IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 4,769 matching records.
AUTO-POLL // 2026-10-10 02:25 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
WARM
COOL WARM ELEVATED HOT CRITICAL
P15 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 10

RANSOMWARE
P15
P15
WARM // 1 ARTICLE
FRI
Oct 9

RANSOMWARE
P4
P4
COOL // 67 ARTICLES
THU
Oct 8

RANSOMWARE
P3
P3
COOL // 62 ARTICLES
WED
Oct 7

RANSOMWARE
P5
P5
COOL // 86 ARTICLES
TUE
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
RESET
2026-09-30 13:26 UTC
Other

Oxygen Forensics, A Russian-run forensics firm spent a decade inside European police departments

Security Affairs · Pierluigi Paganini · indexed 2026-09-30 14:25 UTC

DOJ charges against Oxygen Forensics reveal the Russian-linked firm also sold forensic software to EU projects and European police forces for years. Last week’s Justice Department indictment of Oxygen Forensics looked, at first, like an American procurement scandal. CEO Lee Reiber and Russian co-founder Oleg Davydov stand accused of hiding that the company was Russian-owned […]

DFIRLaw Enforcement
P0
2026-09-30 13:16 UTC
Security Journalism

WatchGuard Patches Critical Fireware OS Code Injection Vulnerability

Security Week · Ionut Arghire · indexed 2026-09-30 13:30 UTC

WatchGuard has rolled out patches for 15 code execution, DoS, authorization, and path traversal bugs in Fireware OS. The post WatchGuard Patches Critical Fireware OS Code Injection Vulnerability appeared first on SecurityWeek.

Vulnerabilities
P0
2026-09-30 12:16 UTC
Security Journalism

Chrome, Firefox Updates Patch Over 100 Vulnerabilities

Security Week · Ionut Arghire · indexed 2026-09-30 12:30 UTC

Some of the flaws could allow remote attackers to execute arbitrary code or escape the browser sandbox. The post Chrome, Firefox Updates Patch Over 100 Vulnerabilities appeared first on SecurityWeek.

Cloud Security
P0
2026-09-30 11:58 UTC
Security Journalism

Know Your Enemy: Browser-Based Attack Techniques in 2026

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-30 13:00 UTC

Given that the browser is where business apps are accessed and used, it makes sense that attacks are happening there too. Most breaches today begin in a browser session. Often, they never leave it, with the entire attack chain from initial access to exfiltration playing out in the browser. Here are the six most dangerous techniques that should be on every security team's radar in 2026. 1.

P0
2026-09-30 11:30 UTC
Security Journalism

AI Coding Agents Exposed 13,000 Internal Images, Including Billing Records, on GitHub

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-30 11:45 UTC

AI coding agents asked to share screenshots of code changes for review have put internal company images in public GitHub repositories, security company Glow said. Its researchers found more than 13,000 internal images from developers at over 300 organizations, including customer billing records and screens of features not yet released. In most cases, they sat under developers' personal accounts

P0
2026-09-30 10:45 UTC
Security Journalism

US-Focused CSuite Phishing Steals Microsoft 365 Sessions and Deploys RMM Tools for Remote Access

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-30 11:45 UTC

ANY.RUN researchers traced a US-focused CSuite phishing campaign across 351 sandbox analyses, with 51% of submissions coming from the United States. Technology, manufacturing, government, and consulting organizations showed the highest exposure. By combining Microsoft 365 session theft with remote-access tool deployment, CSuite can turn a phishing incident into broader account compromise, fraud

CybercrimeMicrosoftPhishing
P0
2026-09-30 10:20 UTC
Security Journalism

ShinyHunters Defiant After FBI Calls on Members to Come Forward

Security Week · Ionut Arghire · indexed 2026-09-30 10:30 UTC

In the wake of a suspected leader’s arrest, ShinyHunters says it never intended to publish data stolen from the FBI. The post ShinyHunters Defiant After FBI Calls on Members to Come Forward appeared first on SecurityWeek.

Law Enforcement
P0
2026-09-30 10:00 UTC
Vendor Research

China-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoor

Cisco Talos Intelligence Blog · Ashley Shen · indexed 2026-09-30 10:10 UTC

Cisco Talos uncovered a cluster of activity we track as UAT-11587 targeting government and policy organizations across Asia, including in Taiwan, India, the Philippines, and Cambodia, to deliver a previously undocumented backdoor referred to as “Antino” in developer artifacts.

Malware
P0
2026-09-30 09:51 UTC
Vendor Research

Phishing Response Protocol: 3 Essential SOC Steps Powered by ANY.RUN’s Latest Updates

ANY.RUN Blog · ANY.RUN · indexed 2026-10-06 14:56 UTC

Phishing investigations put pressure on SOC teams at several points at once: analysts need to uncover hidden activity, make a confident decision from incomplete evidence, prepare the case for escalation, and then determine whether the threat extends beyond a single incident. Every manual step adds time to the response. It also ties up analyst capacity […] The post Phishing Response Protocol: 3 Essential SOC Steps Powered by ANY.RUN’s Latest Updates appeared first on ANY.RUN's Cybersecurity Blog.

DFIRPhishing
P0
2026-09-30 09:14 UTC
Other

Attackers Abuse ChatGPT Custom GPTs to Deploy a Full-Featured RAT

Security Affairs · Pierluigi Paganini · indexed 2026-09-30 10:10 UTC

Threat actors abused fake ChatGPT Custom GPTs and ClickFix to deliver a multi-stage RAT. ChatGPT’s Custom GPT feature is the latest legitimate surface being turned into a delivery mechanism, and Huntress researchers caught it in action across at least 40 incidents. A Custom GPT (now simply called a GPT) is essentially a version of ChatGPT […]

Threat Actors
P0
2026-09-30 08:24 UTC
Security Journalism

Attackers Exploit NetScaler Flaw for Root Access, Deploy WHIPSHOT and SLAPSHOT

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-30 09:55 UTC

Unknown threat actors have been observed exploiting a newly patched security flaw in Citrix NetScaler ADC and NetScaler Gateway appliances to target organizations in North America and Europe. The activity, observed by Mandiant Consulting and Google Threat Intelligence Group (GTIG) in September 2026, has targeted government, financial services, technology, education, and legal and professional

Threat ActorsThreat Intelligence
P0
2026-09-30 08:09 UTC
Security Journalism

OpenSSL Fixes High-Severity DTLS Flaw That Can Leak Heap Memory Unencrypted

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-30 09:55 UTC

A High-severity OpenSSL flaw can leak heap memory to the other side of a DTLS connection or crash the program, OpenSSL said on September 29 as it released fixes. DTLS, the TLS variant used for UDP traffic, resends a handshake message if no reply arrives before the timer expires. The leak or crash can happen when such a resend starts while a larger handshake message is stuck part-way

P0
2026-09-30 08:04 UTC
Other

U.S. CISA adds Apple Multiple Products flaw to its Known Exploited Vulnerabilities catalog

Security Affairs · Pierluigi Paganini · indexed 2026-09-30 09:10 UTC

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Apple Multiple Products flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added an Apple Multiple Products flaw, tracked as CVE-2026-86950 (CVSS score of 8.8), to its Known Exploited Vulnerabilities (KEV) catalog. This week, Apple has released security updates for iOS, iPadOS […]

AppleVulnerabilitiesCVE-2026-86950
P35
2026-09-30 07:25 UTC
Other

WHIPSHOT and SLAPSHOT: the tools behind an active Citrix NetScaler campaign

Security Affairs · Pierluigi Paganini · indexed 2026-09-30 07:50 UTC

Mandiant and GTIG detail active exploitation of a Citrix NetScaler zero-day, deploying custom web shells WHIPSHOT and SLAPSHOT for root access. Mandiant and Google Threat Intelligence Group caught active exploitation of a zero-day in Citrix NetScaler ADC and Gateway appliances in late September 2026. The bug, tracked as CVE-2026-88772 (CVSS score of 9.5), has been […]

Threat IntelligenceVulnerabilitiesCVE-2026-88772
P30
2026-09-30 06:55 UTC
Security Journalism

High-Severity Vulnerabilities Patched in OpenSSL, WolfSSL

Security Week · Eduard Kovacs · indexed 2026-09-30 07:15 UTC

Roughly a dozen vulnerabilities have been patched in each of the open source cryptographic libraries. The post High-Severity Vulnerabilities Patched in OpenSSL, WolfSSL appeared first on SecurityWeek.

P0
2026-09-30 05:30 UTC
Security Journalism

Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-30 07:00 UTC

Cybersecurity researchers have disclosed technical details of a recently patched critical security flaw in Citrix NetScaler ADC and Gateway that has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-88772 (CVSS score: 9.5), has been described as a memory overflow bug in the Datagram Transport Layer Security (DTLS) protocol handling that's rooted in the NetScaler

Security ResearchVulnerabilitiesCVE-2026-88772
P25
2026-09-30 05:00 UTC
Other

ZDI-26-750: WatchGuard FireWare OS spamd statushdlr Stack-based Buffer Overflow Remote Code Execution Vulnerability

Zero Day Initiative · indexed 2026-09-30 21:10 UTC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of WatchGuard FireWare OS. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-18145.

VulnerabilitiesCVE-2026-18145
P20
2026-09-30 05:00 UTC
Other

ZDI-26-749: WatchGuard FireWare OS samld SAMLSession Deserialization of Untrusted Data Remote Code Execution Vulnerability

Zero Day Initiative · indexed 2026-09-30 21:10 UTC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of WatchGuard FireWare OS. An attacker must first obtain the ability to write to the samld session directory on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-13046.

VulnerabilitiesCVE-2026-13046
P20
16 17 18 19 20