IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 4,776 matching records.
AUTO-POLL // 2026-10-10 14:30 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P2 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 10

RANSOMWARE
P2
P2
COOL // 8 ARTICLES
FRI
Oct 9

RANSOMWARE
P4
P4
COOL // 67 ARTICLES
THU
Oct 8

RANSOMWARE
P3
P3
COOL // 62 ARTICLES
WED
Oct 7

RANSOMWARE
P5
P5
COOL // 86 ARTICLES
TUE
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
RESET
2026-09-13 17:27 UTC
Other

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 114

Security Affairs · Pierluigi Paganini · indexed 2026-09-13 17:50 UTC

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter REVSTEALER ramps up Breaking the Seal: Static Deobfuscation of JSCeal’s Compiled V8 Bytecode GuardBreaker: Derailing AI-assisted malware analysis with a code comment DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive […]

APT / Nation-StateMalware
P0
2026-09-13 14:23 UTC
Other

Security Affairs newsletter Round 594 by Pierluigi Paganini – INTERNATIONAL EDITION

Security Affairs · Pierluigi Paganini · indexed 2026-09-13 14:50 UTC

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. The AI Supply Chain Has a Security Problem, and Much of It Is Sitting on the Open […]

P0
2026-09-13 13:27 UTC
Security Journalism

Anthropic CEO Dario Amodei Says AI Industry Needs to Give Safety Measures Time to Catch Up

Security Week · Associated Press · indexed 2026-09-13 13:30 UTC

Dario Amodei warned that within six to 12 months AI could be capable of leading a swarm of agents that could take over the entire internet. The post Anthropic CEO Dario Amodei Says AI Industry Needs to Give Safety Measures Time to Catch Up appeared first on SecurityWeek.

P0
2026-09-13 12:26 UTC
Other

GitLab CVE-2026-85706: One HTTP Request, No Authentication, Full File Read – Exploited Within 24 Hours

Security Affairs · Pierluigi Paganini · indexed 2026-09-13 13:30 UTC

CVE-2026-85706, a CVSS 10.0 GitLab path traversal, was under active exploitation within 24 hours of disclosure. GitLab disclosed CVE-2026-85706 (CVSS score of 10.0) on September 10, 2026, a path traversal vulnerability in its repository commits API. CVE-2026-85706 affects GitLab’s repository commits API and can let attackers access files they should not see. A crafted request […]

VulnerabilitiesCVE-2026-85706
P5
2026-09-13 10:11 UTC
Security Journalism

Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-13 10:25 UTC

Microsoft has disclosed details of two campaigns in which threat actors are abusing third-party email delivery infrastructure to blast financial fraud scam messages and using passkey-themed social engineering to breach cloud environments. The first campaign, per the tech giant, involved sending over a million scam emails between August 3 and 5, 2026, by masquerading as chief executive officers

CybercrimeMicrosoftPhishingThreat Actors
P0
2026-09-13 09:19 UTC
Other

Conti Hacker Who Built Malware and Attacked Victims Gets Four-Year Sentence

Security Affairs · Pierluigi Paganini · indexed 2026-09-13 10:15 UTC

Ukrainian lawyer and Conti malware developer Oleksii Lytvynenko was sentenced to four years in U.S. prison for ransomware attacks. Oleksii Oleksiyovych Lytvynenko had, by most accounts, a fairly ordinary legal career in Ukraine before he switched to writing malware. A US federal court sentenced the 44-year-old to four years in prison this week for conspiracy […]

MalwareNetwork SecurityRansomware
P15
2026-09-12 21:05 UTC
Other

Revolut Exposed KYC Data After Fraudulent Government Email Passed Security Checks

Security Affairs · Pierluigi Paganini · indexed 2026-09-12 22:10 UTC

Revolut handed over KYC documents, selfies, and Bitcoin transaction histories after a fake government email with valid domain credentials passed its checks. Revolut confirmed on September 12, 2026, that it disclosed sensitive customer data to an unauthorized third party after receiving fraudulent information requests sent from an email address operating inside an actual government agency’s […]

Cybercrime
P0
2026-09-12 16:46 UTC
Other

Anthropic: AI Misuse Is Entering a New Phase: From Cybercrime to Surveillance, Propaganda and Weapons

Security Affairs · Pierluigi Paganini · indexed 2026-09-12 17:20 UTC

AI is becoming an operational force for cybercrime, surveillance, propaganda, fraud and weapons development, lowering the cost and scale of attacks. Artificial intelligence (AI) is becoming more than a tool for people who want to do something malicious. It is increasingly becoming part of the operational machinery itself. That is the main message emerging from […]

AI SecurityCybercrime
P0
2026-09-12 15:54 UTC
Security Journalism

CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-12 17:30 UTC

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five security flaws impacting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the wild. Details of the vulnerabilities are as follows - CVE-2026-42016 (CVSS score: 8.1) - An incorrect authorization

Cloud SecurityNetwork SecurityVulnerabilitiesCVE-2026-42016
P80
2026-09-12 10:24 UTC
Security Journalism

When the Whole Company Adopts AI: What It Does to Your SOC

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-12 11:15 UTC

Over the past year, we watched a new class of alert appear in enterprise security operations centers and grow faster than anything else in the stream: alerts that were triggered by AI tools and agents. Not attacks against AI, but the ordinary, everyday footprint of an organization using it, from developers running coding agents and non-technical staff signing consumer AI tools into corporate

P0
2026-09-12 09:07 UTC
Security Journalism

OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-12 10:00 UTC

The "major malicious attack" that targeted RubyGems in May 2026 was the work of a swarm of OpenAI agents, according to a new report published by researchers Spencer Kitts, Thomas Larsen, and Sydney Von Arx. On May 12, Maciej Mensfeld, senior product manager for software supply chain security at Mend.io, disclosed details of a coordinated cyber attack that targeted the package manager for the

AI SecurityVulnerabilities
P15
2026-09-12 01:50 UTC
Security Journalism

Users in Houthi-Held Yemen Tried to Develop Advanced Weapons With AI, Anthropic Says

Security Week · Associated Press · indexed 2026-09-12 02:10 UTC

Anthropic said the users did not succeed in “fielding an operational device” but did carry out a failed test of a guided rocket. The post Users in Houthi-Held Yemen Tried to Develop Advanced Weapons With AI, Anthropic Says appeared first on SecurityWeek.

P0
2026-09-11 19:08 UTC
Vendor Research

CVE-2026-89332 - Kiro IDE Sensitive Workspace Data Exfiltration via Agent-Written Workspace Configuration

AWS Security Bulletins · aws@amazon.com · indexed 2026-09-11 19:15 UTC

Bulletin ID: 2026-111-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/11/2026 12:00 PM PDT Description: Kiro IDE is an agentic development environment that makes it easy for developers to ship real engineering work with the help of AI agents. We identified CVE-2026-89332, where the Kiro agent could modify a workspace's settings file in an untrusted workspace in Kiro IDE. A specially crafted repository could use this to point the Kiro Powers registry URL, which K…

AI SecurityCloud SecurityVulnerabilitiesCVE-2026-89332
P5
2026-09-11 19:00 UTC
Security Journalism

Florida confirms DMV database breached via stolen police account

BleepingComputer · Lawrence Abrams · indexed 2026-09-11 19:05 UTC

The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) has confirmed that its DAVID driver database suffered a data breach, saying the attackers gained access using credentials belonging to a police department employee. [...]

Data Breaches
P0
2026-09-11 18:14 UTC
Security Journalism

Why AI Is So Good at Scamming Humans

Dark Reading · indexed 2026-09-11 18:35 UTC

Fred Heiding of Menlo Park Intelligence talks with the Dark Reading News Desk about his research on frontier models, and their ability to influence human behavior and create emotional dependency.

P0
2026-09-11 17:27 UTC
Other

The AI Supply Chain Has a Security Problem, and Much of It Is Sitting on the Open Internet

Security Affairs · Pierluigi Paganini · indexed 2026-09-11 17:40 UTC

Researchers found 36,769 exposed AI endpoints, but only 2% had an HTTP authentication gate. Running AI locally is supposed to give organizations more control. Models, prompts and documents stay on infrastructure they manage instead of being sent to a third-party cloud. But that advantage disappears quickly when the infrastructure itself is exposed to the public […]

P0
2026-09-11 17:23 UTC
Security Journalism

Phishing Research Challenges Conventional Security Awareness Testing

Security Week · Kevin Townsend · indexed 2026-09-11 17:25 UTC

Analysis of 2.47 million simulated attacks shows why organizations should measure credential leaks and reporting, not just clicks. The post Phishing Research Challenges Conventional Security Awareness Testing appeared first on SecurityWeek.

Phishing
P0
2026-09-11 17:10 UTC
Security Journalism

AI Governance Can't Wait

Dark Reading · Tony Anscombe · indexed 2026-09-11 17:50 UTC

Adversaries can manipulate AI's defensive reasoning to silently compromise target networks.

P0
2026-09-11 17:09 UTC
Vendor Research

CVE-2026-89090 - Denial of service in the event stream header decoder in AWS SDK for Go v2

AWS Security Bulletins · aws@amazon.com · indexed 2026-09-11 17:20 UTC

Bulletin ID: 2026-110-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/11/2026 10:00 AM PDT Description: An issue exists in the the EventStream header decoder in AWS SDK for Go v2 in versions predating 2026-03-23. An actor can send a malformed EventStream response frame containing a crafted header value type byte outside the valid range, which can cause the host process to terminate. Impacted versions: < 2026-03-23 Please refer to the article below for the most u…

Cloud SecurityVulnerabilitiesCVE-2026-89090
P5
2026-09-11 16:37 UTC
Vendor Research

CVE-2026-18061 - XML External Entity (XXE) in AWS Advanced JDBC Wrapper RemoteQueryCachePlugin

AWS Security Bulletins · aws@amazon.com · indexed 2026-09-11 16:40 UTC

Bulletin ID: 2026-109-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/11/2026 09:30 AM PDT Description: The AWS Advanced JDBC Wrapper is an open-source library that enhances existing JDBC drivers with AWS-specific capabilities such as Aurora failover, IAM authentication, and automated SQL query caching for applications connecting to Amazon Aurora, RDS MySQL, and RDS MariaDB. We identified CVE-2026-18061, an improper restriction of XML external entity (XXE) refer…

Cloud SecurityVulnerabilitiesCVE-2026-18061
P5
47 48 49 50 51