IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 4,761 matching records.
AUTO-POLL // 2026-10-09 21:20 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P5 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 9

RANSOMWARE
P5
P5
COOL // 60 ARTICLES
THU
Oct 8

RANSOMWARE
P3
P3
COOL // 62 ARTICLES
WED
Oct 7

RANSOMWARE
P5
P5
COOL // 86 ARTICLES
TUE
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
RESET
2026-10-08 16:52 UTC
Community

Reconstructing AI Agent Activity: Two New Scripts for Forensic Review, (Thu, Oct 8th)

SANS Internet Storm Center · indexed 2026-10-08 17:10 UTC

We just did a major update to FOR577 and added a lot of new material on day 5 about investigating AI usage in incident response. In the new material we dicsuss 8 of the most popular AI coding assistants and agents including Claude Code, Codex, Gemini CLI, Cursor, Copilot, Warp, Windsurf, and Qwen Code. I've been using Claude Code and a little bit of Codex, but I also have recently been playing with OpenCode and am setting up Hermes. I decided t…

AI SecurityDFIR
P0
2026-10-08 15:45 UTC
Security Journalism

Japan Sees Sharp Rise in Web Data Leaks Amid Mobile API Abuse and Metabase Attacks

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-08 17:20 UTC

Attackers behind a string of personal data leaks at Japanese organizations have abused APIs for mobile apps and targeted known software flaws, the JPCERT Coordination Center (JPCERT/CC) said. The Tokyo-based center, which takes incident reports, based its October 8, 2026 alert on those reports and other information. The alert names no attacker and no affected organization. JPCERT/

Cloud SecurityData Breaches
P0
2026-10-08 15:28 UTC
Security Journalism

Cisco Patches a Dozen Critical Vulnerabilities

Security Week · Ionut Arghire · indexed 2026-10-08 15:30 UTC

The security defects could lead to unauthorized access, information leaks, privilege escalation, DoS attacks, and remote code execution. The post Cisco Patches a Dozen Critical Vulnerabilities appeared first on SecurityWeek.

Vulnerabilities
P25
2026-10-08 15:26 UTC
Security Journalism

UAC-0099 Targets Ukrainian Government Personnel With ASHVEIN RAT Hiding Commands in HTML

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-08 15:40 UTC

The Russia-aligned threat actor known as UAC-0099 has been attributed to a previously undocumented .NET infostealer and remote access trojan (RAT) codenamed ASHVEIN. According to TrendAI, the malware has been put to use in attacks targeting Ukrainian government personnel. The cybersecurity company is tracking the cluster under the name Earth Sirrush (previously SHADOW-EARTH-065). ASHVEIN,

MalwareThreat Actors
P0
2026-10-08 14:30 UTC
Security Journalism

Security Awareness Training Isn’t Dead, but It Needs a Rethink

Security Week · Kevin Townsend · indexed 2026-10-08 14:30 UTC

All enterprises conduct security awareness training for their employees. But whether this has tangible benefits is debatable. The post Security Awareness Training Isn’t Dead, but It Needs a Rethink appeared first on SecurityWeek.

P0
2026-10-08 14:12 UTC
Security Journalism

ARTEX AI Pentesting Tool Used in Data Theft Attacks on South Korean Financial Firms

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-08 15:40 UTC

Cybersecurity researchers have disclosed details of a targeted campaign aimed at South Korean financial organizations that used an artificial intelligence (AI) pen testing tool named ARTEX to carry out the attacks. The activity, per CrowdStrike Intelligence, was active from late September to early October 2026, and resulted in data exfiltration from various South Korea-based financial firms,

AI SecuritySecurity Research
P0
2026-10-08 14:11 UTC
Vendor Research

Cisco NX-OS Software NX-API Remote Code Execution Vulnerability

Cisco Security Advisories · indexed 2026-10-07 16:15 UTC

A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges or cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient input validation of data that is sent to the NX-API. An attacker could exploit this vulnerability by sending a crafted HTTP request to the NX-API of an affected device. A successful exploit could allow the attacker to execute arbitra…

VulnerabilitiesCVE-2026-76471
P20
2026-10-08 14:00 UTC
Security Journalism

OAuth grants pile up faster than you can review them. Here's how to keep up.

BleepingComputer · Sponsored by Nudge Security · indexed 2026-10-08 14:05 UTC

OAuth grants create data highways between SaaS apps, AI agents, and other tools. And, they are multiplying faster than any security team can review them. As the recent Klue breach showed, attackers are taking notice and exploiting forgotten OAuth grants to gain access to corporate data. This article covers why OAuth risks are so hard [...]

AI Security
P0
2026-10-08 13:37 UTC
Other

MonsterCloud Owner Charged With Secretly Paying Ransomware Demands

Security Affairs · Pierluigi Paganini · indexed 2026-10-08 14:50 UTC

MonsterCloud owner Zohar Pinhasi allegedly paid ransomware demands behind clients’ backs, then charged them millions for the supposed recovery. Zohar Pinhasi, the owner of Florida-based MonsterCloud, was charged this week with wire fraud. Federal prosecutors say his clients were scammed twice during the same ransomware crisis. Pinhasi (50) also used the names “Zack Silver” and […]

CybercrimeRansomware
P15
2026-10-08 12:50 UTC
Vendor Research

Inside the Exchange Inspector: How Tenable uses OpenAI GPT cyber models to review open-source AI agents

Tenable Blog · Robert McSulla · indexed 2026-10-08 13:10 UTC

Community-built AI agents, skills, and MCP servers are landing in SOC workflows fast. Here’s what the Exchange Inspector tests before a listing earns its vetted tag on the CyberAgents Exchange. Three tools have already passed.Key takeawaysEvery Inspector-vetted listing clears three gates: an automated check, a frontier model assessment, and human verification. Tenable uses Tenable One AI Exposure to screen for prompt injection and exposed secrets, and OpenAI GPT Cyber models to assess the code …

AI SecurityCloud SecurityDFIRICS / OTMalwareMicrosoftNetwork SecurityPhishingSecurity ResearchThreat IntelligenceVulnerabilities
P0
2026-10-08 12:46 UTC
Security Journalism

US Seeks Alleged Chinese Hafnium Hacker With $10 Million Reward

Security Week · Eduard Kovacs · indexed 2026-10-08 12:50 UTC

Zhang Yu was charged alongside Xu Zewei, who was extradited from Italy to the US in April 2026. The post US Seeks Alleged Chinese Hafnium Hacker With $10 Million Reward appeared first on SecurityWeek.

P0
2026-10-08 12:37 UTC
Security Journalism

SonicWall and Splunk Patch Critical Vulnerabilities

Security Week · Ionut Arghire · indexed 2026-10-08 12:50 UTC

Critical and high-severity vulnerabilities could allow attackers to bypass authentication, execute arbitrary code, and elevate their privileges. The post SonicWall and Splunk Patch Critical Vulnerabilities appeared first on SecurityWeek.

P0
2026-10-08 12:00 UTC
Security Journalism

Major Yandex data center in Russia hit by Ukrainian drone strike

The Record · indexed 2026-10-08 12:20 UTC

A drone strike on a large Yandex data center caused a significant disruption to the Russian tech giant's network, with connectivity reportedly falling to around 70 percent of normal levels.

P0
2026-10-08 12:00 UTC
Security Journalism

Writing the Next Chapter

Dark Reading · Kelly Jackson Higgins · indexed 2026-10-08 12:05 UTC

Dark Reading is about to begin a new decade in its storied history, and we have some breaking news of our own to share.

P0
2026-10-08 11:11 UTC
Security Journalism

Rein Security Raises $25 Million to Guard AI Agents at Runtime

Security Week · Ionut Arghire · indexed 2026-10-08 11:30 UTC

The cybersecurity startup will invest in product innovation, agentic research, and employee base expansion. The post Rein Security Raises $25 Million to Guard AI Agents at Runtime appeared first on SecurityWeek.

AI Security
P0
2026-10-08 10:30 UTC
Security Journalism

Wazza Phishkit Targets Banking, Government, and Manufacturing Across the US, EU, and Australia

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-08 11:05 UTC

Phishing kits are no longer limited to copying a familiar login page and waiting for a victim to enter credentials. Attackers are increasingly building filtering, session management, and traffic controls into the infrastructure that delivers the phishing page itself. ANY.RUN has identified Wazza, a new phishkit targeting banking, manufacturing, and government organizations across the US, Europe

Phishing
P0
2026-10-08 10:29 UTC
Security Journalism

Owner of Empire cybercrime market gets 40 years in prison

BleepingComputer · Sergiu Gatlan · indexed 2026-10-08 10:35 UTC

The co-creator of Empire Market, one of the largest dark web marketplaces before its shutdown, has been sentenced to 40 years in prison for facilitating $430 million in illegal transactions from 2018 to 2020. [...]

Cybercrime
P0
2 3 4 5 6