IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 292 matching records.
AUTO-POLL // 2026-10-04 10:30 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P9 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 4

RANSOMWARE
P9
P9
COOL // 5 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
FRI
Oct 2

RANSOMWARE
P7
P7
COOL // 46 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
WED
Sep 30

RANSOMWARE
P10
P10
WARM // 59 ARTICLES
TUE
Sep 29

RANSOMWARE
P4
P4
COOL // 68 ARTICLES
MON
Sep 28

RANSOMWARE
P7
P7
COOL // 52 ARTICLES
RESET
2025-08-29 05:00 UTC
Security Journalism

From a Fake AnyDesk Installer to MetaStealer

Huntress · indexed 2026-09-07 17:30 UTC

Learn how a fake AnyDesk installer led to a unique MetaStealer attack, highlighting how threat actors evolve ClickFix techniques beyond the classic playbook to steal credentials and files.

MalwareThreat Actors
P0
2025-08-19 14:00 UTC
Security Journalism

Exposing Data Exfiltration | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

Threat actors often steal data during the course of their attacks. This is particularly true for ransomware threat actors, who do it before deploying file encryption in order to engage in “double extortion” activities. This activity can be difficult to detect, particularly if it’s not dissimilar to legitimate actions taken by system administrators.

RansomwareThreat Actors
P15
2025-08-14 05:00 UTC
Security Journalism

Kawabunga, Dude, You’ve Been Ransomed!

Huntress · indexed 2026-09-07 17:30 UTC

Thanks in large part to our customer base, Huntress sees a great deal of interesting activity, particularly from threat actors (but also from admins). Part of that activity includes not just ransomware variants that Huntress hasn’t seen before, but also variants that may not have been documented via any public means. Further, when these incidents occur, Huntress very often gets a detailed look at the threat actor’s activity, including commands and their timing.

RansomwareThreat Actors
P15
2025-08-13 22:00 UTC
Security Journalism

Active Exploitation of SonicWall VPNs

Huntress · indexed 2026-09-07 17:30 UTC

A likely zero-day vulnerability in SonicWall VPNs is being actively exploited to bypass MFA and deploy ransomware. Huntress advises disabling the VPN service immediately or severely restricting access via IP allow-listing. We're seeing threat actors pivot directly to domain controllers within hours of the initial breach.

Network SecurityRansomwareThreat ActorsVulnerabilities
P40
2025-07-17 05:00 UTC
Security Journalism

Remote Monitoring and Management Tools | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

When a threat actor exploited an MSP's RMM tool to target businesses, Huntress investigated and uncovered another eerily similar incident with key differences that reveal evolving tactics

Threat Actors
P0
2025-06-13 16:03 UTC
Vendor Research

Mitigating prompt injection attacks with a layered defense strategy

Google Online Security Blog · Kimberly Samra · indexed 2026-08-15 14:33 UTC

Posted by Adam Gavish, Google GenAI Security TeamWith the rapid adoption of generative AI, a new wave of threats is emerging across the industry with the aim of manipulating the AI systems themselves. One such emerging attack vector is indirect prompt injections. Unlike direct prompt injections, where an attacker directly inputs malicious commands into a prompt, indirect prompt injections involve hidden malicious instructions within external data sources. These may include emails, documents, or…

AI SecurityMalwarePhishingSecurity ResearchThreat ActorsThreat IntelligenceVulnerabilities
P0
2025-05-06 05:00 UTC
Security Journalism

Do Tigers Really Change Their Stripes?

Huntress · indexed 2026-09-07 17:30 UTC

Across the larger cybersecurity community, an often-used adage is that “threat actors always change their tactics.” However, when we really start to look at and track incident data, we begin to see that while some changes may be necessitated based on infrastructures and other challenges the threat actor may encounter, there are times when tactics remain consistent across incidents. Recent investigations into exploitation activity for CVE-2025-31151 and CVE-2025-30406 show similar TTPs across di…

DFIRThreat ActorsThreat IntelligenceVulnerabilitiesCVE-2025-30406CVE-2025-31151
P5
2025-04-23 07:05 UTC
Other

Toll of Deception: Where Evasion Drives Phishing Forward

Group-IB · indexed 2026-09-07 17:30 UTC

Discover the latest phishing campaign targeting a major toll road service provider, where cybercriminals use sophisticated evasion techniques to bypass security detections. This in-depth blog reveals how threat actors exploit legitimate platforms and deploy cloaking methods to disguise malicious links, allowing them to evade detection by security solutions. Discover how these sophisticated tactics create highly convincing phishing pages designed to steal victims’ card information, and how to sa…

PhishingThreat Actors
P0
2025-04-22 05:00 UTC
Security Journalism

Say Hello to Mac Malware

Huntress · indexed 2026-09-07 17:30 UTC

In this month’s Tradecraft Tuesday, we talked about how threat actors are finetuning their macOS malware in order to maintain persistent access and avoid detection by Apple’s security features.

AppleMalwareThreat Actors
P0
2025-04-09 05:00 UTC
Security Journalism

How EDR and ITDR Elevate Your Security

Huntress · indexed 2026-09-07 17:30 UTC

Threat actors are now exploiting both endpoints and identities in the latest cyberattacks. Learn about the rise of identity-based threats and why a combined EDR and ITDR approach is crucial for your cybersecurity.

Threat Actors
P0
2025-04-02 05:00 UTC
Security Journalism

The Unwanted Guest

Huntress · indexed 2026-09-07 17:30 UTC

Threat actors are enabling the built-in Windows Guest account to maintain persistence. Learn how they gain access and how to detect this activity.

MicrosoftThreat Actors
P0
2024-11-21 09:33 UTC
Other

Tracing the Path of VietCredCare and DuckTail: Vietnamese dark market of infostealers’ data

Group-IB · indexed 2026-09-07 17:30 UTC

Following the arrest in May 2024 of more than 20 individuals behind Facebook infostealers campaigns in Vietnam, we have compared the tactics of operators behind VietCredCare and DuckTail stealers. These 2 malware families have been active before the arrest in Vietnam and are believed to be controlled by Vietnamese threat actors. Based on the research, we decided that the groups operate in a different way and the arrest probably affected the VietCredCare operators.

MalwareThreat Actors
P0
2024-10-17 00:00 UTC
Security Journalism

Detecting Malicious Use of LOLBins, Pt. II | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

Rhetoric within the cybersecurity community has leaned heavily towards threat actor use of LOLBins as a means of “hiding amongst the noise” of normal, administrative and operational activity. However, as Huntress SOC analysts can attest, this is often far from the case.

Threat Actors
P0
2024-09-20 00:00 UTC
Security Journalism

Akira Ransomware Indicators | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

Tracking various indicators associated with different attacks, Huntress analysts have been able to identify specific indicators (threat actor workstation names, passwords associated with new user account creation or current account modification, CloudFlare tunnel tokens) that are associated with Akira ransomware infections. By detecting these indicators much earlier in the attack chain, organizations can inhibit or even obviate file encryption malware deployment.

MalwareRansomwareThreat Actors
P15
2024-05-30 00:00 UTC
Security Journalism

Attack Behaviors | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

In the cybersecurity community, we may hear analysts say, “Oh, threat actors change their tactics…”, and at times, they may include the word “always” as part of that statement. However, the question at hand is, “Does the data really show that to be the case?” What are we truly seeing in real-world incidents?

Threat Actors
P0
2024-05-01 00:00 UTC
Security Journalism

LOLBin to INC Ransomware

Huntress · indexed 2026-09-07 17:30 UTC

Huntress has observed INC ransomware deployed in the past but recent activity indicates a possible continued shift in/or improvement of tactics employed by these threat actors.

RansomwareThreat Actors
P15
2024-03-28 00:00 UTC
Security Journalism

MSSQL to ScreenConnect | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

Huntress continues to see MSSQL server systems being attacked, and in recent incidents have seen overlap with previous incidents, not only in the use of LOLBins, but also in IP addresses used by the threat actor.

Threat Actors
P0
2024-03-20 00:00 UTC
Security Journalism

Managing Attack Surface | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

Huntress recently detected interesting activity on an endpoint; a threat actor was attempting to establish a foothold on an endpoint by using commands issued via MSSQL to upload a reverse shell accessible from the web server. All attempts were obviated by MAV and process detections, but boy-howdy, did they try!

Threat Actors
P0
7 8 9 10