IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 94 matching records.
AUTO-POLL // 2026-10-04 09:05 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P9 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 4

RANSOMWARE
P9
P9
COOL // 5 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
FRI
Oct 2

RANSOMWARE
P7
P7
COOL // 46 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
WED
Sep 30

RANSOMWARE
P10
P10
WARM // 59 ARTICLES
TUE
Sep 29

RANSOMWARE
P4
P4
COOL // 68 ARTICLES
MON
Sep 28

RANSOMWARE
P7
P7
COOL // 52 ARTICLES
RESET
2026-10-02 14:30 UTC
Security Journalism

In Other News: $15K iCloud Spoofing Bugs, AI Policy Experts Phished, Adblocker Spies on AI Chats

Security Week · SecurityWeek News · indexed 2026-10-02 14:30 UTC

Noteworthy stories that might have slipped under the radar: Kiteworks patches over 100 vulnerabilities, Microsoft publishes 2026 Digital Defense Report, AI finds 24 Android app flaws. The post In Other News: $15K iCloud Spoofing Bugs, AI Policy Experts Phished, Adblocker Spies on AI Chats appeared first on SecurityWeek.

Cloud SecurityMicrosoftMobile SecurityPhishing
P0
2026-10-02 08:01 UTC
Security Journalism

Android 17 Advanced Protection Locks Accessibility Services to Verified Accessibility Tools

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-02 08:20 UTC

Google has announced a new security measure that limits access to Android's accessibility services to verified applications classified as Accessibility Tools when Advanced Protection is enabled. With malicious Android applications abusing the API serving as the main conduit for malware and financial fraud, the tech giant said the move would block a major attack pathway. Advanced Protection is a

CybercrimeMalwareMobile Security
P0
2026-09-28 17:38 UTC
Security Journalism

RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-28 18:40 UTC

RatHat's operators build and publish the Android banking trojan and control infected phones from a web console, according to security company Cleafy. Cleafy has traced nearly 100 deployments of that console since April 2026. It said this fits a malware-as-a-service model, in which each customer runs a separate copy. The console stores what the malware collects from each phone,

MalwareMobile Security
P0
2026-09-24 18:10 UTC
Security Journalism

Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-24 19:00 UTC

A OnePlus 15 running the latest OxygenOS can be rooted by a malicious app the owner installs, one that asks for no special permissions. A researcher, Rasmus Moorats, chained two flaws in OnePlus's own software to gain root access, the highest level of control over an Android phone. OnePlus told him the same flaws affect many more of its own devices and those of OPPO, though it has not

Cloud SecurityMobile Security
P0
2026-09-24 12:05 UTC
Security Journalism

Corp MDM Spyware Targets Logistics Firms, Steals New SMS and Redirects Calls

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-24 12:15 UTC

The logistics sector has become the target of a new malicious cyber campaign that distributes an Android spyware codenamed Corp MDM. According to Have I Been Squatted, the campaign uses fake Google Play pages branded as CEVA and TKW Logistics to distribute an Android Package Kit (APK) file that's dressed up as a system service. The delivered app has the package name "com.corp.mdm" Corp MDM

Mobile Security
P0
2026-09-21 12:51 UTC
Security Journalism

RatHat Android Trojan Uses AI for Automation

Security Week · Ionut Arghire · indexed 2026-09-21 12:55 UTC

The malware relies on AI for real-time device navigation and control, increasing adaptability and evasion. The post RatHat Android Trojan Uses AI for Automation appeared first on SecurityWeek.

MalwareMobile Security
P0
2026-09-18 10:04 UTC
Other

RatHat Turns Android Accessibility Into an Attack Weapon

Security Affairs · Pierluigi Paganini · indexed 2026-09-18 10:50 UTC

RatHat combines AI-driven screen control, Android debugging abuse and advanced credential theft to give attackers deep control of infected phones. RatHat is the new Android trojan you should know about. Zimperium researchers just published a breakdown of a strain they’ve traced to China-based operators, and what makes it different isn’t the credential theft, which is […]

MalwareMobile SecurityPhishing
P0
2026-09-18 06:17 UTC
Security Journalism

RatHat Android Malware Abuses ADB to Retain Shell Access After Uninstall

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-18 06:30 UTC

Cybersecurity researchers have flagged a new Android malware called RatHat that's assessed to be operated by China-based threat actors and features an artificial intelligence (AI)-powered system to navigate and control compromised devices. "Distributed primarily via targeted smishing (SMS/text phishing) and malvertising campaigns leading to deceptive third-party download portals, RatHat uses

AI SecurityMalwareMobile SecurityPhishingSecurity ResearchThreat Actors
P0
2026-09-10 17:47 UTC
Security Journalism

ThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Stories

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-10 19:00 UTC

A lot of this week’s security news has the same awkward answer to one question: “Why was that allowed to work?” An extension asks for access and takes too much. A trusted service becomes part of a phishing chain. An old bug still gets results. An exposed system stays exposed. A package looks useful right up until it isn’t. Different stories, same basic problem: the path in was often already

Cloud SecurityMobile SecurityPhishing
P0
2026-09-10 14:36 UTC
Security Journalism

Google Play Early Access Abused to Push Thousands of Deceptive Android Apps

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-10 14:45 UTC

Bad actors are misusing Google Play's Early Access program to push deceptive apps that claim to offer money, rewards, casino winnings, and premium content. Early Access apps are apps that haven't been released on the official Android app marketplace. The main idea behind the program is for developers to solicit user feedback for new applications or features they may be working on before their

Mobile Security
P0
2026-09-10 11:33 UTC
Security Journalism

Gigabud Creates Android Work Profiles to Hide From Banking App Malware Checks

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-10 13:15 UTC

The Gigabud banking trojan now installs a second Android app that creates a work profile on an infected phone and drops a tampered banking app inside it, security firm Group-IB said in a report published on September 9. A work profile is a separate space that Android typically reserves for employer apps, and what's inside it is kept separate from everything in the personal space. That

MalwareMobile Security
P0
2026-09-08 18:07 UTC
Vendor Research

Microsoft’s September 2026 Patch Tuesday addresses 964 CVEs (CVE-2026-81963, CVE-2026-85880)

Tenable Cyber Exposure Alerts · Research Special Operations · indexed 2026-09-08 18:20 UTC

104Critical860Important0Moderate0LowMicrosoft addresses 964 CVEs, smashing July’s release as the largest Patch Tuesday release. This month’s updates include patches for two zero-days that were exploited in the wild.Microsoft patched a record 964 CVEs in its September 2026 Patch Tuesday release, with 104 rated critical and 860 rated as important.This month’s update includes patches for:.NET.NET and Visual StudioASP.NET CoreActive Directory Certificate Services (AD CS)Active Directory Domain Serv…

Cloud SecurityLinuxMicrosoftMobile SecurityNetwork SecurityVulnerabilitiesCVE-2023-21674CVE-2026-81963CVE-2026-85880
P65
2026-09-08 11:54 UTC
Security Journalism

WeChat Zero-Click Worm Took Over Accounts on iPhone and Android via Incoming Calls

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-08 13:20 UTC

Researchers at the security firm Calif have built a worm that takes over a WeChat account via an incoming call and demonstrated it spreading among three test phones. The person being called does not have to answer or touch their phone for it to work, but the caller must already be one of their WeChat contacts. Calif reported the flaw to Tencent in July and says the company has since

AppleMobile Security
P0
2026-09-02 12:22 UTC
Security Journalism

Meta Ads Push StreamRat Android Trojan That Can Gain Near-Complete Device Control

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-02 13:45 UTC

Cybersecurity researchers have disclosed details of a new Android banking trojan called StreamRat that was promoted to Spanish-speaking users through a fake television-streaming campaign on Meta and can give operators near-complete control of infected devices. ThreatFabric said the campaign's advertisement focused on Spain and reached an estimated 570,950 Meta accounts in the European Union

MalwareMobile SecuritySecurity Research
P0
1 2 3