IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 4,769 matching records.
AUTO-POLL // 2026-10-10 05:40 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
WARM
COOL WARM ELEVATED HOT CRITICAL
P15 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 10

RANSOMWARE
P15
P15
WARM // 1 ARTICLE
FRI
Oct 9

RANSOMWARE
P4
P4
COOL // 67 ARTICLES
THU
Oct 8

RANSOMWARE
P3
P3
COOL // 62 ARTICLES
WED
Oct 7

RANSOMWARE
P5
P5
COOL // 86 ARTICLES
TUE
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
RESET
2026-09-24 20:35 UTC
Security Journalism

Autonomous AI Hacks Raise Thorny Questions of Legal Accountability

Security Week · Associated Press · indexed 2026-09-24 20:40 UTC

The prospect of legal accountability is unclear. Lawsuits are a possibility, but some legal experts believe any criminal investigations would face an extremely high burden. The post Autonomous AI Hacks Raise Thorny Questions of Legal Accountability appeared first on SecurityWeek.

Cloud SecurityDFIR
P0
2026-09-24 20:32 UTC
Security Journalism

SectopRAT Returns, Hiding Inside a Legitimate Application

Dark Reading · Jai Vijayan · indexed 2026-09-24 21:00 UTC

The latest activity from the remote access Trojan (RAT) shows why organizations should monitor the behavior of applications rather than blindly trusting them, experts say.

Malware
P0
2026-09-24 20:15 UTC
Security Journalism

Lawmakers introduce bill for voluntary telecom cyber rules after Salt Typhoon hacks

The Record · indexed 2026-09-24 20:30 UTC

U.S. Sens. Mark Warner (D-VA) and Ted Cruz (R-TX) introduced the Telecommunications Cybersecurity and Resilience Act on Thursday, arguing that the new effort was necessary in light of the Salt Typhoon attacks which saw Chinese hackers breach nearly all of the major telecommunications giants in the U.S.

P0
2026-09-24 19:17 UTC
Vendor Research

CVE-2026-96883 - Type confusion in AWS pgcollection allows remote code execution

AWS Security Bulletins · aws@amazon.com · indexed 2026-09-24 19:35 UTC

Bulletin ID: 2026-118-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/24/2026 12:00 PM PDT Description: pgcollection is an open source extension to PostgreSQL. We identified CVE-2026-96883, an issue in pgcollection's type coercion logic. When requesting a stored icollection value as a type incompatible with how it was actually stored causes the extension to misinterprets the datum's representation, allowing an authenticated database user to crash the PostgreSQL …

Cloud SecurityVulnerabilitiesCVE-2026-96883
P20
2026-09-24 18:16 UTC
Other

AI Helps Uncover MikroTrick Attack Chain in MikroTik RouterOS

Security Affairs · Pierluigi Paganini · indexed 2026-09-24 19:20 UTC

MikroTrick chains two RouterOS flaws to bypass authentication and gain admin access. AI helped researchers uncover the attack chain within days. MikroTik pushed out patches on September 3, 2026 for several RouterOS issues at once, calling it an important security update without saying what it actually fixed. That silence was deliberate, and it didn’t last […]

Cloud SecurityNetwork Security
P5
2026-09-24 18:10 UTC
Security Journalism

Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-24 19:00 UTC

A OnePlus 15 running the latest OxygenOS can be rooted by a malicious app the owner installs, one that asks for no special permissions. A researcher, Rasmus Moorats, chained two flaws in OnePlus's own software to gain root access, the highest level of control over an Android phone. OnePlus told him the same flaws affect many more of its own devices and those of OPPO, though it has not

Cloud SecurityMobile Security
P0
2026-09-24 18:00 UTC
Vendor Research

Trust and the enticing consultancy offer

Cisco Talos Intelligence Blog · Martin Lee · indexed 2026-09-24 18:30 UTC

In this week’s newsletter Martin muses over a very suspicious elicitation over social media and the true value of trust within the cyber ecosystem. Hubris might be the real vulnerability that the cyber industry must worry about.

Vulnerabilities
P0
2026-09-24 17:52 UTC
Security Journalism

ThreatsDay: AI Search Poisoning, AI Coding Tool Leaking Repos, One-Click Code Execution and 13 More Stories

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-24 19:00 UTC

This week, the dangerous stuff keeps arriving dressed as something boring. An update. A login box. A search answer. A coding tool. A link you have clicked a hundred times before. That is the thread running through the pile. Trusted paths get poisoned. Old bugs find new jobs. AI tools leak more than expected. Fake prompts look real enough. And some attacks barely need an exploit at all — just

P0
2026-09-24 17:47 UTC
Security Journalism

Exposed GitLab project email addresses let attackers push code

BleepingComputer · Bill Toulas · indexed 2026-09-24 17:55 UTC

Private GitLab email addresses that allow developers to push issues or tasks to a project are being deliberately exposed in READMEs, contributing guides, and support pages used to collect bug reports. [...]

P0
2026-09-24 17:21 UTC
Vendor Research

CVE-2026-95985 - Kiro IDE Allows Agentic Writes to Global Configurations While Working in Untrusted Workspaces

AWS Security Bulletins · aws@amazon.com · indexed 2026-09-24 18:00 UTC

Bulletin ID: 2026-117-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/24/2026 10:00 AM PDT Description: Kiro is an agentic IDE that users install on their desktop. We identified CVE-2026-95985. The file write tool in Kiro IDE before version 1.0.242 might allow remote unauthenticated actors to execute arbitrary commands and to inject crafted instructions into the agent's context. When a user runs the agent in a crafted repository as an untrusted workspace, sendin…

Cloud SecurityVulnerabilitiesCVE-2026-95985
P5
2026-09-24 17:16 UTC
Vendor Research

Cisco Identity Services Engine Authentication Bypass Vulnerabilities

Cisco Security Advisories · indexed 2026-09-16 16:40 UTC

Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow a remote attacker to access or manipulate data, obtain sensitive information, or cause a reload of certificate and key material on an affected device. For more information about these vulnerabilities, see the Details section of this advisory. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilit…

VulnerabilitiesCVE-2026-76439CVE-2026-76444CVE-2026-76446CVE-2026-76447
P15
2026-09-24 16:00 UTC
Vendor Research

Beyond the ransomware: Tracking Storm-2570’s consistent tradecraft across deployments

Microsoft Security Blog · Microsoft Threat Intelligence · indexed 2026-09-24 18:00 UTC

Storm-2570 is a ransomware affiliate that uses consistent post-compromise tools and techniques across deployments involving Qilin, DragonForce, Anubis, and BERT ransomware, and provides guidance to help defenders detect and disrupt this activity before ransomware deployment. The post Beyond the ransomware: Tracking Storm-2570’s consistent tradecraft across deployments appeared first on Microsoft Security Blog.

MicrosoftRansomware
P15
2026-09-24 15:52 UTC
Security Journalism

Kontext Security Emerges With $4 Million for AI Agent Runtime Controls

Security Week · Ionut Arghire · indexed 2026-09-24 16:00 UTC

The startup’s runtime enforcement platform evaluates AI agents in real time to provide visibility and control over their actions. The post Kontext Security Emerges With $4 Million for AI Agent Runtime Controls appeared first on SecurityWeek.

AI Security
P0
2026-09-24 15:27 UTC
Security Journalism

Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-24 16:35 UTC

The "third-party[.]com" domain, commonly used as a documentation placeholder, has been observed serving a ClickFix lure to Windows browsers while displaying a harmless decoy to other users. "third-party[.]com has been a generic documentation placeholder for years, the same role example.com plays," Manifold Security's Head of Research, Ax Sharma, said. "Unlike 'example[.]com,' third-party[.]com

Microsoft
P0
2026-09-24 14:44 UTC
Security Journalism

3 Cyber Threats That Defined the Summer of 2026

Dark Reading · Arielle Waldman · indexed 2026-09-24 15:45 UTC

This installment of the Reporters' Notebook video series discusses the impact of AI agents breaching Hugging Face, Fairlife's ransomware attack, and Iranian-linked threat actors compromising a dozen US water systems. It was a busy summer.

AI SecurityRansomwareThreat Actors
P15
2026-09-24 14:29 UTC
Security Journalism

Hacked Ukrainian Sites Serve Fake Cloudflare ClickFix Lures for Psychedelic Stealer

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-24 15:10 UTC

An active ClickFix campaign has been observed compromising legitimate Ukrainian business websites to inject bogus Cloudflare verification pages and trick victims into downloading a previously undocumented information stealer called Psychedelic. "When a visitor interacts with the page, the lure copies a Windows Installer command to the clipboard and instructs the visitor to paste it into the

MalwareMicrosoft
P0
2026-09-24 14:02 UTC
Security Journalism

How to Build a SASE Framework for Modern Cybersecurity

Dark Reading · George V. Hulme, Contributing Writer · indexed 2026-09-24 14:30 UTC

Securing edge computing requires organizations to fundamentally rethink security governance. This step-by-step guide to building a SASE framework provides the path forward. (Third in a three-part series.)

P0
2026-09-24 14:02 UTC
Security Journalism

FedRAMP VDR & VER: Daily Scans Are Only the Beginning

BleepingComputer · Sponsored by Anecdotes · indexed 2026-09-24 14:15 UTC

FedRAMP's new VDR and VER requirements make vulnerability management more continuous, with faster scanning, tighter remediation deadlines, and stronger evidence requirements. Anecdotes explains why the December 7 deadline is just the beginning of a broader shift toward continuous, automated compliance validation. [...]

Vulnerabilities
P0
2026-09-24 14:00 UTC
Vendor Research

Proactive Defense: Hardening Code Pipelines and CI/CD Infrastructure

Google Threat Intelligence / Mandiant · Mandiant · indexed 2026-09-24 15:25 UTC

Introduction The landscape of software supply chain security has undergone a significant shift. Recent campaigns demonstrate that sophisticated threat actors are systematically targeting the engineering lifecycle by compromising trusted security and programming tools. These intrusions reveal three key tactics: Attackers target trusted security scanners, utility libraries, and AI developer tools to exploit the elevated privileges granted to these systems within build pipelines. Adversaries targe…

AI SecurityMicrosoftPhishingThreat ActorsVulnerabilities
P0
24 25 26 27 28