IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 4,778 matching records.
AUTO-POLL // 2026-10-10 17:45 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P2 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 10

RANSOMWARE
P2
P2
COOL // 10 ARTICLES
FRI
Oct 9

RANSOMWARE
P4
P4
COOL // 67 ARTICLES
THU
Oct 8

RANSOMWARE
P3
P3
COOL // 62 ARTICLES
WED
Oct 7

RANSOMWARE
P5
P5
COOL // 86 ARTICLES
TUE
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
RESET
2026-09-09 21:02 UTC
Security Journalism

Skullcandy Dime 3 earbuds expose users to Bluetooth hijacking

BleepingComputer · Bill Toulas · indexed 2026-09-09 21:05 UTC

The Carnegie Mellon University CERT Coordination Center (CERT/CC) is warning that Skullcandy Dime 3 wireless earbuds accept Bluetooth pairing requests from nearby unpaired devices without requiring user interaction. [...]

P0
2026-09-09 19:09 UTC
Vendor Research

The state of AI for security: Measuring what matters most for building trust

AWS Security Blog · Anshumali Shrivastava · indexed 2026-09-09 19:30 UTC

Security teams are starting to actively use AI for security work, including vulnerability triage, penetration testing, threat modeling, incident response, and code review. The promise is speed, but a security tool that moves fast and raises too many false alarms doesn’t save time. Engineers spend time on false alarms, on-call is noisier, and teams distrust […]

DFIRVulnerabilities
P0
2026-09-09 18:26 UTC
Security Journalism

U.S. Disrupts Xinbi Guarantee Scam Marketplace, Freezes $52.8 Million in Crypto

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-09 19:50 UTC

The U.S. Department of Justice (DoJ) on Wednesday announced coordinated actions aimed at an illicit online marketplace called Xinbi Guarantee that offered scam services, including seizing Telegram channels used to run the service, confiscating two cryptocurrency wallets, and deploying the Scam Center Strike Force to Madagascar to help disrupt 13 scam compounds run by Chinese organized crime

Law Enforcement
P0
2026-09-09 18:20 UTC
Other

US Agencies Warn Chinese AI Firms Are Extracting Advanced AI Models

Security Affairs · Pierluigi Paganini · indexed 2026-09-09 18:50 UTC

US agencies accuse six Chinese AI firms of extracting billions of tokens from US AI models to accelerate development and copy advanced capabilities. NSA, CISA, and the FBI jointly published an advisory accusing six Chinese AI companies, DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI, of running industrial-scale extraction campaigns against US frontier models since […]

Law Enforcement
P0
2026-09-09 17:46 UTC
Community

Scans for Proxmox Servers, (Wed, Sep 9th)

SANS Internet Storm Center · indexed 2026-09-09 18:00 UTC

About a week ago, Proxmox published an advisory revealing a vulnerability in older versions of Proxmox VE, its flagship Virtual Environment product. The vulnerability only affects version 7, which has not been supported for a couple of years now.

Vulnerabilities
P0
2026-09-09 17:41 UTC
Vendor Research

Passkey-themed social engineering leads to identity and cloud compromise

Microsoft Security Blog · Microsoft Security Research, Krithika Ramakrishnan, Bharat Vaghela, Vaibhav Deshmukh, Subhajit Ghosh, Anusha Chakraborty, Akash Chaudhuri, Victor Chingtham and Ivan Macalintal · indexed 2026-09-09 18:45 UTC

Passkey-themed social engineering is being used to compromise identities and enable broader cloud attacks. Learn how threat actors establish MFA persistence, abuse Microsoft Graph for reconnaissance, and access SharePoint, OneDrive, and email data, along with key detection and mitigation guidance. The post Passkey-themed social engineering leads to identity and cloud compromise appeared first on Microsoft Security Blog.

MicrosoftThreat Actors
P0
2026-09-09 17:23 UTC
Security Journalism

HelmGuard Raises $7.3 Million for Agentic GRC and Security

Security Week · Ionut Arghire · indexed 2026-09-09 17:30 UTC

The company will increase its US market presence and will expand its engineering and go-to-market teams. The post HelmGuard Raises $7.3 Million for Agentic GRC and Security appeared first on SecurityWeek.

P0
2026-09-09 17:03 UTC
Security Journalism

Electronic health record company says customer data stolen in breach

The Record · indexed 2026-09-09 17:20 UTC

Veradigm said access was limited to a specific interface, and did not impact the company’s broader environment such as its networks, servers or databases. The incident did not result in operational disruptions, the company added.

P0
2026-09-09 16:48 UTC
Security Journalism

US says Chinese firms extracted billions of tokens from frontier AI models

BleepingComputer · Bill Toulas · indexed 2026-09-09 16:50 UTC

U.S. cybersecurity and intelligence agencies say that six Chinese AI companies conducted industrial-scale distillation attacks on American frontier AI models since at least late 2024. [...]

P0
2026-09-09 16:34 UTC
Security Journalism

Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-09 19:50 UTC

Multiple espionage-motivated threat activity clusters have been found deploying a previously undocumented exploit kit called BlueMoon that chains together multiple vulnerabilities in Microsoft Windows and Google Chrome. The first in-the-wild use of BlueMoon has been attributed to the China-aligned state-sponsored group tracked as APT31 (aka Bronze Vinewood, Judgement Panda, JungleBamboo,

APT / Nation-StateMicrosoft
P0
2026-09-09 16:22 UTC
Security Journalism

Chipmaker Patch Tuesday: Nvidia, AMD, Arm Issue Security Advisories

Security Week · Ionut Arghire · indexed 2026-09-09 16:30 UTC

Major chipmakers announced patches for vulnerabilities recently discovered in their products. The post Chipmaker Patch Tuesday: Nvidia, AMD, Arm Issue Security Advisories appeared first on SecurityWeek.

P0
2026-09-09 15:37 UTC
Security Journalism

FBI puts its cyber strategy on paper

The Record · indexed 2026-09-09 15:55 UTC

The first public cybersecurity strategy issued by the FBI "directs our teams, our field offices, our global presence" to align their efforts on countering malicious hackers and cybercrime groups, senior official Brett Leatherman says.

CybercrimeLaw Enforcement
P0
2026-09-09 15:16 UTC
Vendor Research

Credentialed Pre-Port Discovery: Don't Probe the Host, Ask it

Rapid7 · Conor McCormick · indexed 2026-09-09 16:10 UTC

If your scan engine already holds credentials for a host, it can ask that host which ports are open instead of probing for them.Every scan begins with the same question: which ports on this host are open? Everything after it, from identifying services to checking for vulnerabilities to evaluating policy, depends on the answer being right. The traditional answer comes from the outside: the scan engine sends traffic to a range of ports and infers each port's state from how the host responds. That…

MicrosoftNetwork SecurityVulnerabilities
P0
2026-09-09 14:39 UTC
Security Journalism

Identity-Based AI Attack Threatens Security of Enterprise Data

Dark Reading · Elizabeth Montalbano · indexed 2026-09-09 15:25 UTC

"Workflow identity hijacking" can bypass standard security controls and hijack an organization's data by sending a basic request through an unauthenticated entry point.

P0
2026-09-09 14:23 UTC
Security Journalism

Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-09 14:40 UTC

Cybercriminals are hijacking artificial intelligence (AI) user accounts via information stealer logs to create "stolen keys" that grant illicit access to tools from model providers like Google, Anthropic, and others. Information stealers like Lumma Stealer or Vidar are equipped to harvest a wide range of data from compromised systems. This can include credential, session tokens, and API

AI SecurityMalware
P0
2026-09-09 14:01 UTC
Security Journalism

MFA's Weakest Link: Account Recovery Is the New Attack Path

BleepingComputer · Sponsored by Specops Software · indexed 2026-09-09 14:10 UTC

MFA makes account takeover harder, but attackers are increasingly targeting the recovery processes used to reset passwords and authentication methods. Specops explains why stronger identity verification at the service desk is critical to preventing social engineering attacks from turning account recovery into account takeover. [...]

P0
2026-09-09 13:47 UTC
Other

Google fixes the seventh actively exploited Chrome zero-day of 2026

Security Affairs · Pierluigi Paganini · indexed 2026-09-09 14:50 UTC

Google patched 230 Chrome flaws, including an actively exploited V8 bug that could let attackers run arbitrary code through a crafted HTML page. Google released a Chrome update fixing 230 security vulnerabilities, including one already exploited in the wild tracked as CVE-2026-87491 (CVSS score of 8.8). The medium-severity flaw affects V8, Google’s open source high-performance […]

Cloud SecurityVulnerabilitiesCVE-2026-87491
P50
2026-09-09 13:07 UTC
Government

2026-011: Critical Vulnerabilities in SAP Kernel and NetWeaver Message Server

CERT-EU Security Advisories · indexed 2026-09-09 13:10 UTC

On 8 September 2026, as part of its September Security Patch Day, SAP released Security Notes addressing two critical vulnerabilities affecting a broad range of SAP products[3]. The most severe, CVE-2026-44756 (CVSS 10.0), is a memory corruption vulnerability in SAP Extended Passport (EPP) processing, nicknamed "OVERPASS" by the Onapsis Research Labs (ORL), which discovered and responsibly disclosed it[3]. The second, CVE-2026-58240 (CVSS 9.8), nicknamed "S4GET", is a missing authentication che…

LinuxVulnerabilitiesCVE-2026-44756CVE-2026-58240
P5
2026-09-09 13:00 UTC
Vendor Research

Introducing the CyberAgents Exchange AI Inspector: Rigorous review for community-built AI

Tenable Blog · Mark Beblow · indexed 2026-09-09 13:10 UTC

Open-source registries for AI agents are only effective when they include a rigorous, transparent security review process for community submissions. That’s why for its new CyberAgents Exchange registry, Tenable paired its exposure management expertise with OpenAI GPT Cyber models to create the CyberAgents Exchange AI Inspector.Key takeawaysThe Exchange Inspector combines Tenable’s exposure detection with OpenAI’s GPT Cyber models and with human oversight to rigorously vet submissions made to th…

AI SecurityData BreachesMicrosoft
P0
54 55 56 57 58