IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 4,785 matching records.
AUTO-POLL // 2026-10-11 22:15 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P5 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 11

ACTIVE EXPLOITATION
P5
P5
COOL // 6 ARTICLES
SAT
Oct 10

RANSOMWARE
P1
P1
COOL // 11 ARTICLES
FRI
Oct 9

RANSOMWARE
P4
P4
COOL // 67 ARTICLES
THU
Oct 8

RANSOMWARE
P3
P3
COOL // 62 ARTICLES
WED
Oct 7

RANSOMWARE
P5
P5
COOL // 86 ARTICLES
TUE
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
RESET
2025-05-14 05:00 UTC
Security Journalism

Simplify Agent Management with Automated Health Checks

Huntress · indexed 2026-09-07 17:30 UTC

Get to know Huntress' new client-side API for EDR, which enables real-time agent health checks and simplifies endpoint management. With instant “healthy” or “unhealthy” status updates, you can ensure your security is running smoothly.

P0
2025-05-14 00:00 UTC
Government

Multiples vulnérabilités dans Ivanti Endpoint Manager Mobile (EPMM) (14 mai 2025)

CERT-FR Alerts · indexed 2026-09-07 17:35 UTC

[Mise à jour du 15 mai 2025] Une preuve de concept est publiquement disponible sur Internet. [Publication initiale] Le 13 mai 2025, Ivanti a publié deux avis de sécurité concernant les vulnérabilités CVE-2025-4427 et CVE-2025-4428. L'utilisation combinée de ces deux vulnérabilités permet...

VulnerabilitiesCVE-2025-4427CVE-2025-4428
P5
2025-05-13 12:00 UTC
Government

Five Years Later: Evolving IoT Cybersecurity Guidelines

NIST Cybersecurity Insights · Katerina Megas, Michael Fagan · indexed 2026-08-15 20:45 UTC

The Background…and NIST’s Plan for Improving IoT Cybersecurity The passage of the Internet of Things (IoT) Cybersecurity Improvement Act in 2020 marked a pivotal step in enhancing the cybersecurity of IoT products. Recognizing the increasing internet connectivity of physical devices, this legislation tasked NIST with developing cybersecurity guidelines to manage and secure IoT effectively. As an early building block, we developed NIST IR 8259, Foundational Cybersecurity Activities for IoT Devic…

P0
2025-05-13 05:00 UTC
Security Journalism

Time to Ransom is Money

Huntress · indexed 2026-09-07 17:30 UTC

During ransomware attacks, the average time-to-ransom for attackers is almost 17 hours. Learn more about what this means for businesses.

Ransomware
P15
2025-05-10 00:00 UTC
Other

FreeRTOS and coreSNTP Security Advisories

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Security advisories were issued for FreeRTOS and coreSNTP releases containing unintended scripts that could potentially transmit AWS credentials if executed on Linux/macOS. Affected releases have been removed and users are advised to rotate credentials and delete downloaded copies.

AppleCloud SecurityLinux
P0
2025-05-08 05:00 UTC
Security Journalism

Utilizing ASNs for Hunting & Response

Huntress · indexed 2026-09-07 17:30 UTC

Autonomous system numbers are like the address book of the internet, and not every IP address belongs to a “friendly” address. Learn more about how the Huntress Hunt & Response teams utilize ASNs.

P0
2025-05-07 12:00 UTC
Government

Impact of AI on cyber threat from now to 2027

UK NCSC Threat Reports · indexed 2026-08-15 18:50 UTC

An NCSC assessment highlighting the impacts on cyber threat from AI developments between now and 2027.

P0
2025-05-07 05:00 UTC
Security Journalism

Rapid Response: Samsung MagicINFO 9 Server Flaw

Huntress · indexed 2026-09-07 17:30 UTC

Huntress has verified Samsung’s MagicINFO 9 Server (version 21.1050.0) is vulnerable to a publicly available proof-of-concept (PoC). Understand why MagicINFO 9 Server shouldn’t be internet-facing until a patch is applied.

P0
2025-05-06 05:00 UTC
Security Journalism

Do Tigers Really Change Their Stripes?

Huntress · indexed 2026-09-07 17:30 UTC

Across the larger cybersecurity community, an often-used adage is that “threat actors always change their tactics.” However, when we really start to look at and track incident data, we begin to see that while some changes may be necessitated based on infrastructures and other challenges the threat actor may encounter, there are times when tactics remain consistent across incidents. Recent investigations into exploitation activity for CVE-2025-31151 and CVE-2025-30406 show similar TTPs across di…

DFIRThreat ActorsThreat IntelligenceVulnerabilitiesCVE-2025-30406CVE-2025-31151
P5
2025-05-06 00:00 UTC
Other

Azure AZNFS-mount Utility Root Privilege Escalation

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A critical vulnerability in AZNFS-mount utility, preinstalled on Azure HPC/AI images, allowed unprivileged users to escalate privileges to root on Linux machines. The flaw existed in versions up to 2.0.10 and involved a SUID binary. Azure classified it as low severity but fixed it in version 2.0.11.

Cloud SecurityLinuxVulnerabilities
P10
2025-05-05 12:00 UTC
Government

Small Businesses Create Big Impact: NIST Celebrates 2025 National Small Business Week

NIST Cybersecurity Insights · Daniel Eliot · indexed 2026-08-15 20:45 UTC

This week we’re celebrating National Small Business Week—which recognizes and celebrates the small and medium-sized business (SMB) community’s significant contributions to the nation. SMBs are a substantial and critical part of the U.S. and global economic and cybersecurity infrastructure. According to the U.S. Small Business Administration’s Office of Advocacy, [1] there are 34.8 million SMBs in the United States (making up 99% of all U.S. businesses). Of those, 81.7% are non-employer firms wi…

P0
2025-05-02 17:38 UTC
Other

ASP.NET Cryptography for Pentesters

Black Lantern Security · Paul Mueller · indexed 2026-09-07 17:30 UTC

This article was originally posted to blog.liquidsec.net on June 1, 2021.

P0
2025-05-01 05:00 UTC
Security Journalism

Applying Criminal Justice Principles to Detection Engineering

Huntress · indexed 2026-09-07 17:30 UTC

Explore how criminal justice principles can improve detection engineering by distinguishing true threats from false positives. And learn how concepts like burden of proof and intent enhance cybersecurity defense strategies.

P0
2025-04-30 06:00 UTC
Other

Ransomware debris: an analysis of the RansomHub operation

Group-IB · indexed 2026-09-07 17:30 UTC

This blog on RansomHub provides an overview into how this Ransomware-as-a-Service (RaaS) group operates, including its extortion tactics, affiliate recruitment strategies, and the features of its affiliate panel.

Ransomware
P15
2025-04-29 05:00 UTC
Security Journalism

Minutes Matter | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

Huntress Managed SIEM makes threat detection and response faster and more accessible. Learn about new features, real-world success stories, and how it enhances cybersecurity and compliance.

P0
2025-04-29 00:00 UTC
Other

AWS Default Roles Can Lead to Service Takeover

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Research uncovered security flaws in default AWS service roles, granting overly broad permissions like full S3 access. This allows privilege escalation, cross-service access, and potential account compromise across services like SageMaker, Glue, and EMR. Attackers could exploit these roles to manipulate critical assets and move laterally within AWS environments. AWS has since updated default policies and documentation to mitigate risks.

Cloud SecurityVulnerabilities
P10
2025-04-28 05:00 UTC
Security Journalism

Identity Threats Got a Whole Lot Nastier, But So Did We

Huntress · indexed 2026-09-07 17:30 UTC

Huntress Managed ITDR with Rogue Apps proactively protects against identity threats, including malicious OAuth apps. Learn about the surge in identity-based attacks and how to defend your business effectively.

P0
2025-04-28 00:00 UTC
Government

Vulnérabilité dans SAP NetWeaver (28 avril 2025)

CERT-FR Alerts · indexed 2026-09-07 17:35 UTC

Le 24 avril 2025, SAP a publié un bulletin de sécurité relatif à la vulnérabilité CVE-2025-31324 qui permet l'exécution de code arbitraire à distance pour un utilisateur non authentifié. Cette vulnérabilité est provoquée par un contournement de la politique de sécurité qui permet de télécharger...

VulnerabilitiesCVE-2025-31324
P5
2025-04-24 05:00 UTC
Security Journalism

How to Stop Malware Attacks with a Security-First Culture

Huntress · indexed 2026-09-07 17:30 UTC

Protect your business from malware attacks by fostering a security-first culture. Learn how to defend against cyber threats, establish strategies, and train employees to spot malware before it strikes.

Malware
P0
2025-04-24 05:00 UTC
Security Journalism

Credential Theft: Expanding Your Reach, Pt. II

Huntress · indexed 2026-09-07 17:30 UTC

As with many tactics within the MITRE ATT&CK framework, credential theft consists of a number of different techniques. Showing what many of them look like on an endpoint helps other security professionals understand what to look for and how to detect and respond to similar activity.

Phishing
P0
2025-04-23 07:05 UTC
Other

Toll of Deception: Where Evasion Drives Phishing Forward

Group-IB · indexed 2026-09-07 17:30 UTC

Discover the latest phishing campaign targeting a major toll road service provider, where cybercriminals use sophisticated evasion techniques to bypass security detections. This in-depth blog reveals how threat actors exploit legitimate platforms and deploy cloaking methods to disguise malicious links, allowing them to evade detection by security solutions. Discover how these sophisticated tactics create highly convincing phishing pages designed to steal victims’ card information, and how to sa…

PhishingThreat Actors
P0
2025-04-22 05:00 UTC
Security Journalism

Say Hello to Mac Malware

Huntress · indexed 2026-09-07 17:30 UTC

In this month’s Tradecraft Tuesday, we talked about how threat actors are finetuning their macOS malware in order to maintain persistent access and avoid detection by Apple’s security features.

AppleMalwareThreat Actors
P0
2025-04-22 00:00 UTC
Other

Google Cloud ConfusedComposer Privilege Escalation Vulnerability

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Tenable discovered a privilege escalation vulnerability in Google Cloud Platform's Cloud Composer service, dubbed ConfusedComposer. It allowed users with composer.environments.update permission to escalate privileges to the default Cloud Build service account by injecting malicious PyPI packages. This could grant broad permissions across the victim's GCP project.

Cloud SecurityVulnerabilities
P10
2025-04-18 13:20 UTC
Other

How to Eat an Entire Elephant

Black Lantern Security · Micheal Reski · indexed 2026-09-07 17:30 UTC

Scanning the Internet with BBOT

P0
125 126 127 128 129