IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 571 matching records.
AUTO-POLL // 2026-10-04 10:20 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P9 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 4

RANSOMWARE
P9
P9
COOL // 5 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
FRI
Oct 2

RANSOMWARE
P7
P7
COOL // 46 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
WED
Sep 30

RANSOMWARE
P10
P10
WARM // 59 ARTICLES
TUE
Sep 29

RANSOMWARE
P4
P4
COOL // 68 ARTICLES
MON
Sep 28

RANSOMWARE
P7
P7
COOL // 52 ARTICLES
RESET
2026-09-01 15:12 UTC
Other

Attackers Access Aesto Health AWS Infrastructure, Exposing 9.5 Million Records

Security Affairs · Pierluigi Paganini · indexed 2026-09-01 15:40 UTC

Aesto Health suffered a breach exposing personal and health data of more than 9.5 million people after attackers accessed its AWS infrastructure. Aesto Health, a U.S. healthcare technology company, disclosed a data breach that exposed personal and health information belonging to more than 9.5 million people. The company discovered the incident on December 18, 2025, […]

Cloud SecurityData Breaches
P0
2026-09-01 14:00 UTC
Vendor Research

Financially Motivated Threat Actor BREEZE COMET Targets Brazil

Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-09-01 03:50 UTC

Introduction Beginning in 2024 Mandiant investigated a string of compromises affecting Brazilian financial services, retail, and eCommerce organizations. Google Threat Intelligence Group (GTIG) tracks this activity as BREEZE COMET (formerly UNC5669), a financially motivated threat actor specializing in manipulating payment systems and banking software in Brazil to conduct fraudulent transfers. This activity overlaps with operations publicly reported as Plump Spider and SHADOW-AETHER-064. In thi…

AI SecurityCloud SecurityCybercrimeMalwareMicrosoftNetwork SecurityPhishingThreat ActorsThreat Intelligence
P0
2026-09-01 08:13 UTC
Other

U.S. CISA adds PaperCut NG/MF flaws to its Known Exploited Vulnerabilities catalog

Security Affairs · Pierluigi Paganini · indexed 2026-09-01 09:05 UTC

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds PaperCut NG/MF flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: PaperCut, the print management software running in schools, hospitals, and offices worldwide, recently confirmed that a pre-authentication remote code execution flaw, tracked as CVE-2026-81578, […]

Cloud SecurityVulnerabilitiesCVE-2026-81578
P50
2026-09-01 07:22 UTC
Security Journalism

Attackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 Activity

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-01 08:00 UTC

Threat actors are exploiting two critical flaws impacting Langflow and Ruby on Rails, according to new findings from VulnCheck. The vulnerabilities in question are listed below - CVE-2026-0768 (CVSS score: 9.8) - A lack of proper validation of a user-supplied input vulnerability that could be exploited to execute arbitrary Python code in the context of the root user. CVE-2026-66066 aka

Cloud SecurityThreat ActorsVulnerabilitiesCVE-2026-0768CVE-2026-66066
P15
2026-08-31 19:00 UTC
Vendor Research

We invited a direct competitor into Security Hub Extended. Here’s why.

AWS Security Blog · Michael Fuller · indexed 2026-08-31 19:05 UTC

When customers keep pointing you to a solution that overlaps with parts of your own offering, you have a choice to make. This post is about the choice we made with Upwind, and why we’d make it again. AWS Security Hub Extended exists because customers told us what was working for them in enterprise security […]

Cloud Security
P0
2026-08-31 17:18 UTC
Vendor Research

Automate IAM Identity Center governance with continuous discovery and reporting

AWS Security Blog · Jonathan Nguyen · indexed 2026-08-31 17:20 UTC

AWS IAM Identity Center integrates with external identity provider (IdP) to provide customers with a centralized authentication and authorization solution for AWS resources across AWS Organizations. AWS continues to invest into IAM Identity Center with a growing number of AWS services that natively integrate with IAM Identity Center. As your AWS organization scales, maintaining visibility […]

Cloud SecurityMicrosoft
P0
2026-08-31 17:07 UTC
Vendor Research

GCP Apigee PE to Service Agent with API Proxy

Tenable Research Advisories · Joshua Martinelle · indexed 2026-08-31 19:05 UTC

GCP Apigee PE to Service Agent with API Proxy Tenable Research has identified and responsibly disclosed a privilege escalation vulnerability in Google Cloud Apigee. This vulnerability allowed an attacker with restricted Apigee permissions to exfiltrate the OAuth access token of the privileged Apigee Core Service Agent.The vulnerability stems from Apigee API Proxies' ability to execute custom JavaScript policy scripts that can access the underlying Instance Metadata Service (IMDS).An attacker wi…

Cloud SecuritySecurity ResearchVulnerabilities
P10
2026-08-30 08:38 UTC
Other

Security Affairs newsletter Round 592 by Pierluigi Paganini – INTERNATIONAL EDITION

Security Affairs · Pierluigi Paganini · indexed 2026-08-30 09:40 UTC

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. Hack One Robot, Reach the Next: Unitree G1 Security Flaws Rhysida Ransomware Group Targets Berlin Government Ahead […]

Cloud SecurityRansomware
P15
2026-08-29 16:25 UTC
Security Journalism

Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-29 17:20 UTC

Multiple critical security flaws have been disclosed in WordPress plugins and themes, including WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP, that could lead to authentication bypass, account takeover, and arbitrary code execution. The vulnerabilities, according to Wordfence and Patchstack, are listed below - CVE-2026-76581 (CVSS score: 9.8) - An authentication bypass flaw in

Cloud SecurityVulnerabilitiesCVE-2026-76581
P30
2026-08-29 11:55 UTC
Other

Hack One Robot, Reach the Next: Unitree G1 Security Flaws

Security Affairs · Pierluigi Paganini · indexed 2026-08-29 12:50 UTC

A researcher chained two Unitree G1 flaws to gain root access remotely and showed how a compromised robot could attack others nearby. Security researcher Olivier Laflamme spent about three months digging into the Unitree G1 humanoid robot and eventually found a way to fully compromise it without plugging in a single cable. In his technical […]

Cloud SecuritySecurity Research
P0
2026-08-29 09:16 UTC
Other

Philippine Nuclear and Naval Targets Hit by Suspected Chinese Operator

Security Affairs · Pierluigi Paganini · indexed 2026-08-29 09:40 UTC

An alleged Chinese-speaking actor breached Philippine nuclear and naval targets by exploiting known flaws, stealing sensitive data. A suspected Chinese-speaking operator targeted a Philippine nuclear research body and a marine engineering company that supports the Philippine Navy, using well-known vulnerabilities in internet-facing ownCloud and WordPress systems. The activity was uncovered after Hunt.io found an exposed […]

Cloud Security
P0
2026-08-28 18:53 UTC
Vendor Research

Extend your data perimeter to the AWS Management Console with Private Access

AWS Security Blog · Madhur Kulkarni · indexed 2026-08-28 19:15 UTC

Organizations in regulated industries such as financial services, government, defense, and healthcare restrict their sensitive workloads to isolated network environments with no access to the public internet. Until now, customers could restrict AWS Management Console access to authorized AWS accounts and corporate networks, but the console itself required internet connectivity. This was creating tension between […]

Cloud Security
P0
2026-08-28 17:12 UTC
Security Journalism

Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-28 18:30 UTC

Malicious actors are exploiting a newly patched security flaw in PaperCut NG and MF to execute arbitrary code on susceptible instances, as the company released a fresh emergency fix with additional hardening. "This vulnerability gives an unauthenticated attacker remote control over PaperCut's trusted configuration, which could be used to execute arbitrary Java code inside the application's

Cloud SecurityVulnerabilities
P0
2026-08-28 14:00 UTC
Security Journalism

AI Is Accelerating Vulnerability Discovery. Can Defenders Keep Up?

BleepingComputer · Sponsored by Action1 · indexed 2026-08-28 14:20 UTC

AI is accelerating vulnerability discovery, putting pressure on systems built to enrich, prioritize, and remediate flaws at a slower pace. Action1 explains why defenders increasingly need to correlate multiple intelligence sources and turn vulnerability data into faster remediation. [...]

Cloud SecurityMicrosoftVulnerabilities
P0
2026-08-28 13:54 UTC
Other

U.S. CISA adds ownCloud, Linux Kernel, and JFrog Artifactory flaws to its Known Exploited Vulnerabilities catalog

Security Affairs · Pierluigi Paganini · indexed 2026-08-28 14:40 UTC

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds ownCloud, Linux Kernel, and JFrog Artifactory flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2023-49105 (CVSS score of 9.8) is an improper-authentication flaw in ownCloud Server’s WebDAV functionality. An unauthenticated attacker who […]

Cloud SecurityLinuxVulnerabilitiesCVE-2023-49105
P35
2026-08-28 12:07 UTC
Security Journalism

Two Unitree G1 EDU Humanoid Robot Flaws Enable Root RCE, One Starts Over Bluetooth

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-28 13:15 UTC

Security researcher Olivier Laflamme has disclosed two independent root remote code execution (RCE) chains affecting the Unitree G1 EDU, including a Bluetooth Low Energy (BLE) path that can reach root on the robot's Locomotion PC. The flaws are tracked as CVE-2026-76639 and CVE-2026-76640, with the first involving a network-adjacent path through chat_go and bashrunner and the

Cloud SecuritySecurity ResearchVulnerabilitiesCVE-2026-76639CVE-2026-76640
P20
2026-08-28 11:20 UTC
Security Journalism

Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-28 11:40 UTC

ServiceNow has released patches for four security flaws impacting the ServiceNow AI Platform, three of them rated 10.0 on the CVSS scoring system and exploitable, in certain circumstances, by an unauthenticated attacker. The company said it deployed a security update to hosted instances and provided the update to its partners and self-hosted customers, which leaves organizations that run their

Cloud SecurityVulnerabilities
P5
2026-08-28 09:07 UTC
Other

U.S. CISA adds Red Hat, Linux Kernel, Ajax.NET Professional, Microsoft SQL Server, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog

Security Affairs · Pierluigi Paganini · indexed 2026-08-28 09:30 UTC

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Red Hat, Linux Kernel, Ajax.NET Professional, Microsoft SQL Server, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2015-3246 is a race condition in Red Hat libuser that could let […]

Cloud SecurityLinuxMicrosoftVulnerabilitiesCVE-2015-3246
P35
2026-08-27 15:13 UTC
Security Journalism

Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-27 17:00 UTC

Credit: Hacktron Vercel has released security patches for two critical-severity vulnerabilities in the Next.js web framework, both of which allow unauthenticated remote code execution, one exploitable via specially crafted AVIF image files and the other through a path traversal flaw affecting servers that use a Windows filesystem. The Windows path traversal, tracked as CVE-2026-75604&

Cloud SecurityMicrosoftVulnerabilitiesCVE-2026-75604
P20
2026-08-27 14:30 UTC
Vendor Research

How to build an exposure management program the business trusts: Lessons from Tenable’s CSO

Tenable Blog · Robert Huber · indexed 2026-08-27 14:40 UTC

Discover how Tenable’s shift to an AI-driven exposure management program helped Tenable’s CSO, Robert Huber, overcome tool sprawl, unify data silos, mitigate the risk of rapid AI adoption, and shift from presenting granular, technical metrics to communicating business risk that the C-suite and the board can understand.Key takeawaysSecurity tool sprawl and data silos make it difficult for CISOs to holistically and accurately assess their organizations’ cyber risk.An exposure management program c…

AI SecurityAppleCloud SecurityMicrosoftVulnerabilities
P0
2026-08-27 07:05 UTC
Security Journalism

CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-27 07:15 UTC

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added six flaws to its Known Exploited Vulnerabilities (KEV) catalog, including a high-severity security vulnerability impacting Citrix NetScaler ADC and NetScaler Gateway, citing evidence of active exploitation. The vulnerabilities are listed below - CVE-2019-1068 - A remote code execution vulnerability in

Cloud SecurityLinuxVulnerabilitiesCVE-2019-1068
P50
2026-08-26 19:32 UTC
Vendor Research

ICYMI: July 2026 @AWS Security

AWS Security Blog · Rodolfo Brenes · indexed 2026-08-26 19:40 UTC

If you found time for a bit of vacation this summer, you might be in catch-up mode. Here’s a list to help: all the expert blog posts, new service capabilities, code samples, and workshops, in case you missed it, from July 2026. AWS Security Blog post This month’s AWS Security Blog posts covered AI agent […]

AI SecurityCloud Security
P0
2026-08-26 17:39 UTC
Vendor Research

Detecting multi-stage attacks on AWS: A guide to cross-service signal correlation

AWS Security Blog · Nisha Kashyap · indexed 2026-08-26 18:00 UTC

A single alert from one security service tells you something happened. Read that signal alongside activity from other services and your own business context, and you will know whether what happened is part of a multi-stage attack. Consider a short sequence. An identity calls GetCallerIdentity from a source address it hasn’t previously used. Within minutes, […]

Cloud Security
P0
2026-08-26 11:55 UTC
Security Journalism

Unpatched Kaltura mwEmbed Flaws Could Let Remote Attackers Read Files and Run Code

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-26 13:10 UTC

The CERT Coordination Center (CERT/CC) has disclosed two unpatched vulnerabilities in Kaltura's HTML5 video player library that allow a remote, unauthenticated attacker to read arbitrary files from a server and execute code on it. The flaws, tracked as CVE-2026-19913 and CVE-2026-19912, both stem from the same unsafe deserialization in the mwEmbedLoader.php endpoint of the mwEmbed player

Cloud SecurityVulnerabilitiesCVE-2026-19912CVE-2026-19913
P5
2026-08-25 21:53 UTC
Vendor Research

Fast Track ISM-ready cloud environments and IRAP Assessments with Landing Zone Accelerator on AWS

AWS Security Blog · Kevin Donohue · indexed 2026-08-25 21:55 UTC

This post announces the availability of a new independent assessment report available on AWS Artifact analyzing how Landing Zone Accelerator on AWS (LZA) can automatically deploy multi-account environments in Amazon Web Services (AWS) with Australian Government Information Security Manual (ISM) security controls coverage at scale. The report includes findings from an independent third-party analysis conducted […]

Cloud Security
P0
6 7 8 9 10