IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 4,769 matching records.
AUTO-POLL // 2026-10-10 08:00 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
WARM
COOL WARM ELEVATED HOT CRITICAL
P15 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 10

RANSOMWARE
P15
P15
WARM // 1 ARTICLE
FRI
Oct 9

RANSOMWARE
P4
P4
COOL // 67 ARTICLES
THU
Oct 8

RANSOMWARE
P3
P3
COOL // 62 ARTICLES
WED
Oct 7

RANSOMWARE
P5
P5
COOL // 86 ARTICLES
TUE
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
RESET
2026-09-22 15:51 UTC
Security Journalism

Two arrested in UK after Microsoft takedown of ‘Eviltokens’ AI-chatbot for cybercriminals

The Record · indexed 2026-09-22 16:00 UTC

Available on Telegram for a $1,500 initiation fee and a recurring monthly $500 subscription, EvilTokens provided cybercriminals with artificial intelligence tools enabling them to compromise accounts, analyze breached inboxes and find the best methods for monetizing their access through fraud.

AI SecurityCybercrimeLaw EnforcementMicrosoft
P0
2026-09-22 15:00 UTC
Vendor Research

Unmasking EvilTokens: Getting to the root of device code phishing

Microsoft Security Blog · Microsoft Threat Intelligence, Microsoft Defender Experts and Microsoft Security Research · indexed 2026-09-22 16:30 UTC

EvilTokens has quickly become one of the top PhaaS platforms, enabling device code phishing attacks through AI-assisted lures, automated infrastructure, and token theft. In collaboration with partners, Microsoft Digital Crimes Unit (DCU) facilitated a disruption of EvilTokens infrastructure and operations. The post Unmasking EvilTokens: Getting to the root of device code phishing appeared first on Microsoft Security Blog.

MicrosoftPhishing
P0
2026-09-22 14:29 UTC
Security Journalism

Cyera Raises $400 Million at $12+ Billion Valuation

Security Week · SecurityWeek News · indexed 2026-09-22 14:30 UTC

The data security company received the new investment from Goldman Sachs Alternatives, extending its Series G funding round. The post Cyera Raises $400 Million at $12+ Billion Valuation appeared first on SecurityWeek.

P0
2026-09-22 14:04 UTC
Other

Chaotic Eclipse Released BigDiskBuster, A PoC For Windows Defender Update DoS Zero-Day

Security Affairs · Pierluigi Paganini · indexed 2026-09-22 14:10 UTC

The researcher Chaotic Eclipse released BigDiskBuster, a PoC exploit for a Windows Defender Update DoS Zero-Day vulnerability. Security researcher Chaotic Eclipse, also known as INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse, released a new zero-day exploit targeting Microsoft Defender. The researcher named the exploit BigDiskBuster, it triggers a Denial of Service Vulnerability in Windows Defender Update. The security researcher […]

MicrosoftSecurity ResearchVulnerabilities
P25
2026-09-22 14:00 UTC
Security Journalism

AI Attacks Move Faster. Huntress’ Agentic SOC Keeps Up

Huntress · indexed 2026-09-22 21:10 UTC

AI hasn't changed attacker tradecraft, just the speed. See how Huntress built Athena, an agentic SOC partner, to help analysts keep pace.

P0
2026-09-22 13:10 UTC
Community

LausivLoader analysis, or how to pass data between malware stages, (Thu, Sep 17th)

SANS Internet Storm Center · indexed 2026-09-17 15:05 UTC

At the end of August, a malspam message was caught in the quarantine of a mail gateway operated by one of my customers. The message was not especially remarkable – it asked the recipient to review some attached requirements and provide a price quotation for a fiber optic system and appeared to impersonate an employee of a legitimate company.

Malware
P0
2026-09-22 12:57 UTC
Security Journalism

Webinar tomorrow: Inside real-world Google Workspace breaches

BleepingComputer · BleepingComputer · indexed 2026-09-22 13:10 UTC

Tomorrow's webinar examines real Google Workspace breaches involving social engineering and malicious OAuth applications, from initial access through the critical first hours of incident response. Learn which security controls and response decisions can make the greatest difference. [...]

DFIR
P0
2026-09-22 12:30 UTC
Security Journalism

AI Agents Are Rewriting the Rules of Lateral Movement

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-22 13:40 UTC

Security teams have spent decades asking whether an identity has too much access. AI agents raise a harder question: how can we determine which paths an autonomous system can discover, given the access it already has? A person may try several ways to complete a task. A deterministic application follows the flow its developer wrote. But an AI agent is relentless in its pursuit of done. In May

AI Security
P0
2026-09-22 12:29 UTC
Security Journalism

New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-22 13:40 UTC

Attackers are exploiting a new flaw in on-premises VeloCloud Orchestrator (VCO), the server that manages the Edge devices in a VeloCloud SD-WAN, Arista said on September 22. The flaw, tracked as CVE-2026-93952, may allow a remote attacker with no login access to privilege internal functions and affect the VCO host. Only orchestrators set up to authenticate their Edges with certificates are

VulnerabilitiesCVE-2026-93952
P30
2026-09-22 12:24 UTC
Security Journalism

Only 13% of OT Network Segments Are Fully Isolated: Analysis

Security Week · Eduard Kovacs · indexed 2026-09-22 12:30 UTC

Forescout’s new network segmentation research shows that OT and medical devices often share network segments with other enterprise assets. The post Only 13% of OT Network Segments Are Fully Isolated: Analysis appeared first on SecurityWeek.

P0
2026-09-22 11:45 UTC
Security Journalism

DORA Year Two: Can Your SOC Actually See the Attack?

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-22 12:10 UTC

When the Digital Operational Resilience Act (DORA) became enforceable across the European Union in January 2025, it triggered an administrative sprint. Financial entities spent the first year establishing risk governance, assessing third-party service providers, updating contract clauses, and documenting incident escalation workflows. Now in its second year, the harder part of DORA is

P0
2026-09-22 11:38 UTC
Security Journalism

New Linux Kernel Flaw Gives ARM64 KVM Guests Read-Write Access to Host Memory

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-22 12:10 UTC

A new flaw in the Linux kernel's KVM virtualization code for ARM64 processors can leave a freed piece of host memory exposed to a guest virtual machine on hosts with nested virtualization enabled. The bug, tracked as CVE-2026-89775, allows a guest to read and write host kernel memory, and the researcher who found it says it can be used to escape the guest and run code on the host machine.

LinuxVulnerabilitiesCVE-2026-89775
P5
2026-09-22 11:33 UTC
Security Journalism

Malicious B-tree NPM Package Accumulates Millions of Downloads

Security Week · Ionut Arghire · indexed 2026-09-22 11:50 UTC

Posing as the legitimate sorted-btree package, indexed-btree hides a malware trigger in its prototype method. The post Malicious B-tree NPM Package Accumulates Millions of Downloads appeared first on SecurityWeek.

Malware
P0
2026-09-22 11:17 UTC
Security Journalism

SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-22 12:10 UTC

A SharePoint Server vulnerability that Microsoft initially classified as a spoofing flaw with a CVSS score of 6.5 actually enables authenticated remote code execution, according to full technical details published today by Viettel Cyber Security researcher Dinh Ho Anh Khoa. The flaw, CVE-2026-65660, affects SharePoint Server 2016, 2019, and Subscription Edition. Patches have been

MicrosoftSecurity ResearchVulnerabilitiesCVE-2026-65660
P20
2026-09-22 11:16 UTC
Vendor Research

CSuite Targets US and EU Organizations with Device-Code Phishing and Remote Access

ANY.RUN Blog · ShiFu · indexed 2026-10-06 14:56 UTC

ANY.RUN researchers investigated CSuite, a phishing and remote-access operation that combines credential theft, Microsoft 365 session hijacking, and the abuse of legitimate management tools. The campaign showed a strong US focus, with 51% of sessions from the United States. By blending trusted business services with legitimate remote-access software, CSuite can give attackers both account and […] The post CSuite Targets US and EU Organizations with Device-Code Phishing and Remote Access appeare…

MicrosoftPhishing
P0
2026-09-22 10:22 UTC
Security Journalism

Shai-Hulud Attack Nips Cyber-Firm CrowdSec's GitHub Data

Dark Reading · Elizabeth Montalbano · indexed 2026-09-22 17:55 UTC

Threat actors stole the contents of 170 private repositories using an OAuth token stolen from a former employee's computer through the TanStack npm supply chain attack.

Threat Actors
P0
2026-09-22 10:22 UTC
Security Journalism

WordPress Patches ‘Click2Shell’ Vulnerability

Security Week · Ionut Arghire · indexed 2026-09-22 10:35 UTC

The bug lets attackers automatically install and preview themes and could lead to remote code execution. The post WordPress Patches ‘Click2Shell’ Vulnerability appeared first on SecurityWeek.

Vulnerabilities
P15
2026-09-22 10:13 UTC
Other

Public PoC Exposes Critical Veeam Agent Privilege Escalation

Security Affairs · Pierluigi Paganini · indexed 2026-09-22 10:50 UTC

A Veeam Agent flaw lets local users gain SYSTEM privileges. A public PoC is available, raising the risk of exploitation on shared Windows systems. If you’re running Veeam Agent on a Windows endpoint with more than one local user, now’s the time to check the version, not tomorrow. On September 14, 2026, public technical details […]

MicrosoftVulnerabilities
P10
2026-09-22 10:00 UTC
Vendor Research

The Closed Quorum: Inside the first reported autonomous AI C2 implant

Cisco Talos Intelligence Blog · Ryan Fetterman · indexed 2026-09-22 10:05 UTC

CLOSEDQUORUM, a malware binary discovered through Cisco Talos’ CAIRN project, exhibits fully autonomous command and control (C2). It represents a shift in effort displacement for attackers, in which expanding portions of the attack chain can be executed without operator involvement.

Malware
P0
31 32 33 34 35