IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 627 matching records.
AUTO-POLL // 2026-10-04 09:05 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P9 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 4

RANSOMWARE
P9
P9
COOL // 5 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
FRI
Oct 2

RANSOMWARE
P7
P7
COOL // 46 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
WED
Sep 30

RANSOMWARE
P10
P10
WARM // 59 ARTICLES
TUE
Sep 29

RANSOMWARE
P4
P4
COOL // 68 ARTICLES
MON
Sep 28

RANSOMWARE
P7
P7
COOL // 52 ARTICLES
RESET
2026-09-23 10:00 UTC
Security Journalism

Outerlimit Raises $16 Million to Stop Rogue AI Agents From Causing Harm

Security Week · Kevin Townsend · indexed 2026-09-23 10:10 UTC

Emerging from stealth with $16 million in pre-seed funding, Outerlimit offers a decentralized authorization layer designed to discover, observe, and block harmful autonomous AI actions. The post Outerlimit Raises $16 Million to Stop Rogue AI Agents From Causing Harm appeared first on SecurityWeek.

AI SecurityMicrosoft
P0
2026-09-23 08:29 UTC
Security Journalism

Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-23 08:45 UTC

A Chinese threat actor codenamed UTA0565 has been observed exploiting the recently disclosed Google Chrome-Microsoft Windows exploit chain as zero-days through fake websites. The attacks, detected on September 3 and 4, 2026, involved the chaining of two vulnerabilities in Chrome (CVE-2026-85046, CVE-2026-87491) and one impacting Windows Advanced Local Procedure Call (CVE-2026-85880) to break

MalwareMicrosoftThreat ActorsVulnerabilitiesCVE-2026-85046CVE-2026-85880CVE-2026-87491
P30
2026-09-23 08:25 UTC
Other

Fake LastPass on GitHub Led to an Infostealer That Killed 145 Security Tools

Security Affairs · Pierluigi Paganini · indexed 2026-09-23 08:50 UTC

Attackers spoofed LastPass on GitHub, used a Microsoft-signed driver to disable 145 security products, then deployed an infostealer. Someone impersonated LastPass on GitHub, got users to download a fake authenticator, and ended up killing 145 different antivirus and EDR products using a driver that Microsoft itself had signed. That last part is the one worth […]

MalwareMicrosoft
P0
2026-09-22 17:17 UTC
Security Journalism

Reducing shadow IT visibility gaps with Wazuh

BleepingComputer · Sponsored by Wazuh · indexed 2026-09-22 17:20 UTC

Shadow IT can leave security teams unaware of unmanaged endpoints, unauthorized software, and other assets that fall outside existing monitoring. Wazuh explains how endpoint inventory, agentless monitoring, and centralized analysis can help organizations identify and reduce these visibility gaps. [...]

Microsoft
P0
2026-09-22 17:03 UTC
Security Journalism

Microsoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox Compromises

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-22 17:55 UTC

Microsoft on Tuesday announced the takedown of the EvilTokens device code phishing service that it said used artificial intelligence (AI) "at every step of the attack chain." The action, carried out with authorization from the U.S. District Court for the Eastern District of Virginia, involved the efforts of Health-ISAC, alongside Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, The Shadowserver

AI SecurityMicrosoftPhishing
P0
2026-09-22 16:14 UTC
Security Journalism

Researcher Drops BigDiskBuster Zero-Day PoC That Blocks Microsoft Defender Updates

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-22 17:55 UTC

A zero-day proof-of-concept tool that stops Microsoft Defender from installing platform and signature updates by filling all available disk space was published on GitHub on September 19. The tool, called BigDiskBuster, has no patch, no CVE, and no Microsoft advisory. Its author, Abdelhamid Naceri, is a former Microsoft security researcher whose earlier Defender exploits were used in

MicrosoftSecurity ResearchVulnerabilities
P25
2026-09-22 15:51 UTC
Security Journalism

Two arrested in UK after Microsoft takedown of ‘Eviltokens’ AI-chatbot for cybercriminals

The Record · indexed 2026-09-22 16:00 UTC

Available on Telegram for a $1,500 initiation fee and a recurring monthly $500 subscription, EvilTokens provided cybercriminals with artificial intelligence tools enabling them to compromise accounts, analyze breached inboxes and find the best methods for monetizing their access through fraud.

AI SecurityCybercrimeLaw EnforcementMicrosoft
P0
2026-09-22 15:00 UTC
Vendor Research

Unmasking EvilTokens: Getting to the root of device code phishing

Microsoft Security Blog · Microsoft Threat Intelligence, Microsoft Defender Experts and Microsoft Security Research · indexed 2026-09-22 16:30 UTC

EvilTokens has quickly become one of the top PhaaS platforms, enabling device code phishing attacks through AI-assisted lures, automated infrastructure, and token theft. In collaboration with partners, Microsoft Digital Crimes Unit (DCU) facilitated a disruption of EvilTokens infrastructure and operations. The post Unmasking EvilTokens: Getting to the root of device code phishing appeared first on Microsoft Security Blog.

MicrosoftPhishing
P0
2026-09-22 14:04 UTC
Other

Chaotic Eclipse Released BigDiskBuster, A PoC For Windows Defender Update DoS Zero-Day

Security Affairs · Pierluigi Paganini · indexed 2026-09-22 14:10 UTC

The researcher Chaotic Eclipse released BigDiskBuster, a PoC exploit for a Windows Defender Update DoS Zero-Day vulnerability. Security researcher Chaotic Eclipse, also known as INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse, released a new zero-day exploit targeting Microsoft Defender. The researcher named the exploit BigDiskBuster, it triggers a Denial of Service Vulnerability in Windows Defender Update. The security researcher […]

MicrosoftSecurity ResearchVulnerabilities
P25
2026-09-22 11:17 UTC
Security Journalism

SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-22 12:10 UTC

A SharePoint Server vulnerability that Microsoft initially classified as a spoofing flaw with a CVSS score of 6.5 actually enables authenticated remote code execution, according to full technical details published today by Viettel Cyber Security researcher Dinh Ho Anh Khoa. The flaw, CVE-2026-65660, affects SharePoint Server 2016, 2019, and Subscription Edition. Patches have been

MicrosoftSecurity ResearchVulnerabilitiesCVE-2026-65660
P20
2026-09-22 10:13 UTC
Other

Public PoC Exposes Critical Veeam Agent Privilege Escalation

Security Affairs · Pierluigi Paganini · indexed 2026-09-22 10:50 UTC

A Veeam Agent flaw lets local users gain SYSTEM privileges. A public PoC is available, raising the risk of exploitation on shared Windows systems. If you’re running Veeam Agent on a Windows endpoint with more than one local user, now’s the time to check the version, not tomorrow. On September 14, 2026, public technical details […]

MicrosoftVulnerabilities
P10
2026-09-21 17:31 UTC
Security Journalism

Fake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus and EDR

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-21 18:15 UTC

A fake LastPass Authenticator installer offered on GitHub installs a Windows kernel driver that shuts off antivirus and other security software before a password stealer runs if a victim downloads and runs it, researchers at LastPass and Delphos Labs said on September 17. Microsoft's own hardware-compatibility program signs the driver, scored zero detections on VirusTotal when researchers

LinuxMalwareMicrosoft
P0
2026-09-21 13:16 UTC
Security Journalism

Microsoft reminds admins to migrate Entra ID users to passkeys

BleepingComputer · Sergiu Gatlan · indexed 2026-09-21 13:30 UTC

Microsoft has reminded admins to migrate Entra ID users to phishing-resistant authentication methods to avoid sign-in disruptions after it retires SMS first-factor sign-in starting in February 2027. [...]

MicrosoftPhishing
P0
2026-09-21 10:33 UTC
Community

TerminalFix: PNG Steganography, (Mon, Sep 21st)

SANS Internet Storm Center · indexed 2026-09-21 10:30 UTC

Microsoft Security Research published an interesting blog post "TerminalFix campaign deploys a reverse tunnel through multistage intrusion" about a malware campaign. The aspect that I want to take a closer look at, is the fact that the threat actors used PNG files with steganography. I reached out to the researchers and they kindly shared the IOCs for the PNG files with me.

MalwareMicrosoftSecurity ResearchThreat ActorsThreat Intelligence
P0
2026-09-21 08:39 UTC
Security Journalism

ClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 Infrastructure

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-21 08:45 UTC

Threat actors are leveraging ClickFix-like lures to deliver a previously undocumented remote access trojan (RAT) called ChainScript. "ChainScript has appeared under multiple build names, including ComponentTask33, UpdateDigital, HostShared, and OrchidViolet66, while presenting itself as Spotify, Zoom Workplace, and Microsoft Teams software," Blackpoint Adversary Pursuit Group (APG)

MalwareMicrosoftThreat Actors
P0
2026-09-21 07:28 UTC
Other

UK Police Data Faces Long-Standing Microsoft Cloud Security Concerns

Security Affairs · Pierluigi Paganini · indexed 2026-09-21 08:25 UTC

A 2017 UK assessment warned that police data on Microsoft Azure could face foreign access risks. The risks may still exist. A Guardian investigation has surfaced a 2017 document signed off by then City of London police commissioner Ian Dyson, who also held the title of senior information risk owner for the entire country. That […]

Cloud SecurityDFIRMicrosoft
P0
2026-09-18 15:50 UTC
Vendor Research

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software IKEv2 Certificate Authentication Denial of Service Vulnerability

Cisco Security Advisories · indexed 2026-09-16 16:40 UTC

A vulnerability in the certification authentication feature of Internet Key Exchange version 2 (IKEv2) for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly. This vulnerability is due to a logic error during the certificate authentication phase of the IKEv2 connection setup. An attacker could exploit this vulnerability by attem…

MicrosoftNetwork SecurityVulnerabilitiesCVE-2026-20249
P5
2026-09-18 14:00 UTC
Security Journalism

Secure enterprise sharing with access reviews for Microsoft 365

BleepingComputer · Sponsored by tenfold Software · indexed 2026-09-18 14:15 UTC

Microsoft 365 makes sharing files easy, but access can remain long after its original purpose has ended, leaving organizations with little visibility into who can still reach sensitive data. tenfold Software explains how centralized access governance and owner-driven reviews can help identify and remove unnecessary access. [...]

Microsoft
P0
2026-09-18 13:58 UTC
Security Journalism

Microsoft Teams will let admins block custom file extensions

BleepingComputer · Sergiu Gatlan · indexed 2026-09-18 14:15 UTC

Microsoft Teams will soon let administrators tweak the list of file extensions commonly associated with security threats to meet their company's security requirements. [...]

Microsoft
P0
2026-09-18 12:47 UTC
Security Journalism

Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-18 13:55 UTC

Microsoft has released fixes for a maximum-severity security flaw in Azure AI Foundry that could be exploited to achieve privilege escalation. No customer action is required. The vulnerability, tracked as CVE-2026-85889, carries a CVSS score of 10.0. "Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network,"

Cloud SecurityMicrosoftVulnerabilitiesCVE-2026-85889
P15
2 3 4 5 6