IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 4,779 matching records.
AUTO-POLL // 2026-10-10 23:15 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P1 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 10

RANSOMWARE
P1
P1
COOL // 11 ARTICLES
FRI
Oct 9

RANSOMWARE
P4
P4
COOL // 67 ARTICLES
THU
Oct 8

RANSOMWARE
P3
P3
COOL // 62 ARTICLES
WED
Oct 7

RANSOMWARE
P5
P5
COOL // 86 ARTICLES
TUE
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
RESET
2026-09-01 11:30 UTC
Security Journalism

Threat Actors Don’t Want Better Attacks. They Want Repeatable Ones

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-01 11:50 UTC

The most common way into a company last year was to ask. A web page tells the visitor to prove they are not a robot. While they read the instructions, it quietly places a command on their clipboard. Then it talks them through opening a terminal and pasting it in. The technique is called ClickFix, and it was the most common initial access method Microsoft’s team observed last year, accounting

MicrosoftThreat Actors
P0
2026-09-01 11:08 UTC
Other

North Korea-linked IT Workers Are Getting Hired Inside Western Companies

Security Affairs · Pierluigi Paganini · indexed 2026-09-01 11:20 UTC

Huntress found five DPRK-linked workers hired in 2026 using fake identities, remote-access setups and proxy tools to infiltrate legitimate companies. Companies keep accidentally hiring North Korea-linked individuals as remote workers, and Huntress just published the receipts. The security firm’s investigation documents five confirmed cases in 2026 alone where DPRK-aligned workers, tracked under the name FAMOUS […]

DFIR
P0
2026-09-01 09:34 UTC
Other

Chaotic Eclipse Releases Kaspersky Zero-Day HardBreacher

Security Affairs · Pierluigi Paganini · indexed 2026-09-01 10:20 UTC

Chaotic Eclipse released HardBreacher, a PoC exploit for a Kaspersky Endpoint Security privilege escalation flaw, adding another zero-day to his list. Security researcher Chaotic Eclipse, also known as INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse, released a new zero-day exploit targeting Kaspersky Endpoint Security. The researcher named the exploit HardBreacher, it triggers a privilege escalation flaw. Nightmare Eclipse […]

Security ResearchVulnerabilities
P35
2026-09-01 09:05 UTC
Security Journalism

Attackers Steal METR API Key and Consume AI Credits Worth About $600,000

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-01 10:35 UTC

METR (short for Model Evaluation and Threat Research and pronounced "Meter"), a research non-profit that evaluates frontier artificial intelligence (AI) models for their ability to carry out long-horizon, agentic tasks, disclosed that it suffered "two notable security incidents" where external actors attempted to gain unauthorized access to its systems. No sensitive information is believed to

AI Security
P0
2026-09-01 08:26 UTC
Security Journalism

Russia-Aligned UAC-0099 Plants Nuclear Weapon Prompt in Malware to Disrupt AI Analysis

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-01 08:55 UTC

Cybersecurity researchers have disclosed a new technique dubbed GuardBreaker that's been put to use by a Russia-aligned threat actor known as UAC-0099 against a target in Ukraine with an aim to interfere with artificial intelligence (AI)-assisted analysis. The idea, ESET said in a series of posts on X, is to deliberately trip a large language model's (LLM) safety mechanisms and prevent its

AI SecurityMalwareSecurity ResearchThreat Actors
P0
2026-09-01 08:13 UTC
Other

U.S. CISA adds PaperCut NG/MF flaws to its Known Exploited Vulnerabilities catalog

Security Affairs · Pierluigi Paganini · indexed 2026-09-01 09:05 UTC

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds PaperCut NG/MF flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: PaperCut, the print management software running in schools, hospitals, and offices worldwide, recently confirmed that a pre-authentication remote code execution flaw, tracked as CVE-2026-81578, […]

Cloud SecurityVulnerabilitiesCVE-2026-81578
P50
2026-09-01 07:22 UTC
Security Journalism

Attackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 Activity

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-01 08:00 UTC

Threat actors are exploiting two critical flaws impacting Langflow and Ruby on Rails, according to new findings from VulnCheck. The vulnerabilities in question are listed below - CVE-2026-0768 (CVSS score: 9.8) - A lack of proper validation of a user-supplied input vulnerability that could be exploited to execute arbitrary Python code in the context of the root user. CVE-2026-66066 aka

Cloud SecurityThreat ActorsVulnerabilitiesCVE-2026-0768CVE-2026-66066
P15
2026-08-31 20:47 UTC
Security Journalism

Cronos blockchain restarts after $74 million Tectonic exploit

BleepingComputer · Bill Toulas · indexed 2026-08-31 21:00 UTC

The Cronos blockchain network has resumed trading activity after a price-manipulation attack on the Tectonic cryptocurrency lending platform allowed an attacker to borrow $74 million. [...]

P0
2026-08-31 20:00 UTC
Community

The Coding-Agent Trap: When a "Free" LLM Endpoint Is the Adversary, (Mon, Aug 31st)

SANS Internet Storm Center · indexed 2026-08-31 20:10 UTC

One of my internet-exposed inference honeypots was discovered, relabeled with sought-after model names, and incorporated into infrastructure apparently used to provide "free" LLM backends. It then received a real coding-agent session — history, filesystem output, working paths, and the agent's local tool manifest. The honeypot did not request or cause any tool execution; what the request exposed is what a malicious operator in that position could do.

AI Security
P0
2026-08-31 19:45 UTC
Other

ValleyRAT: When Legitimate Software Becomes a Malware Delivery Tool

Security Affairs · Pierluigi Paganini · indexed 2026-08-31 20:50 UTC

ValleyRAT hides behind legitimate adware, using DLL sideloading to evade detection, steal data and give Silver Fox control of infected systems. ValleyRAT doesn’t always need to disguise itself as a cracked game or a fake browser update. It can also hide behind something much more ordinary: an application that looks like adware and appears to […]

Malware
P0
2026-08-31 19:00 UTC
Vendor Research

We invited a direct competitor into Security Hub Extended. Here’s why.

AWS Security Blog · Michael Fuller · indexed 2026-08-31 19:05 UTC

When customers keep pointing you to a solution that overlaps with parts of your own offering, you have a choice to make. This post is about the choice we made with Upwind, and why we’d make it again. AWS Security Hub Extended exists because customers told us what was working for them in enterprise security […]

Cloud Security
P0
2026-08-31 18:51 UTC
Security Journalism

Microsoft warns of TerminalFix attacks deploying reverse tunnels

BleepingComputer · Bill Toulas · indexed 2026-08-31 19:05 UTC

A new ClickFix variant dubbed TerminalFix uses fake Cloudflare CAPTCHA prompts on compromised websites to trick victims into running malicious PowerShell commands in Windows Terminal. [...]

Microsoft
P0
2026-08-31 17:34 UTC
Security Journalism

AI Model Rules Are Not Security Controls

Dark Reading · Jacob Krell · indexed 2026-08-31 17:55 UTC

OpenAI's Hugging Face attack postmortem shows agents don't care about rules — they need strong controls.

P0
2026-08-31 17:24 UTC
Security Journalism

North Korean Job Fraud Expands Beyond IT Into Healthcare and Sales

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-31 18:05 UTC

Threat actors with ties to the Democratic People's Republic of Korea (aka DPRK or North Korea) have been observed seeking job opportunities beyond the information technology (IT) sector, with recent investigations identifying suspected workers employed in sales and marketing and the medical profession. The ongoing insider threat is part of what has been described as the IT worker scheme,

CybercrimeDFIRThreat Actors
P0
2026-08-31 17:18 UTC
Vendor Research

Automate IAM Identity Center governance with continuous discovery and reporting

AWS Security Blog · Jonathan Nguyen · indexed 2026-08-31 17:20 UTC

AWS IAM Identity Center integrates with external identity provider (IdP) to provide customers with a centralized authentication and authorization solution for AWS resources across AWS Organizations. AWS continues to invest into IAM Identity Center with a growing number of AWS services that natively integrate with IAM Identity Center. As your AWS organization scales, maintaining visibility […]

Cloud SecurityMicrosoft
P0
2026-08-31 17:07 UTC
Vendor Research

GCP Apigee PE to Service Agent with API Proxy

Tenable Research Advisories · Joshua Martinelle · indexed 2026-08-31 19:05 UTC

GCP Apigee PE to Service Agent with API Proxy Tenable Research has identified and responsibly disclosed a privilege escalation vulnerability in Google Cloud Apigee. This vulnerability allowed an attacker with restricted Apigee permissions to exfiltrate the OAuth access token of the privileged Apigee Core Service Agent.The vulnerability stems from Apigee API Proxies' ability to execute custom JavaScript policy scripts that can access the underlying Instance Metadata Service (IMDS).An attacker wi…

Cloud SecuritySecurity ResearchVulnerabilities
P10
2026-08-31 16:50 UTC
Security Journalism

OpenAI confirms ChatGPT outage as users report errors

BleepingComputer · Mayank Parmar · indexed 2026-08-31 17:00 UTC

ChatGPT Work is experiencing a partial outage, and users across multiple subscription plans may be unable to start or continue tasks. [...]

P0
67 68 69 70 71