IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 292 matching records.
AUTO-POLL // 2026-10-04 11:15 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P8 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 4

RANSOMWARE
P8
P8
COOL // 6 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
FRI
Oct 2

RANSOMWARE
P7
P7
COOL // 46 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
WED
Sep 30

RANSOMWARE
P10
P10
WARM // 59 ARTICLES
TUE
Sep 29

RANSOMWARE
P4
P4
COOL // 68 ARTICLES
MON
Sep 28

RANSOMWARE
P7
P7
COOL // 52 ARTICLES
RESET
2024-03-13 00:00 UTC
Security Journalism

Using Backup Utilities for Data Exfiltration | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

“Double extortion” attacks, often perpetrated by ransomware threat actors, include data exfiltration prior to file encryption. Huntress analysts have observed various means of data exfiltration, but recently observed the use of a legitimate backup application seen by others to be associated with a Noberus/ALPHV ransomware affiliate.

RansomwareThreat Actors
P15
2024-03-04 00:00 UTC
Security Journalism

Insights: RMM Tools | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

Over the past year, the Huntress team has posted a number of blog posts related to remote monitoring and management (RMM) tools being installed or abused by threat actors.

Threat Actors
P0
2024-02-08 00:00 UTC
Security Journalism

Attacking MSSQL Servers | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

In addition to social engineering attacks, threat actors target organizations' attack surface, looking for exposed services and applications to gain access into an infrastructure. Microsoft SQL database servers have long been a target for attackers.

MicrosoftThreat Actors
P0
2023-11-09 00:00 UTC
Security Journalism

Bitter Pill | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

Huntress has uncovered a series of unauthorized access, revealing a threat actor using ScreenConnect to infiltrate multiple healthcare organizations.

Threat Actors
P0
2023-11-02 00:00 UTC
Other

ApatchMe

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Amazon Managed Workflows for Apache Airflow (MWAA) and the Task instance details page in the Google Composer UI were not patched against CVE-2023-29247 (Stored XSS). This meant that post-authentication, a threat actor could have exploited this to store their JavaScript payload in the victim's managed Apache Airflow instance and run JavaScript on behalf of the victim (who could be an admin or another user with higher permissions than the threat actor, thereby leading to privilege escalation). Wi…

Threat ActorsVulnerabilitiesCVE-2023-29247
P15
2023-06-08 00:00 UTC
Security Journalism

Calm In The Storm: Reviewing Volt Typhoon

Huntress · indexed 2026-09-07 17:30 UTC

Explore the recent disclosures concerning Volt Typhoon, a threat actor engaged in the widespread exploitation of external-facing services and network appliances.

Threat Actors
P0
2023-05-18 00:00 UTC
Other

GuardDuty bypass via S3 permission modification

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Threat actors in possession of IAM active credentials that had the power to update S3 bucket policies could have bypassed GuardDuty’s S3 detections and silently updated permissions for S3 resources, resulting in a bucket configuration that allowed anonymous data access. This gap in GuardDuty’s alert coverage occurred only when S3’s Block Public Access was not enabled on the account or the bucket, and when KMS-based server-side bucket encryption was not in use. In order to trigger on opening pub…

Cloud SecurityThreat Actors
P0
2023-04-21 00:00 UTC
Other

GhostToken

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Google users can find and install third-party OAuth applications from Google Marketplace that are integrated with Google Workspace. Each OAuth application client in Google is associated with a GCP project. A bug in the way a GCP project enters a "pending deletion" state when deleted, could have allowed threat actors to make a malicious application invisible and unremovable from the user's account. If an attacker had managed to install an application in an account (e.g., through a phishing attac…

PhishingThreat ActorsVulnerabilities
P0
2017-08-02 12:29 UTC
Other

Hacktivists unmasked

Group-IB · indexed 2026-09-07 17:30 UTC

Group-IB reveals the identity of alleged members of the Islamic hacker group United Islamic Cyber Force

Threat Actors
P0
8 9 10