IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 4,779 matching records.
AUTO-POLL // 2026-10-10 21:25 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P1 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 10

RANSOMWARE
P1
P1
COOL // 11 ARTICLES
FRI
Oct 9

RANSOMWARE
P4
P4
COOL // 67 ARTICLES
THU
Oct 8

RANSOMWARE
P3
P3
COOL // 62 ARTICLES
WED
Oct 7

RANSOMWARE
P5
P5
COOL // 86 ARTICLES
TUE
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
RESET
2026-09-04 14:01 UTC
Security Journalism

39 New Methods That Compromise Passkey Authentication

BleepingComputer · Sponsored by Token · indexed 2026-09-04 14:15 UTC

Passkeys eliminate many password-based attacks, but researchers have documented 39 methods for compromising authentication built around them. Token explains how attackers can abuse authentication prompts, synced credentials, enrollment, recovery, and other trust boundaries without breaking FIDO2 cryptography. [...]

P0
2026-09-04 13:41 UTC
Other

PostgreSQL Hit by 12-Year-Old Vulnerability Allowing Server Takeover

Security Affairs · Pierluigi Paganini · indexed 2026-09-04 14:25 UTC

PostGREShell (CVE-2026-6471) is a 12-year-old PostgreSQL flaw that lets low-privileged attackers execute code and take over servers. Cyera researchers found a severe PostgreSQL vulnerability, dubbed PostGREShell and tracked as CVE-2026-6471 (CVSS score of 7.2). Present in releases dating back to 2014, the flaw can be exploited by attackers with low-level replication access to execute code, […]

VulnerabilitiesCVE-2026-6471
P5
2026-09-04 12:34 UTC
Security Journalism

G7 urges organizations to prepare for quantum cyber threats

The Record · indexed 2026-09-04 12:55 UTC

In a joint advisory released Thursday, the G7 Cyber Security Working Group and the U.S. Cybersecurity and Infrastructure Security Agency, CISA, said organizations should begin moving to post-quantum cryptography now.

P0
2026-09-04 12:15 UTC
Security Journalism

Insurers Search for Answers to Rein in Rogue AI

Dark Reading · Robert Lemos · indexed 2026-09-04 21:40 UTC

As incidents of unintended harm caused by rogue AI agents mount, CISOs and insurance firms are figuring out how to handle the fallout.

AI Security
P0
2026-09-04 12:00 UTC
Vendor Research

DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors

Rapid7 · Rapid7 Intelligence · indexed 2026-09-04 12:25 UTC

OverviewA new Linux toolkit, identified by Rapid7 Labs, has been targeting organizations across South Korea’s automotive and media industries with minimal detection. The campaign made use of a HAProxy instance named “ted backdoor”, alongside trojanized versions of crond, agetty, atd, sshd, and polkitd. This previously undocumented framework enabled threat actors to execute remote commands on compromised servers, inject malicious scripts into web traffic, perform credential harvesting, and engag…

APT / Nation-StateLinuxMalwarePhishingThreat ActorsVulnerabilities
P15
2026-09-04 11:00 UTC
Other

Chinese Hackers Use AI Agents in Multi-Country Cyber Campaign

Security Affairs · Pierluigi Paganini · indexed 2026-09-04 11:10 UTC

Hunt.io uncovered a Chinese-speaking campaign using AI agents to automate cyberattacks against Asian government, education and industrial targets. Threat intelligence firm Hunt.io just documented a second, separate China-linked campaign wiring commercial AI models directly into live cyberespionage operations, this time hitting Taiwan’s Kuomintang Party archives, Indonesia’s Ministry of Foreign Affairs, government and education systems in […]

AI SecurityAPT / Nation-StateThreat Intelligence
P0
2026-09-04 08:48 UTC
Security Journalism

Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-04 09:40 UTC

Threat actors are exploiting two critical security flaws in WordPress plugins Super Forms and Elementor Pro, according to findings from Wordfence. The vulnerabilities in question are - CVE-2026-14894 (CVSS score: 9.8) - A missing file type validation vulnerability in Super Forms – Drag & Drop Form Builder that allows unauthenticated attackers to upload files of any type, including

Cloud SecurityThreat ActorsVulnerabilitiesCVE-2026-14894
P20
2026-09-04 08:24 UTC
Other

Google fixes the sixth actively exploited Chrome zero-day of 2026

Security Affairs · Pierluigi Paganini · indexed 2026-09-04 08:50 UTC

Google patched 12 Chrome flaws, including an actively exploited V8 zero-day that could enable remote code execution through a crafted webpage. Google released a Chrome security update fixing 12 vulnerabilities, including CVE-2026-85046 (CVSS score of 8.8), an actively exploited V8 type confusion flaw. The bug affects Chrome’s JavaScript and WebAssembly engine and could let a […]

Cloud SecurityVulnerabilitiesCVE-2026-85046
P45
2026-09-04 07:35 UTC
Security Journalism

Plex Urges Immediate Updates After Patching Multiple Undisclosed Security Flaws

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-04 08:40 UTC

Plex is urging users to update their instances to the latest version following the release of an update that patches multiple security flaws. The fixes are available in Plex Media Server 1.43.3 and Plex Desktop 1.115.0. The streaming media service did not elaborate on what those issues are, but said CVE identifiers have been requested for them. "We recommend all server owners and Desktop users

Cloud Security
P0
2026-09-04 07:18 UTC
Security Journalism

Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-04 08:40 UTC

Google on Thursday released security updates to patch 12 vulnerabilities, including one that has come under active exploitation in the wild. The high-severity vulnerability, tracked as CVE-2026-85046 (CVSS score: 8.8), has been described as a type confusion bug in V8, Chrome's JavaScript and WebAssembly engine. "Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote

VulnerabilitiesCVE-2026-85046
P50
2026-09-04 07:02 UTC
Other

Dark Web Service Nexus Sells 153M+ Driver’s Licenses

Security Affairs · Pierluigi Paganini · indexed 2026-09-04 07:55 UTC

FBI probes suspected breach at IDScan.net after dark web service Nexus offered 153M+ US and Canadian driver’s license scans. A dark web identity theft service called Nexus appeared on September 1, 2026, offering searchable access to more than 153 million scanned driver’s licenses belonging to people in the United States and Canada. The FBI’s New […]

CybercrimeLaw Enforcement
P0
2026-09-04 06:57 UTC
Other

One Adversary: The 90-Day Fusion Playbook

Group-IB · indexed 2026-09-07 17:30 UTC

Fusion is a capability you mature into, not a team you hire. Here is the honest maturity path, the metrics that fund it, and the on-ramp that costs no headcount, startable this quarter.

Vulnerabilities
P25
2026-09-04 06:47 UTC
Security Journalism

GPT-6 Astra Scores 100% on ExploitBench as OpenAI Blocks PoC Exploit Requests

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-04 08:40 UTC

OpenAI on Thursday officially unveiled GPT‑6 Astra, which it described as the "world's most intelligent and aligned model." The development comes days after the artificial intelligence (AI) company said the model had reached the "Critical" cybersecurity capability threshold under its Preparedness Framework. "Astra is state-of-the-art on computer use, browsing, software engineering,

AI SecuritySecurity Research
P0
2026-09-03 22:01 UTC
Security Journalism

French hospital fined €500,000 after breach exposes data of 727,000

BleepingComputer · Bill Toulas · indexed 2026-09-03 22:10 UTC

France's data protection authority (CNIL) has fined Hôpital privé de la Loire €500,000 ($580,000) for failing to adequately protect patients' and their relatives' data. [...]

P0
2026-09-03 21:22 UTC
Security Journalism

Managed EDR: What It Is & How to Choose a Provider

Huntress · indexed 2026-09-07 17:30 UTC

Huntress breaks down what managed EDR is, how it differs from unmanaged, and what to look for when choosing a provider for your business.

P0
2026-09-03 21:15 UTC
Vendor Research

Incident response guide for AWS CloudTrail investigations – Part 2

AWS Security Blog · Oscar Diaz · indexed 2026-09-03 21:35 UTC

In Part 1 of this guide, we examined two common incident scenarios: cross-account Amazon Simple Storage Service (Amazon S3) data deletion with ransomware implications, and cryptocurrency mining deployed through AWS CloudFormation using exposed AWS Management Console credentials. We also introduced key incident response terminology and investigative frameworks for analyzing AWS CloudTrail events. In this second […]

AppleCloud SecurityDFIRRansomware
P15
2026-09-03 21:15 UTC
Vendor Research

Incident response guide for AWS CloudTrail investigations – Part 1

AWS Security Blog · Oscar Diaz · indexed 2026-09-03 21:35 UTC

AWS CloudTrail logs contain the evidence you need when investigating suspicious activity in your AWS environment, but knowing which fields matter and how to interpret them can mean the difference between surface-level analysis and uncovering the full scope of an incident. This guide walks you through real-world scenarios, showing you how to analyze CloudTrail events […]

AppleCloud SecurityDFIR
P0
2026-09-03 21:03 UTC
Vendor Research

Introducing context-aware vulnerability discovery and remediation with Cloudflare Managed Defense and OpenAI Daybreak models

Cloudflare Security · Ken Sanderson · indexed 2026-09-03 21:05 UTC

Use production traffic and security signals to prioritize findings, prepare edge mitigations when safe, and propose code patches. By combining WAF data with OpenAI Daybreak models, Vulnerability Discovery and Remediation helps teams identify and patch the most critical threats first.

Vulnerabilities
P0
2026-09-03 20:17 UTC
Other

Pegasus and NoviSpy Used Against Serbian Protesters

Security Affairs · Pierluigi Paganini · indexed 2026-09-03 20:25 UTC

Serbian activists were targeted with zero-click Pegasus and NoviSpy spyware, exposing a major surveillance campaign ahead of elections. A member of Serbia’s student protest movement had their iPhone infected with NSO Group‘s Pegasus spyware without ever clicking a link or opening a file. The Citizen Lab confirmed the infection in collaboration with the SHARE Foundation, […]

Apple
P0
2026-09-03 20:04 UTC
Security Journalism

Coder's registry infrastructure compromised to push malicious modules

BleepingComputer · Bill Toulas · indexed 2026-09-03 20:15 UTC

Attackers compromised Coder's Cloudflare infrastructure and added unauthorized registry servers that delivered malicious Terraform modules containing credential-stealing code. [...]

P0
62 63 64 65 66