IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 4,774 matching records.
AUTO-POLL // 2026-10-10 12:30 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P3 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 10

RANSOMWARE
P3
P3
COOL // 6 ARTICLES
FRI
Oct 9

RANSOMWARE
P4
P4
COOL // 67 ARTICLES
THU
Oct 8

RANSOMWARE
P3
P3
COOL // 62 ARTICLES
WED
Oct 7

RANSOMWARE
P5
P5
COOL // 86 ARTICLES
TUE
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
RESET
2026-09-15 15:53 UTC
Vendor Research

Operationalizing least privilege: Automate IAM remediation through your CI/CD pipeline

AWS Security Blog · Luis Pastor · indexed 2026-09-15 16:05 UTC

The principle of least privilege is straightforward to articulate but challenging to maintain at scale. When teams first deploy applications to AWS, they often grant broader permissions than strictly necessary; it’s faster to get things working, and the plan is always to tighten permissions later. But later rarely comes. Permissions accumulate, AWS Identity and Access […]

Cloud Security
P0
2026-09-15 15:45 UTC
Security Journalism

Exein Secures $270M at $1.7B Valuation for Physical AI Security

Security Week · Ionut Arghire · indexed 2026-09-15 16:00 UTC

The cybersecurity startup is building a proprietary foundation model and plans to accelerate global expansion. The post Exein Secures $270M at $1.7B Valuation for Physical AI Security appeared first on SecurityWeek.

AI Security
P0
2026-09-15 15:30 UTC
Security Journalism

Texas Utility CenterPoint Energy Confirms Breach After Hacker Leaks Data

Security Week · Eduard Kovacs · indexed 2026-09-15 15:40 UTC

A hacker claims to have stolen 7.5 million customer records after breaching the company’s systems. The post Texas Utility CenterPoint Energy Confirms Breach After Hacker Leaks Data appeared first on SecurityWeek.

P0
2026-09-15 15:23 UTC
Community

MacOS 27 - First Boot, (Tue, Sep 15th)

SANS Internet Storm Center · indexed 2026-09-15 15:40 UTC

I have not done this type of diary in a while: What traffic will you see from a system on boot, before a user logs in? I just took a quick look at macOS 27 "Golden Gate" to see what traffic you should expect. Here are some of the highlights:

Apple
P0
2026-09-15 15:23 UTC
Security Journalism

BambooToken Malware Uses MQTT to Control Windows and Linux Systems

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-15 15:50 UTC

Cybersecurity researchers have disclosed details of a multi-platform campaign that uses the Message Queueing Telemetry Transport (MQTT) protocol as a communication channel to control Windows and Linux systems. The emerging malware family, codenamed BambooToken, is assessed to be active since at least February 2023 and put to use in attacks targeting organizations across Asia and South America.

LinuxMalwareMicrosoftSecurity Research
P0
2026-09-15 13:45 UTC
Security Journalism

What Zero-Day Response Should Be in the Post-Mythos Era

BleepingComputer · Sponsored by Picus Security · indexed 2026-09-15 14:05 UTC

AI is shrinking the time between vulnerability disclosure and exploitation, leaving defenders less time to wait for patches or public exploits. Picus Security explains how exploitability validation, security control testing, and autonomous pentesting can help teams close exposure gaps before attackers arrive. [...]

MicrosoftVulnerabilities
P25
2026-09-15 13:32 UTC
Vendor Research

Australia is replacing the Essential Eight with a new cyber framework. Here’s how exposure management can help you get ahead of it.

Tenable Blog · Ben Mudie · indexed 2026-09-15 13:40 UTC

Australia’s move from the Essential Eight to an outcomes-based cybersecurity model will push organizations from conducting periodic point-in-time, checklist compliance assessments to having continuous evidence of a solid security posture.Key takeawaysThe Australian Signals Directorate (ASD) is moving from the Essential Eight cybersecurity framework to a new outcomes-focused Essentials series covering enterprise IT, cloud, operational technology (OT), and potentially agentic AI.The Essential Eig…

Cloud SecurityICS / OTMicrosoftNetwork SecurityVulnerabilities
P0
2026-09-15 13:00 UTC
Other

Cisco Warns of Ongoing Exploitation of Critical Email Gateway Zero-Day

Security Affairs · Pierluigi Paganini · indexed 2026-09-15 13:45 UTC

Cisco warns of a critical zero-day in Secure Email Gateway, exploited in the wild to gain root access through malicious emails. Cisco disclosed a critical zero-day, tracked as CVE-2026-76461 (CVSS score of 9.8), affecting Secure Email Gateway appliances. The flaw can be exploited remotely without authentication. Attackers can send specially crafted emails containing malicious SQL […]

VulnerabilitiesCVE-2026-76461
P50
2026-09-15 13:00 UTC
Vendor Research

Give every teammate and agent the right level of access to your Workers

Cloudflare Security · Dina Kozlov · indexed 2026-09-15 13:05 UTC

You can now scope access to individual Workers and assign narrower Developer Platform roles, so teammates, CI tokens, and agents get only the access they need to debug, deploy, or monitor safely.

P0
2026-09-15 12:54 UTC
Security Journalism

China spy chief points at US AI models in cyber threat warning

The Record · indexed 2026-09-15 13:10 UTC

China's spy chief identified Anthropic’s Claude Mythos and OpenAI’s GPT-5.5-Cyber as signs of what he called a “disruptive upgrade” in cyber capabilities, increasing the speed and potential weaponization of vulnerability discovery and malware development.

MalwareVulnerabilities
P0
2026-09-15 12:42 UTC
Security Journalism

OpenAI Investigates Report Linking AI Agents to RubyGems Attack

Security Week · Eduard Kovacs · indexed 2026-09-15 12:50 UTC

The incident occurred in May, when RubyGems maintainers suspended new account registrations due to what appeared like malicious activity. The post OpenAI Investigates Report Linking AI Agents to RubyGems Attack appeared first on SecurityWeek.

AI Security
P0
2026-09-15 12:42 UTC
Security Journalism

Manhattan DA takes down 12 AI deepfake porn sites

The Record · indexed 2026-09-15 12:55 UTC

Manhattan District Attorney Alvin Bragg held a press conference on Monday touting the takedown of the sites, which hosted AI-generated videos of more than 1,200 people. The sites allowed users to use the faces and bodies of real people to create illegal pornography.

P0
2026-09-15 12:22 UTC
Vendor Research

CVE-2026-76461: Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild

Rapid7 · Rapid7 · indexed 2026-09-15 12:55 UTC

OverviewOn September 14, 2026, Cisco published a security advisory for CVE-2026-76461, a critical SQL injection vulnerability affecting Cisco AsyncOS Software for Cisco Secure Email Gateway. The vulnerability has a reported CVSS v3.1 base score of 9.8 and could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on an affected appliance.Cisco Secure Email Gateway, formerly known as IronPort Email Security Appliance, is an enterprise email security produc…

MalwarePhishingThreat ActorsVulnerabilitiesCVE-2026-76461
P80
2026-09-15 12:19 UTC
Other

Shared Hosting at Risk: LiteSpeed Enterprise Bug Can Grant Root from a Single Tenant

Security Affairs · Pierluigi Paganini · indexed 2026-09-15 12:50 UTC

Critical LiteSpeed Enterprise flaw lets one shared hosting account gain root, bypassing CageFS; patch now to 6.3.7 via forced update. cPanel warned that a critical flaw in LiteSpeed Enterprise can let a low‑privilege website user break out of their account and gain root on the whole server. On a box where dozens or hundreds of […]

P15
2026-09-15 11:52 UTC
Security Journalism

Human Attacker Exploits Marimo RCE, Reaches SSH Bastion in Eight Seconds

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-15 12:25 UTC

With artificial intelligence (AI) shrinking the window between vulnerability discovery and exploitation and lowering the barrier to entry for bad actors, new findings from Sysdig show that skilled human operators can move just as swiftly after gaining initial access. In one instance highlighted by the cloud security company, the threat actor pivoted from a vulnerable Marimo notebook to an SSH

AI SecurityCloud SecurityThreat ActorsVulnerabilities
P0
2026-09-15 11:26 UTC
Security Journalism

Attack Chains, Not Just Attack Surfaces: Why Testing Individual Techniques Misses the Point

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-15 12:25 UTC

Introduction Security teams have gotten pretty good at testing against what can hurt them. Can this EDR agent catch this payload? Will my organization fail the phishing simulation? Does this SIEM rule fire on this particular technique? And, in more mature organizations, this testing happens continuously rather than as a one-off exercise. But no matter how much you validate against these

Phishing
P0
2026-09-15 11:12 UTC
Security Journalism

Mass-Scanning Campaign Exploits Vite Flaw to Extract Cloud Credentials From Exposed Dev Servers

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-15 12:25 UTC

Cybersecurity researchers have disclosed details of a mass-scanning campaign that has targeted Vite deployments siphon sensitive data. The first is an automated effort aimed at internet-exposed Vite development servers that's designed to steal cloud credentials, configurations from Amazon Web Services (AWS) and Microsoft Azure instances, and infrastructure state files, per F5 Labs. The

Cloud SecurityMicrosoftSecurity Research
P0
2026-09-15 10:17 UTC
Other

One Exploit Chain, Two Espionage Campaigns: Chrome and Windows Under Fire

Security Affairs · Pierluigi Paganini · indexed 2026-09-15 11:30 UTC

Two China-linked groups ran identical Chrome/Windows zero-day exploits against NGOs, before Chrome’s patch shipped, deploying different backdoors each. Two China-linked threat actors used the same Chrome/Windows zero-day against NGOs starting September 1, 2026, Volexity’s new report lays out the whole chain in detail. On September 1, Volexity detected a spear-phishing campaign by UTA0560 targeting several […]

APT / Nation-StateMalwareMicrosoftPhishingThreat ActorsVulnerabilities
P25
43 44 45 46 47