IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 4,779 matching records.
AUTO-POLL // 2026-10-10 20:20 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P1 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 10

RANSOMWARE
P1
P1
COOL // 11 ARTICLES
FRI
Oct 9

RANSOMWARE
P4
P4
COOL // 67 ARTICLES
THU
Oct 8

RANSOMWARE
P3
P3
COOL // 62 ARTICLES
WED
Oct 7

RANSOMWARE
P5
P5
COOL // 86 ARTICLES
TUE
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
RESET
2026-09-08 10:37 UTC
Security Journalism

N-able Patches Critical Zero-Day in N-central

Security Week · Ionut Arghire · indexed 2026-09-08 10:50 UTC

Administrators are advised to check their deployments for newly created user accounts they don’t recognize. The post N-able Patches Critical Zero-Day in N-central appeared first on SecurityWeek.

MicrosoftVulnerabilities
P25
2026-09-08 10:00 UTC
Vendor Research

StyleSmuggler (CVE-2026-75650): Frequently asked questions about Adobe Commerce and Magento zero-day

Tenable Cyber Exposure Alerts · Satnam Narang · indexed 2026-09-08 14:20 UTC

A critical unauthenticated remote code execution (RCE) zero-day in Adobe Commerce and Magento Open Source, dubbed StyleSmuggler, has been actively exploited since September 4 with attacks observed three days before a vendor patch became available.Key takeawaysCVE-2026-75650 is a critical remote code execution vulnerability in Adobe Commerce, Adobe Commerce B2B and Magento Open Source that can be triggered without authentication.Active exploitation of CVE-2026-75650 began on September 4, 2026, t…

DFIRLinuxMalwareThreat ActorsThreat IntelligenceVulnerabilitiesCVE-2026-75650
P95
2026-09-08 10:00 UTC
Vendor Research

ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2

Cisco Talos Intelligence Blog · Sean Gallagher · indexed 2026-09-08 10:30 UTC

Cisco Talos is tracking a cryptocurrency-stealing campaign that abuses the Google Visualization API for command and control (C2), retrieving obfuscated JavaScript from a publicly published Google Sheets document and injecting it into the victim's browser session.

P0
2026-09-08 09:13 UTC
Security Journalism

Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-08 10:00 UTC

Adobe on Monday released security patches to address a maximum-severity flaw impacting Adobe Commerce and Magento Open Source that has come under active exploitation in the wild. The vulnerability, now tracked as CVE-2026-75650 (CVSS score: 10.0), has been codenamed StyleSmuggler by Sansec, which discovered zero-day exploitation starting September 4, 2026. "This update resolves a critical

MalwareVulnerabilitiesCVE-2026-75650
P50
2026-09-08 09:11 UTC
Other

North Korea-linked Hackers Hide a Backdoor Inside HAProxy

Security Affairs · Pierluigi Paganini · indexed 2026-09-08 10:10 UTC

North Korea-linked hackers hid a backdoor inside HAProxy, masking C2 traffic and stealing data while keeping the load balancer working normally. North Korean-linked hackers found a genuinely clever hiding spot for their malware: inside the actual source code of HAProxy, the load balancing software running at the edge of two South Korean companies’ networks. Rapid7’s […]

Malware
P0
2026-09-08 08:43 UTC
Security Journalism

BengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support Scams

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-08 10:00 UTC

Cybersecurity researchers have disclosed details of a sprawling search engine optimization (SEO) poisoning campaign that paves the way for malware deployment and tech support scams. The campaign, discovered by the DFIR Report in March 2026, has been codenamed BengalSEO. It has operated out of the Indian state of Rajasthan since at least 2015, driven by two IT service providers named WeConnect

DFIRMalwareSecurity Research
P0
2026-09-08 07:41 UTC
Other

IT Help Desk Impersonation Lets Hackers Bypass MFA

Security Affairs · Pierluigi Paganini · indexed 2026-09-08 08:15 UTC

Attackers bypass endpoint security by posing as IT staff, stealing Microsoft 365 sessions, draining SaaS data and demanding extortion. Forget installing malware because today’s extortionists just pick up the phone instead of writing code. A widespread threat cluster tracked as PREY-0058 bypasses endpoint security entirely by targeting Microsoft 365 and SaaS environments through pure social […]

MalwareMicrosoft
P0
2026-09-08 07:35 UTC
Security Journalism

220 million traveler records exposed in Vietnam-linked APIS leak

BleepingComputer · Ax Sharma · indexed 2026-09-08 07:45 UTC

Exclusive: An exposed Advance Passenger Information System (APIS) database held 220 million passenger and crew records containing names, passport numbers, dates of birth, nationalities, and flight details spanning 2017 to 2026. Researchers accessed the Vietnam-linked system through a cloud-based path using default credentials. [...]

P0
2026-09-08 07:00 UTC
Security Journalism

Grindr to Pay £26 Million to Settle U.K. Claims Over HIV Status Data Sharing

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-08 08:20 UTC

Online dating app Grindr has opted to pay £26 million ($35.1 million) to settle a lawsuit in the U.K. over allegations that it shared users' personal information, including their HIV status, with third-parties. Grindr, which is the largest LGBTQ+ dating app, was sued in April 2024, accusing it of violating U.K. privacy laws by sharing sensitive data for commercial purposes such as advertising.

Cloud Security
P0
2026-09-08 05:00 UTC
Other

ZDI-26-622: Microsoft Windows IKEv2 AES-GCM Decryption Integer Underflow Remote Code Execution Vulnerability

Zero Day Initiative · indexed 2026-09-08 21:50 UTC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Windows. Authentication is not required to exploit this vulnerability, but only systems with specific IPsec configurations are vulnerable. The ZDI has assigned a CVSS rating of 8.1. The following CVEs are assigned: CVE-2026-50696.

MicrosoftVulnerabilitiesCVE-2026-50696
P20
2026-09-08 05:00 UTC
Other

ZDI-26-621: Microsoft Windows UMPDDrvRealizeBrush Improper Object Management Local Privilege Escalation Vulnerability

Zero Day Initiative · indexed 2026-09-08 21:50 UTC

This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-62712.

MicrosoftVulnerabilitiesCVE-2026-62712
P15
2026-09-08 05:00 UTC
Other

ZDI-26-620: Microsoft Windows UMPDDrvPlgBlt Improper Object Management Local Privilege Escalation Vulnerability

Zero Day Initiative · indexed 2026-09-08 21:50 UTC

This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-62712.

MicrosoftVulnerabilitiesCVE-2026-62712
P15
2026-09-08 05:00 UTC
Other

ZDI-26-619: Microsoft Windows UMPDDrvStretchBltROP Improper Object Management Local Privilege Escalation Vulnerability

Zero Day Initiative · indexed 2026-09-08 21:50 UTC

This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-62712.

MicrosoftVulnerabilitiesCVE-2026-62712
P15
2026-09-08 05:00 UTC
Other

ZDI-26-618: Microsoft Windows UMPDDrvStretchBlt Improper Object Management Local Privilege Escalation Vulnerability

Zero Day Initiative · indexed 2026-09-08 21:50 UTC

This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-62712.

MicrosoftVulnerabilitiesCVE-2026-62712
P15
2026-09-08 05:00 UTC
Other

ZDI-26-617: Microsoft Windows MIDI Service Incorrect Permission Assignment Local Privilege Escalation Vulnerability

Zero Day Initiative · indexed 2026-09-08 21:50 UTC

This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-66804.

MicrosoftVulnerabilitiesCVE-2026-66804
P15
2026-09-08 04:00 UTC
Security Journalism

AD Rights Management Service (Part 1): Architecture, Deprecation, and Reconnaissance

Huntress · indexed 2026-09-08 13:30 UTC

Active Directory Rights Management Services still ships in Windows Server 2025, years after Microsoft began steering customers to the cloud, and it remains fully supported on-premises. Part 1 maps the AD RMS trust model (the Server Licensor Certificate, the license flow, the SOAP surface) and shows how to discover an RMS deployment, fingerprint an AD RMS-protected file, and trace the path to that certificate's private key.

Microsoft
P0
2026-09-07 19:40 UTC
Other

Condé Nast Data of 32.8 Million Users Offered for Sale After WIRED Leak

Security Affairs · Pierluigi Paganini · indexed 2026-09-07 19:55 UTC

Condé Nast user data from 32.8 million accounts is reportedly for sale, raising risks of targeted phishing, fraud and scams. A database said to contain 32.8 million Condé Nast user records is being offered for $15,000 on a Russian-language cybercrime forum. Ransomnews reviewed a 5,000-record sample and concluded that it is consistent with genuine Condé […]

CybercrimePhishing
P0
2026-09-07 18:12 UTC
Security Journalism

PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-07 18:40 UTC

Cybersecurity researchers have disclosed details of a complex Chromium-based post-exploitation toolkit called PEEP that masquerades as a bookmarks extension for the web browser. "Requiring prior administrative or code execution access, its installer injects the extension directly into Chrome/Edge profiles, bypassing Web Store checks and user prompts by forging Chromium's own Secure Preferences

MalwareSecurity Research
P0
2026-09-07 17:49 UTC
Other

StyleSmuggler: The Magento Zero-Day Behind New Store Attacks

Security Affairs · Pierluigi Paganini · indexed 2026-09-07 18:00 UTC

StyleSmuggler Magento zero-day is under active attack, letting unauthenticated attackers execute code and install backdoors on stores that may already be patched. A new zero-day flaw, dubbed StyleSmuggler, in Magento and Adobe Commerce is under active attack, giving unauthenticated attackers a path to run code on vulnerable online stores. Sansec researchers say it affects current […]

MalwareVulnerabilities
P25
2026-09-07 15:51 UTC
Security Journalism

Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-07 16:10 UTC

Threat hunters have disclosed details of a widespread data theft and extortion threat cluster that's targeting Microsoft 365 and other software-as-a-service (SaaS) offerings through information technology (IT) help desk vishing, adversary-in-the-middle (AitM) token theft, and residential-proxy sign-ins. The activity, which mainly singles out directors, vice presidents, and other executive staff

Microsoft
P0
2026-09-07 14:54 UTC
Other

7th September – Threat Intelligence Report

Check Point Research · urias@checkpoint.com · indexed 2026-09-07 17:30 UTC

For the latest discoveries in cyber research for the week of 7th Setpember, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Thomson Reuters, a global information and technology company, has disclosed a breach of its C-Track court case-management platform affecting courts across 11 US states and Canada. An unauthorized party obtained C-Track files […] The post 7th September – Threat Intelligence Report appeared first on Check Point Research.

Threat Intelligence
P0
2026-09-07 14:36 UTC
Security Journalism

⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-07 16:10 UTC

Turning off email images should at least stop the pictures. This week, attackers had a workaround: a scannable QR code built out of text. It still appears, even with images blocked. A small detail, but an annoying one if that was a precaution you were counting on. Elsewhere, a trusted software source delivered code that stole credentials, and a protocol designed for secure network management

Network SecurityVulnerabilities
P25
2026-09-07 14:00 UTC
Security Journalism

AI SIEM Search

Huntress · indexed 2026-09-08 13:30 UTC

The new Huntress AI SIEM search feature lets you find answers in plain English, with no query language fluency required. Ask questions, get results, and skip the syntax.

P0
59 60 61 62 63