IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 4,771 matching records.
AUTO-POLL // 2026-10-10 09:25 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P5 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 10

RANSOMWARE
P5
P5
COOL // 3 ARTICLES
FRI
Oct 9

RANSOMWARE
P4
P4
COOL // 67 ARTICLES
THU
Oct 8

RANSOMWARE
P3
P3
COOL // 62 ARTICLES
WED
Oct 7

RANSOMWARE
P5
P5
COOL // 86 ARTICLES
TUE
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
RESET
2026-09-18 20:24 UTC
Security Journalism

Vectra AI Launches Ascent to Help Address New Era of AI-Driven Attacks

Dark Reading · indexed 2026-09-18 20:40 UTC

The new program expands Vectra AI's partner strategy as increasingly complex security environments and the growing use of AI create demand for broader AI expertise, services, and security outcomes.

P0
2026-09-18 18:15 UTC
Security Journalism

MFA Won't Save You From OAuth Consent Abuse

Dark Reading · Vishnu Galata · indexed 2026-09-18 18:55 UTC

MFA is essential, but it cannot replace OAuth governance, least-privilege scopes, consent monitoring, and rapid revocation.

P0
2026-09-18 18:02 UTC
Security Journalism

Public Exploits Released for Four Linux Kernel Flaws That Enable Local Root

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-18 20:25 UTC

A security researcher has released working exploit code for four Linux kernel flaws that each let a local user gain root, the highest level of access on a machine. Kernel maintainers have fixed all four over the past few weeks, so a system running an up-to-date kernel is not affected. But the exploit code is now public, and any machine still running an older kernel should be updated. The flaws

Cloud SecurityLinuxSecurity Research
P0
2026-09-18 17:10 UTC
Other

Gyazo Data Breach Exposes 23 Million User Records

Security Affairs · Pierluigi Paganini · indexed 2026-09-18 17:20 UTC

A Gyazo breach exposed 23 million user records after attackers exploited a vulnerability in Helpfeel’s image upload server. Japanese software company Helpfeel is notifying Gyazo users about a data breach that compromised 23 million user records. Attackers gained unauthorized access by exploiting a vulnerability in the service’s image upload server. “We have confirmed that approximately […]

Data BreachesVulnerabilities
P0
2026-09-18 16:56 UTC
Security Journalism

New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-18 17:55 UTC

WordPress today released patches to fix a new set of vulnerabilities in its core software, one of which could allow a crafted web link, opened by a logged-in administrator, to install a theme from the official WordPress.org directory without anyone clicking Install. The security firm pwn.ai, whose researchers reported the flaw, calls the attack chain Click2Shell. On its own the flaw only

P0
2026-09-18 15:50 UTC
Vendor Research

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Logging Denial of Service Vulnerability

Cisco Security Advisories · indexed 2026-09-16 16:40 UTC

A vulnerability in the system rate-limiting process for syslog message 419002 of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause high CPU utilization on an affected device, resulting in a denial of service (DoS) condition. This vulnerability is due to improper rate limiting for syslog message 419002. An attacker could exploit this vulnerability by sending a flood of …

Network SecurityVulnerabilitiesCVE-2026-20154
P5
2026-09-18 15:50 UTC
Vendor Research

Cisco Secure Firewall Adaptive Security Appliance, Secure Firewall Threat Defense, and Secure Firewall Management Center Software Hardening Release: September 2026

Cisco Security Advisories · indexed 2026-09-16 16:05 UTC

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software and Cisco Secure Firewall Management Center (FMC) Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. These vulnerabilities were found during internal te…

Network SecurityVulnerabilitiesCVE-2026-20329CVE-2026-20330CVE-2026-20331CVE-2026-20332CVE-2026-20333CVE-2026-20334CVE-2026-20335CVE-2026-20336
P40
2026-09-18 15:50 UTC
Vendor Research

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software for Secure Firewall 3100 and 4200 Series DTLS Denial of Service Vulnerability

Cisco Security Advisories · indexed 2026-09-16 16:40 UTC

A vulnerability in Datagram TLS (DTLS) message handling of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software for Cisco Secure Firewall 3100 Series and 4200 Series devices could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper resource management when processing certain DTLS messages. An attacker could exploit this vulnerability…

Network SecurityVulnerabilitiesCVE-2026-20250
P5
2026-09-18 15:50 UTC
Vendor Research

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Object Group Access Control List Bypass Vulnerabilities

Cisco Security Advisories · indexed 2026-09-16 16:40 UTC

Multiple vulnerabilities in the access control list (ACL) Object Group Search (OGS) implementation of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured access controls. These vulnerabilities are due to a logic error in populating group access control policies (ACPs) with OGS configured. An attacker could exploit these vulnerabilities by sending traffic that…

Network SecurityVulnerabilitiesCVE-2026-20120CVE-2026-20121
P5
2026-09-18 15:50 UTC
Vendor Research

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software IKEv2 Certificate Authentication Denial of Service Vulnerability

Cisco Security Advisories · indexed 2026-09-16 16:40 UTC

A vulnerability in the certification authentication feature of Internet Key Exchange version 2 (IKEv2) for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly. This vulnerability is due to a logic error during the certificate authentication phase of the IKEv2 connection setup. An attacker could exploit this vulnerability by attem…

MicrosoftNetwork SecurityVulnerabilitiesCVE-2026-20249
P5
2026-09-18 15:50 UTC
Vendor Research

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software TCP DNS Denial of Service Vulnerability

Cisco Security Advisories · indexed 2026-09-16 16:40 UTC

A vulnerability in the DNS over TCP implementation of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the TCP DNS response handler to unexpectedly restart, causing the device to reload. This vulnerability is due to a logic error when parsing a DNS query and tracking the size of the incoming buffers. An attacker could exploit this vulnerability by formatting a crafted…

Network SecurityVulnerabilitiesCVE-2026-20248
P5
2026-09-18 15:50 UTC
Vendor Research

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software EIGRP Denial of Service Vulnerability

Cisco Security Advisories · indexed 2026-09-16 16:40 UTC

A vulnerability in the EIGRP implementation in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, adjacent attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to improper resource management when handling EIGRP update messages. An attacker could exploit this vulnerability by sending crafted EIGRP updates at a high rate…

Network SecurityVulnerabilitiesCVE-2026-20222
P5
2026-09-18 15:24 UTC
Security Journalism

Transparent Tribe Deploys New Rust Backdoor Using Private GitHub Repositories for C2

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-18 15:55 UTC

The Pakistan-aligned threat group tracked as Transparent Tribe (aka APT36 and Earth Karkaddan) has been attributed to a fresh set of cyber attacks targeting government and defense entities in India and Afghanistan. The attacks, per Zscaler ThreatLabz, involve the use of previously undocumented tools called RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH. The activity has been codenamed Operation

APT / Nation-StateMalware
P0
2026-09-18 14:29 UTC
Security Journalism

Nations take action on North Korean IT workers after UN report

The Record · indexed 2026-09-18 14:40 UTC

A report published Wednesday said that as of July, Vietnam, Laos, Pakistan and Argentina took meaningful steps to respond to allegations involving North Korea listed in an October study.

P0
2026-09-18 14:25 UTC
Security Journalism

In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw

Security Week · SecurityWeek News · indexed 2026-09-18 14:30 UTC

Noteworthy stories that might have slipped under the radar: Mandiant's 2026 AI risk report, PhantomRaven malware used by bug bounty hunter, WordPress plugin bug exploited. The post In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw appeared first on SecurityWeek.

MalwareRansomware
P15
2026-09-18 14:00 UTC
Security Journalism

Secure enterprise sharing with access reviews for Microsoft 365

BleepingComputer · Sponsored by tenfold Software · indexed 2026-09-18 14:15 UTC

Microsoft 365 makes sharing files easy, but access can remain long after its original purpose has ended, leaving organizations with little visibility into who can still reach sensitive data. tenfold Software explains how centralized access governance and owner-driven reviews can help identify and remove unnecessary access. [...]

Microsoft
P0
2026-09-18 13:58 UTC
Security Journalism

Microsoft Teams will let admins block custom file extensions

BleepingComputer · Sergiu Gatlan · indexed 2026-09-18 14:15 UTC

Microsoft Teams will soon let administrators tweak the list of file extensions commonly associated with security threats to meet their company's security requirements. [...]

Microsoft
P0
2026-09-18 13:10 UTC
Security Journalism

Webinar: Which Google Workspace security controls actually matter?

BleepingComputer · BleepingComputer · indexed 2026-09-18 13:45 UTC

Fast-growing companies face countless recommendations for securing Google Workspace, but not every control provides the same value. This webinar examines real-world breaches to explore which security controls matter most, which may be overrated, and where lean security teams should focus their resources. [...]

P0
2026-09-18 12:47 UTC
Security Journalism

Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-18 13:55 UTC

Microsoft has released fixes for a maximum-severity security flaw in Azure AI Foundry that could be exploited to achieve privilege escalation. No customer action is required. The vulnerability, tracked as CVE-2026-85889, carries a CVSS score of 10.0. "Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network,"

Cloud SecurityMicrosoftVulnerabilitiesCVE-2026-85889
P15
2026-09-18 12:45 UTC
Security Journalism

AI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code

Security Week · Eduard Kovacs · indexed 2026-09-18 12:50 UTC

Hacktron researchers earned a bug bounty after demonstrating access to OpenAI employee accounts. The post AI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code appeared first on SecurityWeek.

P0
2026-09-18 11:01 UTC
Security Journalism

An Abandoned CDN Domain Was Re-Registered. Thousands of Sites Still Call It.

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-18 13:55 UTC

In July 2025, someone registered a domain that used to belong to a content delivery network. The CDN had been wound down years earlier, and the domain it served assets from was allowed to expire. What it had not lost were its callers. Thousands of websites, code repositories, and documentation pages still carry hard-coded references to hostnames beneath it. The new owner holds

P0
2026-09-18 11:01 UTC
Security Journalism

Plugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding Agents

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-18 13:55 UTC

A flaw in four widely used AI coding agents lets someone who controls a plugin's code repository swap the plugin an agent installs for a malicious one, even when the agent locked that plugin to a specific reviewed version, security firm Air Security said on Thursday. The firm said Anthropic has patched the flaw in Claude Code 2.1.179 and OpenAI in Codex 0.146.0, that GitHub Copilot has no

P0
35 36 37 38 39