IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 4,779 matching records.
AUTO-POLL // 2026-10-10 21:05 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P1 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 10

RANSOMWARE
P1
P1
COOL // 11 ARTICLES
FRI
Oct 9

RANSOMWARE
P4
P4
COOL // 67 ARTICLES
THU
Oct 8

RANSOMWARE
P3
P3
COOL // 62 ARTICLES
WED
Oct 7

RANSOMWARE
P5
P5
COOL // 86 ARTICLES
TUE
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
RESET
2026-09-06 08:27 UTC
Other

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 113

Security Affairs · Pierluigi Paganini · indexed 2026-09-06 08:55 UTC

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Hackers Steal Claude Login Sessions With Infostealer Malware to Hijack Accounts Fire Ant Evolves: From Hypervisors to Trusted Infrastructure Gryxa: The AI-Built Toolkit That Watches How You Remove It ValleyRAT masquerading as adware […]

Malware
P0
2026-09-06 07:56 UTC
Other

Security Affairs newsletter Round 593 by Pierluigi Paganini – INTERNATIONAL EDITION

Security Affairs · Pierluigi Paganini · indexed 2026-09-06 08:55 UTC

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. PaperCut Flaws Exploited in Attacks on U.S. and European Schools Broadcom Patches Critical VMware Workstation and Fusion […]

Cloud Security
P20
2026-09-05 21:14 UTC
Other

OpenAI Announced $1B in Defensive Tools for Water Utilities

Security Affairs · Pierluigi Paganini · indexed 2026-09-05 21:50 UTC

OpenAI pledges $1B in subsidized Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. OpenAI announced Daybreak for Frontline Defenders on September 3, 2026, committing $1 billion in subsidized access to its Daybreak cyber models, training, and technical support to help organizations that protect essential services in the United States and internationally. “A $1 billion […]

Microsoft
P0
2026-09-05 20:14 UTC
Security Journalism

Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-05 20:50 UTC

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is

MalwareVulnerabilities
P25
2026-09-05 18:47 UTC
Other

PaperCut Flaws Exploited in Attacks on U.S. and European Schools

Security Affairs · Pierluigi Paganini · indexed 2026-09-05 19:35 UTC

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed threat […]

Cloud SecurityVulnerabilitiesCVE-2026-81578CVE-2026-82078
P25
2026-09-05 16:52 UTC
Security Journalism

Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-05 16:55 UTC

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.

Cloud SecurityThreat ActorsVulnerabilities
P10
2026-09-05 16:05 UTC
Security Journalism

Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-05 16:55 UTC

Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an integer-overflow vulnerability that a local attacker with elevated privileges can exploit to run arbitrary code. "A

Cloud SecurityVulnerabilitiesCVE-2026-59346
P5
2026-09-05 14:29 UTC
Security Journalism

Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain

BleepingComputer · Bill Toulas · indexed 2026-09-05 14:30 UTC

A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC). [...]

P0
2026-09-05 14:17 UTC
Security Journalism

Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was Deleted

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-05 15:30 UTC

Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk. The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware wallets

P0
2026-09-05 11:11 UTC
Security Journalism

OpenAI admits it didn't disclose rogue AI wiki hijacking incident

BleepingComputer · Ax Sharma · indexed 2026-09-05 11:25 UTC

OpenAI admits it did not disclose an incident where autonomous AI agents hijacked a German wiki, created 18,000 posts, shared answers, and bypassed restrictions, saying it treated the activity as model "misalignment" rather than a security breach. [...]

AI Security
P0
2026-09-05 07:55 UTC
Security Journalism

Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordination Channel

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-05 08:55 UTC

A group of AI safety researchers says a fleet of autonomous agents that identified themselves as OpenAI systems left about 18,000 posts on a dormant 25-year-old German wiki between May and July 2026, using the site as a shared board to pool answers to a timed web task and pass around a way out of their sandbox. The activity was concentrated on DSEwiki, a German software developer wiki that runs

AI SecurityMicrosoft
P0
2026-09-05 07:31 UTC
Security Journalism

Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-05 07:45 UTC

Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe. The Arctic Wolf Adversary Research Team said it observed attackers exploiting CVE-2026-81578 and CVE-2026-82078 – an authentication bypass and remote code execution chain – to conduct command execution and reconnaissance, as well as

Cloud SecurityPhishingThreat ActorsVulnerabilitiesCVE-2026-81578CVE-2026-82078
P30
2026-09-05 04:54 UTC
Other

Broadcom Patches Critical VMware Workstation and Fusion VM-Escape Vulnerabilities

Security Affairs · Pierluigi Paganini · indexed 2026-09-05 06:00 UTC

Broadcom patched two VMware Workstation/Fusion VM-escape bugs. No workarounds exist. Update to version 26H1u1 immediately. Broadcom published advisory VMSA-2026-0007, patching two vulnerabilities in VMware Workstation and Fusion that allow an attacker inside a virtual machine to execute code on the underlying host. One is rated Critical. Neither has a workaround. The first vulnerability, tracked as […]

Vulnerabilities
P0
2026-09-04 22:50 UTC
Other

U.S. CISA adds Google Chromium V8 flaw to its Known Exploited Vulnerabilities catalog

Security Affairs · Pierluigi Paganini · indexed 2026-09-04 23:15 UTC

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Google Chromium V8 flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Google Chromium V8 flaw, tracked as CVE-2026-85046 (CVSS score of 8,8), to its Known Exploited Vulnerabilities (KEV) catalog. This week, Google released a Chrome security update fixing 12 […]

VulnerabilitiesCVE-2026-85046
P35
2026-09-04 19:10 UTC
Vendor Research

How to secure edge AI in customer-owned environments

Microsoft Security Blog · Shayak Lahiri · indexed 2026-09-04 20:30 UTC

As AI moves into customer-owned environments, organizations need new ways to verify the systems, software, and AI assets they trust before releasing sensitive data, credentials, and models. The post How to secure edge AI in customer-owned environments appeared first on Microsoft Security Blog.

Microsoft
P0
2026-09-04 18:30 UTC
Other

Crooks Behind Manchester Airports Group Hack Leaked Data of 8.8 Million People

Security Affairs · Pierluigi Paganini · indexed 2026-09-04 18:55 UTC

Manchester Airports Group (MAG) data allegedly leaked by FulcrumSec exposes emails and phone numbers of 8.8 million people. Manchester Airports Group, which operates Manchester, London Stansted and East Midlands airports, has confirmed a data breach involving customer information held in a third-party database. The company says airport operations, passenger safety and aviation security were not […]

Data Breaches
P0
2026-09-04 18:13 UTC
Vendor Research

OSPAR 2026 report now available with 167 services in scope

AWS Security Blog · James Chang · indexed 2026-09-04 18:35 UTC

We’re pleased to confirm the successful completion of our annual Amazon Web Services (AWS) Outsourced Service Provider’s Audit Report (OSPAR) assessment on July 29, 2026, in line with the OSPAR version 2.0 framework. The Association of Banks in Singapore (ABS) established the Guidelines on Control Objectives and Procedures for Outsourced Service Providers (ABS Guidelines) to […]

Cloud Security
P0
2026-09-04 16:18 UTC
Security Journalism

In Other News: Microsoft’s Cloud Patches, Hacked Dropbox Accounts, Guardio’s $1.1B Valuation

Security Week · SecurityWeek News · indexed 2026-09-07 17:25 UTC

Noteworthy stories that might have slipped under the radar: Microsoft rolled out patches for cloud services, hackers compromised 5,000 Dropbox accounts, and Guardio is now valued at $1.1 billion. The post In Other News: Microsoft’s Cloud Patches, Hacked Dropbox Accounts, Guardio’s $1.1B Valuation appeared first on SecurityWeek.

Microsoft
P0
2026-09-04 16:11 UTC
Security Journalism

HPE Patches Critical RCE Vulnerabilities in AOS-CX

Security Week · Ionut Arghire · indexed 2026-09-07 17:25 UTC

Nearly two dozen issues, tracked collectively as CVE-2026-73749 (CVSS score of 9.8), were addressed with the updates. The post HPE Patches Critical RCE Vulnerabilities in AOS-CX appeared first on SecurityWeek.

VulnerabilitiesCVE-2026-73749
P20
2026-09-04 16:07 UTC
Security Journalism

OpenAI Pledges $1 Billion to Bring Frontier AI to Critical Infrastructure Defenders

Security Week · Kevin Townsend · indexed 2026-09-07 17:25 UTC

The Daybreak initiative will provide subsidized AI cyber capabilities, training and technical assistance, though OpenAI has disclosed few details about costs and eligibility. The post OpenAI Pledges $1 Billion to Bring Frontier AI to Critical Infrastructure Defenders appeared first on SecurityWeek.

Microsoft
P0
2026-09-04 15:57 UTC
Security Journalism

Companies Have 6 Months to Prepare for Automated Attacks

Dark Reading · Robert Lemos · indexed 2026-09-04 16:15 UTC

Frontier AI models have already demonstrated they can autonomously — and in some cases, inadvertently — conduct end-to-end compromises, but researchers warn the situation will become more urgent very soon.

P0
2026-09-04 15:57 UTC
Security Journalism

Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-04 16:10 UTC

Microsoft is alerting of a "high-volume phishing campaign" that's using invisible Unicode tag characters to bypass email filters. "Instead of using these characters to hide instructions from people while exposing them to AI models, the attacker used them to split financial lure words such as 'funding' to prevent email filters from parsing them," the Microsoft Security Research team said. The

MicrosoftPhishingSecurity Research
P0
2026-09-04 15:42 UTC
Security Journalism

US, Britain to coordinate on scam center takedowns

The Record · indexed 2026-09-04 16:00 UTC

The U.S. Department of Justice and the U.K.'s National Crime Agency and Crown Prosecutor signed a memorandum to cooperate on cases involving Southeast Asian scam operations.

Law Enforcement
P0
2026-09-04 15:20 UTC
Security Journalism

PostgreSQL Fixes 12-Year-Old Logical Decoding Flaw Enabling Replication-Role Code Execution

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-04 16:10 UTC

PostgreSQL has released updates to address a security flaw that allows an account with the REPLICATION attribute to run arbitrary code as the operating-system user running the database server. The flaw, tracked as CVE-2026-6471 (CVSS score: 7.2), has been present since logical decoding was introduced in PostgreSQL 9.4 in 2014. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are

VulnerabilitiesCVE-2026-6471
P5
2026-09-04 14:51 UTC
Security Journalism

New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-04 15:10 UTC

A previously undocumented Linux toolkit has been found compiled directly into the trojanized HAProxy load balancers of two South Korean organizations, where it intercepted web traffic and served altered pages to selected visitors. The attackers named the implant ted in debug strings left in the binary. It is not a HAProxy vulnerability, and installing it requires code execution on the host and

LinuxMalwareVulnerabilities
P0
2026-09-04 14:45 UTC
Security Journalism

UK account-hack losses surge as new reporting system exposes hidden cases

The Record · indexed 2026-09-04 15:00 UTC

In its first annual assessment, published Friday, the City of London Police said victims reported losing £6.3 million ($8.5 million) to account hacks in the year ending March 31, up from £1.2 million ($1.6 million) a year earlier.

P0
61 62 63 64 65