IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 4,775 matching records.
AUTO-POLL // 2026-10-10 13:00 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P2 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 10

RANSOMWARE
P2
P2
COOL // 7 ARTICLES
FRI
Oct 9

RANSOMWARE
P4
P4
COOL // 67 ARTICLES
THU
Oct 8

RANSOMWARE
P3
P3
COOL // 62 ARTICLES
WED
Oct 7

RANSOMWARE
P5
P5
COOL // 86 ARTICLES
TUE
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
RESET
2026-09-15 10:17 UTC
Other

One Exploit Chain, Two Espionage Campaigns: Chrome and Windows Under Fire

Security Affairs · Pierluigi Paganini · indexed 2026-09-15 11:30 UTC

Two China-linked groups ran identical Chrome/Windows zero-day exploits against NGOs, before Chrome’s patch shipped, deploying different backdoors each. Two China-linked threat actors used the same Chrome/Windows zero-day against NGOs starting September 1, 2026, Volexity’s new report lays out the whole chain in detail. On September 1, Volexity detected a spear-phishing campaign by UTA0560 targeting several […]

APT / Nation-StateMalwareMicrosoftPhishingThreat ActorsVulnerabilities
P25
2026-09-15 09:50 UTC
Security Journalism

Suspected Black Axe gang leaders face cybercrime charges in the US

BleepingComputer · Sergiu Gatlan · indexed 2026-09-15 10:00 UTC

Five alleged leaders of the Black Axe cybercrime syndicate, known for its involvement in global-scale cyber-enabled financial fraud, have been extradited to the United States to face wire fraud and money laundering charges. [...]

Cybercrime
P0
2026-09-15 07:48 UTC
Other

Telegram Desktop Flaw Could Turn Old Chat Exports Into Data Theft Traps

Security Affairs · Pierluigi Paganini · indexed 2026-09-15 09:00 UTC

A Telegram Desktop flaw let bots inject JavaScript into exported chats, enabling data theft and page manipulation. Old HTML exports remain unsafe. A vulnerability in Telegram Desktop could have turned an ordinary chat export into a serious data leak. Security researchers Denis and Aleksander Rostilov of ExPatch found a stored cross-site scripting flaw in the […]

Data BreachesSecurity ResearchVulnerabilities
P0
2026-09-15 07:19 UTC
Other

Non-Zero-Day VPN Flaw Left Japan ‘s Government Shared Network Platform Exposed: 246,000 Records at Risk

Security Affairs · Pierluigi Paganini · indexed 2026-09-15 08:00 UTC

Japan ‘s Digital Agency disclosed a VPN breach exposing 246,000 government employee records across 23 ministries. Detected June 25, publicly disclosed September 11. Japan ‘s Digital Agency disclosed that attackers exploited a vulnerability in a VPN device to access its Government Solution Service (GSS), potentially leaking personal information belonging to approximately 246,000 government employees, public […]

Network SecurityVulnerabilities
P25
2026-09-15 06:52 UTC
Security Journalism

LiteSpeed Enterprise Flaw Could Let One Hosting Account Gain Root Access on a Shared Server

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-15 08:25 UTC

A critical vulnerability in LiteSpeed Web Server Enterprise could let a low-privilege website user gain root access on a shared-hosting server, cPanel warned in an advisory published on September 14. On such servers, many customers' sites run on a single machine, and an attacker with one of those hosting accounts could exploit the flaw to access or alter other sites and the server itself,

Vulnerabilities
P10
2026-09-15 06:11 UTC
Security Journalism

Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-15 06:25 UTC

Cisco has warned that a new critical vulnerability impacting AsyncOS Software for Cisco Secure Email Gateway has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-76461, carries a CVSS score of 9.8 out of a maximum of 10.0. It has been described as a case of insufficient validation in the email parsing logic that could allow an unauthenticated, remote attacker

VulnerabilitiesCVE-2026-76461
P35
2026-09-15 05:31 UTC
Security Journalism

China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-15 06:25 UTC

A Chinese threat actor has been attributed to a spear-phishing campaign that exploits recently patched security flaws in Google Chrome and Microsoft Windows to deliver a malicious JavaScript backdoor called GRIMWEDGE. Volexity, which is tracking the threat cluster under the moniker UTA0560, said the activity targeted multiple non-governmental organizations (NGOs) on September 1, 2026. "The

Cloud SecurityMalwareMicrosoftPhishingThreat ActorsVulnerabilities
P25
2026-09-14 20:52 UTC
Security Journalism

Microsoft releases emergency Windows updates to fix RDS failures

BleepingComputer · Lawrence Abrams · indexed 2026-09-14 20:55 UTC

Microsoft has released emergency out-of-band Windows updates to fix Remote Desktop Services failures caused by this month's security updates, along with Hyper-V and USB audio problems on some Windows versions. [...]

Microsoft
P5
2026-09-14 20:35 UTC
Other

ENISA: Frontier AI Is Changing the Speed of Cyberattacks. Europe Needs to Catch Up

Security Affairs · Pierluigi Paganini · indexed 2026-09-14 20:45 UTC

Frontier AI is compressing the attack lifecycle from vulnerability discovery to exploitation, forcing defenders to detect, patch and respond at machine speed. Cybersecurity has always been a race between attackers and defenders. ENISA’s latest assessment suggests that frontier AI is changing the speed of that race, and the gap between discovering a vulnerability and exploiting […]

MicrosoftVulnerabilities
P0
2026-09-14 19:51 UTC
Security Journalism

Homebrew 7.0.0 gets built-in GUI, better security controls

BleepingComputer · Bill Toulas · indexed 2026-09-14 19:55 UTC

Homebrew package manager version 7.0.0 has been released with a built-in vulnerability scanner, stronger security controls, and the full release of its native BrewUI graphical interface. [...]

Vulnerabilities
P0
2026-09-14 19:03 UTC
Security Journalism

Twitch extension with 30K installs exposes users’ OAuth tokens

BleepingComputer · Bill Toulas · indexed 2026-09-14 19:15 UTC

A browser extension called Twitch Enhanced Viewer | JeetBot, available in the official Chrome and Firefox stores, sends users' Twitch OAuth session tokens to a commercial bot service. [...]

P0
2026-09-14 18:33 UTC
Community

Apple Updates Everything, (Mon, Sep 14th)

SANS Internet Storm Center · indexed 2026-09-14 18:50 UTC

Today, Apple released its annual update across all its operating systems. With that, Apple not only released new features but also patched 261 different vulnerabilities. This is the most vulnerabilities Apple has ever patched, but the increase is not as significant as other vendors' "post-AI" patch releases. 

Apple
P0
2026-09-14 18:11 UTC
Other

China Calls Amodei’s AI Proposal a New Cold War Playbook

Security Affairs · Pierluigi Paganini · indexed 2026-09-14 18:45 UTC

China rejects Amodei’s AI slowdown proposal, calling it fearmongering and a US attempt to contain China’s technology sector. The debate over whether the world should slow down the development of advanced AI has quickly turned into something bigger than a technology argument. Dario Amodei, CEO of Anthropic, has called for a slower pace of development, […]

P0
2026-09-14 18:04 UTC
Vendor Research

CVE-2026-86830 - Incorrect privilege assignment in Temporary Elevated Access Management (TEAM) for AWS IAM Identity Center

AWS Security Bulletins · aws@amazon.com · indexed 2026-09-14 18:10 UTC

Bulletin ID: 2026-112-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/14/2026 10:45 AM PDT Description: Temporary Elevated Access Management (TEAM) is an open source AWS sample solution for managing temporary elevated access via AWS IAM Identity Center. We identified CVE-2026-86830, where an authenticated user with application-level access could gain unintended temporary elevated access to AWS accounts managed by TEAM. Impacted versions:

Cloud SecurityVulnerabilitiesCVE-2026-86830
P5
2026-09-14 18:02 UTC
Security Journalism

New DDRop Attack Breaks Intel TDX and AMD SEV-SNP Confidential Computing

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-14 17:30 UTC

Researchers have disclosed a new hardware attack, called DDRop, that breaks the memory protection in Intel and AMD confidential computing by silently dropping writes to a server's memory, so the processor keeps reading old encrypted data as if it were current. The attack requires an attacker who already controls the server's software and can briefly access the machine to insert a small circuit

P0
2026-09-14 18:01 UTC
Security Journalism

3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-14 19:45 UTC

An attacker was operating inside the network of 3BB, one of Thailand's largest broadband providers, and maintained remote control of internal machines using a legitimate management tool called MeshCentral, threat intelligence firm Hunt.io said. The company uncovered the intrusion by examining a server the attacker had left open on the internet, which held the attacker's own tools and a list of

MalwareMicrosoftThreat Intelligence
P0
2026-09-14 17:58 UTC
Security Journalism

Telegram Desktop Flaw Lets Hidden JavaScript Exfiltrate Messages From HTML Exports

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-14 19:45 UTC

A flaw in Telegram Desktop let a bot's message plant hidden JavaScript inside chats that users exported to HTML files, security researchers at ExPatch said in a writeup published on September 12. In Telegram, the message looked ordinary, with a link button, and the script ran only when someone opened the export file in a web browser. It could then copy every message in that file to

Security Research
P0
2026-09-14 17:46 UTC
Vendor Research

AWS Security Reference Architecture: A deep dive into PCI DSS compliance

AWS Security Blog · Avik Mukherjee · indexed 2026-09-14 18:10 UTC

Amazon Web Services (AWS) is excited to announce the publication of the AWS Security Reference Architecture (AWS SRA) Payment Card Industry (PCI) Data Security Standard (DSS) Deep Dive. This new guide extends the core AWS SRA to provide prescriptive, architecture-level guidance for organizations that store, process, or transmit cardholder data on AWS. Organizations subject to […]

Cloud Security
P0
2026-09-14 16:56 UTC
Security Journalism

Red Heron Exploits Gitea RCE to Compromise 13 Organizations Across Six Countries

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-14 17:30 UTC

A suspected Chinese threat actor tracked as Red Heron has been attributed to the rapid exploitation of a recently disclosed security vulnerability in Gitea to compromise internet-facing instances as part of a multi-national campaign. "Red Heron scanned 1,386 Gitea instances across seven countries and maintained a separate dataset of 477 Taiwan-based systems," Acronis Threat Research Unit (TRU)

Threat ActorsVulnerabilities
P15
44 45 46 47 48