IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 4,779 matching records.
AUTO-POLL // 2026-10-10 21:55 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P1 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 10

RANSOMWARE
P1
P1
COOL // 11 ARTICLES
FRI
Oct 9

RANSOMWARE
P4
P4
COOL // 67 ARTICLES
THU
Oct 8

RANSOMWARE
P3
P3
COOL // 62 ARTICLES
WED
Oct 7

RANSOMWARE
P5
P5
COOL // 86 ARTICLES
TUE
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
RESET
2026-09-03 19:47 UTC
Other

Cisco Fixed Critical RCE in Nexus 9000 Series Switches

Security Affairs · Pierluigi Paganini · indexed 2026-09-03 20:25 UTC

Cisco patched a critical Nexus 9000 vulnerability, CVE-2026-20212, allowing unauthenticated remote root code execution. Cisco has released patches for a critical flaw, tracked as tracked as CVE-2026-20212 (CVSS score of 9.8) in 10 Silicon One-based Nexus 9000 switches. The vulnerability could let an unauthenticated remote attacker execute code with root privileges. Cisco’s Technical Assistance Center […]

Network SecurityVulnerabilitiesCVE-2026-20212
P30
2026-09-03 19:42 UTC
Security Journalism

What We Missed: Did ShinyHunters 'Breach' ReliaQuest?

Dark Reading · Rob Wright, Alexander Culafi · indexed 2026-09-03 20:15 UTC

In this video conversation, Dark Reading editors discuss some of the news they didn't get a chance to cover, from the latest antics of ShinyHunters to new research about the prevalence (or lack thereof) of AI-generated malware.

Malware
P0
2026-09-03 19:30 UTC
Security Journalism

Large group of Serbian opposition, activist figures targeted with spyware

The Record · indexed 2026-09-03 19:45 UTC

At least 14 Serbians have been targeted with advanced spyware since December, with victims including a member of Parliament, a local opposition politician and student protesters, according to digital forensic researchers.

P0
2026-09-03 18:02 UTC
Security Journalism

ThreatsDay: CEO Phishing Kits, 5K Dropbox Account Hacks, OAuth Traps + 17 More Stories

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-03 19:15 UTC

The worst part is how normal these attacks look. A call from IT. A shared file. A trusted app. A simple request to click “Allow.” Why break in when someone might open the door? That idea runs through this edition. Attackers use real tools, fake login pages, old account links, and software guides that point to unsafe downloads. One wrong letter in a web address can be enough. There is also

Phishing
P0
2026-09-03 18:00 UTC
Vendor Research

The story behind the intelligence

Cisco Talos Intelligence Blog · Hazel Burton · indexed 2026-09-03 18:05 UTC

From engaging with cybercriminals to surviving a live Flamin’ Hot Cheetos taste test, Hazel reflects on the latest Beers with Talos with Azim, where they cover the full spectrum of what it takes to gather threat intel.

P0
2026-09-03 17:23 UTC
Security Journalism

What the AI Warning Letter Completely Missed

Dark Reading · James Lyne · indexed 2026-09-04 17:45 UTC

The recent open letter is right about the "window," but it omits naming who is coming through it or, critically, who will close it.

P0
2026-09-03 16:00 UTC
Vendor Research

ASCII smuggling crosses over from AI prompt injection to phishing evasion

Microsoft Security Blog · Microsoft Security Research, Noam Kochavi and Sarah Wolstencroft · indexed 2026-09-03 16:45 UTC

Invisible Unicode characters popularized for hiding instructions from AI models are now being used to obfuscate words before email filters parse them. The post ASCII smuggling crosses over from AI prompt injection to phishing evasion appeared first on Microsoft Security Blog.

AI SecurityMicrosoftPhishing
P0
2026-09-03 15:52 UTC
Security Journalism

Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-03 16:45 UTC

Cisco has released patches to address a critical security flaw affecting 10 Silicon One-based Nexus 9000 switches that could allow an unauthenticated, remote attacker to execute code as root, alongside an IOS XR hardening release bundling 7 umbrella CVEs, 2 of which are rated 9.8, with no workaround for any IOS XR version. The Nexus vulnerability, tracked as CVE-2026-20212 (CVSS score: 9.8), is

AppleNetwork SecurityVulnerabilitiesCVE-2026-20212
P5
2026-09-03 15:26 UTC
Security Journalism

BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-03 16:45 UTC

Cybersecurity researchers have disclosed details of a sophisticated Python-based Windows malware framework called BraZetsu that fuels an underground marketplace commercializing access to compromised hosts. "Unlike the standard infostealer model, BraZetsu is a comprehensive master toolkit that empowers Initial Access Brokers (IABs) by turning compromised systems into highly valuable commercial

CybercrimeMalwareMicrosoftSecurity Research
P0
2026-09-03 15:02 UTC
Security Journalism

Anthropic confirms Claude is down, multiple models affected

BleepingComputer · Mayank Parmar · indexed 2026-09-03 15:10 UTC

Claude is experiencing an outage, with users encountering elevated errors when sending requests to multiple Anthropic AI models. [...]

P0
2026-09-03 14:39 UTC
Security Journalism

Thomson Reuters Court Software Breach May Have Exposed SSNs and Sealed Data

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-03 16:45 UTC

Thomson Reuters disclosed on Wednesday that an unauthorized party obtained files from C-Track, the court case management platform sold by its West Publishing Corporation unit, in March 2026, affecting courts in 11 U.S. states, the U.S. Virgin Islands, and Ontario, Canada. West Publishing said it discovered the activity on June 30, 2026. A subset of court records could contain individuals' names

P0
2026-09-03 14:38 UTC
Security Journalism

AI 'Machine Speed' Cuts 2-Week Attack Down to 10 Hours

Dark Reading · Elizabeth Montalbano · indexed 2026-09-03 15:00 UTC

The incident demonstrates how frontier AI agents can dramatically compress an attack timeline and coordinate a large-scale breach, according to researchers.

AI Security
P0
2026-09-03 13:50 UTC
Security Journalism

Your Employee’s Password Appeared in an Infostealer Log. Now What?

BleepingComputer · Sponsored by Flare · indexed 2026-09-03 14:00 UTC

Infostealers can expose far more than passwords, including authenticated sessions that may let attackers bypass MFA. Flare explains how defenders can prioritize compromised identities, determine whether stolen access is still usable, and respond before it leads to account takeover. [...]

MalwareMicrosoft
P0
2026-09-03 13:17 UTC
Other

412,000 The Town 2025 Ticket Buyers’ Data Hits the Dark Web

Security Affairs · Pierluigi Paganini · indexed 2026-09-03 14:00 UTC

412,000 The Town 2025 festival buyer records are being sold for $10,000, with Brazil’s data openly marketed for bank fraud, loans and SIM registration. A seller on a Russian-language data-trading forum listed what they’re calling a Ticketmaster database on September 2, claiming over 412,000 Latin American purchase records with a heavy concentration of Brazilian data. […]

CybercrimeMicrosoft
P0
2026-09-03 13:00 UTC
Security Journalism

Shadow AI in Financial Services | Risk & Governance

Huntress · indexed 2026-09-08 13:30 UTC

Shadow AI is spreading faster than governance in financial services. See the risks, why blocking AI backfires, and how to build policies that work.

P0
2026-09-03 12:00 UTC
Security Journalism

US and Canadian court data exposed in Thomson Reuters breach

The Record · indexed 2026-09-03 12:15 UTC

Sealed court information and sensitive personal data were exposed in a breach of a Thomson Reuters records platform affecting courts in at least 12 U.S. states, the U.S. Virgin Islands and Canada.

P0
2026-09-03 12:00 UTC
Government

Cyber Brief 26-09 - August 2026

CERT-EU Threat Intelligence · indexed 2026-09-03 10:25 UTC

Cyber Briefs are monthly executive reports that aim to present an overview of the most relevant developments in cyber security, based exclusively on open sources, with a view to inform political leadership and senior management in its constituency. Additional information on any item in this Brief can be provided upon request. Cyber Briefs are TLP:CLEAR.

P0
2026-09-03 11:58 UTC
Security Journalism

US Becomes Top Target in RMM Phishing Campaign Spanning 46 Countries

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-03 12:45 UTC

An RMM phishing campaign initially associated with Canadian targeting due to its use of Canada Revenue Agency (CRA) tax forms as lures has turned out to be part of a broader campaign spanning 46 countries. Around 45% of observed activity was associated with the United States, making it the campaign's top geographic target. ANY.RUN research connected 601 cases to the wider operation, which uses

Phishing
P0
2026-09-03 11:02 UTC
Security Journalism

Plex warns users to patch security vulnerabilities immediately

BleepingComputer · Sergiu Gatlan · indexed 2026-09-03 11:15 UTC

Plex urged users this week to update their desktop clients and media servers immediately to patch multiple security vulnerabilities. [...]

P0
2026-09-03 10:43 UTC
Security Journalism

Attackers Turn Trusted Node.js Runtime Into Malware Delivery Tool in Targeted Attacks

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-03 11:30 UTC

Threat actors are leveraging the trusted Node.js JavaScript runtime in multiple cyber attacks as a way to deploy malicious payloads. According to a new report published by the Symantec Threat Hunter Team today, the attack method has been put to use in attacks targeting government departments, technology companies, and hotels since February 2026. "The technique's appeal is that node.exe (the

MalwareThreat Actors
P0
2026-09-03 10:36 UTC
Security Journalism

Shai-Hulud's Reach Just Grew to 469 Credential Locations. Here's What That Means

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-03 11:30 UTC

In early August, GitGuardian researchers found that a recent Shai-Hulud infostealer worm variant had evolved to scan for credentials across 469 locations across developer environments, Continuous Integration/Continuous Deployment (CI/CD) tooling, cloud configurations, and even AI tool configs. Earlier variants of the infostealer worm only checked 189 paths. The jump says a lot. Attackers have

Malware
P0
2026-09-03 10:00 UTC
Vendor Research

Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America

Palo Alto Networks Unit 42 · Reese Lewis and Sara McBroom · indexed 2026-09-03 10:20 UTC

Explore how attackers targeting Latin American entities use AI for data exfiltration and how basic OpSec errors allow defenders to disrupt operations. The post Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America appeared first on Unit 42.

Microsoft
P0
2026-09-03 09:52 UTC
Other

Chaotic Eclipse Releases Crowdstrike Falcon ZeroDay FalconFlank

Security Affairs · Pierluigi Paganini · indexed 2026-09-03 10:40 UTC

Chaotic Eclipse released FalconFlank, a PoC exploit for a Crowdstrike Falcon ZeroDay Elevation of Privileges Vulnerability Security researcher Chaotic Eclipse, also known as INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse, released a new zero-day exploit targeting Crowdstrike Falcon cybersecurity platform. The researcher named the exploit FalconFlank, it triggers a privilege escalation flaw. According to the researcher, FalconFlank abuses […]

Security ResearchVulnerabilities
P35
63 64 65 66 67