Intelligence
P0
2026-04-22 20:00 UTC
Security Journalism

What Cybersecurity Leaders Must Prioritize in 2026

Huntress · indexed 2026-09-07 17:30 UTC

The threat landscape has shifted. Here's what cybersecurity leaders need to know about RMM abuse, AI-powered attacks, ransomware, and identity threats in 2026.

Ransomware
P15
2026-04-21 13:00 UTC
Security Journalism

Tradecraft Tuesday Recap: axios npm Supply Chain Compromise

Huntress · indexed 2026-09-07 17:30 UTC

A few weeks after the major axios npm supply chain attack, a group of researchers from Huntress, Wiz, and Aikido Security debriefed on the compromise’s lasting impacts.

Apple
P0
2026-04-20 18:00 UTC
Security Journalism

Nightmare-Eclipse Tooling Seen in Real-World Intrusion

Huntress · indexed 2026-09-07 17:30 UTC

Huntress observed in-the-wild use of Nightmare-Eclipse tooling, including BlueHammer, RedSun, and UnDefend, in a live intrusion involving FortiGate VPN compromise as the initial access, reconnaissance commands, and likely tunneling activity.

Network Security
P0
2026-04-17 20:00 UTC
Security Journalism

Uptick in Bomgar RMM Exploitation

Huntress · indexed 2026-09-07 17:30 UTC

The Huntress SOC has seen a recent uptick in incidents involving compromised Bomgar remote monitoring and management (RMM) instances.

P0
2026-04-17 14:00 UTC
Security Journalism

Untangling a Linux Incident With an OpenAI Twist

Huntress · indexed 2026-09-07 17:30 UTC

A Linux user recently tried to respond to potentially malicious behavior on their machine using OpenAI’s Codex coding agent, before installing the Huntress agent. What ensued shows the unexpected impacts of this AI use case on DFIR investigations.

DFIRLinux
P0
2026-04-17 14:00 UTC
Security Journalism

Disrupting Attacks on Endpoints | Attack Disruption Engine

Huntress · indexed 2026-09-07 17:30 UTC

Standard EDR creates a gap between detection and action. Huntress closes it. Learn how our Attack Disruption Engine automatically disrupts threat actors and reduces the impact of endpoint attacks.

Threat Actors
P0
2026-04-17 07:00 UTC
Security Journalism

Attackers Love Your VPN To-Do List

Huntress · indexed 2026-09-07 17:30 UTC

VPN misconfiguration is behind 70% of intrusions. See real Huntress SOC incidents and learn the simple steps to close your biggest open door before attackers walk through it.

Network Security
P0
2026-04-16 14:00 UTC
Vendor Research

Defending Your Enterprise When AI Models Can Find Vulnerabilities Faster Than Ever

Google Threat Intelligence / Mandiant · Francis deSouza · indexed 2026-08-15 18:55 UTC

Introduction Advances in AI model-powered exploitation have demonstrated that general-purpose AI models can excel at vulnerability discovery, even without being purpose-built for the task. Eventually, capabilities such as these will be integrated directly into the development cycle, and code will be more difficult to exploit than ever; however, this transition creates a critical window of risk. As we harden existing software with AI, threat actors will use it to discover and exploit novel vulne…

AI SecurityAPT / Nation-StateCloud SecurityDFIRMicrosoftRansomwareThreat ActorsVulnerabilities
P60
112 113 114 115 116