IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 627 matching records.
AUTO-POLL // 2026-10-04 12:05 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P8 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 4

RANSOMWARE
P8
P8
COOL // 6 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
FRI
Oct 2

RANSOMWARE
P7
P7
COOL // 46 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
WED
Sep 30

RANSOMWARE
P10
P10
WARM // 59 ARTICLES
TUE
Sep 29

RANSOMWARE
P4
P4
COOL // 68 ARTICLES
MON
Sep 28

RANSOMWARE
P7
P7
COOL // 52 ARTICLES
RESET
2026-08-20 13:07 UTC
Other

BTR Reforged: Weaponizing Defender’s Remediation Driver as a Kernel Operation Primitive

Check Point Research · shlomoo@checkpoint.com · indexed 2026-09-07 17:30 UTC

Research by: Jiří Vinopal (@vinopaljiri) Abstract What if a trusted security component could be repurposed into an attacker-controlled kernel primitive? What if a signed Microsoft remediation driver could be instructed to execute arbitrary file and registry operations from Ring 0 – without exploits, vulnerabilities, or memory corruption? In this publication, we present the first full […] The post BTR Reforged: Weaponizing Defender’s Remediation Driver as a Kernel Operation Primitive appeared fi…

LinuxMicrosoft
P0
2026-08-20 12:45 UTC
Community

Using Microsoft Graph and Powershell to Mine for Information - Stale Accounts and Licenses, (Thu, Aug 20th)

SANS Internet Storm Center · indexed 2026-08-20 12:00 UTC

Microsoft Graph is a newer API that is meant to replace several others.  OK, it's at version 2.3.9, so it's not all that new, but it's new enough that lots of folks (and commercial tools) aren't using it yet.   It allows you to Get and Set info from/to M365, Entra Users and Entra managed machines for starters.  Let's dig in!

Microsoft
P0
2026-08-20 10:01 UTC
Vendor Research

Frequently asked questions about the active threat to Siemens S7 Series PLCs

Tenable Cyber Exposure Alerts · Research Special Operations · indexed 2026-08-20 14:10 UTC

A joint cybersecurity advisory released by multiple U.S. government agencies warns that threat actors are using AI-generated exploitation scripts to target exposed Siemens S7 Series PLCs across critical infrastructure sectors.Key TakeawaysUnattributed threat actors are exploiting known weaknesses and unnecessary internet exposure to conduct reconnaissance and possible pre-positioning for future disruptive attacks against Siemens S7 Series PLCs.The attackers are leveraging AI to build and refine…

DFIRICS / OTLaw EnforcementMicrosoftThreat ActorsVulnerabilities
P25
2026-08-20 06:51 UTC
Security Journalism

Microsoft says August Windows updates may cause gaming issues

BleepingComputer · Sergiu Gatlan · indexed 2026-08-20 06:55 UTC

Microsoft is investigating a potential issue with the August 2026 updates that may prevent some games from launching or cause them to crash on affected Windows 11 systems. [...]

Microsoft
P0
2026-08-19 17:30 UTC
Vendor Research

Microsoft named a Leader in the Frost Radar™: Cloud Workload Protection Platforms, 2026

Microsoft Security Blog · Ran Rosin · indexed 2026-08-19 18:05 UTC

Microsoft is named a visionary leader in the 2026 Frost Radar for Cloud Workload Protection Platforms, recognized for unified runtime security with Microsoft Defender for Cloud. The post Microsoft named a Leader in the Frost Radar™: Cloud Workload Protection Platforms, 2026 appeared first on Microsoft Security Blog.

Microsoft
P0
2026-08-19 13:12 UTC
Security Journalism

SilkParasite Espionage Campaign Targets Central Asian Governments with Five New RATs

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-19 13:35 UTC

A previously unreported cyber espionage operation dubbed SilkParasite has been observed targeting government bodies in Central Asia. The intrusion set makes use of seven remote access tool (RAT) families, five of which have never been previously documented: DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT. SilkParasite, first discovered in late 2025, is assessed to be a

APT / Nation-StateMicrosoft
P0
2026-08-19 11:14 UTC
Security Journalism

Microsoft fixes known issue causing Windows Defender crashes

BleepingComputer · Sergiu Gatlan · indexed 2026-08-19 11:35 UTC

Microsoft has resolved a bug that caused Windows Defender to crash after a recent security update, resulting in 0xc0000005 access violation errors on some affected systems. [...]

Microsoft
P5
2026-08-19 11:01 UTC
Security Journalism

Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-19 11:35 UTC

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added four critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, stating they are being exploited in the wild. The shortcomings added to the KEV catalog are listed below - CVE-2026-65400 (CVSS score: 9.8) - An improper authentication vulnerability impacting Apple macOS that could allow an

AppleCloud SecurityMicrosoftVulnerabilitiesCVE-2026-65400
P55
2026-08-19 08:55 UTC
Other

Microsoft Tracks MacSync Stealer by Its Behavior, Not Its Domains

Security Affairs · Pierluigi Paganini · indexed 2026-08-19 09:50 UTC

Microsoft tracked over 30 MacSync Stealer domains by focusing on behavioral patterns, revealing a campaign targeting passwords, keys, wallets and other data. Domain blocking is a losing game when the thing you’re blocking can register a new domain faster than you can add it to a list. That’s the exact problem Microsoft Defender Experts ran […]

MalwareMicrosoft
P0
2026-08-19 07:19 UTC
Other

U.S. CISA adds Apple macOS, Microsoft SharePoint, Broadcom VMware vCenter, and Microsoft IKE flaws to its Known Exploited Vulnerabilities catalog

Security Affairs · Pierluigi Paganini · indexed 2026-08-19 07:35 UTC

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Apple macOS, Microsoft SharePoint, Broadcom VMware vCenter, and Microsoft IKE flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2026-33824 is a Windows Internet Key Exchange (IKE) Service Extensions Remote Code Execution […]

AppleCloud SecurityMicrosoftVulnerabilitiesCVE-2026-33824
P50
2026-08-19 06:01 UTC
Security Journalism

Microsoft Links 30+ Rotating Domains to MacSync Stealer Infrastructure

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-19 09:45 UTC

Microsoft Defender Experts have linked more than 30 web domains to MacSync Stealer, a macOS-focused information stealer, after correlating recurring endpoint and network behaviors across changing infrastructure, tracing the malware from payload retrieval through data collection, staging, and exfiltration. The tech giant said it required multiple endpoint and network behaviors to align before

AppleMalwareMicrosoft
P0
2026-08-18 19:05 UTC
Vendor Research

Threat Brief: Mitigating Large-Scale Credential Attacks (Updated August 18)

Palo Alto Networks Unit 42 · Unit 42 · indexed 2026-08-18 20:45 UTC

In August 2026, the actor TheHatman claimed to have stolen large volume of credentials from organizations' Microsoft Entra tenants. We provide guidance on mitigating large-scale credential attacks. The post Threat Brief: Mitigating Large-Scale Credential Attacks (Updated August 18) appeared first on Unit 42.

Microsoft
P0
2026-08-18 17:47 UTC
Security Journalism

Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-18 18:35 UTC

Varonis Threat Labs has disclosed three vulnerabilities in Microsoft Copilot Personal that it said could allow a single click on a crafted link to silently pull data from connected apps and other information available to the victim's Copilot session. The flaws, which the researchers collectively named CoSnitch, turn in part on an undocumented URL parameter that the assistant itself surfaced

Cloud SecurityMicrosoft
P0
2026-08-18 17:08 UTC
Vendor Research

Hunting MacSync Stealer infrastructure through behavioral pivots

Microsoft Security Blog · Microsoft Defender Experts and Microsoft Security Research · indexed 2026-08-18 18:40 UTC

MacSync Stealer rapidly rotates domains to evade detection, but its behavior remains consistent. Learn how Microsoft uncovered 30+ related domains using durable hunting pivots. The post Hunting MacSync Stealer infrastructure through behavioral pivots appeared first on Microsoft Security Blog.

MalwareMicrosoft
P0
2026-08-18 16:58 UTC
Security Journalism

Ransom Busters Claims It Hacked Ransomware Servers, Asks Victims for Up to $60,000

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-18 18:35 UTC

A ransomware affiliate calling itself Ransom Busters has been spotted proactively sending emails to victim organizations and claims to delete stolen data from ransomware groups' servers in exchange for a fee ranging from $20,000 to $60,000. "In these messages, the third-party offers to help the victim recover from ransomware attack. This immediately stands out as anomalous," GuidePoint Research

Data BreachesMicrosoftRansomware
P15
2026-08-18 14:00 UTC
Vendor Research

Staying Ahead of Adversarial AI Through Agentic Source Code Review

Google Threat Intelligence / Mandiant · Mandiant · indexed 2026-08-18 15:55 UTC

Written by: Alex Tselevich, Michael Maturi Introduction Adversarial misuse of AI has increased the risk of data theft and extortion events, because when proprietary source code is exposed, defenders must scramble to identify and patch vulnerabilities while attackers deploy machine-speed AI tools against them. By structuring the analysis process, enforcing skeptical validation steps, and injecting domain-specific human expertise directly into the pipeline, we’ve achieved a leap in efficacy. Comb…

AI SecurityCloud SecurityDFIRMicrosoftThreat IntelligenceVulnerabilitiesCVE-2026-13242CVE-2026-55803
P20
2026-08-18 12:49 UTC
Vendor Research

New Report: AI threats are here. Why Q2 2026 signals the end of traditional patch cycles

Rapid7 · Rapid7 Labs · indexed 2026-08-18 15:35 UTC

You can’t patch everything. So what do you fix first? Findings in Q2 2026 have changed traditional answers.The latest Quarterly Threat Landscape Report from Rapid7 Labs shows vulnerability disclosures still surging while attackers use automation and AI-assisted tooling to compress the time between disclosure and exploitation. The gap that patch cycles were built to fill is closing. Speed and volume are overwhelming security teams that have relied on traditional patch cycles and reactive program…

APT / Nation-StateCloud SecurityCybercrimeDFIRICS / OTMicrosoftPhishingRansomwareVulnerabilities
P15
2026-08-18 12:38 UTC
Security Journalism

TWINLOOT Abuses SharePoint and Teams to Steal Credentials and Move Across Networks

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-18 13:05 UTC

Cybersecurity researchers have disclosed details of a previously undocumented Python implant framework dubbed TWINLOOT. "TWINLOOT is a modular, PyArmor-hardened Python implant designed to operate its entire command-and-control infrastructure inside trusted Microsoft services," Ontinue said in a technical report shared with The Hacker News. "Tasking flows through SharePoint Online file

MicrosoftSecurity Research
P0
2026-08-18 11:20 UTC
Security Journalism

16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-18 11:55 UTC

Cybersecurity researchers have flagged a new typosquatting campaign targeting RubyGems users with a Windows-based information stealer. OpenSourceMalware, which discovered the activity on August 15, 2026, is tracking the threat under the moniker StubMaker. The complete list of packages published as part of the campaign is below - ubnuler ubnlder ri18nr reaker rakier orakw joxn

MalwareMicrosoftSecurity Research
P0
2026-08-18 11:14 UTC
Security Journalism

Microsoft tests faster Windows File Explorer, new context menu

BleepingComputer · Sergiu Gatlan · indexed 2026-08-18 11:25 UTC

Microsoft has started testing a faster File Explorer and a less cluttered and more customizable context menu in Windows 11 preview builds rolling out to Insiders this week. [...]

Microsoft
P0
2026-08-18 08:12 UTC
Security Journalism

Microsoft starts removing WMIC tool used by cybercriminals

BleepingComputer · Sergiu Gatlan · indexed 2026-08-18 08:15 UTC

Microsoft announced that it removed the Windows Management Instrumentation Command-line (WMIC) tool from Windows 11 24H2 and 25H2, as well as from Windows 11 beta builds released this week. [...]

Microsoft
P0
2026-08-17 15:15 UTC
Vendor Research

Detecting cloud ransomware in Azure with Tenable One’s cloud detection and response capabilities

Tenable Blog · Clément Notin · indexed 2026-08-17 15:35 UTC

Learn how Tenable One Cloud Exposure helps you unmask the sophisticated tactics of cybercrime group Storm-0501, which carries out Azure-based cloud ransomware campaigns. Tenable One Cloud Exposure uses AI-powered threat stories to expose Storm-0501 TTPs, backed by precision-engineered threat detection alerts.Key takeawaysStorm-0501 demonstrates that cloud-first ransomware groups have shifted from simple endpoint encryption to the total hijacking of cloud tenants.Storm-0501 systematically neutra…

AppleCloud SecurityCybercrimeDFIRMalwareMicrosoftRansomwareThreat ActorsThreat Intelligence
P15
10 11 12 13 14