IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 292 matching records.
AUTO-POLL // 2026-10-04 10:30 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P9 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 4

RANSOMWARE
P9
P9
COOL // 5 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
FRI
Oct 2

RANSOMWARE
P7
P7
COOL // 46 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
WED
Sep 30

RANSOMWARE
P10
P10
WARM // 59 ARTICLES
TUE
Sep 29

RANSOMWARE
P4
P4
COOL // 68 ARTICLES
MON
Sep 28

RANSOMWARE
P7
P7
COOL // 52 ARTICLES
RESET
2026-04-23 21:38 UTC
Vendor Research

AI threats in the wild: The current state of prompt injections on the web

Google Online Security Blog · Kimberly Samra · indexed 2026-08-15 14:33 UTC

Posted by Thomas Brunner, Yu-Han Liu, Moni PandeAt Google, our Threat Intelligence teams are dedicated to staying ahead of real-world adversarial activity, proactively monitoring emerging threats before they can impact users. Right now, Indirect Prompt Injection (IPI) is a top priority for the security community, anticipating it as a primary attack vector for adversaries to target and compromise AI agents. But while the danger of IPI is widely discussed, are threat actors actually exploiting th…

AI SecurityMicrosoftSecurity ResearchThreat ActorsThreat Intelligence
P20
2026-04-23 14:00 UTC
Vendor Research

Snow Flurries: How UNC6692 Employed Social Engineering to Deploy a Custom Malware Suite

Google Threat Intelligence / Mandiant · Mandiant · indexed 2026-08-15 18:55 UTC

Written by: JP Glab, Tufail Ahmed, Josh Kelley, Muhammad Umair Introduction Google Threat Intelligence Group (GTIG) identified a multistage intrusion campaign by a newly tracked threat group, UNC6692, that leveraged persistent social engineering, a custom modular malware suite, and deft pivoting inside the victim’s environment to achieve deep network penetration. As with many other intrusions in recent years, UNC6692 relied heavily on impersonating IT helpdesk employees, convincing their victim…

Cloud SecurityMalwareMicrosoftPhishingThreat ActorsThreat Intelligence
P0
2026-04-17 14:00 UTC
Security Journalism

Disrupting Attacks on Endpoints | Attack Disruption Engine

Huntress · indexed 2026-09-07 17:30 UTC

Standard EDR creates a gap between detection and action. Huntress closes it. Learn how our Attack Disruption Engine automatically disrupts threat actors and reduces the impact of endpoint attacks.

Threat Actors
P0
2026-04-16 14:00 UTC
Vendor Research

Defending Your Enterprise When AI Models Can Find Vulnerabilities Faster Than Ever

Google Threat Intelligence / Mandiant · Francis deSouza · indexed 2026-08-15 18:55 UTC

Introduction Advances in AI model-powered exploitation have demonstrated that general-purpose AI models can excel at vulnerability discovery, even without being purpose-built for the task. Eventually, capabilities such as these will be integrated directly into the development cycle, and code will be more difficult to exploit than ever; however, this transition creates a critical window of risk. As we harden existing software with AI, threat actors will use it to discover and exploit novel vulne…

AI SecurityAPT / Nation-StateCloud SecurityDFIRMicrosoftRansomwareThreat ActorsVulnerabilities
P60
2026-04-15 14:00 UTC
Vendor Research

The German Cyber Criminal Überfall: Shifts in Europe's Data Leak Landscape

Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-08-15 18:55 UTC

Written by: Jamie Collier, Robin Grunewald Germany has reclaimed its position as a primary focus for cyber extortion in Europe. While data leak site (DLS) posts rose almost 50% globally in 2025, Google Threat Intelligence (GTI) data shows that the surge is hitting German infrastructure harder and faster than its regional neighbors, marking a significant return to the high-pressure levels previously observed in the country during 2022 and 2023. Cyber Criminals Pivoting Back to Germany Germany mo…

CybercrimeData BreachesRansomwareThreat ActorsThreat Intelligence
P15
2026-04-09 17:07 UTC
Vendor Research

Protecting Cookies with Device Bound Session Credentials

Google Online Security Blog · Google · indexed 2026-08-15 14:33 UTC

Posted by Ben Ackerman, Chrome team, Daniel Rubery, Chrome team and Guillaume Ehinger, Google Account Security team Following our April 2024 announcement, Device Bound Session Credentials (DBSC) is now entering public availability for Windows users on Chrome 146, and expanding to macOS in an upcoming Chrome release. This project represents a significant step forward in our ongoing efforts to combat session theft, which remains a prevalent threat in the modern security landscape. Session theft t…

AppleCybercrimeMalwareMicrosoftThreat Actors
P0
2026-04-08 14:00 UTC
Security Journalism

The ADWS Architecture That Hides PowerShell AD Enumeration

Huntress · indexed 2026-09-07 17:30 UTC

A threat actor enumerated our entire AD with Get-ADComputer, and none of our detections fired. The problem wasn't their evasion - it was an architectural blind spot in how PowerShell talks to Active Directory.

Threat Actors
P0
2026-04-08 07:30 UTC
Other

Cyber Saga: In the Footsteps of the DPRK IT Workers

Group-IB · indexed 2026-09-07 17:30 UTC

Discover how North Korean threat actors use synthetic identities, AI-assisted workflows, and overlapping infrastructure to infiltrate companies, and learn actionable strategies to mitigate this insider threat.

Threat Actors
P0
2026-04-01 10:32 UTC
Other

Hooking the Archipelago: Dissecting a Phishing Campaign Targeting Philippine Banking Users

Group-IB · indexed 2026-09-07 17:30 UTC

Group-IB researchers uncover an ongoing phishing campaign targeting major banks in the Philippines. This blog details how threat actors abuse trusted and legitimate platforms to deceive users and evade detection. It highlights a significant threat escalation with the successful hijacking of a legitimate domain to host malicious infrastructure, enabling threat actors to operate with even greater credibility and reduced detection.

PhishingThreat Actors
P0
2026-03-06 21:00 UTC
Security Journalism

A Threat Actor Abuses Another Free Trial

Huntress · indexed 2026-09-07 17:30 UTC

A deep dive into a threat actor who exploited SolarWinds Web Help Desk, abused an Elastic Cloud SIEM free trial for exfiltration and triage, revealing key infrastructure.

Threat Actors
P0
2026-01-15 06:07 UTC
Other

DeadLock Ransomware: Smart Contracts for Malicious Purposes

Group-IB · indexed 2026-09-07 17:30 UTC

This blog uncovers DeadLock’s stealthy usage of Polygon smart contracts for proxy address storage, a poorly-documented and under-reported technique that Group-IB analysts have observed increased usage in the wild. Variants of this technique are very wide and offer great alternatives to threat actors for bypassing traditional defenses by abusing decentralized blockchains available worldwide.

MicrosoftRansomwareThreat Actors
P35
2025-12-18 08:00 UTC
Security Journalism

A Series of Unfortunate (RMM) Events

Huntress · indexed 2026-09-07 17:30 UTC

Recently, the Huntress SOC has observed threat actors increasingly use PDQ and GoTo Resolve to deploy further remote monitoring and management (RMM) tools in attacks.

Threat Actors
P0
2025-11-24 06:00 UTC
Security Journalism

ClickFix Gets Creative: Malware Buried in Images

Huntress · indexed 2026-09-07 17:30 UTC

Huntress uncovered an attack utilizing a ClickFix lure to initiate a multi-stage malware execution chain. This analysis reveals how threat actors use steganography to conceal infostealers like LummaC2 and Rhadamanthys within seemingly harmless PNGs.

MalwareThreat Actors
P0
2025-11-20 15:00 UTC
Security Journalism

Velociraptor WSUS Exploitation, Pt. I: WSUS-Up?

Huntress · indexed 2026-09-07 17:30 UTC

Huntress has seen an uptick in threat actors abusing the Velociraptor open-source DFIR tool in a range of attacks, including a recent incident involving WSUS exploitation.

DFIRThreat Actors
P0
2025-10-07 05:00 UTC
Security Journalism

Ditch Lame Cybersecurity Tips | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

Tired of hearing the same old cybersecurity tips? Learn actionable, modern strategies to protect yourself and your organization from bad threat actors.

Threat Actors
P0
2025-09-29 05:58 UTC
Other

E-commerce Fraud-as-a-Service: How Scammers Exploit Brand Trust at Scale

Red Hunt Labs · Hariharan M · indexed 2026-09-07 17:30 UTC

In the rapidly evolving digital marketplace, e-commerce brands have become prime targets for cybercriminals. Beyond traditional data breaches, these brands now face sophisticated scams that exploit their reputation, deceive consumers, and erode trust. Drawing from investigations conducted by RedHunt Labs’ threat intelligence team, this blog delves into some of the most prevalent scams targeting e-commerce platforms and highlights how a Digital Risk Protection (DRP) solution can help fortify you…

CybercrimeData BreachesDFIRPhishingThreat ActorsThreat Intelligence
P0
6 7 8 9 10