IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 237 matching records.
AUTO-POLL // 2026-10-04 09:05 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P9 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 4

RANSOMWARE
P9
P9
COOL // 5 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
FRI
Oct 2

RANSOMWARE
P7
P7
COOL // 46 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
WED
Sep 30

RANSOMWARE
P10
P10
WARM // 59 ARTICLES
TUE
Sep 29

RANSOMWARE
P4
P4
COOL // 68 ARTICLES
MON
Sep 28

RANSOMWARE
P7
P7
COOL // 52 ARTICLES
RESET
2026-09-14 09:56 UTC
Security Journalism

Telus Warns Customers of Account Breaches

Security Week · Eduard Kovacs · indexed 2026-09-14 10:10 UTC

Stolen credentials were used in a multi-month campaign to access subscriber personal data and billing records. The post Telus Warns Customers of Account Breaches appeared first on SecurityWeek.

Cybercrime
P0
2026-09-13 10:11 UTC
Security Journalism

Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-13 10:25 UTC

Microsoft has disclosed details of two campaigns in which threat actors are abusing third-party email delivery infrastructure to blast financial fraud scam messages and using passkey-themed social engineering to breach cloud environments. The first campaign, per the tech giant, involved sending over a million scam emails between August 3 and 5, 2026, by masquerading as chief executive officers

CybercrimeMicrosoftPhishingThreat Actors
P0
2026-09-12 21:05 UTC
Other

Revolut Exposed KYC Data After Fraudulent Government Email Passed Security Checks

Security Affairs · Pierluigi Paganini · indexed 2026-09-12 22:10 UTC

Revolut handed over KYC documents, selfies, and Bitcoin transaction histories after a fake government email with valid domain credentials passed its checks. Revolut confirmed on September 12, 2026, that it disclosed sensitive customer data to an unauthorized third party after receiving fraudulent information requests sent from an email address operating inside an actual government agency’s […]

Cybercrime
P0
2026-09-12 16:46 UTC
Other

Anthropic: AI Misuse Is Entering a New Phase: From Cybercrime to Surveillance, Propaganda and Weapons

Security Affairs · Pierluigi Paganini · indexed 2026-09-12 17:20 UTC

AI is becoming an operational force for cybercrime, surveillance, propaganda, fraud and weapons development, lowering the cost and scale of attacks. Artificial intelligence (AI) is becoming more than a tool for people who want to do something malicious. It is increasingly becoming part of the operational machinery itself. That is the main message emerging from […]

AI SecurityCybercrime
P0
2026-09-11 13:33 UTC
Vendor Research

The Fraud Ecosystem: A Transition From Known Marketplaces to a Fragmented Environment

Rapid7 · Gal Givon · indexed 2026-09-11 15:05 UTC

IntroductionThe surge in emerging threat actors directly correlates with the rapid escalation of victim counts and stolen financial resources. Simultaneously, this growth has spurred the proliferation of specialized supply storefronts across social media platforms, dark web channels, and various smaller niche marketplaces. Security teams today face evolving challenges, requiring them to continuously refine monitoring channels, adjust operational strategies, and foster cross-functional internal …

CybercrimeMalwarePhishingThreat ActorsThreat Intelligence
P0
2026-09-10 17:23 UTC
Vendor Research

Protecting organizations from AI-assisted executive impersonation and invoice fraud

Microsoft Security Blog · Microsoft Security Research · indexed 2026-09-10 19:15 UTC

Microsoft examines an AI-assisted business email compromise campaign that used executive impersonation and fake invoices to target finance teams with ACH payment fraud. The post Protecting organizations from AI-assisted executive impersonation and invoice fraud appeared first on Microsoft Security Blog.

CybercrimeMicrosoftPhishing
P0
2026-09-09 15:37 UTC
Security Journalism

FBI puts its cyber strategy on paper

The Record · indexed 2026-09-09 15:55 UTC

The first public cybersecurity strategy issued by the FBI "directs our teams, our field offices, our global presence" to align their efforts on countering malicious hackers and cybercrime groups, senior official Brett Leatherman says.

CybercrimeLaw Enforcement
P0
2026-09-07 19:40 UTC
Other

Condé Nast Data of 32.8 Million Users Offered for Sale After WIRED Leak

Security Affairs · Pierluigi Paganini · indexed 2026-09-07 19:55 UTC

Condé Nast user data from 32.8 million accounts is reportedly for sale, raising risks of targeted phishing, fraud and scams. A database said to contain 32.8 million Condé Nast user records is being offered for $15,000 on a Russian-language cybercrime forum. Ransomnews reviewed a 5,000-record sample and concluded that it is consistent with genuine Condé […]

CybercrimePhishing
P0
2026-09-07 07:19 UTC
Other

Berlin Ransomware Leak Exposes State Secrets

Security Affairs · Pierluigi Paganini · indexed 2026-09-07 08:30 UTC

Berlin refused a 30 Bitcoin ransom, leading hackers to leak 6TB of sensitive state administration and national defense data on the dark web. When a ransomware gang dumps nearly six terabytes of state administration files onto the dark web, ignoring them does not make the problem go away. The Rhysida ransomware group recently carried out […]

CybercrimeRansomware
P15
2026-09-04 07:02 UTC
Other

Dark Web Service Nexus Sells 153M+ Driver’s Licenses

Security Affairs · Pierluigi Paganini · indexed 2026-09-04 07:55 UTC

FBI probes suspected breach at IDScan.net after dark web service Nexus offered 153M+ US and Canadian driver’s license scans. A dark web identity theft service called Nexus appeared on September 1, 2026, offering searchable access to more than 153 million scanned driver’s licenses belonging to people in the United States and Canada. The FBI’s New […]

CybercrimeLaw Enforcement
P0
2026-09-03 15:26 UTC
Security Journalism

BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-03 16:45 UTC

Cybersecurity researchers have disclosed details of a sophisticated Python-based Windows malware framework called BraZetsu that fuels an underground marketplace commercializing access to compromised hosts. "Unlike the standard infostealer model, BraZetsu is a comprehensive master toolkit that empowers Initial Access Brokers (IABs) by turning compromised systems into highly valuable commercial

CybercrimeMalwareMicrosoftSecurity Research
P0
2026-09-03 13:17 UTC
Other

412,000 The Town 2025 Ticket Buyers’ Data Hits the Dark Web

Security Affairs · Pierluigi Paganini · indexed 2026-09-03 14:00 UTC

412,000 The Town 2025 festival buyer records are being sold for $10,000, with Brazil’s data openly marketed for bank fraud, loans and SIM registration. A seller on a Russian-language data-trading forum listed what they’re calling a Ticketmaster database on September 2, claiming over 412,000 Latin American purchase records with a heavy concentration of Brazilian data. […]

CybercrimeMicrosoft
P0
2026-09-02 13:44 UTC
Security Journalism

Malicious Apache Modules Hijack Brazilian Government Site Traffic to Push Betting Pages

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-02 14:15 UTC

A Chinese-speaking cybercrime cluster known as Gambling Goblin has been observed installing malicious Apache modules on compromised web servers run by Brazilian government and educational institutions, and using them to divert visitors to attacker-controlled pages promoting online gambling and sports betting. Check Point Research said it has tracked the campaign since mid-2025. The modules

Cybercrime
P0
2026-09-02 10:16 UTC
Other

Gaming the system: how a Chinese-speaking actor turned Brazilian government sites into an SEO weapon

Check Point Research · stcpresearch · indexed 2026-09-07 17:30 UTC

Research by: Amit Yardeni Key Points Introduction Since mid-2025, Check Point Research has tracked a sustained campaign against Brazilian organizations. The tradecraft points to a Chinese-speaking cybercrime group connected to Earth Berberoka, an actor first documented targeting gambling sites across Asia. Once inside a victim, the group deploys a broad Linux toolkit: a custom downloader, several backdoors, […] The post Gaming the system: how a Chinese-speaking actor turned Brazilian government…

CybercrimeLinuxMalware
P0
2026-09-01 22:40 UTC
Independent Research

FBI Probes Service Selling 153M+ Drivers Licenses

Krebs on Security · BrianKrebs · indexed 2026-09-01 23:05 UTC

A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada. Based on interviews with individuals whose licenses are available for purchase on this service, it appears to be siphoning images collected by a widely-used identity verification company based in Louisiana. KrebsOnSecurity also has learned that the New Orleans field office of the Federal Bureau of Investigation (FBI) toda…

CybercrimeDFIRLaw Enforcement
P0
2026-09-01 17:19 UTC
Security Journalism

Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-01 18:15 UTC

Brazilian financial services, retail, and e-commerce organizations have become the target of a financially motivated threat actor dubbed Breeze Comet (formerly UNC5669) since 2024. Google Threat Intelligence Group (GTIG) and Mandiant teams described the threat actor as "specializing in manipulating payment systems and banking software in Brazil to conduct fraudulent transfers." The adversary

CybercrimeThreat ActorsThreat Intelligence
P0
2026-09-01 14:07 UTC
Security Journalism

13 Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Wallet Seeds

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-01 14:45 UTC

Cybersecurity researchers have identified a set of 13 malicious Composer theme packages on Packagist that are designed to inject JavaScript into Vietnamese movie and comic streaming sites that install those libraries and initiate the deployment of spyware aimed at unpatched iOS devices. "The injected code runs two operations against a site's visitors: a mobile ad-fraud and gambling-redirect

AppleCybercrimeSecurity Research
P0
2026-09-01 14:00 UTC
Vendor Research

Financially Motivated Threat Actor BREEZE COMET Targets Brazil

Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-09-01 03:50 UTC

Introduction Beginning in 2024 Mandiant investigated a string of compromises affecting Brazilian financial services, retail, and eCommerce organizations. Google Threat Intelligence Group (GTIG) tracks this activity as BREEZE COMET (formerly UNC5669), a financially motivated threat actor specializing in manipulating payment systems and banking software in Brazil to conduct fraudulent transfers. This activity overlaps with operations publicly reported as Plump Spider and SHADOW-AETHER-064. In thi…

AI SecurityCloud SecurityCybercrimeMalwareMicrosoftNetwork SecurityPhishingThreat ActorsThreat Intelligence
P0
2026-08-31 17:24 UTC
Security Journalism

North Korean Job Fraud Expands Beyond IT Into Healthcare and Sales

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-31 18:05 UTC

Threat actors with ties to the Democratic People's Republic of Korea (aka DPRK or North Korea) have been observed seeking job opportunities beyond the information technology (IT) sector, with recent investigations identifying suspected workers employed in sales and marketing and the medical profession. The ongoing insider threat is part of what has been described as the IT worker scheme,

CybercrimeDFIRThreat Actors
P0
2026-08-31 11:47 UTC
Security Journalism

Aurora Ransomware Operators Use Cursor AI in Attacks Against 10 Targets

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-31 12:30 UTC

Threat actors associated with Aurora (aka Aur0ra) ransomware have been observed using SpaceX's artificial intelligence (AI)-powered coding assistant Cursor to break into target networks, according to findings from CloudSEK and Gambit Security. The two independent analyses are based on exposed infrastructure associated with the Russian-speaking cybercrime group, leading to the discovery of its

AI SecurityCybercrimeRansomwareThreat Actors
P15
1 2 3 4