IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 4,774 matching records.
AUTO-POLL // 2026-10-10 12:10 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P3 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 10

RANSOMWARE
P3
P3
COOL // 6 ARTICLES
FRI
Oct 9

RANSOMWARE
P4
P4
COOL // 67 ARTICLES
THU
Oct 8

RANSOMWARE
P3
P3
COOL // 62 ARTICLES
WED
Oct 7

RANSOMWARE
P5
P5
COOL // 86 ARTICLES
TUE
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
RESET
2026-09-16 05:00 UTC
Other

ZDI-26-711: NoMachine Redis Improper Authentication Local Privilege Escalation Vulnerability

Zero Day Initiative · indexed 2026-09-17 00:20 UTC

This vulnerability allows local attackers to escalate privileges on affected installations of NoMachine. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-92209.

VulnerabilitiesCVE-2026-92209
P15
2026-09-16 05:00 UTC
Other

ZDI-26-709: Cisco Secure Firewall Management Center CommandSinkRmi Deserialization of Untrusted Data Remote Code Execution Vulnerability

Zero Day Initiative · indexed 2026-09-17 00:20 UTC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Cisco Secure Firewall Management Center. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.1. The following CVEs are assigned: CVE-2026-20242.

Network SecurityVulnerabilitiesCVE-2026-20242
P20
2026-09-16 05:00 UTC
Other

ZDI-26-706: (0Day) CrewAI crewAI Framework Agent Loading Unsafe Reflection Remote Code Execution Vulnerability

Zero Day Initiative · indexed 2026-09-16 15:20 UTC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of CrewAI crewAI. User interaction is required to exploit this vulnerability in that the target must load a malicious agent configuration from the repository. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-92206.

VulnerabilitiesCVE-2026-92206
P20
2026-09-16 05:00 UTC
Other

ZDI-26-705: (0Day) BusyBox libarchive Symlink Directory Traversal Arbitrary File Creation Vulnerability

Zero Day Initiative · indexed 2026-09-16 15:20 UTC

This vulnerability allows remote attackers to create arbitrary files on affected installations of BusyBox. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 6.1. The following CVEs are assigned: CVE-2026-92205.

VulnerabilitiesCVE-2026-92205
P5
2026-09-16 05:00 UTC
Other

ZDI-26-704: (0Day) Airbyte OneDrive Connector _get_shared_drive_object Server-Side Request Forgery Information Disclosure Vulnerability

Zero Day Initiative · indexed 2026-09-16 15:20 UTC

This vulnerability allows remote attackers to initiate arbitrary server-side requests on affected installations of Airbyte. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.7. The following CVEs are assigned: CVE-2026-92204.

VulnerabilitiesCVE-2026-92204
P5
2026-09-16 05:00 UTC
Other

ZDI-26-703: (0Day) Airbyte SharePoint Connector _get_shared_drive_object Server-Side Request Forgery Information Disclosure Vulnerability

Zero Day Initiative · indexed 2026-09-16 15:20 UTC

This vulnerability allows remote attackers to initiate arbitrary server-side requests on affected installations of Airbyte. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.7. The following CVEs are assigned: CVE-2026-92203.

MicrosoftVulnerabilitiesCVE-2026-92203
P5
2026-09-15 22:21 UTC
Vendor Research

AWS STS simplifies session token size limits and adds session token size monitoring

AWS Security Blog · Rishi Tripathy · indexed 2026-09-15 22:45 UTC

AWS Security Token Service (AWS STS) has simplified session token size limits, giving you more room for your session policies and session tags. STS has replaced the packed policy size and the overall session token size limits with a single token size limit of 4,096 bytes. STS now reports session token size in API responses, […]

Cloud Security
P0
2026-09-15 20:46 UTC
Other

U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog

Security Affairs · Pierluigi Paganini · indexed 2026-09-15 21:35 UTC

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Cisco Secure Email Gateway flaw, tracked as CVE-2026-76461 (CVSS score of 9,8), to its Known Exploited Vulnerabilities (KEV) catalog. Cisco disclosed a critical zero-day CVE-2026-76461 this week; […]

VulnerabilitiesCVE-2026-76461
P60
2026-09-15 20:36 UTC
Vendor Research

Cisco Integrated Management Controller Argument Injection Vulnerabilities

Cisco Security Advisories · indexed 2026-08-15 14:33 UTC

Multiple vulnerabilities in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected system and elevate privileges to root. For more information about these vulnerabilities, see the Details section of this advisory. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities…

VulnerabilitiesCVE-2026-20200CVE-2026-20288
P5
2026-09-15 20:34 UTC
Vendor Research

Cisco UCS and UCS-Based Appliances UEFI Shell Secure Boot Bypass Vulnerability

Cisco Security Advisories · indexed 2026-09-08 16:35 UTC

A vulnerability in the Unified Extensible Firmware Interface (UEFI) Shell implementation of Cisco UCS Servers and UCS-based appliances could allow an authenticated attacker with valid credentials for a user account with the role of user or admin or an unauthenticated attacker with physical access to an affected device to bypass UEFI Secure Boot validation checks and execute unauthorized software. This vulnerability is due to the availability of memory write commands in the UEFI Shell while UEFI…

VulnerabilitiesCVE-2026-20293
P5
2026-09-15 19:30 UTC
Security Journalism

“We Think the Security Control Is Working” Is No Longer Good Enough

Security Week · Sravish Sridhar · indexed 2026-09-15 19:40 UTC

Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today. The post “We Think the Security Control Is Working” Is No Longer Good Enough appeared first on SecurityWeek.

P0
2026-09-15 19:00 UTC
Vendor Research

Architecting resilient authentication with Amazon Cognito multi-Region replication

AWS Security Blog · Abrom Douglas · indexed 2026-09-15 19:30 UTC

Your consumer identity and access management (CIAM) system is the foundation of your customer experience. It’s how users sign in, access services, and engage with your applications. As your business scales across geographies, ensuring authentication is always available becomes a core architectural requirement. However, building multi-Region authentication has traditionally required complex custom replication solutions that […]

P0
2026-09-15 18:54 UTC
Security Journalism

KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-15 19:10 UTC

Cybersecurity researchers have shed light on a previously undocumented Brazilian banking malware operation that delivers a toolkit called KREMLIN. Elastic Security Labs is tracking the activity under the moniker REF9334. Active since at least May 2025, the threat actor has used lures that impersonate a dozen Brazilian banks and install a malicious browser extension on Google Chrome and

MalwareSecurity ResearchThreat Actors
P0
2026-09-15 17:00 UTC
Vendor Research

Oracle September 2026 Critical Security Patch Update addresses 672 CVEs

Tenable Blog · Research Special Operations · indexed 2026-09-15 21:15 UTC

Oracle addresses 672 CVEs in its September 2026 Critical Security Patch Update with 673 patches, including 104 critical updates.Key TakeawaysThe September 2026 Critical Security Patch Update (CSPU) contains fixes for 672 unique CVEs in 673 security updates104 issues (15.5% of all patches) were assigned a critical severity ratingOracle E-Business Suite received the highest number of patches at 159, accounting for 23.6% of all patchesBackgroundOn September 15, Oracle released its Critical Securit…

P5
2026-09-15 16:40 UTC
Security Journalism

CenterPoint Energy confirms customer data stolen in cyberattack

BleepingComputer · Bill Toulas · indexed 2026-09-15 16:45 UTC

CenterPoint Energy disclosed a breach compromising some customers' personal information after an attacker leaked data allegedly stolen from the utility company. [...]

P0
2026-09-15 16:29 UTC
Security Journalism

Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journalists

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-15 17:45 UTC

Cybersecurity agencies in the United States, the United Kingdom, and the Netherlands have detailed a Windows malware that they say Iran's intelligence service uses to spy on dissidents, journalists, and activists around the world. The malware is controlled via the Telegram messaging app and can copy a target's emails and chat messages, take screenshots, and activate the microphone to record

MalwareMicrosoft
P0
2026-09-15 16:28 UTC
Security Journalism

Iranian cyber spies used fake MRI scan results to hack ‘enemy of regime’

The Record · indexed 2026-09-15 16:35 UTC

According to the United Kingdom’s National Cyber Security Centre (NCSC), Iran has used this and similar cyber activity to “support the repression of individuals who are seen as a threat to the regime, such as dissidents, activists and journalists.”

P0
42 43 44 45 46