IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 153 matching records.
AUTO-POLL // 2026-10-04 08:20 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
WARM
COOL WARM ELEVATED HOT CRITICAL
P10 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 4

RANSOMWARE
P10
P10
WARM // 4 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
FRI
Oct 2

RANSOMWARE
P7
P7
COOL // 46 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
WED
Sep 30

RANSOMWARE
P10
P10
WARM // 59 ARTICLES
TUE
Sep 29

RANSOMWARE
P4
P4
COOL // 68 ARTICLES
MON
Sep 28

RANSOMWARE
P7
P7
COOL // 52 ARTICLES
RESET
2026-09-14 18:33 UTC
Community

Apple Updates Everything, (Mon, Sep 14th)

SANS Internet Storm Center · indexed 2026-09-14 18:50 UTC

Today, Apple released its annual update across all its operating systems. With that, Apple not only released new features but also patched 261 different vulnerabilities. This is the most vulnerabilities Apple has ever patched, but the increase is not as significant as other vendors' "post-AI" patch releases. 

Apple
P0
2026-09-09 05:00 UTC
Other

ZDI-26-641: Oracle VirtualBox VirtioSCSI Out-Of-Bounds Read Information Disclosure Vulnerability

Zero Day Initiative · indexed 2026-09-09 22:50 UTC

This vulnerability allows local attackers to disclose sensitive information on affected installations of Oracle VirtualBox. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.1. The following CVEs are assigned: CVE-2026-71114.

AppleVulnerabilitiesCVE-2026-71114
P5
2026-09-09 05:00 UTC
Other

ZDI-26-640: Oracle VirtualBox VirtioSCSI Uninitialized Memory Information Disclosure Vulnerability

Zero Day Initiative · indexed 2026-09-09 22:50 UTC

This vulnerability allows local attackers to disclose sensitive information on affected installations of Oracle VirtualBox. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.3. The following CVEs are assigned: CVE-2026-71132.

AppleVulnerabilitiesCVE-2026-71132
P5
2026-09-08 11:54 UTC
Security Journalism

WeChat Zero-Click Worm Took Over Accounts on iPhone and Android via Incoming Calls

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-08 13:20 UTC

Researchers at the security firm Calif have built a worm that takes over a WeChat account via an incoming call and demonstrated it spreading among three test phones. The person being called does not have to answer or touch their phone for it to work, but the caller must already be one of their WeChat contacts. Calif reported the flaw to Tencent in July and says the company has since

AppleMobile Security
P0
2026-09-03 21:15 UTC
Vendor Research

Incident response guide for AWS CloudTrail investigations – Part 2

AWS Security Blog · Oscar Diaz · indexed 2026-09-03 21:35 UTC

In Part 1 of this guide, we examined two common incident scenarios: cross-account Amazon Simple Storage Service (Amazon S3) data deletion with ransomware implications, and cryptocurrency mining deployed through AWS CloudFormation using exposed AWS Management Console credentials. We also introduced key incident response terminology and investigative frameworks for analyzing AWS CloudTrail events. In this second […]

AppleCloud SecurityDFIRRansomware
P15
2026-09-03 21:15 UTC
Vendor Research

Incident response guide for AWS CloudTrail investigations – Part 1

AWS Security Blog · Oscar Diaz · indexed 2026-09-03 21:35 UTC

AWS CloudTrail logs contain the evidence you need when investigating suspicious activity in your AWS environment, but knowing which fields matter and how to interpret them can mean the difference between surface-level analysis and uncovering the full scope of an incident. This guide walks you through real-world scenarios, showing you how to analyze CloudTrail events […]

AppleCloud SecurityDFIR
P0
2026-09-03 20:17 UTC
Other

Pegasus and NoviSpy Used Against Serbian Protesters

Security Affairs · Pierluigi Paganini · indexed 2026-09-03 20:25 UTC

Serbian activists were targeted with zero-click Pegasus and NoviSpy spyware, exposing a major surveillance campaign ahead of elections. A member of Serbia’s student protest movement had their iPhone infected with NSO Group‘s Pegasus spyware without ever clicking a link or opening a file. The Citizen Lab confirmed the infection in collaboration with the SHARE Foundation, […]

Apple
P0
2026-09-03 15:52 UTC
Security Journalism

Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-03 16:45 UTC

Cisco has released patches to address a critical security flaw affecting 10 Silicon One-based Nexus 9000 switches that could allow an unauthenticated, remote attacker to execute code as root, alongside an IOS XR hardening release bundling 7 umbrella CVEs, 2 of which are rated 9.8, with no workaround for any IOS XR version. The Nexus vulnerability, tracked as CVE-2026-20212 (CVSS score: 9.8), is

AppleNetwork SecurityVulnerabilitiesCVE-2026-20212
P5
2026-09-03 08:43 UTC
Security Journalism

Pegasus Zero-Click Spyware Exploit Infects Serbian Student Movement Member's iPhone

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-03 10:00 UTC

The iPhone belonging to a member of Serbia's student protest movement was infected with NSO Group's Pegasus spyware, according to new findings from the Citizen Lab in collaboration with the SHARE Foundation. "Our analysis confirmed that an iMessage zero-click exploit was used to infect the device with NSO Group's Pegasus spyware," the Citizen Lab said. "We found high-confidence indicators of

Apple
P0
2026-09-02 16:02 UTC
Vendor Research

Cisco Advance Notification for Publication of September 2, 2026, Security Advisories

Cisco Security Advisories · indexed 2026-08-26 16:20 UTC

On September 2, 2026, the Cisco Product Security Incident Response Team (PSIRT) published the following advisories: Cisco Security Advisory CVE ID Security Impact Rating CVSS Base Score Cisco IOS XR Software Security Hardening Release: September 2026 CVE-2026-20277CVE-2026-20278CVE-2026-20280CVE-2026-20279CVE-2026-20276CVE-2026-20275CVE-2026-20274 Critical 9.8 Cisco Nexus 9000 Series Switches Silicon One Remote Code Execution Vulnerability CVE-2026-20212 Critical 9.8 Cisco Desk Phone 9800 Serie…

AppleDFIRNetwork SecurityVulnerabilitiesCVE-2026-20212CVE-2026-20281
P20
2026-09-01 14:07 UTC
Security Journalism

13 Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Wallet Seeds

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-01 14:45 UTC

Cybersecurity researchers have identified a set of 13 malicious Composer theme packages on Packagist that are designed to inject JavaScript into Vietnamese movie and comic streaming sites that install those libraries and initiate the deployment of spyware aimed at unpatched iOS devices. "The injected code runs two operations against a site's visitors: a mobile ad-fraud and gambling-redirect

AppleCybercrimeSecurity Research
P0
2026-09-01 13:08 UTC
Security Journalism

Iranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding Tests

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-01 13:20 UTC

The Iranian Nimbus Manticore hacking group has been attributed to two previously undocumented malware families that highlight the continued evolution of its toolset and likely expand its targeting footprint to infect Linux and Apple macOS systems using cross-platform remote access trojans (RATs) developed using Node.js and JavaScript. Russian cybersecurity company Kaspersky is tracking the

AppleLinuxMalware
P0
2026-08-31 09:04 UTC
Security Journalism

China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-31 10:35 UTC

A China-nexus cyber espionage actor tracked as Fire Ant has expanded a long-running campaign beyond VMware hypervisors to compromise Cisco IOS XR routers, Terminal Access Controller Access-Control System (TACACS) servers, and Linux management hosts used to route, authenticate, and manage high-value networks. Sygnia, the incident response firm that investigated the intrusion, said the actor

AppleAPT / Nation-StateDFIRLinuxNetwork Security
P0
2026-08-27 14:30 UTC
Vendor Research

How to build an exposure management program the business trusts: Lessons from Tenable’s CSO

Tenable Blog · Robert Huber · indexed 2026-08-27 14:40 UTC

Discover how Tenable’s shift to an AI-driven exposure management program helped Tenable’s CSO, Robert Huber, overcome tool sprawl, unify data silos, mitigate the risk of rapid AI adoption, and shift from presenting granular, technical metrics to communicating business risk that the C-suite and the board can understand.Key takeawaysSecurity tool sprawl and data silos make it difficult for CISOs to holistically and accurately assess their organizations’ cyber risk.An exposure management program c…

AI SecurityAppleCloud SecurityMicrosoftVulnerabilities
P0
2026-08-26 05:47 UTC
Security Journalism

Fake Apple Support AI Calls Target Stolen-Device Owners for Passcodes and 2FA Codes

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-26 07:10 UTC

Cybersecurity researchers have disclosed details of a phishing-as-a-service (PhaaS) platform built to strip Apple's Activation Lock from stolen devices, using rented AI voice agents that call theft victims posing as Apple Support and ask for their device passcode. SOCRadar Threat Research Unit (STRU) said the platform, which it tracks as AnonyMousKIT, is credit-metered and drives lures across

ApplePhishingSecurity Research
P0
2026-08-25 13:19 UTC
Security Journalism

WhatsApp Adds Multiple Passkeys for Phishing-Resistant Sign-Ins Across iOS and Android

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-25 13:45 UTC

Meta on Tuesday announced a set of WhatsApp account security features, including support for multiple passkeys to a single account to help users with both iOS and Android devices sign into their accounts using the phishing-resistant method. The tech giant said more than 1 billion people use a passkey to log into WhatsApp. Support for passkeys was first introduced in Android in October 2023,

AppleMobile SecurityPhishing
P0
2026-08-24 05:00 UTC
Other

ZDI-26-610: Apple Safari JavaScriptCore B3 ReduceStrength Phase Use-After-Free Remote Code Execution Vulnerability

Zero Day Initiative · indexed 2026-09-07 17:35 UTC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Apple Safari. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-64715.

AppleVulnerabilitiesCVE-2026-64715
P20
2026-08-19 11:01 UTC
Security Journalism

Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-19 11:35 UTC

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added four critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, stating they are being exploited in the wild. The shortcomings added to the KEV catalog are listed below - CVE-2026-65400 (CVSS score: 9.8) - An improper authentication vulnerability impacting Apple macOS that could allow an

AppleCloud SecurityMicrosoftVulnerabilitiesCVE-2026-65400
P55
2026-08-19 07:19 UTC
Other

U.S. CISA adds Apple macOS, Microsoft SharePoint, Broadcom VMware vCenter, and Microsoft IKE flaws to its Known Exploited Vulnerabilities catalog

Security Affairs · Pierluigi Paganini · indexed 2026-08-19 07:35 UTC

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Apple macOS, Microsoft SharePoint, Broadcom VMware vCenter, and Microsoft IKE flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2026-33824 is a Windows Internet Key Exchange (IKE) Service Extensions Remote Code Execution […]

AppleCloud SecurityMicrosoftVulnerabilitiesCVE-2026-33824
P50
2026-08-19 06:01 UTC
Security Journalism

Microsoft Links 30+ Rotating Domains to MacSync Stealer Infrastructure

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-19 09:45 UTC

Microsoft Defender Experts have linked more than 30 web domains to MacSync Stealer, a macOS-focused information stealer, after correlating recurring endpoint and network behaviors across changing infrastructure, tracing the malware from payload retrieval through data collection, staging, and exfiltration. The tech giant said it required multiple endpoint and network behaviors to align before

AppleMalwareMicrosoft
P0
2026-08-17 20:26 UTC
Community

Apple Patches iOS and macOS, (Mon, Aug 17th)

SANS Internet Storm Center · indexed 2026-08-17 20:35 UTC

Apple today released updates for iOS/iPadOS (26 and 18) and macOS 26. This update fixes 108 vulnerabilities and comes about two weeks after the much smaller macOS update that addressed the single screen-sharing vulnerability. This vulnerability did not affect iOS/iPadOS.

AppleVulnerabilities
P0
2026-08-17 15:15 UTC
Vendor Research

Detecting cloud ransomware in Azure with Tenable One’s cloud detection and response capabilities

Tenable Blog · Clément Notin · indexed 2026-08-17 15:35 UTC

Learn how Tenable One Cloud Exposure helps you unmask the sophisticated tactics of cybercrime group Storm-0501, which carries out Azure-based cloud ransomware campaigns. Tenable One Cloud Exposure uses AI-powered threat stories to expose Storm-0501 TTPs, backed by precision-engineered threat detection alerts.Key takeawaysStorm-0501 demonstrates that cloud-first ransomware groups have shifted from simple endpoint encryption to the total hijacking of cloud tenants.Storm-0501 systematically neutra…

AppleCloud SecurityCybercrimeDFIRMalwareMicrosoftRansomwareThreat ActorsThreat Intelligence
P15
2026-08-17 14:33 UTC
Community

Apple Screen Sharing Security, (Mon, Aug 17th)

SANS Internet Storm Center · indexed 2026-08-17 14:55 UTC

About 20 years ago, with macOS 10.5 (Leopard), Apple introduced screen sharing. Apple did not invent a new protocol for screen sharing. Instead, it used the established VNC protocol. VNC is a pretty simple, unencrypted protocol using TCP port 5900. Historically, the protocol used a simple global password for authentication. Apple adapted the protocol for its own use, but overall, left the VNC protocol itself alone.

Apple
P0
1 2 3 4