IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 4,785 matching records.
AUTO-POLL // 2026-10-11 22:05 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P5 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 11

ACTIVE EXPLOITATION
P5
P5
COOL // 6 ARTICLES
SAT
Oct 10

RANSOMWARE
P1
P1
COOL // 11 ARTICLES
FRI
Oct 9

RANSOMWARE
P4
P4
COOL // 67 ARTICLES
THU
Oct 8

RANSOMWARE
P3
P3
COOL // 62 ARTICLES
WED
Oct 7

RANSOMWARE
P5
P5
COOL // 86 ARTICLES
TUE
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
RESET
2025-07-02 08:08 UTC
Other

June’s Dark Gift: The Rise of Qwizzserial

Group-IB · indexed 2026-09-07 17:30 UTC

Discovered by Group-IB in mid-2024, the Qwizzserial, which was initially not very active, began to spread strongly in Uzbekistan, masquerading as legitimate applications. The malware steals banking information and intercepts 2FA sms, transmitting it to fraudsters via Telegram bots.

CybercrimeMalware
P0
2025-07-01 00:00 UTC
Government

Multiples vulnérabilités dans Citrix NetScaler ADC et NetScaler Gateway (01 juillet 2025)

CERT-FR Alerts · indexed 2026-09-07 17:35 UTC

**[Mise à jour du 17 juillet 2025]** L'éditeur a publié un lien contenant une méthode d'évaluation permettant d'identifier des tentatives d'exploitation dans les journaux applicatifs et systèmes [12]. **[Mise à jour du 7 juillet 2025]** Le 17 juin 2025, Citrix a publié un bulletin de sécurité...

P0
2025-06-25 05:00 UTC
Security Journalism

Recutting the Kerberos Diamond Ticket

Huntress · indexed 2026-09-07 17:30 UTC

Clear up common misconceptions about the Kerberos Diamond Ticket and learn how to refine the technique for better OPSEC, including more realistic PAC details and support for service tickets. You’ll learn how to apply the idea securely to both Ticket Granting Tickets and Service Tickets, creating forgeries that blend in more effectively with legitimate Kerberos traffic. The result is a stealthier alternative to traditional Silver Tickets and a more convincing method that raises the bar for Kerbe…

P0
2025-06-20 05:00 UTC
Security Journalism

Cybersecurity Leadership: Build Unstoppable Security Teams | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

Learn cybersecurity leadership insights on developing elite cybersecurity teams from a seasoned NSA, NASA, and Huntress leader. Learn to hire, retain, and prevent burnout with impactful team growth and success strategies.

P0
2025-06-17 05:00 UTC
Security Journalism

Proactive Account Review Uncovers Unauthorized | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

A routine account review revealed the use of productivity monitoring tools in a medical clinic, highlighting the hidden risks associated with employee monitoring software. Learn the importance of proactive audits in protecting critical systems and sensitive data from potential threats.

P0
2025-06-16 05:00 UTC
Security Journalism

Introducing Behavior-Based Assignments

Huntress · indexed 2026-09-07 17:30 UTC

Manage human risk by turning real-world incidents into teachable moments with Behavior-Based Assignments. This new feature integrates with Managed EDR and Managed ITDR to provide targeted security awareness training.

P0
2025-06-13 16:03 UTC
Vendor Research

Mitigating prompt injection attacks with a layered defense strategy

Google Online Security Blog · Kimberly Samra · indexed 2026-08-15 14:33 UTC

Posted by Adam Gavish, Google GenAI Security TeamWith the rapid adoption of generative AI, a new wave of threats is emerging across the industry with the aim of manipulating the AI systems themselves. One such emerging attack vector is indirect prompt injections. Unlike direct prompt injections, where an attacker directly inputs malicious commands into a prompt, indirect prompt injections involve hidden malicious instructions within external data sources. These may include emails, documents, or…

AI SecurityMalwarePhishingSecurity ResearchThreat ActorsThreat IntelligenceVulnerabilities
P0
2025-06-12 12:00 UTC
Government

The Impact of Artificial Intelligence on the Cybersecurity Workforce

NIST Cybersecurity Insights · Karen Wetzel · indexed 2026-08-15 20:45 UTC

The NICE Workforce Framework for Cybersecurity ( NICE Framework) was revised in November 2020 as NIST Special Publication 800-181 rev.1 to enable more effective and rapid updates to the NICE Framework Components, including how the advent of emerging technologies would impact cybersecurity work. NICE has been actively engaging in conversations with: federal departments and agencies; industry; education, training, and certification providers; and international representatives to understand how Ar…

AI Security
P0
2025-06-11 16:25 UTC
Other

Doomla! Zero Days

Black Lantern Security · Jack Pas · indexed 2026-09-07 17:30 UTC

Discovery and Exploitation of two Zero Days from the perspective of a first year Penetration Tester.

P0
2025-06-05 00:00 UTC
Government

[MàJ] Vulnérabilité dans Roundcube (05 juin 2025)

CERT-FR Alerts · indexed 2026-09-07 17:35 UTC

[Mise à jour du 06 juin 2025] Une preuve de concept est publiquement disponible. [Publication initiale] Le 01 juin 2025, Roundcube a publié des correctifs concernant une vulnérabilité critique affectant son portail de messagerie ainsi que tous les produits l'incluant (par exemple cPanel et...

P0
2025-06-03 05:00 UTC
Security Journalism

Infostealers Crash Course: A Tradecraft Tuesday Recap

Huntress · indexed 2026-09-07 17:30 UTC

Cybercriminals are sitting on a pile of stolen credentials, financial information, and sensitive data, thanks to the success of infostealers. Read more to learn how infostealers have grown to become a scourge to defenders, and how businesses can protect themselves.

CybercrimeMalwareMicrosoft
P0
2025-05-27 05:00 UTC
Security Journalism

'Advanced' Intrusion Targeting a Marketing Research Company | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

An intrusion at a market research company used living-off-the-land techniques, but Huntress detected and mitigated the threat, uncovering tactics like service creation and registry manipulation. Learn more and get detection guidance and mitigation strategies.

P0
2025-05-22 12:00 UTC
Government

Cybersecurity and AI: Integrating and Building on Existing NIST Guidelines

NIST Cybersecurity Insights · Katerina Megas, Victoria Yan Pillitteri · indexed 2026-08-15 20:45 UTC

What is NIST up to? On April 3, 2025, NIST hosted a Cybersecurity and AI Profile Workshop at our National Cybersecurity Center of Excellence (NCCoE) to hear feedback on our concept paper which presented opportunities to create profiles of the NIST Cybersecurity Framework (CSF) and the NIST AI Risk Management Framework (AI RMF). These would serve to support the cybersecurity community as they adopt AI for cybersecurity, need to defend against AI-enabled cybersecurity attacks, as well as protect …

P0
2025-05-22 00:00 UTC
Other

Remote Prompt Injection in GitLab Duo Leaks Source Code

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A remote prompt injection vulnerability in GitLab Duo allowed attackers to steal source code from private projects, manipulate code suggestions, and exfiltrate confidential information. The attack chain involved hidden prompts, HTML injection, and exploitation of Duo's access to private data. GitLab has since patched both the HTML and prompt injection vectors.

AI SecurityVulnerabilities
P0
2025-05-19 00:00 UTC
Other

AWS Security Tool Introduces Privilege Escalation Risk

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

AWS's Account Assessment for AWS Organizations tool, designed to audit cross-account access, inadvertently introduced privilege escalation risks due to flawed deployment instructions. Customers were encouraged to deploy the tool in lower-sensitivity accounts, creating risky trust paths from insecure environments into highly sensitive ones. This could allow attackers to pivot from compromised development accounts into production and management accounts.

Cloud SecurityVulnerabilities
P10
124 125 126 127 128