IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 1,373 matching records.
AUTO-POLL // 2026-10-04 12:40 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P8 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 4

RANSOMWARE
P8
P8
COOL // 6 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
FRI
Oct 2

RANSOMWARE
P7
P7
COOL // 46 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
WED
Sep 30

RANSOMWARE
P10
P10
WARM // 59 ARTICLES
TUE
Sep 29

RANSOMWARE
P4
P4
COOL // 68 ARTICLES
MON
Sep 28

RANSOMWARE
P7
P7
COOL // 52 ARTICLES
RESET
2026-09-15 11:52 UTC
Security Journalism

Human Attacker Exploits Marimo RCE, Reaches SSH Bastion in Eight Seconds

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-15 12:25 UTC

With artificial intelligence (AI) shrinking the window between vulnerability discovery and exploitation and lowering the barrier to entry for bad actors, new findings from Sysdig show that skilled human operators can move just as swiftly after gaining initial access. In one instance highlighted by the cloud security company, the threat actor pivoted from a vulnerable Marimo notebook to an SSH

AI SecurityCloud SecurityThreat ActorsVulnerabilities
P0
2026-09-15 10:17 UTC
Other

One Exploit Chain, Two Espionage Campaigns: Chrome and Windows Under Fire

Security Affairs · Pierluigi Paganini · indexed 2026-09-15 11:30 UTC

Two China-linked groups ran identical Chrome/Windows zero-day exploits against NGOs, before Chrome’s patch shipped, deploying different backdoors each. Two China-linked threat actors used the same Chrome/Windows zero-day against NGOs starting September 1, 2026, Volexity’s new report lays out the whole chain in detail. On September 1, Volexity detected a spear-phishing campaign by UTA0560 targeting several […]

APT / Nation-StateMalwareMicrosoftPhishingThreat ActorsVulnerabilities
P25
2026-09-15 07:48 UTC
Other

Telegram Desktop Flaw Could Turn Old Chat Exports Into Data Theft Traps

Security Affairs · Pierluigi Paganini · indexed 2026-09-15 09:00 UTC

A Telegram Desktop flaw let bots inject JavaScript into exported chats, enabling data theft and page manipulation. Old HTML exports remain unsafe. A vulnerability in Telegram Desktop could have turned an ordinary chat export into a serious data leak. Security researchers Denis and Aleksander Rostilov of ExPatch found a stored cross-site scripting flaw in the […]

Data BreachesSecurity ResearchVulnerabilities
P0
2026-09-15 07:19 UTC
Other

Non-Zero-Day VPN Flaw Left Japan ‘s Government Shared Network Platform Exposed: 246,000 Records at Risk

Security Affairs · Pierluigi Paganini · indexed 2026-09-15 08:00 UTC

Japan ‘s Digital Agency disclosed a VPN breach exposing 246,000 government employee records across 23 ministries. Detected June 25, publicly disclosed September 11. Japan ‘s Digital Agency disclosed that attackers exploited a vulnerability in a VPN device to access its Government Solution Service (GSS), potentially leaking personal information belonging to approximately 246,000 government employees, public […]

Network SecurityVulnerabilities
P25
2026-09-15 06:52 UTC
Security Journalism

LiteSpeed Enterprise Flaw Could Let One Hosting Account Gain Root Access on a Shared Server

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-15 08:25 UTC

A critical vulnerability in LiteSpeed Web Server Enterprise could let a low-privilege website user gain root access on a shared-hosting server, cPanel warned in an advisory published on September 14. On such servers, many customers' sites run on a single machine, and an attacker with one of those hosting accounts could exploit the flaw to access or alter other sites and the server itself,

Vulnerabilities
P10
2026-09-15 06:11 UTC
Security Journalism

Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-15 06:25 UTC

Cisco has warned that a new critical vulnerability impacting AsyncOS Software for Cisco Secure Email Gateway has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-76461, carries a CVSS score of 9.8 out of a maximum of 10.0. It has been described as a case of insufficient validation in the email parsing logic that could allow an unauthenticated, remote attacker

VulnerabilitiesCVE-2026-76461
P35
2026-09-15 05:31 UTC
Security Journalism

China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-15 06:25 UTC

A Chinese threat actor has been attributed to a spear-phishing campaign that exploits recently patched security flaws in Google Chrome and Microsoft Windows to deliver a malicious JavaScript backdoor called GRIMWEDGE. Volexity, which is tracking the threat cluster under the moniker UTA0560, said the activity targeted multiple non-governmental organizations (NGOs) on September 1, 2026. "The

Cloud SecurityMalwareMicrosoftPhishingThreat ActorsVulnerabilities
P25
2026-09-14 20:35 UTC
Other

ENISA: Frontier AI Is Changing the Speed of Cyberattacks. Europe Needs to Catch Up

Security Affairs · Pierluigi Paganini · indexed 2026-09-14 20:45 UTC

Frontier AI is compressing the attack lifecycle from vulnerability discovery to exploitation, forcing defenders to detect, patch and respond at machine speed. Cybersecurity has always been a race between attackers and defenders. ENISA’s latest assessment suggests that frontier AI is changing the speed of that race, and the gap between discovering a vulnerability and exploiting […]

MicrosoftVulnerabilities
P0
2026-09-14 19:51 UTC
Security Journalism

Homebrew 7.0.0 gets built-in GUI, better security controls

BleepingComputer · Bill Toulas · indexed 2026-09-14 19:55 UTC

Homebrew package manager version 7.0.0 has been released with a built-in vulnerability scanner, stronger security controls, and the full release of its native BrewUI graphical interface. [...]

Vulnerabilities
P0
2026-09-14 18:04 UTC
Vendor Research

CVE-2026-86830 - Incorrect privilege assignment in Temporary Elevated Access Management (TEAM) for AWS IAM Identity Center

AWS Security Bulletins · aws@amazon.com · indexed 2026-09-14 18:10 UTC

Bulletin ID: 2026-112-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/14/2026 10:45 AM PDT Description: Temporary Elevated Access Management (TEAM) is an open source AWS sample solution for managing temporary elevated access via AWS IAM Identity Center. We identified CVE-2026-86830, where an authenticated user with application-level access could gain unintended temporary elevated access to AWS accounts managed by TEAM. Impacted versions:

Cloud SecurityVulnerabilitiesCVE-2026-86830
P5
2026-09-14 16:56 UTC
Security Journalism

Red Heron Exploits Gitea RCE to Compromise 13 Organizations Across Six Countries

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-14 17:30 UTC

A suspected Chinese threat actor tracked as Red Heron has been attributed to the rapid exploitation of a recently disclosed security vulnerability in Gitea to compromise internet-facing instances as part of a multi-national campaign. "Red Heron scanned 1,386 Gitea instances across seven countries and maintained a separate dataset of 477 Taiwan-based systems," Acronis Threat Research Unit (TRU)

Threat ActorsVulnerabilities
P15
2026-09-14 16:00 UTC
Vendor Research

Cisco Secure Email Gateway and Secure Email and Web Manager Security Hardening Release: September 2026

Cisco Security Advisories · indexed 2026-09-14 16:20 UTC

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. These vulnerabilities were found during internal testing. One of them is known to be actively exploited. For more information, see Cisco Secure Email Gateway SQL …

VulnerabilitiesCVE-2026-20353CVE-2026-76440CVE-2026-76441CVE-2026-76442CVE-2026-76443
P30
2026-09-14 14:51 UTC
Vendor Research

Rapid7 Named Among Notable Vendors in Forrester MDR Landscape: Why the Future is Exposure-informed, Preemptive MDR

Rapid7 · Rapid7 · indexed 2026-09-14 15:25 UTC

The managed detection and response (MDR) market has reached a turning point. We’ve gone beyond the baseline of 24/7 monitoring focusing on the speed of detection and moved to a world with a convergence of exposure management and response to deliver measurable, outcome-based defenses of a larger, AI-driven attack surface.For anyone evaluating MDR right now, the Managed Detection and Response Services Landscape, Q3 2026 report by Forrester is a useful map that lays out where the market is heading…

DFIRVulnerabilities
P0
2026-09-14 14:08 UTC
Other

U.S. CISA adds GitLab, JFrog Artifactory, and ConnectWise ScreenConnect flaws to its Known Exploited Vulnerabilities catalog

Security Affairs · Pierluigi Paganini · indexed 2026-09-14 14:25 UTC

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds GitLab, JFrog Artifactory, and ConnectWise ScreenConnect flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added [1, 2] the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: Two of the above vulnerabilities affect JFrog Artifactory. CVE-2026-42016 can allow attackers to bypass authorization checks and […]

Cloud SecurityVulnerabilitiesCVE-2026-42016
P35
2026-09-14 11:58 UTC
Security Journalism

AI Changed the Exposure Problem. Validation Needs to Change With It.

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-14 12:25 UTC

There's a lot of noise around AI and cybersecurity right now. What’s actually important is far simpler, if often lost in the hubbub. Vulnerability discovery is getting faster and happening at a much greater scale, while defenders still have to work out which findings actually deserve their action. In the first half of 2026, a whopping 35,853 CVEs were published, roughly 49% more than in the

MicrosoftVulnerabilities
P0
2026-09-14 10:02 UTC
Vendor Research

CVE-2026-85706: Critical GitLab Path Traversal Exploited in the Wild

Rapid7 · Rapid7 · indexed 2026-09-14 10:50 UTC

OverviewOn September 10, 2026, GitLab published a critical patch release for GitLab Community Edition (CE) and Enterprise Edition (EE). The release addresses CVE-2026-85706, a critical path traversal vulnerability (CWE-22) in the repository commits API with a CVSSv3.1 score of 10.0. According to GitLab, improper path confinement and missing authentication enforcement could allow an unauthenticated user to read arbitrary files from an affected GitLab server under certain conditions.On September …

VulnerabilitiesCVE-2026-85706CVE-2026-87719
P55
2026-09-14 09:43 UTC
Other

Dutch NCSC Warns: Critical Check Point VPN Flaws Put Networks at Risk

Security Affairs · Pierluigi Paganini · indexed 2026-09-14 09:50 UTC

Two critical Check Point VPN flaws score 9.8 and could enable remote code execution. Patch now and restrict VPN access before exploitation begins. The Dutch NCSC warns that two critical vulnerabilities in Check Point VPN products, both rated CVSS score of 9.8, could soon be actively exploited. If you use Check Point VPN, you should […]

Cloud SecurityNetwork SecurityVulnerabilities
P45
2026-09-14 05:00 UTC
Other

ZDI-26-701: Linux Kernel TLS Protocol Out-Of-Bounds Read Information Disclosure Vulnerability

Zero Day Initiative · indexed 2026-09-14 15:10 UTC

This vulnerability allows local attackers to disclose sensitive information on affected installations of Linux Kernel. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.7. The following CVEs are assigned: CVE-2026-64046.

LinuxVulnerabilitiesCVE-2026-64046
P5
2026-09-14 05:00 UTC
Other

ZDI-26-700: Linux Kernel QFQ Plus Scheduler Use-After-Free Local Privilege Escalation Vulnerability

Zero Day Initiative · indexed 2026-09-14 15:10 UTC

This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-22999.

LinuxVulnerabilitiesCVE-2026-22999
P15
11 12 13 14 15