IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 4,768 matching records.
AUTO-POLL // 2026-10-10 00:35 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
NO DATA
NO INTELLIGENCE AGGREGATED TODAY
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 10
NO DATA
--
NO INTEL
FRI
Oct 9

RANSOMWARE
P4
P4
COOL // 67 ARTICLES
THU
Oct 8

RANSOMWARE
P3
P3
COOL // 62 ARTICLES
WED
Oct 7

RANSOMWARE
P5
P5
COOL // 86 ARTICLES
TUE
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
RESET
2026-10-05 09:37 UTC
Security Journalism

Microsoft: Windows KB5124010 update crashes some games and apps

BleepingComputer · Sergiu Gatlan · indexed 2026-10-05 09:45 UTC

Microsoft confirmed over the weekend that some games and applications using AC-3 (Dolby Digital) audio decoding will crash after installing the September 2026 KB5124010 Windows 11 preview update. [...]

Microsoft
P0
2026-10-05 09:12 UTC
Other

MI5 Raises Alarm Over Chinese Funding of UK Academic Research

Security Affairs · Pierluigi Paganini · indexed 2026-10-05 09:20 UTC

MI5 warns UK universities that over 100 academics may have unknowingly worked on research funded by a Chinese institute linked to the MSS. On September 30, MI5 published a formal warning naming the China General Technology Research Institute, CGTRI, also called CAGT in some translations, as an outfit with very strong ties to China’s Ministry […]

P0
2026-10-05 08:33 UTC
Other

Iranian hacker accused of draining 31TB from university inboxes extradited to the US

Security Affairs · Pierluigi Paganini · indexed 2026-10-05 09:20 UTC

Iranian hacker Amir Barati faces extradition to the US over an alleged Iranian campaign that stole 31TB of data from universities. Amir Barati spent June 25 getting arrested in Montenegro, and this week a Montenegrin court signed off on sending him to the United States. He’s a dual Turkish and Iranian citizen, 40 years old, […]

Law Enforcement
P0
2026-10-05 08:09 UTC
Security Journalism

Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-05 09:30 UTC

A critical security flaw impacting Rejetto HTTP File Server (HFS) is witnessing active exploitation attempts, according to VulnCheck. The vulnerability in question is CVE-2026-61500 (CVSS score: 9.3), a case of session forgery stemming from the use of a weak pseudo-random number generator (PRNG) that can lead to a predictable key, which an attacker can then use to gain unauthorized access and

VulnerabilitiesCVE-2026-61500
P20
2026-10-05 07:30 UTC
Other

Another OpenAI Safety Expert Quits and Raises New AI Safety Concerns

Security Affairs · Pierluigi Paganini · indexed 2026-10-05 08:25 UTC

OpenAI safety veteran David Robinson resigns, warning that the company’s culture and fast AI development model could create bigger risks. OpenAI safety veteran David Robinson knows how his resignation looks. He starts his essay by calling himself “something of a cliché”: an AI company employee who quits and then raises concerns about the company. But […]

P0
2026-10-05 07:16 UTC
Security Journalism

Alleged ShinyHunters Leader Arrested in Jordan

Security Week · Ionut Arghire · indexed 2026-10-05 07:30 UTC

Known as Rey, the suspect is reportedly helping the FBI identify and locate other members of the extortion group. The post Alleged ShinyHunters Leader Arrested in Jordan appeared first on SecurityWeek.

Law Enforcement
P0
2026-10-05 06:40 UTC
Security Journalism

New NetScaler Zero-Day Exploited in Targeted Attacks Can Knock SAML Deployments Offline

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-05 08:00 UTC

Citrix has released security updates for a high-severity security flaw in NetScaler ADC and NetScaler Gateway that has been exploited as part of targeted zero-day attacks. The vulnerability, tracked as CVE-2026-88779, carries a CVSS score of 8.7 out of 10.0. "CVE-2026-88779 is a memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway that can lead to

VulnerabilitiesCVE-2026-88779
P30
2026-10-05 00:15 UTC
Community

TTY Logs and the Data it Captures, (Sun, Oct 4th)

SANS Internet Storm Center · indexed 2026-10-05 00:25 UTC

For an experiment, I created a script [1] that parses and send the TTY logs collected from actors or bots activity that run various commands after they successfully login the DShield sensor. Those TTY logs are sent daily at the end of each day to the DShield SIEM [2] to be correlated with all the data. 

P0
2026-10-04 21:58 UTC
Security Journalism

Citrix patches NetScaler SAML zero-day exploited in attacks

BleepingComputer · Lawrence Abrams · indexed 2026-10-04 22:00 UTC

Citrix has released emergency updates for a new NetScaler denial-of-service vulnerability tracked as CVE-2026-88779 that has been exploited in zero-day attacks, with researchers investigating whether it can also be exploited for remote code execution. [...]

VulnerabilitiesCVE-2026-88779
P65
2026-10-04 15:28 UTC
Other

SECURITY AFFAIRS AI-CYBERSECURITY NEWSLETTER ROUND 2

Security Affairs · Pierluigi Paganini · indexed 2026-10-04 15:50 UTC

Security Affairs AI-CYBERSECURITY newsletter includes a collection of the best articles and research on AI in the international landscape Artificial intelligence is rapidly changing cybersecurity, reshaping both the techniques used by attackers and the tools available to defenders. AI agents can automate tasks, analyze large amounts of data, discover vulnerabilities and accelerate offensive operations. At […]

AI SecurityMicrosoft
P0
2026-10-04 14:00 UTC
Other

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 117

Security Affairs · Pierluigi Paganini · indexed 2026-10-04 14:35 UTC

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Lunex Unmasked: A New Information Stealer Deployed Through BYOVD Storm-3168: Agentic-driven cloud attacks using compromised service principals Don’t Call Us, We’ll Call Your APIs | TraderTraitor Backdoors Resurface on Victim With No Crypto Ties […]

Malware
P0
2026-10-04 13:41 UTC
Other

ShinyHunters Suspect Detained in Jordan Helps FBI Track Down the Group

Security Affairs · Pierluigi Paganini · indexed 2026-10-04 14:35 UTC

A suspected ShinyHunters member arrested in Jordan is reportedly cooperating with the FBI, helping investigators track down the group. A suspected member of ShinyHunters, the group that claims to have stolen data on every FBI employee, was picked up in Jordan this week. The man is Saif al-Din Khader, detained by Jordanian authorities, with two […]

Data BreachesLaw Enforcement
P0
2026-10-04 07:58 UTC
Community

User Agent Strings Curiosities, (Sun, Oct 4th)

SANS Internet Storm Center · indexed 2026-10-04 08:00 UTC

Sometimes I have to smile, or my interest is triggered, when I review new User Agent Strings in the honeypot logs.

Apple
P0
2026-10-04 07:58 UTC
Other

Security Affairs newsletter Round 598 by Pierluigi Paganini – INTERNATIONAL EDITION

Security Affairs · Pierluigi Paganini · indexed 2026-10-04 09:00 UTC

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. Fake Zoom installer hides macOS backdoor CloudSyncD CVE-2026-90970: Critical GitLab AI Gateway Flaw Fixed Antino Backdoor Lets […]

AppleMalwareVulnerabilitiesCVE-2026-90970
P5
2026-10-04 07:49 UTC
Other

Warlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical Infrastructure

Security Affairs · Pierluigi Paganini · indexed 2026-10-04 08:00 UTC

Warlock ransomware continues to exploit unpatched SharePoint flaws to breach water utilities, telecoms, governments, and universities worldwide. Warlock ransomware made headlines back in mid-2025 for exploiting a chain of SharePoint zero-days collectively dubbed ToolShell. More than a year later, the same group is still using that door, and it’s still getting in. Symantec tracks the […]

Cloud SecurityMicrosoftRansomwareVulnerabilities
P40
2026-10-04 07:22 UTC
Security Journalism

ShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group Members

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-04 07:45 UTC

A suspected member of the ShinyHunters digital extortion group, who goes by the online alias "Rey," has been allegedly detained by authorities in Jordan, Reuters reported, citing three people familiar with the matter. Rey, whose real name is Saif ‌al-Din Khader, is said to have been brought into custody on September 29, 2026, and cooperating with the U.S. Federal Bureau of Investigation (FBI)

DFIRLaw Enforcement
P0
2026-10-04 07:20 UTC
Security Journalism

China-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM Phishing

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-04 07:45 UTC

A new China-nexus cyber espionage group known as TA419 has been attributed to multiple credential phishing campaigns targeting artificial intelligence (AI) experts working for U.S. think tanks, universities, and legal sector organizations. The campaigns have impersonated prominent economists and AI policymakers, as well as a prominent Anthropic employee, to single out an AI policy expert at a

AI SecurityAPT / Nation-StateMicrosoftPhishing
P0
2026-10-03 19:09 UTC
Security Journalism

ShinyHunters hacker reportedly detained in Jordan, aiding FBI

BleepingComputer · Lawrence Abrams · indexed 2026-10-03 19:20 UTC

A suspected ShinyHunters hacking group member known online as "Rey" has reportedly been detained in Jordan and is cooperating with the FBI to help locate other members of the extortion group. [...]

Law Enforcement
P0
2026-10-03 15:11 UTC
Other

Fake Zoom installer hides macOS backdoor CloudSyncD

Security Affairs · Pierluigi Paganini · indexed 2026-10-03 15:30 UTC

Jamf Threat Labs details CloudSyncD, a fake macOS Zoom installer that hides a phished password using invisible zero-width Unicode characters. Jamf Threat Labs found CloudSyncD while doing routine scanning on VirusTotal, buried inside a disguised Zoom client. They first spotted it on September 15, clearly still under construction, and within two days watched it move […]

AppleMalwarePhishing
P0
2026-10-03 14:40 UTC
Community

YARA-X 1.21.0 Release, (Sat, Oct 3rd)

SANS Internet Storm Center · indexed 2026-10-03 14:50 UTC

YARA-X's 1.21.0 release brings 5 improvements and 4 bugfixes.

P0
2026-10-03 14:38 UTC
Security Journalism

MI5 Says China’s MSS Funded Research Involving 100+ U.K.-Linked Academics

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-03 15:25 UTC

The U.K.'s domestic intelligence and security agency has warned that more than 100 academics have helped China boost its intelligence gathering efforts on behalf of Beijing's state security service. In a "Security Service Espionage Alert" issued on September 30, 2026, MI5 said the "primary purpose of the China General Technology Research Institute (CGTRI) 中国通用技术研究院 is to fund research that

APT / Nation-State
P0
2026-10-03 14:36 UTC
Security Journalism

Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-03 15:25 UTC

The suspected China-linked threat actor known as Warlock is still continuing to weaponize Microsoft SharePoint vulnerabilities, likely both old and new, in attacks targeting organizations in Portuguese- and Spanish-speaking countries. The activity, observed by the Symantec and Carbon Black Threat Hunter Team, has hit critical infrastructure, government, and education organizations. "In the

Cloud SecurityMicrosoftRansomwareThreat Actors
P15
2026-10-03 14:35 UTC
Security Journalism

Danish university DTU breach exposes data of up to 200,000 people

BleepingComputer · Ionut Ilascu · indexed 2026-10-03 14:45 UTC

The Technical University of Denmark (DTU) says information belonging to up to 200,000 users may have been exposed after hackers accessed its identity and access management system and downloaded a large amount of data. [...]

P0
10 11 12 13 14