IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 4,759 matching records.
AUTO-POLL // 2026-10-09 20:40 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P5 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 9

RANSOMWARE
P5
P5
COOL // 58 ARTICLES
THU
Oct 8

RANSOMWARE
P3
P3
COOL // 62 ARTICLES
WED
Oct 7

RANSOMWARE
P5
P5
COOL // 86 ARTICLES
TUE
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
RESET
2026-10-09 13:56 UTC
Other

Claude Helps Secure Open Source as Anthropic Offers Free Vulnerability Scanning

Security Affairs · Pierluigi Paganini · indexed 2026-10-09 14:20 UTC

Anthropic launches free OSS Scanner, using AI to find open-source vulnerabilities and help maintainers fix bugs before attackers exploit them. Anthropic is launching OSS Scanner, a vulnerability scanner for open-source code that costs nothing for projects to join. It grew directly out of lessons learned running Claude against real-world targets during Project Glasswing. The backdrop […]

Vulnerabilities
P0
2026-10-09 13:22 UTC
Security Journalism

TP-Link Sued by Four More U.S. States Over Router Security and China Ties

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-09 14:35 UTC

Four more U.S. states sued router maker TP-Link Systems on October 6, bringing the total to five, with Texas filing a suit in February. Florida, Iowa, Montana and Nebraska allege the California company misled buyers about how secure its routers are and how separate it is from China. TP-Link denies the claims and says it will fight them in court. TP-Link Systems is based in

Network Security
P0
2026-10-09 12:59 UTC
Security Journalism

Researchers Publish Working Exploit for Pre-Auth AnyDesk Linux Flaw That Gives Root Access

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-09 14:35 UTC

Security researchers have published a full working exploit for a pre-authentication remote code execution flaw in AnyDesk Linux that gives attackers root access before anyone approves the connection. AnyDesk patched the flaw in version 8.0.3 in June, but its changelog described the fix only as "fixed a bug that could lead to a crash," with no CVE assigned and no security

LinuxSecurity ResearchVulnerabilities
P15
2026-10-09 12:47 UTC
Security Journalism

Anthropic Launches Free AI Vulnerability Scanner for Open-Source Projects

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-09 14:35 UTC

Anthropic on Thursday unveiled OSS Scanner as an opt-in vulnerability scanner to help secure the open-source ecosystem using artificial intelligence (AI). "It's an opt-in service informed by our experience using Claude to find vulnerabilities during Project Glasswing," Anthropic said. "Projects that join will receive thorough, periodic security scans by our strongest models at no cost."

AI SecurityVulnerabilities
P0
2026-10-09 12:47 UTC
Security Journalism

Attackers Exploit AhsayCBS Flaws to Deploy XMRig Miners Disguised as Microsoft Edge

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-09 14:35 UTC

Threat actors have been observed exploiting two recently disclosed flaws in the AhsayCBS backup utility to seize control of affected devices and deploy web shells and XMRig cryptocurrency miners. Details of the flaws are below - CVE-2026-105133 (CVSS v4 score: 5.5) - An improper authentication vulnerability in the checkSysPwd() function in the "com/ahsay/obs/api/ApiStructsAction.java"

Cloud SecurityMicrosoftThreat ActorsVulnerabilitiesCVE-2026-105133
P5
2026-10-09 12:21 UTC
Security Journalism

Flax Typhoon Exploits Five Flaws as CISA Sets October 11 Deadline for Federal Agencies

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-09 12:55 UTC

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added five security flaws to its Known Exploited Vulnerabilities (KEV) catalog, following their abuse by a China-linked threat actor known as Flax Typhoon. The vulnerabilities in question are listed below - CVE-2015-3306 (CVSS score: 10.0) - An improper access control vulnerability in ProFTPD that could allow

Cloud SecurityThreat ActorsVulnerabilitiesCVE-2015-3306
P35
2026-10-09 12:03 UTC
Security Journalism

In Other News: AI Used in Korean Bank Breaches, Poem-Guided Botnet, Empire Admin Gets 40 Years

Security Week · SecurityWeek News · indexed 2026-10-09 12:10 UTC

Noteworthy stories that might have slipped under the radar: Tensorlake npm SDK compromised, Empire Market co-founder gets 40 years, exposed NVIDIA GPU monitors leak telemetry. The post In Other News: AI Used in Korean Bank Breaches, Poem-Guided Botnet, Empire Admin Gets 40 Years appeared first on SecurityWeek.

Malware
P0
2026-10-09 11:43 UTC
Security Journalism

Google Domains Impacted by Recent ccTLD Hijacks

Security Week · Ionut Arghire · indexed 2026-10-09 11:50 UTC

Hackers hijacked the .gh, .sl, and .as ccTLDs and obtained HTTPS certificates for several Google domains. The post Google Domains Impacted by Recent ccTLD Hijacks appeared first on SecurityWeek.

P0
2026-10-09 11:30 UTC
Security Journalism

The AI Velocity Paradox: Why Security Is Decades Behind AI Ambition

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-09 11:40 UTC

As enterprises race to deploy autonomous AI agents to accelerate business, a new report reveals they are tethered to security architectures built for a different era. The "Horizons of Identity Security" report from SailPoint highlights a critical “velocity paradox,” in which organizations invest in AI-speed business operations while continuing to rely on human-speed security controls, creating a

AI Security
P0
2026-10-09 10:49 UTC
Other

US Disrupts China-Linked Integrity Tech ‘s Cyber Espionage Tools

Security Affairs · Pierluigi Paganini · indexed 2026-10-09 10:50 UTC

DOJ and FBI seized China-linked hacking tools Microscan and FishHub, linked to Integrity Tech and attacks on critical infrastructure worldwide. The Justice Department and FBI took down two hacking tools this week, Microscan and FishHub, both built and run by a Beijing-based company with direct government contracts. The tools were used to scan, and in […]

APT / Nation-StateLaw Enforcement
P0
2026-10-09 10:04 UTC
Other

CVE-2026-107406: Citrix Fixes Critical NetScaler ADC and Gateway Vulnerability

Security Affairs · Pierluigi Paganini · indexed 2026-10-09 10:50 UTC

Citrix patched CVE-2026-107406, a critical NetScaler ADC and Gateway flaw that could allow remote code execution or denial-of-service attacks. Citrix has released security updates to fix CVE-2026-107406 (CVSS score of 9.5), a critical flaw affecting NetScaler ADC and NetScaler Gateway that could allow remote code execution or denial-of-service (DoS) under certain conditions. The vulnerability is […]

VulnerabilitiesCVE-2026-107406
P30
2026-10-09 09:03 UTC
Security Journalism

GoBalance Flaw Lets Attackers Hijack .onion Addresses by Recovering Tor-Format Keys

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-09 09:55 UTC

A bug in GoBalance, a tool many dark-web sites use to stay reachable during attacks, lets anyone work out the secret key that controls a site's .onion address using only public information, and then take that address over. Searchlight Cyber, which disclosed the flaw on October 8, says an attacker who recovers the key can redirect the site's visitors to a copy of the site they control.

P0
2026-10-09 08:36 UTC
Security Journalism

US Disrupts Chinese State-Sponsored Hacking Tools

Security Week · Ionut Arghire · indexed 2026-10-09 08:50 UTC

Flax Typhoon and other APTs used MicroScan and FishHub to scan and hack US and foreign critical infrastructure. The post US Disrupts Chinese State-Sponsored Hacking Tools appeared first on SecurityWeek.

APT / Nation-State
P0
2026-10-09 08:27 UTC
Security Journalism

Citrix warns admins to patch new NetScaler RCE flaw immediately

BleepingComputer · Sergiu Gatlan · indexed 2026-10-09 08:40 UTC

Citrix has warned IT administrators to patch systems immediately against a new critical vulnerability affecting NetScaler ADC networking appliances and NetScaler Gateway secure remote access solutions. [...]

Vulnerabilities
P25
2026-10-09 08:26 UTC
Security Journalism

Three Teams Demonstrate Remote Hacks of Fully Patched Google Pixel 10 at Pwn2Own

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-09 09:55 UTC

Three research teams broke into Google's Pixel 10 on October 8 at Pwn2Own Ireland, a hacking contest in Cork whose rules require every target to be fully patched. The contest pays researchers to show working exploits and passes the flaws to the vendors. One of the three Pixel exploits earned Ikotas Labs $300,000, the contest's top prize, and made the team the overall winner. Trend Micro's Zero

Cloud Security
P0
2026-10-09 08:11 UTC
Security Journalism

Citrix Patches Critical NetScaler Flaw That Could Enable RCE in SAML Deployments

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-09 09:55 UTC

Citrix has released patches for yet another critical security flaw impacting NetScaler ADC and NetScaler Gateway that could result in remote code execution or denial-of-service (DoS) under certain conditions. "CVE-2026-107406 is a memory overflow vulnerability that may lead to remote code execution or denial-of-service under specific configuration conditions," Citrix said. The vulnerability

VulnerabilitiesCVE-2026-107406
P20
2026-10-09 07:53 UTC
Other

AI-Driven tool ARTEX used in attacks against South Korean Banks

Security Affairs · Pierluigi Paganini · indexed 2026-10-09 08:30 UTC

CrowdStrike analyzes open directories left by an attacker who used the ARTEX AI pentest tool and LLMs to breach South Korean financial firms. CrowdStrike published a research on a campaign against South Korean financial organizations that ran from late September to early October 2026 and ended with stolen data. The attacker left their working notes […]

AI SecurityData Breaches
P0
2026-10-09 07:00 UTC
Other

Agentic AI In Cybersecurity: What Changes When The System Chooses The Next Step

Group-IB · indexed 2026-10-09 08:00 UTC

Agentic AI is the breakthrough of the moment, in security as everywhere else: agents that are threat-aware, active, and proactive in investigation. But it is also the technology behind a recent documented autonomous AI intrusion. Both facts are true, and the distance between them is what this article is about.

DFIR
P0
2026-10-09 06:39 UTC
Security Journalism

Google Pixel 10 Exploits Earned Hackers $560,000 at Pwn2Own

Security Week · Eduard Kovacs · indexed 2026-10-09 06:50 UTC

$1.2 million was paid out at Pwn2Own Ireland 2026 for exploits targeting phones, printers, smart speakers, smart home hubs, and AI infrastructure and coding tools. The post Google Pixel 10 Exploits Earned Hackers $560,000 at Pwn2Own appeared first on SecurityWeek.

P0
1 2 3 4