IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 4,769 matching records.
AUTO-POLL // 2026-10-10 01:45 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
WARM
COOL WARM ELEVATED HOT CRITICAL
P15 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 10

RANSOMWARE
P15
P15
WARM // 1 ARTICLE
FRI
Oct 9

RANSOMWARE
P4
P4
COOL // 67 ARTICLES
THU
Oct 8

RANSOMWARE
P3
P3
COOL // 62 ARTICLES
WED
Oct 7

RANSOMWARE
P5
P5
COOL // 86 ARTICLES
TUE
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
RESET
2026-10-01 12:08 UTC
Other

Public PoC Released for Apple CoreGraphics Zero-Day CVE-2026-86950

Security Affairs · Pierluigi Paganini · indexed 2026-10-01 12:40 UTC

Apple patched a CoreGraphics zero-day that may have been exploited in targeted attacks. A public PoC for the flaw is now available. Apple patched a zero-day vulnerability, tracked as CVE-2026-86950, in CoreGraphics that attackers may have exploited to target specific individuals. The flaw is an out-of-bounds write that can lead to arbitrary code execution when […]

AppleVulnerabilitiesCVE-2026-86950
P30
2026-10-01 12:05 UTC
Other

Milk Dragon: Huge Discounts on Social Media? Think Twice Before You Buy

Group-IB · indexed 2026-10-01 14:20 UTC

Milk Dragon, also known as NaiLong is an Adversary-in-the-Middle (AiTM) phishing kit active since October 2025. Unlike conventional phishing tactics that rely on fear and urgency, Milk Dragon lures victims with big discounts on consumer goods distributed via Facebook and TikTok marketplace advertisements.

Phishing
P0
2026-10-01 12:05 UTC
Other

Milk Dragon: Huge Discounts on Social Media? Think Twice Before You Buy

Group-IB · indexed 2026-10-01 12:40 UTC

Milk Dragon, also known as NaiLong is an Adversary-in-the-Middle (AiTM) phishing kit active since October 2025. Unlike conventional phishing tactics that rely on fear and urgency, Milk Dragon lures victims with big discounts on consumer goods distributed via Facebook and TikTok marketplace advertisements.

Phishing
P0
2026-10-01 12:00 UTC
Government

Securing Water and Wastewater Operational Technology Environments

NIST Cybersecurity Insights · CheeYee Tang , Robert Stea, John Wiltberger · indexed 2026-10-01 13:15 UTC

Recent cyberattacks on the U.S. water and wastewater systems (WWS) sector are highlighting the escalating threat to our nation’s critical infrastructure and the practical challenges of securing it. These incidents underscore an important challenge: the connectivity that utilities depend upon must be designed and operated with security as a core priority rather than a secondary consideration. They also provide a critical insight — that effective cybersecurity protections require a broad-based un…

ICS / OT
P0
2026-10-01 11:45 UTC
Security Journalism

How Financial Services Companies Can Modernize Their Software Supply Chain

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-01 12:25 UTC

Every security leader at a bank, insurer, or asset manager has had a version of this conversation: Security wants to eliminate a class of vulnerabilities. Engineering explains what it would take to upgrade the platform where they live. Somebody prices out the regression testing. Somebody else raises the change-freeze calendar. The finding gets an exception, a compensating control, and a date

P0
2026-10-01 11:40 UTC
Security Journalism

Kevin Mandia’s Armadin Raises $255 Million at $2.5 Billion Valuation

Security Week · Mike Lennon · indexed 2026-10-01 12:00 UTC

The Series B brings the AI-powered offensive security startup’s total funding to roughly $445 million only seven months after its public launch. The post Kevin Mandia’s Armadin Raises $255 Million at $2.5 Billion Valuation appeared first on SecurityWeek.

P0
2026-10-01 11:14 UTC
Security Journalism

Microsoft enables Windows settings backup by default for orgs

BleepingComputer · Sergiu Gatlan · indexed 2026-10-01 11:30 UTC

Microsoft announced that Windows settings backup and restore is now enabled by default on all Microsoft Entra-joined or Microsoft Entra hybrid-joined enterprise systems upgraded to Windows 11 26H2. [...]

Microsoft
P0
2026-10-01 10:51 UTC
Security Journalism

Treasury Blacklists Most-Wanted ATM Malware Developer and His Network

Security Week · Eduard Kovacs · indexed 2026-10-01 11:00 UTC

The US government continues its crackdown on Tren de Aragua over its ATM jackpotting scheme. The post Treasury Blacklists Most-Wanted ATM Malware Developer and His Network appeared first on SecurityWeek.

Malware
P0
2026-10-01 10:42 UTC
Security Journalism

OpenAI Disrupts Reasoning Extraction Campaign Linked to Moonshot AI Associates

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-01 11:10 UTC

OpenAI on Wednesday said it identified and disrupted a coordinated distillation campaign that was designed to illicitly extract protected reasoning from its artificial intelligence (AI) models. A "core cluster of the activity," going back to the first week of July, has been attributed to individuals associated with Moonshot AI, a Chinese AI company based in Beijing. It did not cite any

AI Security
P0
2026-10-01 10:33 UTC
Security Journalism

CISA Adds Exploited Cisco Catalyst SD-WAN Manager Auth Bypass to KEV

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-01 11:10 UTC

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a critical authentication bypass flaw impacting Cisco Catalyst SD-WAN Manager to its Known Exploited Vulnerabilities (KEV), following reports of active exploitation. The vulnerability, tracked as CVE-2026-76504 (CVSS score: 9.8), could allow an unauthenticated, remote attacker to access an affected system with

VulnerabilitiesCVE-2026-76504
P45
2026-10-01 10:00 UTC
Vendor Research

The Fine Art of Frustrating the Adversary

Cisco Talos Intelligence Blog · Hazel Burton · indexed 2026-10-01 10:25 UTC

What really frustrates an adversary? Eight Cisco Talos researchers share practical ways to make their next move slower and riskier, from deception and behavioral detection to breaking attack dependencies and resisting manufactured urgency.

P0
2026-10-01 09:44 UTC
Security Journalism

Hackers stole Pentagon personnel records of over 3 million people

BleepingComputer · Sergiu Gatlan · indexed 2026-10-01 09:45 UTC

The Pentagon's Defense Manpower Data Center (DMDC) is notifying millions of military service members that hackers stole their data after breaching the Pentagon's human resources management system in October 2025. [...]

P0
2026-10-01 09:43 UTC
Security Journalism

500,000 Active Credentials Left Exposed on GitHub

Security Week · Ionut Arghire · indexed 2026-10-01 09:45 UTC

Roughly 200,000 of the credentials were exposed after GitHub enabled push protections by default. The post 500,000 Active Credentials Left Exposed on GitHub appeared first on SecurityWeek.

P0
2026-10-01 08:35 UTC
Other

U.S. CISA adds Cisco Catalyst SD-WAN Manager flaw to its Known Exploited Vulnerabilities catalog

Security Affairs · Pierluigi Paganini · indexed 2026-10-01 09:10 UTC

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Cisco Catalyst SD-WAN Manager flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Cisco Catalyst SD-WAN Manager flaw, tracked as CVE-2026-76504 (CVSS score of 9.8), to its Known Exploited Vulnerabilities (KEV) catalog. The vulnerability resides in Cisco Catalyst SD-WAN Manager’s […]

VulnerabilitiesCVE-2026-76504
P35
2026-10-01 08:26 UTC
Security Journalism

Cisco Patches Exploited Catalyst SD-WAN Zero-Day Vulnerability

Security Week · Ionut Arghire · indexed 2026-10-01 08:30 UTC

The flaw could allow remote, unauthenticated attackers to access vulnerable appliances with administrative privileges. The post Cisco Patches Exploited Catalyst SD-WAN Zero-Day Vulnerability appeared first on SecurityWeek.

Vulnerabilities
P25
2026-10-01 08:04 UTC
Other

AI Agent Chains Zammad Zero-Days To Take Over DIVD Systems in Seconds

Security Affairs · Pierluigi Paganini · indexed 2026-10-01 08:10 UTC

DIVD was breached through two Zammad zero-days that let an AI agent reach root in seconds, steal data and pivot to other services before being stopped. The Dutch Institute for Vulnerability Disclosure, a nonprofit organization of volunteer security researchers whose whole job is finding and responsibly disclosing vulnerabilities in other people’s software, just disclosed that […]

AI SecuritySecurity ResearchVulnerabilities
P25
2026-10-01 07:49 UTC
Security Journalism

Google Rolls Out Gemini 4 Argon to Trusted Cyber Defenders, Plans Guardrail-Free Version

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-01 08:55 UTC

Google on Wednesday announced its latest frontier artificial intelligence (AI) model, Gemini 4 Argon, that it said is being rolled out to a set of trusted cyber defenders through its Fairwind Program. "It delivers frontier performance in complex workflows across real-world software engineering, enterprise knowledge work like legal and finance, and cybersecurity defense," Koray Kavukcuoglu,

AI SecurityMicrosoft
P0
2026-10-01 07:33 UTC
Security Journalism

Metamask discloses security incident affecting its infrastructure

BleepingComputer · Sergiu Gatlan · indexed 2026-10-01 07:35 UTC

On Thursday, cryptocurrency wallet provider MetaMask has disclosed an ongoing infrastructure security incident affecting some of its infrastructure. [...]

P0
2026-10-01 05:54 UTC
Security Journalism

Apple CoreGraphics PoC Emerges as WhatsApp PDF Checks Hint at Possible Delivery Path

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-01 07:20 UTC

Security researchers have published the first public proof-of-concept for CVE-2026-86950, an Apple CoreGraphics flaw Apple says may have been used in attacks against specific targeted individuals. The trigger is a malicious PDF with a crafted embedded font that crashes unpatched iPhones and Macs. The code causes a crash, not an execution error. Turning the memory corruption into a working

AppleSecurity ResearchVulnerabilitiesCVE-2026-86950
P5
2026-10-01 05:21 UTC
Security Journalism

Bitget Confirms Third-Party Zero-Day Behind $387.5 Million Cryptocurrency Theft

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-01 05:55 UTC

Cryptocurrency exchange Bitget on Wednesday confirmed that attackers who stole $387.5 million last week exploited a zero-day flaw in third-party security products, citing ongoing investigation findings from SlowMist. "Their investigation identified malicious activity involving third-party security products, including a zero-day vulnerability, and recovered a customized tool used by the attacker

DFIRMicrosoftVulnerabilities
P25
2026-10-01 05:10 UTC
Security Journalism

MetaMask Security Incident Prompts Exit of Affected Ethereum Validators

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-01 05:55 UTC

MetaMask on Thursday said it's responding to what it described as an "ongoing security incident" impacting part of its infrastructure. "We are actively addressing and remediating the issue internally, in coordination with external partners and security advisors," the software cryptocurrency wallet maker said. "At this time, we have identified no immediate threat to MetaMask wallets." MetaMask

P0
2026-10-01 05:00 UTC
Other

ZDI-26-751: Microsoft Windows dxgkrnl Time-Of-Check Time-Of-Use Local Privilege Escalation Vulnerability

Zero Day Initiative · indexed 2026-10-01 19:10 UTC

This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-50375.

MicrosoftVulnerabilitiesCVE-2026-50375
P15
2026-10-01 04:35 UTC
Security Journalism

Citrix NetScaler Post-Exploitation Payload Creates Superuser, Maps Web Shell to CSS-Like URLs

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-01 04:45 UTC

Threat actors have been observed exploiting a critical pre-authentication command injection vulnerability in Citrix NetScaler ADC and NetScaler Gateway to drop web shells and attempt theft of configuration data. LevelBlue's Threat Hunt Operations & Research (THOR) team, which analyzed the exploitation activity across multiple customer environments, said it identified malicious NetScaler

Threat ActorsVulnerabilities
P0
14 15 16 17 18