IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 4,763 matching records.
AUTO-POLL // 2026-10-09 22:10 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P5 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 9

RANSOMWARE
P5
P5
COOL // 62 ARTICLES
THU
Oct 8

RANSOMWARE
P3
P3
COOL // 62 ARTICLES
WED
Oct 7

RANSOMWARE
P5
P5
COOL // 86 ARTICLES
TUE
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
RESET
2026-10-07 19:34 UTC
Security Journalism

OpenAI Agent Escape Causes Wikimedia Service Outage

Dark Reading · Elizabeth Montalbano · indexed 2026-10-07 19:55 UTC

Autonomous agents also tried to abuse other websites and services hosted by the foundation, using them as proxies for unauthorized activities.

AI Security
P0
2026-10-07 19:29 UTC
Vendor Research

Four compliance frameworks, one security team: Why fragmented university security raises regulatory risk

Rapid7 · Rapid7 · indexed 2026-10-07 19:50 UTC

In Part 1 of this series, we looked at the security challenges created by fragmented, campus-by-campus environments. Higher education also faces a second pressure that makes that fragmentation harder to sustain: overlapping compliance obligations across FERPA, GLBA, HIPAA, and CMMC.Each framework brings different requirements, reporting timelines, and consequences for failure. Managing them across one institution is already complex, but across a multi-campus university system with separate tool…

DFIRMicrosoftRansomware
P15
2026-10-07 19:27 UTC
Vendor Research

Microsoft, Adobe, Apple, and Foxit vulnerabilities

Cisco Talos Intelligence Blog · Kri Dontje · indexed 2026-10-07 20:00 UTC

Cisco Talos’ Vulnerability Discovery & Research team recently disclosed vulnerabilities in Adobe, Apple, Foxit Reader, and Microsoft.The vulnerabilities mentioned in this blog post have been patched by their respective vendors, in adherence to Cisco’s third-party vulnerability disclosure policy. For Snort coverage that can detect

AppleMicrosoftVulnerabilities
P0
2026-10-07 18:48 UTC
Security Journalism

Attackers Hijack .gh, .sl, and .as Registries to Obtain Certificates for Google Domains

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-07 19:20 UTC

Attackers compromised three country-code top-level domains (ccTLDs) and obtained unauthorized HTTPS certificates for several Google domains, Google said on October 6. Google's own systems were not breached, but any domain ending in .gh (Ghana), .sl (Sierra Leone) or .as (American Samoa) was put at risk. With such a certificate, an attacker could pose as the real site over an encrypted

P0
2026-10-07 18:31 UTC
Security Journalism

Arizona courts say hackers stole info on more than 1.3 million people

The Record · indexed 2026-10-07 18:45 UTC

The investigation into the incident revealed cybercriminals were able to breach the Fines/Fees and Restitution Enforcement (FARE) Program, a statewide program that helps the court collect outstanding debts tied to traffic and criminal violations.

DFIR
P0
2026-10-07 18:25 UTC
Vendor Research

CVE-2026-105811 - Authorization bypass through a user-controlled key in the Amazon Q Business Lambda hook sample in QnABot on AWS

AWS Security Bulletins · aws@amazon.com · indexed 2026-10-07 18:30 UTC

Bulletin ID: 2026-126-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 10/06/2026 13:00 PM PDT Description: QnABot on AWS is a sample solution of a multi-channel, multi-language conversational interface (chatbot) that responds to your customer's questions, answers, and feedback. We identified CVE-2026-105811 in the optional Amazon Q Business Lambda hook sample of QnABot on AWS. The Amazon Q Business Lambda hook sample (q-business-lambda-hook) is an optional integrat…

Cloud SecurityVulnerabilitiesCVE-2026-105811
P5
2026-10-07 18:17 UTC
Other

SonicWall Fixes Max Severity Pre-Auth Flaw in SMA1000 Appliances

Security Affairs · Pierluigi Paganini · indexed 2026-10-07 18:50 UTC

SonicWall patched a CVSS 10 pre-auth SSRF flaw in SMA1000 appliances that could let unauthenticated attackers reach internal functions. SonicWall released hotfixes for four vulnerabilities in its SMA1000 remote access appliances, including a critical flaw tracked as CVE-2026-102255 (CVSS score of 10.0. The issue is a pre-authentication SSRF bug in the WorkPlace portal that could […]

VulnerabilitiesCVE-2026-102255
P15
2026-10-07 17:43 UTC
Security Journalism

Eight Malicious npm Packages Downloaded 40,767 Times Deliver Overlord RAT and Stealer

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-07 17:55 UTC

Cybersecurity researchers have disclosed details of a long-running npm supply chain malware campaign that pushes information stealers and remote access trojans (RAT) to compromised hosts. The campaign has been codenamed MALFEX by CloudSEK and Checkmarx. The activity is assessed to be the work of a lone threat actor who appears to have published 12 packages since August 2023, eight of which have

MalwareSecurity ResearchThreat Actors
P0
2026-10-07 16:30 UTC
Vendor Research

Building an evidence-grounded agentic security operations harness on Cloudflare

Cloudflare Security · Deanna Tran · indexed 2026-10-07 16:50 UTC

Cloudflare Managed Defense uses a team of specialized AI agents built on Workers and global network telemetry to analyze security alerts. By separating deterministic evidence collection from model inference, the system delivers grounded recommendations to Managed Defense Analysts.

AI Security
P0
2026-10-07 16:21 UTC
Vendor Research

Part 1 – Cybersecurity journeys: I didn’t plan this

AWS Security Blog · Shannon Brazil · indexed 2026-10-07 16:35 UTC

If you’ve ever wondered whether your background qualifies you for a career in cybersecurity, you’re not alone — and you’re probably more prepared than you think. My name is Shannon Brazil, and I work in security communications at Amazon Web Services (AWS). I have been in the security space for over a decade, and my […]

Cloud Security
P0
2026-10-07 16:17 UTC
Security Journalism

SonicWall Patches CVSS 10.0 Pre-Authentication SSRF Flaw in SMA1000 Appliances

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-07 17:55 UTC

SonicWall has released hotfixes for four flaws in its SMA1000 appliances, the gateways that give remote workers access to a company's network and applications. The most serious could allow an attacker without a login to send requests through the appliance and reach internal functions. SonicWall rates it 10.0 on the CVSS scale and says it has no evidence that any of the four flaws is being

Cloud SecurityVulnerabilities
P0
2026-10-07 16:00 UTC
Vendor Research

Cisco Advance Notification for Publication of October 7, 2026, Security Advisories

Cisco Security Advisories · indexed 2026-09-30 16:25 UTC

On October 7, 2026, the Cisco Product Security Incident Response Team (PSIRT) published the advisories that are listed in the following tables. To remediate the vulnerabilities that were disclosed on October 7, 2026, Cisco strongly recommends that customers upgrade to the fixed software that is indicated in the advisories. For more information about changes in Cisco PSIRT vulnerability disclosure, see Strengthening the Foundation: A Predictable, Customer-Focused Response to AI-Accelerated Vulne…

DFIRNetwork SecurityVulnerabilitiesCVE-2026-20032CVE-2026-20038CVE-2026-20173CVE-2026-76465CVE-2026-76471
P20
2026-10-07 16:00 UTC
Vendor Research

3 lessons from frontier AI vulnerability research

Microsoft Security Blog · Taesoo Kim · indexed 2026-10-07 16:50 UTC

Read how How Microsoft Security's FORGE Lab is scaling vulnerability research from Windows to the Linux kernel. The post 3 lessons from frontier AI vulnerability research appeared first on Microsoft Security Blog.

LinuxMicrosoftVulnerabilities
P0
4 5 6 7 8