IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 4,779 matching records.
AUTO-POLL // 2026-10-10 23:55 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P1 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 10

RANSOMWARE
P1
P1
COOL // 11 ARTICLES
FRI
Oct 9

RANSOMWARE
P4
P4
COOL // 67 ARTICLES
THU
Oct 8

RANSOMWARE
P3
P3
COOL // 62 ARTICLES
WED
Oct 7

RANSOMWARE
P5
P5
COOL // 86 ARTICLES
TUE
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
RESET
2026-08-31 15:42 UTC
Vendor Research

WordPress - Kubio AI Website Builder DoS

Tenable Research Advisories · Joshua Martinelle · indexed 2026-08-31 19:05 UTC

WordPress - Kubio AI Website Builder DoS The REST endpoint `GET /wp-json/kubio/v1/enable-theme` passes the client-supplied `name` parameter directly and without validation into WordPress core's `switch_theme()`:// lib/api/colibri.php function kubio_enable_theme( WP_REST_Request $data ) { switch_theme( $data['name'] ); // $data['name'] ) ); }Because `$data['name']` is not type-checked, an authorized request can supply `name` as an array instead of a string. `switch_theme()` persists that value i…

Network Security
P0
2026-08-31 14:00 UTC
Security Journalism

File servers are here to stay. Here’s how to manage them securely

BleepingComputer · Sponsored by Tenfold Software · indexed 2026-08-31 14:20 UTC

File servers remain a critical part of many IT environments, but managing access securely can become complex as permissions accumulate. tenfold Software outlines five best practices for simplifying file server administration and maintaining least-privilege access. [...]

P0
2026-08-31 14:00 UTC
Security Journalism

Huntress API Update: New Endpoints, Webhooks, and Automation

Huntress · indexed 2026-09-07 17:30 UTC

The Huntress API has grown from six read-only endpoints into a full integration and automation platform. See what’s new, including webhooks and MCP support.

P0
2026-08-31 13:50 UTC
Security Journalism

⚡ Weekly Recap: Chinese Spy Proxy, AI Agents Go Off-Task, Router Backdoors and More

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-31 14:30 UTC

The boring parts caused most of the trouble. A router shipped ready to listen. A fake check turned the user into the installer. Trusted systems collected traffic and passwords, then cleaned the logs. Old bugs formed new attack chains. Even an AI agent decided its assigned task was optional. Elsewhere, fake apps, helpful support calls, cheap banking kits, exposed systems, and weak defaults kept

AI SecurityMalwareNetwork Security
P0
2026-08-31 13:38 UTC
Other

Breaking the Seal: Static Deobfuscation of JSCeal’s Compiled V8 Bytecode

Check Point Research · shlomoo@checkpoint.com · indexed 2026-09-07 17:30 UTC

Research by: hasherezade Key Points Introduction JSCeal is a stealer delivered as compiled V8 bytecode (.jsc) and executed by a bundled Node.js runtime, targeting cryptocurrency applications (other vendors also tag it with the names WEEVILPROXY or MeadowLocust). Its campaign activity dates back to March 2024 [1]; Check Point Research has been tracking the malware since early […] The post Breaking the Seal: Static Deobfuscation of JSCeal’s Compiled V8 Bytecode appeared first on Check Point Resea…

Malware
P0
2026-08-31 12:58 UTC
Other

31st August – Threat Intelligence Report

Check Point Research · urias@checkpoint.com · indexed 2026-09-07 17:30 UTC

For the latest discoveries in cyber research for the week of 31st August, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Manchester Airports Group, the UK operator of Manchester, London Stansted, and East Midlands airports, has disclosed a cyberattack that exposed data belonging to about 8.7 million customers. The compromised information includes contact details, […] The post 31st August – Threat Intelligence Report appeared first on Check Point Research.

Threat Intelligence
P0
2026-08-31 12:14 UTC
Security Journalism

ValleyRAT Backdoor Hides in Signed Adware That Users Add to Antivirus Exclusions

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-31 12:30 UTC

The threat actor known as Silver Fox has been observed distributing the ValleyRAT backdoor disguised as a signed Chinese adware application, running the malware under a trusted process to slip past users who add such software to their antivirus exclusions. Russian cybersecurity vendor Kaspersky said the attackers built the disguise around QN Wallpaper, a genuine Chinese desktop-wallpaper tool

MalwareThreat Actors
P0
2026-08-31 11:47 UTC
Security Journalism

Aurora Ransomware Operators Use Cursor AI in Attacks Against 10 Targets

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-31 12:30 UTC

Threat actors associated with Aurora (aka Aur0ra) ransomware have been observed using SpaceX's artificial intelligence (AI)-powered coding assistant Cursor to break into target networks, according to findings from CloudSEK and Gambit Security. The two independent analyses are based on exposed infrastructure associated with the Russian-speaking cybercrime group, leading to the discovery of its

AI SecurityCybercrimeRansomwareThreat Actors
P15
2026-08-31 11:31 UTC
Security Journalism

Securing Claude Code: The New Compliance API, Local Visibility, and Identity Governance

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-31 12:30 UTC

Claude Code reads files, runs shell commands, invokes MCP tools, and acts through the credentials available on a developer’s machine. Anthropic’s new Compliance API endpoints give security teams their clearest view yet into that activity. They also expose a larger problem: activity logs alone cannot tell you whether an agent’s access is legitimate. AI has moved from the browser tab to the

P0
2026-08-31 11:10 UTC
Other

China-linked Fire Ant Hides Inside Trusted Infrastructure

Security Affairs · Pierluigi Paganini · indexed 2026-08-31 11:40 UTC

Fire Ant hijacked Cisco routers, stole credentials and altered logs to hide its tracks, using trusted infrastructure to reach high-value networks. Chinese-linked cyber espionage group Fire Ant has spent the past year quietly graduating from hacking individual computers to hacking the infrastructure that connects them. Sygnia’s new report traces how the group expanded from compromising […]

APT / Nation-StateNetwork Security
P0
2026-08-31 09:22 UTC
Security Journalism

Nigerians extradited to US for sextortion, deaths of two teens

BleepingComputer · Sergiu Gatlan · indexed 2026-08-31 09:35 UTC

Two Nigerian men extradited to the U.S. on Thursday have been charged with involvement in sextortion schemes that resulted in the deaths of two minor victims in Mississippi and North Carolina. [...]

P0
2026-08-31 09:17 UTC
Other

Infostealers Are Hijacking Claude Sessions and Draining Subscriptions

Security Affairs · Pierluigi Paganini · indexed 2026-08-31 09:40 UTC

Infostealers can steal active Claude sessions, bypass 2FA and drain paid usage. Anthropic is revoking access and refunding unauthorized charges. Anthropic confirmed that several infostealer malware can hijack an active Claude login session and let attackers burn through your usage without ever touching your password. “Our investigation is ongoing. Our findings to date suggest that […]

DFIRMalware
P0
2026-08-31 09:04 UTC
Security Journalism

China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-31 10:35 UTC

A China-nexus cyber espionage actor tracked as Fire Ant has expanded a long-running campaign beyond VMware hypervisors to compromise Cisco IOS XR routers, Terminal Access Controller Access-Control System (TACACS) servers, and Linux management hosts used to route, authenticate, and manage high-value networks. Sygnia, the incident response firm that investigated the intrusion, said the actor

AppleAPT / Nation-StateDFIRLinuxNetwork Security
P0
2026-08-31 07:56 UTC
Security Journalism

DoJ Corrects China Hacking Claim, Says U.S. Agencies Were Targets, Not Victims

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-31 08:40 UTC

The U.S. Department of Justice (DoJ) on Friday corrected a previously issued press statement that several of its agencies were victims of attacks carried out by Chinese threat actors, instead now pointing out that they were among those targeted. Last week, the DoJ said the National Aeronautics and Space Administration, Federal Reserve, Department of Energy, Department of Justice, Department

Law EnforcementThreat Actors
P0
2026-08-31 07:41 UTC
Other

Critical GiveWP Flaw Lets Attackers Run Commands on WordPress Servers

Security Affairs · Pierluigi Paganini · indexed 2026-08-31 08:40 UTC

A critical GiveWP flaw lets unauthenticated attackers execute server commands. Version 4.16.7.2 fixes the PHP object injection chain. A critical vulnerability in GiveWP, one of the most widely used WordPress plugins for online donations and fundraising, can let an unauthenticated attacker execute commands on the server. Patchstack disclosed the flaw on August 28, after researcher […]

Vulnerabilities
P10
2026-08-31 05:00 UTC
Other

ZDI-26-615: (0Day) pdfforge PDF Architect activation-service Update Service Uncontrolled Search Path Element Local Privilege Escalation Vulnerability

Zero Day Initiative · indexed 2026-09-07 17:35 UTC

This vulnerability allows local attackers to escalate privileges on affected installations of pdfforge PDF Architect. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8.

Vulnerabilities
P10
2026-08-31 05:00 UTC
Other

ZDI-26-614: (0Day) pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability

Zero Day Initiative · indexed 2026-09-07 17:35 UTC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8.

Vulnerabilities
P15
2026-08-31 05:00 UTC
Other

ZDI-26-613: (0Day) pdfforge PDF Architect PDF File Parsing Memory Corruption Remote Code Execution Vulnerability

Zero Day Initiative · indexed 2026-09-07 17:35 UTC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8.

Vulnerabilities
P15
2026-08-31 05:00 UTC
Other

ZDI-26-612: (0Day) pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability

Zero Day Initiative · indexed 2026-09-07 17:35 UTC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8.

Vulnerabilities
P15
2026-08-31 05:00 UTC
Other

ZDI-26-611: (0Day) pdfforge PDF Architect App Object Out-Of-Bounds Read Remote Code Execution Vulnerability

Zero Day Initiative · indexed 2026-09-07 17:35 UTC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8.

Vulnerabilities
P15
68 69 70 71 72