IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 4,763 matching records.
AUTO-POLL // 2026-10-09 22:50 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P5 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 9

RANSOMWARE
P5
P5
COOL // 62 ARTICLES
THU
Oct 8

RANSOMWARE
P3
P3
COOL // 62 ARTICLES
WED
Oct 7

RANSOMWARE
P5
P5
COOL // 86 ARTICLES
TUE
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
RESET
2026-10-07 12:11 UTC
Vendor Research

CVE-2026-21589: Critical unauthenticated arbitrary file access in Atlassian products

Rapid7 · Rapid7 · indexed 2026-10-07 12:30 UTC

OverviewOn October 5, 2026, Atlassian published a security advisory for CVE-2026-21589, a critical arbitrary file access vulnerability affecting eight products: Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center, Crowd Data Center, Crucible, and Fisheye. Atlassian assigned the vulnerability a CVSSv4 score of 9.3. An unauthenticated remote attacker who knows a target file's exact name and path can access it within the…

DFIRNetwork SecurityVulnerabilitiesCVE-2026-21589
P5
2026-10-07 11:57 UTC
Security Journalism

The Sixth Voice of the CISO Data Shows Cyber Risk Has Moved Inside the Workflow

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-07 12:20 UTC

The 2026 findings are not just a year-over-year shift. They mark the latest point in a five-year arc where resilience, AI governance, human risk, and board scrutiny are converging inside the systems where work actually happens. For years, the enterprise cybersecurity story has been told as a straight line of escalation: more attacks, more data loss, more pressure, and more urgency. That

P0
2026-10-07 11:56 UTC
Security Journalism

FBI Warns FortiBleed Remains Active After Amassing 86,644 Fortinet Device Credentials

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-07 12:20 UTC

The U.S. Federal Bureau of Investigation (FBI) and Secret Service (USSS) on Tuesday warned that the FortiBleed credential harvesting campaign remains an active threat aimed at internet-facing Fortinet FortiGate firewalls and secure socket layer (SSL) virtual private network (VPN) gateways. "The campaign exploits reused or leaked credentials and legacy SHA-256 password storage, enabling threat

DFIRLaw EnforcementNetwork SecurityPhishing
P0
2026-10-07 11:49 UTC
Security Journalism

Atlassian Data Center Flaw Draws Exploitation Attempts Within Two Hours of Public Details

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-07 12:20 UTC

Threat actors have begun to exploit a newly disclosed critical security flaw impacting Atlassian Data Center products that could allow access to sensitive files under certain conditions. The arbitrary file access flaw, tracked as CVE-2026-21589 (CVSS score: 9.3) affects multiple products, including Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software

Cloud SecurityThreat ActorsVulnerabilitiesCVE-2026-21589
P5
2026-10-07 11:42 UTC
Security Journalism

What Is Agentic Pentesting? What It Proves, and Where It Stops.

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-07 12:20 UTC

If you’re evaluating an agentic pentesting solution right now, you’ve probably heard the same pitch more than once: point it at a target, and it discovers, validates, and exploits attack paths autonomously, the way a real attacker would. That promise is worth taking seriously. It’s also worth pressure testing, and three questions do the heavy lifting. What can the assessment actually

P0
2026-10-07 11:37 UTC
Security Journalism

SonicWall warns of max severity SSRF flaw in SMA1000 gateways

BleepingComputer · Sergiu Gatlan · indexed 2026-10-07 11:55 UTC

SonicWall has released hotfixes to address a maximum-severity server-side request forgery (SSRF) flaw in SMA1000 series appliances. [...]

P0
2026-10-07 10:51 UTC
Security Journalism

Chrome 155 Update Patches 247 Vulnerabilities

Security Week · Ionut Arghire · indexed 2026-10-07 11:00 UTC

Four critical-severity use-after-free defects were fixed in Chromecast, Browser, Navigation, and Track. The post Chrome 155 Update Patches 247 Vulnerabilities appeared first on SecurityWeek.

P0
2026-10-07 10:40 UTC
Vendor Research

The ASOS Incident: When Attackers Use the Channels Customers Trust

Rapid7 · Emma Burdett · indexed 2026-10-07 10:50 UTC

This week, ASOS customers opened their phones to find a hostile push notification delivered through the retailer’s own app. The message claimed the company’s Snowflake environment had been compromised and directed ASOS to engage with the sender through Telegram. ASOS later confirmed to Sky News that an unauthorized customer notification had been sent and said it was investigating activity involving third-party platforms used to communicate with customers. The company also said basic personal in…

CybercrimeDFIRMalwarePhishingVulnerabilities
P0
2026-10-07 10:07 UTC
Security Journalism

Anthropic Introduces 3-Tier Cyber Verification Program for AI Access

Security Week · Eduard Kovacs · indexed 2026-10-07 10:20 UTC

Anthropic is integrating the CVP and Project Glasswing into a single offering, with three levels of access to its most capable AI models. The post Anthropic Introduces 3-Tier Cyber Verification Program for AI Access appeared first on SecurityWeek.

P0
2026-10-07 10:06 UTC
Other

Anthropic Creates Three Tiers for Claude Cyber Access

Security Affairs · Pierluigi Paganini · indexed 2026-10-07 11:10 UTC

Anthropic created three access tiers for Claude’s offensive security use, matching cyber capabilities and safeguards to the user’s level of trust. Anthropic is trying to solve the difficult balance between using AI for cybersecurity and preventing misuse. The same model that helps security teams fix vulnerabilities can also help attackers break into systems. Its answer, […]

P0
2026-10-07 10:00 UTC
Vendor Research

One breach, please, and make no mistakes

Cisco Talos Intelligence Blog · Jerzy ‘Yuri’ Kramarz · indexed 2026-10-07 10:30 UTC

The cybersecurity community has seen examples of autonomous agents, built inside AI labs, attacking public infrastructure. How you prepare for agentic threats is what makes the difference during real incidents.

P0
2026-10-07 09:46 UTC
Security Journalism

ASOS Confirms Cyberattack, Data Breach

Security Week · Ionut Arghire · indexed 2026-10-07 10:00 UTC

Hackers compromised a third-party communication platform and sent rogue notifications to ASOS users. The post ASOS Confirms Cyberattack, Data Breach appeared first on SecurityWeek.

Data Breaches
P0
2026-10-07 08:07 UTC
Security Journalism

Anthropic Expands Claude Access for Vetted Cyber Teams as Glasswing Finds 129,000 Flaws

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-07 09:40 UTC

Anthropic on Tuesday said it's expanding a program that allows vetted cybersecurity professionals to test its advanced artificial intelligence (AI) models with reduced safeguards and blocking classifiers, as the company claimed its Project Glasswing initiative uncovered at least 129,000 verified software vulnerabilities between April and July 2026. The company said it also found an additional

AI SecurityCloud Security
P0
2026-10-07 07:58 UTC
Security Journalism

Wikimedia Says Rogue OpenAI Agents Tried to Turn Its Tools Into Proxies

Security Week · Eduard Kovacs · indexed 2026-10-07 08:00 UTC

Wikimedia looked into whether its own websites had seen activity like that disclosed by other organizations The post Wikimedia Says Rogue OpenAI Agents Tried to Turn Its Tools Into Proxies appeared first on SecurityWeek.

AI Security
P0
2026-10-07 07:52 UTC
Government

2026-015: Critical Vulnerability in Multiple Atlassian Products

CERT-EU Security Advisories · indexed 2026-10-07 08:00 UTC

On 5 October 2026, Atlassian published a security advisory addressing a critical arbitrary file access vulnerability. It affects Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center, Crowd Data Center, Crucible and Fisheye. CERT-EU strongly recommends upgrading all affected installations to a fixed version as soon as possible, starting with instances accessible from the internet. CERT-EU also recommends checking access…

Vulnerabilities
P10
2026-10-07 07:50 UTC
Other

Wikimedia Finds Unauthorized OpenAI Agent Activity on Wikipedia

Security Affairs · Pierluigi Paganini · indexed 2026-10-07 08:40 UTC

Wikimedia found unauthorized OpenAI agent activity on its platforms, including unapproved edits, proxy attempts and millions of automated API requests. Wikimedia ran its own investigation after other organizations started reporting rogue AI agents breaking into websites, and the answer came back yes, it happened here too. The foundation found unauthorized bot activity tied to OpenAI […]

AI SecurityDFIR
P0
2026-10-07 07:30 UTC
Vendor Research

5 Critical Pain Points of Modern US SOCs and How to Solve Them

ANY.RUN Blog · ANY.RUN · indexed 2026-10-07 07:50 UTC

US SOC teams are under pressure to detect and contain threats faster, but the real challenge is often not a lack of security solutions. It’s the growing amount of alerts, fragmented investigation data, evasive attack techniques, and the time analysts spend connecting the dots. As attacks become harder to validate and easier to hide inside […] The post 5 Critical Pain Points of Modern US SOCs and How to Solve Them appeared first on ANY.RUN's Cybersecurity Blog.

DFIR
P0
2026-10-07 06:57 UTC
Security Journalism

100+ Compromised Websites Use Fake Cloudflare Checks to Deliver LunexStealer

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-07 07:45 UTC

The Computer Emergency Response Team of Ukraine (CERT-UA) has identified more than 100 compromised websites that have been injected with malicious JavaScript to serve an information-stealing malware called LunexStealer (aka Psychedelic Stealer). The activity, which was observed by the agency in September 2026, has been attributed to a threat cluster dubbed UAC-0277. It did not disclose who the

Malware
P0
2026-10-07 06:37 UTC
Security Journalism

Atlassian Patches Critical Vulnerability Affecting 8 Products

Security Week · Ionut Arghire · indexed 2026-10-07 06:50 UTC

Unauthenticated attackers could exploit the flaw to access specific files in the web application root directory. The post Atlassian Patches Critical Vulnerability Affecting 8 Products appeared first on SecurityWeek.

Vulnerabilities
P10
2026-10-06 21:00 UTC
Security Journalism

Ninja Forms plugin flaw exploited to hack WordPress sites

BleepingComputer · Bill Toulas · indexed 2026-10-06 21:05 UTC

Hackers are exploiting stored cross-site scripting (XSS) vulnerabilities in two unrelated WordPress plugins, Ninja Forms and WPC Product Bundles for WooCommerce, to install backdoors and create rogue admin accounts. [...]

Malware
P0
2026-10-06 20:41 UTC
Vendor Research

CVE-2026-105812 and CVE-2026-106032: Issue with Bedrock AgentCore Starter Toolkit - Import Agent Code Injection and SSRF

AWS Security Bulletins · aws@amazon.com · indexed 2026-10-06 20:55 UTC

Bulletin ID: 2026-127-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 10/06/2026 13:30 PM PDT Description: bedrock-agentcore-starter-toolkit is an AWS-maintained open-source Python package, distributed via GitHub and PyPI, that provides a command-line interface for importing Amazon Bedrock Agents into local development environments. We identified CVE-2026-105812, a code injection issue that could allow arbitrary code execution when a specially crafted agent is impo…

Cloud SecurityVulnerabilitiesCVE-2026-105812CVE-2026-106032
P5
6 7 8 9 10