IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 4,769 matching records.
AUTO-POLL // 2026-10-10 05:00 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
WARM
COOL WARM ELEVATED HOT CRITICAL
P15 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 10

RANSOMWARE
P15
P15
WARM // 1 ARTICLE
FRI
Oct 9

RANSOMWARE
P4
P4
COOL // 67 ARTICLES
THU
Oct 8

RANSOMWARE
P3
P3
COOL // 62 ARTICLES
WED
Oct 7

RANSOMWARE
P5
P5
COOL // 86 ARTICLES
TUE
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
RESET
2026-09-25 14:00 UTC
Vendor Research

ShinyHunters Renewed Mass Exploitation Campaign Targeting Oracle PeopleSoft

Google Threat Intelligence / Mandiant · Mandiant · indexed 2026-09-26 06:55 UTC

Introduction As an update to the June 2026 post, ShinyHunters Targets Education Sector with Oracle PeopleSoft Exploit, Mandiant and Google Threat Intelligence Group (GTIG) have identified renewed mass exploitation of CVE-2026-35273 by UNC6240 (ShinyHunters), along with expanded global targeting across multiple sectors. In June, the threat actor exploited this vulnerability as a zero-day predominantly against academic institutions. This new wave of activity stems from UNC6240 modifying its explo…

LinuxMicrosoftNetwork SecurityThreat ActorsThreat IntelligenceVulnerabilitiesCVE-2026-35273
P50
2026-09-25 13:49 UTC
Other

ClickFix Campaign Abuses Trusted Websites to Deploy Psychedelic Stealer

Security Affairs · Pierluigi Paganini · indexed 2026-09-25 14:10 UTC

Attackers hijacked Ukrainian websites to deliver a fake Cloudflare CAPTCHA that installs Psychedelic Stealer and steals browser and crypto credentials. Psychedelic Stealer is being distributed through compromised Ukrainian business websites. Attackers injected hidden iframes into legitimate pages and used them to display a fake Cloudflare verification screen to visitors. The affected sites included a hair-treatment […]

Malware
P0
2026-09-25 13:18 UTC
Security Journalism

PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-25 16:10 UTC

Cybersecurity researchers have flagged a new version of PamStealer that ensures that the main payload can only be recovered using a server-side decryption chain. The latest artifacts, per Jamf Threat Labs, continue to rely on the same JavaScript for Automation (JXA) dropper mechanism, but modify the lure and the delivery method. "Where earlier variants embedded their payload key material

AppleMalwareSecurity Research
P0
2026-09-25 13:00 UTC
Security Journalism

Culture at Speed: Protecting What Makes Huntress Work

Huntress · indexed 2026-09-26 07:35 UTC

As Huntress scales past 800 teammates, Chief People Officer Kristin Dean reflects on protecting culture and not just letting it happen.

P0
2026-09-25 13:00 UTC
Vendor Research

Agents can now set up your website’s security with Turnstile Spin

Cloudflare Security · Jules Lemee · indexed 2026-09-25 13:10 UTC

Misconfiguring Turnstile by skipping backend validation leaves sites exposed to bots. Turnstile Spin fixes incomplete setups by using your preferred AI coding agent to wire up server-side verification.

P0
2026-09-25 12:39 UTC
Security Journalism

CISA Election Security Plan Flags Patching Barriers, Voter Database Attacks

Security Week · Eduard Kovacs · indexed 2026-09-25 12:40 UTC

Homeland Security Secretary Markwayne Mullin tasked CISA with developing the plan in July. The post CISA Election Security Plan Flags Patching Barriers, Voter Database Attacks appeared first on SecurityWeek.

P0
2026-09-25 12:16 UTC
Security Journalism

Kosovar Owner of Rydox Marketplace Pleads Guilty in US Court

Security Week · Ionut Arghire · indexed 2026-09-25 12:20 UTC

Ardit Kutleshi created and operated Rydox, which allowed miscreants to trade PII and cybercrime tools and services. The post Kosovar Owner of Rydox Marketplace Pleads Guilty in US Court appeared first on SecurityWeek.

Cybercrime
P0
2026-09-25 12:14 UTC
Vendor Research

ANY.RUN at RootedCON Valencia 2026: Where Cybersecurity Meets the Next Wave of AI

ANY.RUN Blog · ANY.RUN · indexed 2026-10-06 14:56 UTC

ANY.RUN once again joined the RootedCON community this year, taking part in Rooted Valencia 2026 on September 18. The event brought together cybersecurity professionals, researchers, hackers, and technology enthusiasts from across the global cybersecurity community. For our team, the event became yet another opportunity to meet security professionals, speak with clients, and demonstrate how interactive […] The post ANY.RUN at RootedCON Valencia 2026: Where Cybersecurity Meets the Next Wave of A…

P0
2026-09-25 12:00 UTC
Security Journalism

Doubts grow over claims OpenAI agent hacked Australian Medicare portal

The Record · indexed 2026-09-25 12:15 UTC

Researchers are questioning whether an OpenAI agent needed to hack an Australian government health portal to access it, after a review of the website’s archived code found it explicitly directed visitors to an unauthenticated endpoint.

AI Security
P0
2026-09-25 11:35 UTC
Security Journalism

Rydox marketplace admin pleads guilty, faces 22 years in prison

BleepingComputer · Sergiu Gatlan · indexed 2026-09-25 11:50 UTC

A Kosovar national has pleaded guilty to operating Rydox, a large illegal online marketplace that sold stolen personal information, login credentials, credit card details, and cybercrime tools. [...]

Cybercrime
P0
2026-09-25 11:30 UTC
Security Journalism

The SOC Doesn't Need to Start Over with Every Alert

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-25 13:10 UTC

Security leaders keep debating whether AI will produce an entirely new class of cyberattack. The nearer change is quieter and already visible: AI has made a failed attack cheap to retry. The routine version looks like this. An attacker lands on a low-privilege cloud account, and the first try at privilege escalation goes nowhere. That dead end used to cost hours of documentation reading,

Vulnerabilities
P10
2026-09-25 10:35 UTC
Security Journalism

Bitget Says Suspected North Korean Hackers Stole $351.6M After Backend Compromise

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-25 11:15 UTC

Cryptocurrency exchange Bitget said suspected North Korean threat actors have stolen $351.6 million from its hot and warm wallets. "At 18:31 UTC on September 24, 2026, Bitget's security systems identified unauthorized transfers involving a limited number of hot wallets," Bitget said in a post shared on X. "Bitget's cold wallets and the overwhelming majority of platform assets remain

MicrosoftThreat Actors
P0
2026-09-25 10:30 UTC
Security Journalism

Microsoft: Recent Windows updates cause desktop loading issues

BleepingComputer · Sergiu Gatlan · indexed 2026-09-25 10:35 UTC

Microsoft has confirmed that some users may experience desktop loading issues, including black screens, after installing the August 2026 preview updates and subsequent updates. [...]

Microsoft
P0
2026-09-25 10:14 UTC
Security Journalism

Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-25 10:15 UTC

The Canadian Centre for Cyber Security has warned that a now-patched Roundcube Webmail vulnerability is being actively exploited in the wild. The vulnerability in question is CVE-2026-48842 (CVSS score: 8.1), a pre-authentication SQL injection in the virtuser_query plugin of Roundcube Webmail versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1. The issue stems from a preg_replace() backslash

VulnerabilitiesCVE-2026-48842
P50
2026-09-25 09:55 UTC
Other

AI-Powered CARBONATO Botnet Steals Credentials to Fund Its Own LLM Gateway

Security Affairs · Pierluigi Paganini · indexed 2026-09-25 10:40 UTC

CARBONATO exploits exposed Docker daemons, installs an AI agent, steals API keys and spreads across networks with autonomous command execution. CARBONATO is a Docker-based botnet that has been active since at least October 2024. ThreatDown discovered the operation after finding an unauthenticated container registry exposed to the internet. The registry contained the attackers’ entire toolchain […]

AI SecurityMalware
P0
2026-09-25 08:22 UTC
Other

U.S. CISA adds Adobe and WSO2 flaws to its Known Exploited Vulnerabilities catalog

Security Affairs · Pierluigi Paganini · indexed 2026-09-25 08:25 UTC

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Adobe and WSO2 flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: The first flaw added to the catalog, tracked as CVE-2026-5430 (CVSS score 10.0), is an authentication bypass in multiple WSO2 products […]

Cloud SecurityVulnerabilitiesCVE-2026-5430
P45
2026-09-25 07:00 UTC
Security Journalism

Russia's Hybrid Cyber-Physical War in Europe Heats Up

Dark Reading · Alexander Culafi · indexed 2026-09-25 07:15 UTC

A storm is raging in the form of cyber sabotage, disinformation, and drone attacks on European nations, particularly those that provide material support to Ukraine.

P0
2026-09-25 04:49 UTC
Security Journalism

Cloudflare Fixes Flaw That Let One Container Read Another Customer's Leftover Disk Data

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-25 06:35 UTC

A flaw in Cloudflare Containers let a paying customer read data that other customers' containers had left behind on the same server, Cloudflare and the researchers who found it said on Thursday. The data came from disk space that earlier containers had used and given up, not from any live workload, and an attacker could not choose whose data they got, according to Cloudflare. The company

P0
2026-09-25 04:46 UTC
Security Journalism

WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-25 06:35 UTC

The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added two critical security flaws impacting WSO2 and Adobe Commerce and Magento to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation. The vulnerabilities are listed below - CVE-2026-5430 (CVS score: 9.8) - A path traversal vulnerability in WSO2 API Control Plane,

Cloud SecurityVulnerabilitiesCVE-2026-5430
P55
2026-09-24 20:50 UTC
Other

Ryuk Member Karen Vardanyan Sentenced to Two Years in U.S. Prison

Security Affairs · Pierluigi Paganini · indexed 2026-09-24 21:35 UTC

Ryuk member Karen Vardanyan was sentenced to 24 months in U.S. prison after extradition from Ukraine and ordered to pay $1.2M in restitution. Karen Vardanyan, a 35-year-old Armenian citizen who went by “Maneeken” and, oddly, “Karl Lagerfeld” online, was extradited from Ukraine and sentenced to 24 months in federal prison plus three years of supervised […]

P0
23 24 25 26 27