IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 4,763 matching records.
AUTO-POLL // 2026-10-09 22:10 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P5 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 9

RANSOMWARE
P5
P5
COOL // 62 ARTICLES
THU
Oct 8

RANSOMWARE
P3
P3
COOL // 62 ARTICLES
WED
Oct 7

RANSOMWARE
P5
P5
COOL // 86 ARTICLES
TUE
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
RESET
2026-10-07 16:00 UTC
Vendor Research

Cisco NX-OS Software Python Sandbox Escape Vulnerability

Cisco Security Advisories · indexed 2026-10-07 16:15 UTC

A vulnerability in the Python interpreter of Cisco NX-OS Software could allow an authenticated, local attacker with low privileges to escape the Python sandbox and gain unauthorized access to the underlying operating system of an affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by manipulating specific functions within the Python interpreter. A successful exploit could allow an attacker to escape the Pytho…

VulnerabilitiesCVE-2026-20032
P5
2026-10-07 16:00 UTC
Vendor Research

Cisco Finesse Server-Side Request Forgery Vulnerability

Cisco Security Advisories · indexed 2026-10-07 16:15 UTC

A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device. This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to obtain limited sensitive information for services that are assoc…

VulnerabilitiesCVE-2026-20362
P5
2026-10-07 16:00 UTC
Vendor Research

Cisco Nexus 3000 and 9000 Series Switches MPLS OAM Remote Code Execution Vulnerability

Cisco Security Advisories · indexed 2026-10-07 16:15 UTC

A vulnerability in the MPLS Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software for Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges or cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper validation when an affected device is processing an MPLS echo-request packet. An attacker could exploit this vulner…

Network SecurityVulnerabilitiesCVE-2026-76465
P20
2026-10-07 16:00 UTC
Vendor Research

Cisco Application Policy Infrastructure Controller Unauthorized File Access Vulnerability

Cisco Security Advisories · indexed 2026-10-07 16:15 UTC

A vulnerability in the export policies functionality of Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated, remote attacker to access sensitive files on an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to insufficient access control to file system resources. An attacker could exploit this vulnerability by submitting crafted values in specific UI fields. A successful exploit c…

Network SecurityVulnerabilitiesCVE-2026-76488
P5
2026-10-07 16:00 UTC
Vendor Research

Cisco Application Policy Infrastructure Controller API Command Injection Vulnerability

Cisco Security Advisories · indexed 2026-10-07 16:15 UTC

A vulnerability in the web-based management API for Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated, remote attacker to execute arbitrary commands as the root user. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to insufficient input validation of user-controlled command arguments. An attacker could exploit this vulnerability by authenticating using the API and sending crafted input. A succ…

VulnerabilitiesCVE-2026-20321
P5
2026-10-07 16:00 UTC
Vendor Research

Cisco License (Smart Software Manager) On-Prem Security Hardening Release: October 2026

Cisco Security Advisories · indexed 2026-10-07 16:15 UTC

As part of Cisco's ongoing commitment to proactive security and product quality, the engineering team for Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. These vulnerabilities were found during internal testing and are not known to be actively exploited. To assist customers in patching and str…

VulnerabilitiesCVE-2026-76480CVE-2026-76482CVE-2026-76483CVE-2026-76484
P30
2026-10-07 16:00 UTC
Vendor Research

Cisco Nexus 9000 Series Fabric Switches in ACI Mode Endpoint Group Contract Bypass Vulnerability

Cisco Security Advisories · indexed 2026-10-07 16:15 UTC

A vulnerability in the endpoint group (EPG) contract functionality of Cisco Nexus 9000 Series Fabric Switches in ACI Mode could allow an unauthenticated, remote attacker to bypass configured EPG contracts. This vulnerability is due to an improper control with EPG contracts. An attacker could exploit this vulnerability by sending IPv4 or IPv6 packets using UDP source and destination ports that are assigned to DHCP traffic through an affected device. A successful exploit could allow the attacker …

Network SecurityVulnerabilitiesCVE-2026-20038
P5
2026-10-07 16:00 UTC
Vendor Research

Cisco Nexus 3000 and 9000 Series Switches NGOAM Remote Code Execution Vulnerabilities

Cisco Security Advisories · indexed 2026-10-07 16:15 UTC

Multiple vulnerabilities in the Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software, known as Next Generation OAM (NGOAM), could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges or cause a denial of service (DoS) condition on an affected device. These vulnerabilities are due to improper input validation of IP traffic when NGOAM is enabled. An attacker could exploit these vulnerabilities by sending crafted packets to an IP inte…

Network SecurityVulnerabilitiesCVE-2026-76485CVE-2026-76486CVE-2026-76501
P20
2026-10-07 16:00 UTC
Vendor Research

Cisco Application Policy Infrastructure Controller Security Hardening Release: October 2026

Cisco Security Advisories · indexed 2026-10-07 16:15 UTC

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Application Policy Infrastructure Controller (APIC) engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. These vulnerabilities were found during internal testing and are not known to be actively exploited. To assist customers in patching and streamline the disclosure process…

VulnerabilitiesCVE-2026-76498CVE-2026-76499CVE-2026-76500
P30
2026-10-07 16:00 UTC
Vendor Research

Cisco NX-OS Software Control Plane Denial of Service Vulnerability

Cisco Security Advisories · indexed 2026-10-07 16:15 UTC

A vulnerability in Cisco NX-OS Software could allow an unauthenticated, remote attacker to exhaust system resources, causing a denial of service (DoS) condition. This vulnerability exists because rate limiting was improperly applied to some protocols. An attacker could exploit this vulnerability by sending a high rate of UDP or TCP connections to a data plane interface on an affected device. A successful exploit could allow the attacker to cause instability to various routing and control plane …

VulnerabilitiesCVE-2026-20173
P5
2026-10-07 16:00 UTC
Vendor Research

Cisco License (Smart Software Manager) On-Prem Vulnerabilities

Cisco Security Advisories · indexed 2026-10-07 16:15 UTC

Multiple vulnerabilities in the web-based management interface and API endpoints of Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), could allow a remote attacker to gain unauthorized access, access sensitive information, cause a denial of service (DoS) condition, or elevate privileges. For more information about these vulnerabilities, see the Details section of this advisory. Cisco has released software updates that address these vulnerabilities. There are no…

VulnerabilitiesCVE-2026-20328CVE-2026-76437CVE-2026-76452CVE-2026-76454
P5
2026-10-07 16:00 UTC
Vendor Research

Cisco NX-OS Software Security Hardening Release: October 2026

Cisco Security Advisories · indexed 2026-10-07 16:15 UTC

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco NX-OS Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. These vulnerabilities were found during internal testing and are not known to be actively exploited. To assist customers in patching and streamline the disclosure process, Cisco has grouped these issues by t…

VulnerabilitiesCVE-2026-76453CVE-2026-76455CVE-2026-76456CVE-2026-76457CVE-2026-76458CVE-2026-76459
P30
2026-10-07 15:44 UTC
Security Journalism

Microsoft Outlook to block MSIX attachments starting November

BleepingComputer · Sergiu Gatlan · indexed 2026-10-07 16:00 UTC

Microsoft announced that it will add .msix and .msixbundle attachments to the list of blocked attachments in Outlook Web and the new Outlook Windows client starting next month. [...]

Microsoft
P0
2026-10-07 15:34 UTC
Security Journalism

Unpatched Critical LMCache Flaw Lets Unauthenticated Attackers Run Code Remotely

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-07 16:15 UTC

A critical vulnerability in LMCache, open-source software that speeds up large language model (LLM) servers such as vLLM, lets an attacker run code on the cache server without logging in, and no fixed version is available. The flaw is in LMCache's multiprocess mode, where the cache runs as a standalone server that LLM workers reach over the ZeroMQ messaging library. A single network

AI SecurityVulnerabilities
P10
2026-10-07 15:33 UTC
Security Journalism

PoeLLM Malware Infects 3,400+ Servers to Expand Crypto Mining Botnet

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-07 16:15 UTC

Cybersecurity researchers are calling attention to a new malware family that has been observed targeting exposed artificial intelligence (AI) and large language model (LLM) infrastructure with an aim to deploy cryptocurrency miners and further expand the scale of the botnet. The financially motivated campaign, dubbed Canto Incognito, has been found to install cryptocurrency miners, including

AI SecurityMalwareSecurity Research
P0
2026-10-07 14:59 UTC
Community

Scans for Atlassian vulnerablity (CVE-2026-21589), (Wed, Oct 7th)

SANS Internet Storm Center · indexed 2026-10-07 15:15 UTC

On October 5th, Atlassian published patches for multiple products to fix an "Arbitrary File Access" vulnerability [CVE-2026-21589]. An attacker can read arbitrary files in the web application's directory, potentially exposing sensitive information such as configuration files.

VulnerabilitiesCVE-2026-21589
P5
2026-10-07 14:15 UTC
Security Journalism

Georgia Power, Alabama Power Data Breach Hits 400,000 Accounts

Security Week · Eduard Kovacs · indexed 2026-10-07 14:30 UTC

Southern Company is notifying customers that their utility account information was accessed by hackers. The post Georgia Power, Alabama Power Data Breach Hits 400,000 Accounts appeared first on SecurityWeek.

Data Breaches
P0
2026-10-07 14:03 UTC
Security Journalism

Cyber experts call on CISA to create mandatory federal OT rules

The Record · indexed 2026-10-07 14:10 UTC

The Operational Technology Cybersecurity Coalition released a white paper urging the CISA to create a new directive centered around operational technology, which is used to monitor and control critical infrastructure.

ICS / OT
P0
2026-10-07 14:01 UTC
Security Journalism

Ransomware has a new target. Is your backup ready?

BleepingComputer · Sponsored by Kaseya · indexed 2026-10-07 14:10 UTC

Ransomware groups are increasingly targeting backup infrastructure to eliminate recovery options and increase pressure on victims to pay. Kaseya explains why organizations need isolated, immutable, and regularly tested backups that attackers cannot easily reach. [...]

Ransomware
P15
2026-10-07 13:49 UTC
Other

FortiBleed hit 86,000 firewalls by exploiting something nobody can patch away

Security Affairs · Pierluigi Paganini · indexed 2026-10-07 14:30 UTC

FBI and Secret Service warn FortiBleed, a credential-harvesting campaign against Fortinet firewalls, has compromised 86,644 devices and is locking out admins. The FBI and the U.S. Secret Service issued a joint advisory about FortiBleed, and the headline number alone is worth sitting with: more than 86,644 compromised Fortinet FortiGate devices across 194 countries, according to […]

Law EnforcementNetwork Security
P0
2026-10-07 13:48 UTC
Independent Research

ShinyHunters Extorted Boeing Spin-off Prior to Arrests

Krebs on Security · BrianKrebs · indexed 2026-10-07 13:55 UTC

A teenager from Amman, Jordan suspected of leading the prolific data theft and extortion group ShinyHunters has been detained and is reportedly cooperating with the FBI to identify other members of the hacking gang. KrebsOnSecurity has learned that the suspect, who uses the hacker handle "Rey," was detained as ShinyHunters was in the process of extorting a business unit recently divested by the global aerospace company Boeing, which manufactures the fleet of planes used by the employer of Rey's…

Law Enforcement
P0
2026-10-07 13:22 UTC
Other

CERT-UA: Fake Cloudflare Checks Deliver LunexStealer Malware

Security Affairs · Pierluigi Paganini · indexed 2026-10-07 14:30 UTC

Over 100 hacked websites used fake Cloudflare checks to trick visitors into installing LunexStealer through ClickFix commands. The lure is the now-familiar ClickFix technique, dressed up as Cloudflare’s standard bot check. The fake page asks you to run a command, supposedly to confirm you’re not a bot, and that command quietly downloads and installs an […]

Malware
P0
2026-10-07 13:06 UTC
Security Journalism

Hadrian Raises $40 Million to Expand Autonomous Offensive Security Platform

Security Week · Kevin Townsend · indexed 2026-10-07 13:10 UTC

Hadrian offers an agentic offensive security platform that allows defenders to operate at the same speed as attackers. The post Hadrian Raises $40 Million to Expand Autonomous Offensive Security Platform appeared first on SecurityWeek.

Microsoft
P0
5 6 7 8 9