IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 4,785 matching records.
AUTO-POLL // 2026-10-11 21:10 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P5 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 11

ACTIVE EXPLOITATION
P5
P5
COOL // 6 ARTICLES
SAT
Oct 10

RANSOMWARE
P1
P1
COOL // 11 ARTICLES
FRI
Oct 9

RANSOMWARE
P4
P4
COOL // 67 ARTICLES
THU
Oct 8

RANSOMWARE
P3
P3
COOL // 62 ARTICLES
WED
Oct 7

RANSOMWARE
P5
P5
COOL // 86 ARTICLES
TUE
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
RESET
2025-09-23 09:20 UTC
Other

Echoes of AI Exposure: Thousands of Secrets Leaking Through Vibe Coded Sites | Wave 15 | Project Resonance

Red Hunt Labs · redhuntAdmin · indexed 2026-09-07 17:30 UTC

1. Introduction The vibe coding revolution has empowered millions to build and deploy websites using natural languages. Entrepreneurs, artists, and small businesses can now bring their ideas to life online without writing a single line of code. But has this convenience come at a hidden security cost? In this post, we present the 15th wave of Project Resonance: A RedHunt Labs Research Initiative, investigating the security posture of websites built on modern “vibe coding” platforms. Our research…

Microsoft
P0
2025-09-23 05:00 UTC
Security Journalism

SAT effectiveness | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

Learn the truth about SAT effectiveness. Our latest report reveals why increased spending on training isn’t reducing human risk—and how to fix it.

P0
2025-09-22 11:45 UTC
Other

System Update Completed

Buf0rd Blog · indexed 2026-08-16 11:15 UTC

All packages were updated successfully.

P0
2025-09-22 05:00 UTC
Security Journalism

How EDR Telemetry Powers Managed Investigations

Huntress · indexed 2026-09-07 17:30 UTC

Learn more about what it actually means to go up against hackers–and why creative, human-led investigations are essential for keeping your organization safe from modern threats.

DFIR
P0
2025-09-18 05:00 UTC
Security Journalism

How Malicious Hackers Try to Infiltrate Your IT Team

Huntress · indexed 2026-09-07 17:30 UTC

Malicious hackers are impersonating IT and cybersecurity professionals to infiltrate your systems and steal sensitive data. Learn how to identify and defend against these insider threats and protect your organization from "fake workers."

P0
2025-09-17 00:00 UTC
Other

Entra ID actor token validation bug allowing cross-tenant global admin

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A critical vulnerability discovered in Microsoft's Entra ID (formerly Azure AD) allowed for cross-tenant access and potential global admin privilege escalation. The flaw was found in the legacy Azure AD Graph API, which improperly validated the originating tenant for undocumented "Actor tokens." An attacker could use a token from their own tenant to authenticate as any user, including Global Admins, in any other tenant. This vulnerability bypassed security policies like Conditional Access. The …

Cloud SecurityMicrosoftVulnerabilities
P10
2025-09-15 17:01 UTC
Vendor Research

Supporting Rowhammer research to protect the DRAM ecosystem

Google Online Security Blog · Kimberly Samra · indexed 2026-08-15 14:33 UTC

Posted by Daniel MoghimiRowhammer is a complex class of vulnerabilities across the industry. It is a hardware vulnerability in DRAM where repeatedly accessing a row of memory can cause bit flips in adjacent rows, leading to data corruption. This can be exploited by attackers to gain unauthorized access to data, escalate privileges, or cause denial of service. Hardware vendors have deployed various mitigations, such as ECC and Target Row Refresh (TRR) for DDR5 memory, to mitigate Rowhammer and e…

Security ResearchVulnerabilities
P10
2025-09-15 05:44 UTC
Other

Agneyastra to the Rescue: Protecting your Firebase Projects before the Tea spills out!

Red Hunt Labs · Bhavarth Karmarkar · indexed 2026-09-07 17:30 UTC

In July 2025, the Tea app 🔗, a mental health and social community platform, experienced a devastating breach that spilled 72,000 images (including 13,000 driver’s license and verification selfies) and over 1.1 million private direct messages onto the internet. The leaks first surfaced on 4chan and quickly spread across forums, torrents, and underground channels. This was not “just another API key leak.” Instead, it was a story about Firebase misconfigurations, poor data retention practices, an…

APT / Nation-StateSecurity ResearchVulnerabilities
P25
2025-09-10 15:59 UTC
Vendor Research

How Pixel and Android are bringing a new level of trust to your images with C2PA Content Credentials

Google Online Security Blog · Edward Fernandez · indexed 2026-08-15 14:33 UTC

Posted by Eric Lynch, Senior Product Manager, Android Security, and Sherif Hanna, Group Product Manager, Google C2PA Core At Made by Google 2025, we announced that the new Google Pixel 10 phones will support C2PA Content Credentials in Pixel Camera and Google Photos. This announcement represents a series of steps towards greater digital media transparency: The Pixel 10 lineup is the first to have Content Credentials built in across every photo created by Pixel Camera. The Pixel Camera app achie…

AppleMobile Security
P0
2025-09-09 05:54 UTC
Other

AI-Powered Celebrity Impersonation Scams: A Threat Intelligence Report by RedHunt Labs

Red Hunt Labs · Hariharan M · indexed 2026-09-07 17:30 UTC

Introduction A new wave of AI-powered investment scams is targeting Indian users on Facebook and Instagram, luring them with fake celebrity endorsements and deepfake interviews. Ads featuring figures like Nirmala Sitharaman, Sadhguru, and Neha Kakkar promote fraudulent schemes, directing users to counterfeit news websites mimicking The Times of India, IndiaTime, and NDTV. These sites claim celebrities have built fortunes using exclusive investment strategies, persuading victims to deposit ₹21,0…

AppleCybercrimeThreat Intelligence
P0
2025-09-09 05:00 UTC
Security Journalism

An Attacker’s Blunder Gave Us a Look Into Their Operations

Huntress · indexed 2026-09-07 17:30 UTC

An attacker installed Huntress onto their operating machine, giving us a detailed look at how they’re using AI to build workflows, searching for tools like Evilginx, and researching targets like software development companies.

P0
2025-09-02 05:00 UTC
Security Journalism

Debunking Microsoft 365 & Identity Myths

Huntress · indexed 2026-09-07 17:30 UTC

Don’t fall for common Microsoft 365 identity security myths. Here, Huntress debunks misconceptions around logins, MFA, Conditional Access, Impossible Travel, and security tuning.

Microsoft
P0
2025-08-29 05:00 UTC
Security Journalism

From a Fake AnyDesk Installer to MetaStealer

Huntress · indexed 2026-09-07 17:30 UTC

Learn how a fake AnyDesk installer led to a unique MetaStealer attack, highlighting how threat actors evolve ClickFix techniques beyond the classic playbook to steal credentials and files.

MalwareThreat Actors
P0
2025-08-27 07:50 UTC
Other

ShadowSilk: A Cross-Border Binary Union for Data Exfiltration

Group-IB · indexed 2026-09-07 17:30 UTC

This blog describes attacks on victims in Central Asia and APAC. Research into the attack has identified a group also called YoroTrooper. We also identified profiles of attackers on hacker forums, their malicious web-panels, test infections of attackers' own machines, and screenshots of attackers' desktops.

Microsoft
P0
2025-08-25 09:04 UTC
Other

Trust issues: How email threats hide behind your partners

Group-IB · indexed 2026-09-07 17:30 UTC

The most widely used email security tools still focus on yesterday’s threats. Meanwhile, attackers have moved on. By hijacking legitimate business relationships and embedding infostealers in familiar-sounding, well-written emails, cybercriminals bypass conventional defenses. The only way to keep up is by using a behavioral approach.

Malware
P0
2025-08-25 05:00 UTC
Security Journalism

Ten Years of Resilience, Innovation & Community-Driven Defense

Huntress · indexed 2026-09-07 17:30 UTC

Celebrate 10 years of wrecking hackers! See how Huntress has evolved and elevated in an ever-changing cybersecurity landscape, shaped by key milestones and critical lessons.

P0
2025-08-21 21:00 UTC
Security Journalism

Cephalus Ransomware: Don’t Lose Your Head

Huntress · indexed 2026-09-07 17:30 UTC

In mid-August, Huntress saw two incidents that linked back to a ransomware variant called Cephalus, which included DLL sideloading via a legitimate SentinelOne executable.

Ransomware
P15
2025-08-21 00:00 UTC
Other

Dataform cross-tenant path traversal

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Dataform could have allowed a malicious customer to gain unauthorized cross-tenant access to other customer's code repositories and data. By preparing a maliciously crafted package.json file, an attacker could exploit a path traversal vulnerability in the npm package installation process, thereby gaining read and write access in other customers' repositories. According to Google, there was no evidence of exploitation in the wild.

Vulnerabilities
P20
2025-08-20 06:44 UTC
Other

Evolving Mule Tactics in the META Region Banking Sector

Group-IB · indexed 2026-09-07 17:30 UTC

Discover how mule operators evolved in META-region banks—from IP masking to Starlink tactics with advanced GPS spoofing, SIM abuse, and device muling—and how layered fraud detection strategies fought back.

Cybercrime
P0
2025-08-19 14:00 UTC
Security Journalism

Exposing Data Exfiltration | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

Threat actors often steal data during the course of their attacks. This is particularly true for ransomware threat actors, who do it before deploying file encryption in order to engage in “double extortion” activities. This activity can be difficult to detect, particularly if it’s not dissimilar to legitimate actions taken by system administrators.

RansomwareThreat Actors
P15
2025-08-15 16:00 UTC
Security Journalism

90 Data Breach Trends & Statistics for 2026

Huntress · indexed 2026-09-07 17:30 UTC

Learn the top data breach statistics of the last several years and learn about common causes, how they vary by industry, and future trends.

Data Breaches
P0
2025-08-14 05:00 UTC
Security Journalism

Kawabunga, Dude, You’ve Been Ransomed!

Huntress · indexed 2026-09-07 17:30 UTC

Thanks in large part to our customer base, Huntress sees a great deal of interesting activity, particularly from threat actors (but also from admins). Part of that activity includes not just ransomware variants that Huntress hasn’t seen before, but also variants that may not have been documented via any public means. Further, when these incidents occur, Huntress very often gets a detailed look at the threat actor’s activity, including commands and their timing.

RansomwareThreat Actors
P15
122 123 124 125 126