IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 4,761 matching records.
AUTO-POLL // 2026-10-09 21:20 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P5 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 9

RANSOMWARE
P5
P5
COOL // 60 ARTICLES
THU
Oct 8

RANSOMWARE
P3
P3
COOL // 62 ARTICLES
WED
Oct 7

RANSOMWARE
P5
P5
COOL // 86 ARTICLES
TUE
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
RESET
2026-10-08 10:11 UTC
Other

U.S. Offers $10 Million Reward for Alleged HAFNIUM Hacker Zhang Yu

Security Affairs · Pierluigi Paganini · indexed 2026-10-08 10:30 UTC

The U.S. offers $10M for Zhang Yu, accused of helping run HAFNIUM attacks that compromised thousands of organizations worldwide. The U.S. State Department is offering a $10 million reward for information leading to the arrest of Zhang Yu. He is accused of being a key figure in the HAFNIUM campaign, the 2021 operation that targeted […]

P0
2026-10-08 09:46 UTC
Security Journalism

16 Malicious Firefox Extensions Pose as Rabby and OKX Wallets to Steal Recovery Phrases

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-08 09:55 UTC

Cybersecurity researchers have discovered a cluster of 16 malicious Mozilla Firefox extensions that are capable of stealing cryptocurrency wallet recovery phrases and private keys. "The extensions masquerade as wallet portals, desktop utilities, and browser tools, but their code intercepts recovery phrases and private keys during wallet import flows and attempts to send those secrets to

Security Research
P0
2026-10-08 09:27 UTC
Security Journalism

Fake Decryption Tools Masked $11M Markup in Ransomware Recovery Scheme

Security Week · Ionut Arghire · indexed 2026-10-08 09:30 UTC

Zohar Pinhasi was paying ransoms to obtain decryption keys and then charging victims substantially more for remediation. The post Fake Decryption Tools Masked $11M Markup in Ransomware Recovery Scheme appeared first on SecurityWeek.

Ransomware
P15
2026-10-08 08:23 UTC
Security Journalism

Oracle Health Data Breach Tally Climbs to Nearly 20 Million

Security Week · Eduard Kovacs · indexed 2026-10-08 08:30 UTC

The figure is far higher than the counts that surfaced in earlier filings and patient notifications. The post Oracle Health Data Breach Tally Climbs to Nearly 20 Million appeared first on SecurityWeek.

Data Breaches
P0
2026-10-08 07:52 UTC
Security Journalism

FortiBleed Attackers Locking Victims Out of Fortinet Devices

Security Week · Ionut Arghire · indexed 2026-10-08 07:55 UTC

Attackers are creating new accounts and deleting existing ones and passwords to prevent legitimate access. The post FortiBleed Attackers Locking Victims Out of Fortinet Devices appeared first on SecurityWeek.

Network Security
P0
2026-10-08 07:46 UTC
Vendor Research

Making Threat Intelligence Work for SOC Teams: ANY.RUN & Elastic Webinar Insights

ANY.RUN Blog · ANY.RUN · indexed 2026-10-08 07:50 UTC

Threat intelligence on its own is only data. Its value depends on how effectively SOC teams can turn it into action. Simply put, this was the premise of our recent webinar. The SOC and business impact of threat intelligence depends largely on how quickly analysts can use it to validate threats, make confident decisions, and […] The post Making Threat Intelligence Work for SOC Teams: ANY.RUN & Elastic Webinar Insights appeared first on ANY.RUN's Cybersecurity Blog.

Threat Intelligence
P0
2026-10-08 07:42 UTC
Security Journalism

U.S. Offers Up to $10 Million for Tips on Zhang Yu, Charged in HAFNIUM Hacks

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-08 08:10 UTC

The U.S. State Department is offering up to $10 million for information leading to the identification or location of Zhang Yu, a Chinese national charged in the United States in connection with the 2021 Microsoft Exchange Server attacks known as HAFNIUM. The reward is for information leading to his identification or location, the news outlet NTD reported this week, citing a notice

Microsoft
P0
2026-10-08 07:41 UTC
Security Journalism

MonsterCloud Owner Accused of Billing Over $19M While Secretly Paying Ransoms to Decrypt Data

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-08 08:10 UTC

The U.S. Department of Justice (DoJ) on Wednesday announced charges against a 50-year-old U.S. and Israeli national for allegedly defrauding ransomware victims by secretly paying the attackers to obtain decryptors while claiming to use proprietary tools to recover their data. Zohar Pinhasi (aka Zack Silver and Zack Green) has been charged with two counts of wire fraud and one count of wire

CybercrimeLaw EnforcementRansomware
P15
2026-10-08 07:26 UTC
Other

Atlassian Vulnerability Comes Under Attack Hours After Details Go Public

Security Affairs · Pierluigi Paganini · indexed 2026-10-08 08:10 UTC

Threat actors are exploiting CVE-2026-21589, a critical Atlassian flaw that can expose sensitive files across multiple Data Center products. Threat actors have started exploiting CVE-2026-21589 (CVSS score of 9.3), a critical arbitrary file access flaw in Atlassian Data Center products. The vulnerability could allow attackers to access sensitive files under certain conditions. Affected products include […]

Threat ActorsVulnerabilitiesCVE-2026-21589
P5
2026-10-08 05:46 UTC
Security Journalism

Tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-08 06:40 UTC

The npm package known as "tensorlake," a TypeScript software development kit (SDK) for Tensorlake applications, sandboxes, and cloud services, was compromised as part of a ChainDrop / Shai-Hulud supply chain attack. The malicious version 0.5.144 "contains obfuscated malware that harvests credentials, exfiltrates secrets, establishes persistence, and executes remotely supplied code," Socket said

Malware
P0
2026-10-08 00:18 UTC
Vendor Research

Cisco Meraki Security Hardening Release: October 2026

Cisco Security Advisories · indexed 2026-10-07 16:15 UTC

As part of Cisco's ongoing commitment to proactive security and product quality, engineering teams conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. These vulnerabilities were found during internal testing and are not known to be actively exploited. To assist customers in patching and streamline the disclosure process, Cisco has grouped these issues by their underlying vulnerabilit…

VulnerabilitiesCVE-2026-76463CVE-2026-76464CVE-2026-76467CVE-2026-76468CVE-2026-76469CVE-2026-76470CVE-2026-76472
P30
2026-10-07 23:04 UTC
Security Journalism

Ransomware recovery CEO charged over secret ransom payments

BleepingComputer · Lawrence Abrams · indexed 2026-10-07 23:15 UTC

The owner of ransomware remediation company MonsterCloud has been charged with allegedly defrauding ransomware victims by secretly paying their attackers for decryptors while claiming to use proprietary technology to recover encrypted data. [...]

CybercrimeRansomware
P15
2026-10-07 22:00 UTC
Vendor Research

Evolution of Web3 in Cloud Supply Chain Attacks

Palo Alto Networks Unit 42 · Eyal Rafian · indexed 2026-10-07 22:10 UTC

Unit 42 details how threat actors leverage Web3 infrastructure and open-source supply chain attacks to breach enterprise cloud environments The post Evolution of Web3 in Cloud Supply Chain Attacks appeared first on Unit 42.

Threat Actors
P0
2026-10-07 21:49 UTC
Vendor Research

Configuring your AI vulnerability harness, Part 2: The steering file

AWS Security Blog · Justin Kontny · indexed 2026-10-07 22:20 UTC

This post shows you how to configure an AI model to perform structured, evidence-based vulnerability triage with the consistency of a seasoned security analyst. You’ll learn the design decisions behind five configuration sections that enforce structural verification, evidence-based scoring, and infrastructure-aware prioritization across every analysis session. Our companion post—Building your AI vulnerability harness—covered the architecture; […]

Vulnerabilities
P0
2026-10-07 21:49 UTC
Vendor Research

Building your AI vulnerability harness, Part 1

AWS Security Blog · Nidhi Ramakant · indexed 2026-10-07 22:20 UTC

Vulnerability scanners produce findings faster than manual triage can process them. Your developers ship more code with more dependencies, and the volume of candidate findings grows with it. Many findings a scanner produces are unlikely to be exploited. The ones that matter need to reach an engineer fast, with enough evidence that they can act […]

Vulnerabilities
P0
2026-10-07 21:42 UTC
Security Journalism

Australian Gov't Weighs Mandatory AI Incident Reporting

Dark Reading · Nate Nelson · indexed 2026-10-07 22:05 UTC

In the wake of an agentic attack against its own Medicare systems, Australia's government is feeling out what regulations might look like for frontier AI companies.

P0
2026-10-07 20:50 UTC
Security Journalism

Hackers hijack Google domains after breaching ccTLD registries

BleepingComputer · Bill Toulas · indexed 2026-10-07 21:05 UTC

Hackers obtained unauthorized HTTPS certificates for several Google domains and hijacked domains in the country-code top-level domains (ccTLDs) for Ghana, American Samoa, and Sierra Leone after compromising third-party operators and modifying authoritative DNS records. [...]

P0
2026-10-07 20:19 UTC
Vendor Research

CVE-2026-107352 - Missing authorization checks in Amazon Athena engine version 3 request handling

AWS Security Bulletins · aws@amazon.com · indexed 2026-10-07 20:30 UTC

Bulletin ID: 2026-128-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 10/07/2026 13:00 PM PDT Description: Missing authorization checks in Amazon Athena engine version 3 request handling could have allowed an authenticated user to read limited query metadata (AWS account identifiers and SQL statement text) from other AWS accounts. AWS remediated the issue on September 1, 2026, and has confirmed no customer metadata was accessed. Query results, credentials, and Amaz…

Cloud SecurityVulnerabilitiesCVE-2026-107352
P5
3 4 5 6 7