IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 1,373 matching records.
AUTO-POLL // 2026-10-04 13:20 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P8 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 4

RANSOMWARE
P8
P8
COOL // 6 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
FRI
Oct 2

RANSOMWARE
P7
P7
COOL // 46 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
WED
Sep 30

RANSOMWARE
P10
P10
WARM // 59 ARTICLES
TUE
Sep 29

RANSOMWARE
P4
P4
COOL // 68 ARTICLES
MON
Sep 28

RANSOMWARE
P7
P7
COOL // 52 ARTICLES
RESET
2026-09-14 05:00 UTC
Other

ZDI-26-696: Linux Kernel NTFS3 Journal Heap-based Buffer Overflow Code Execution Vulnerability

Zero Day Initiative · indexed 2026-09-14 15:10 UTC

This vulnerability allows local attackers to execute arbitrary code on affected installations of Linux Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-72196.

LinuxVulnerabilitiesCVE-2026-72196
P5
2026-09-14 05:00 UTC
Other

ZDI-26-695: Linux Kernel NFSv4 Server Race Condition Remote Code Execution Vulnerability

Zero Day Initiative · indexed 2026-09-14 15:10 UTC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Linux Kernel. Authentication is required to exploit this vulnerability. Furthermore, only systems with nfsd enabled are vulnerable. The ZDI has assigned a CVSS rating of 8.5. The following CVEs are assigned: CVE-2026-89688.

LinuxVulnerabilitiesCVE-2026-89688
P20
2026-09-14 05:00 UTC
Other

ZDI-26-694: Linux Kernel Net Scheduler Clsact Qdisc Use-After-Free Local Privilege Escalation Vulnerability

Zero Day Initiative · indexed 2026-09-14 15:10 UTC

This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.2. The following CVEs are assigned: CVE-2026-23413.

LinuxVulnerabilitiesCVE-2026-23413
P15
2026-09-14 05:00 UTC
Other

ZDI-26-691: Linux Kernel Netlink-based Wireless Configuration Integer Overflow Local Privilege Escalation Vulnerability

Zero Day Initiative · indexed 2026-09-14 15:10 UTC

This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.2. The following CVEs are assigned: CVE-2026-53182.

LinuxVulnerabilitiesCVE-2026-53182
P15
2026-09-14 05:00 UTC
Other

ZDI-26-690: Linux Kernel MCTP Routing Uninitialized Memory Information Disclosure Vulnerability

Zero Day Initiative · indexed 2026-09-14 15:10 UTC

This vulnerability allows local attackers to disclose sensitive information on affected installations of Linux Kernel. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.0. The following CVEs are assigned: CVE-2026-45930.

LinuxVulnerabilitiesCVE-2026-45930
P5
2026-09-14 05:00 UTC
Other

ZDI-26-689: Linux Kernel SCTP Subsystem Race Condition Information Disclosure Vulnerability

Zero Day Initiative · indexed 2026-09-14 15:10 UTC

This vulnerability allows local attackers to disclose sensitive information on affected installations of Linux Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.4. The following CVEs are assigned: CVE-2026-46227.

LinuxVulnerabilitiesCVE-2026-46227
P5
2026-09-14 05:00 UTC
Other

ZDI-26-688: Linux Kernel OpenvSwitch Race Condition Local Privilege Escalation Vulnerability

Zero Day Initiative · indexed 2026-09-14 15:10 UTC

This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-74465.

LinuxNetwork SecurityVulnerabilitiesCVE-2026-74465
P15
2026-09-14 05:00 UTC
Other

ZDI-26-687: Linux Kernel Open vSwitch Flow Delete Use-After-Free Information Disclosure Vulnerability

Zero Day Initiative · indexed 2026-09-14 15:10 UTC

This vulnerability allows local attackers to disclose sensitive information on affected installations of the Linux Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.4. The following CVEs are assigned: CVE-2026-80994.

LinuxNetwork SecurityVulnerabilitiesCVE-2026-80994
P5
2026-09-14 05:00 UTC
Other

ZDI-26-686: Linux Kernel nftables Race Condition Local Privilege Escalation Vulnerability

Zero Day Initiative · indexed 2026-09-14 14:50 UTC

This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-74565.

LinuxVulnerabilitiesCVE-2026-74565
P15
2026-09-14 05:00 UTC
Other

ZDI-26-685: Linux Kernel NFC NCI UART Driver Race Condition Local Privilege Escalation Vulnerability

Zero Day Initiative · indexed 2026-09-14 14:50 UTC

This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2025-38416.

LinuxVulnerabilitiesCVE-2025-38416
P15
2026-09-14 05:00 UTC
Other

ZDI-26-684: Linux Kernel KSMBD Query Directory Request Race Condition Remote Code Execution Vulnerability

Zero Day Initiative · indexed 2026-09-14 14:50 UTC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Linux Kernel KSMBD. Authentication is not required to exploit this vulnerability. Furthermore, only systems with KSMBD enabled are vulnerable. The ZDI has assigned a CVSS rating of 9.0. The following CVEs are assigned: CVE-2026-64397.

LinuxVulnerabilitiesCVE-2026-64397
P20
2026-09-14 05:00 UTC
Other

ZDI-26-683: Linux Kernel IPv6 VTI Subsystem Use-After-Free Local Privilege Escalation Vulnerability

Zero Day Initiative · indexed 2026-09-14 14:50 UTC

This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-72463.

LinuxVulnerabilitiesCVE-2026-72463
P15
2026-09-14 05:00 UTC
Other

ZDI-26-682: Linux Kernel IPv6 Neighbour Discovery Uninitialized Memory Information Disclosure Vulnerability

Zero Day Initiative · indexed 2026-09-14 14:50 UTC

This vulnerability allows local attackers to disclose sensitive information on affected installations of Linux Kernel. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.0. The following CVEs are assigned: CVE-2026-43040.

LinuxVulnerabilitiesCVE-2026-43040
P5
2026-09-14 05:00 UTC
Other

ZDI-26-681: Linux Kernel FUSE Subsystem Race Condition Local Privilege Escalation Vulnerability

Zero Day Initiative · indexed 2026-09-14 14:50 UTC

This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-64265.

LinuxVulnerabilitiesCVE-2026-64265
P15
2026-09-14 05:00 UTC
Other

ZDI-26-680: Linux Kernel Crypto Subsystem Use-After-Free Local Privilege Escalation Vulnerability

Zero Day Initiative · indexed 2026-09-14 14:50 UTC

This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-31719.

LinuxVulnerabilitiesCVE-2026-31719
P15
2026-09-13 12:26 UTC
Other

GitLab CVE-2026-85706: One HTTP Request, No Authentication, Full File Read – Exploited Within 24 Hours

Security Affairs · Pierluigi Paganini · indexed 2026-09-13 13:30 UTC

CVE-2026-85706, a CVSS 10.0 GitLab path traversal, was under active exploitation within 24 hours of disclosure. GitLab disclosed CVE-2026-85706 (CVSS score of 10.0) on September 10, 2026, a path traversal vulnerability in its repository commits API. CVE-2026-85706 affects GitLab’s repository commits API and can let attackers access files they should not see. A crafted request […]

VulnerabilitiesCVE-2026-85706
P5
2026-09-12 15:54 UTC
Security Journalism

CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-12 17:30 UTC

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five security flaws impacting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the wild. Details of the vulnerabilities are as follows - CVE-2026-42016 (CVSS score: 8.1) - An incorrect authorization

Cloud SecurityNetwork SecurityVulnerabilitiesCVE-2026-42016
P80
2026-09-12 09:07 UTC
Security Journalism

OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-12 10:00 UTC

The "major malicious attack" that targeted RubyGems in May 2026 was the work of a swarm of OpenAI agents, according to a new report published by researchers Spencer Kitts, Thomas Larsen, and Sydney Von Arx. On May 12, Maciej Mensfeld, senior product manager for software supply chain security at Mend.io, disclosed details of a coordinated cyber attack that targeted the package manager for the

AI SecurityVulnerabilities
P15
2026-09-11 19:08 UTC
Vendor Research

CVE-2026-89332 - Kiro IDE Sensitive Workspace Data Exfiltration via Agent-Written Workspace Configuration

AWS Security Bulletins · aws@amazon.com · indexed 2026-09-11 19:15 UTC

Bulletin ID: 2026-111-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/11/2026 12:00 PM PDT Description: Kiro IDE is an agentic development environment that makes it easy for developers to ship real engineering work with the help of AI agents. We identified CVE-2026-89332, where the Kiro agent could modify a workspace's settings file in an untrusted workspace in Kiro IDE. A specially crafted repository could use this to point the Kiro Powers registry URL, which K…

AI SecurityCloud SecurityVulnerabilitiesCVE-2026-89332
P5
2026-09-11 17:09 UTC
Vendor Research

CVE-2026-89090 - Denial of service in the event stream header decoder in AWS SDK for Go v2

AWS Security Bulletins · aws@amazon.com · indexed 2026-09-11 17:20 UTC

Bulletin ID: 2026-110-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/11/2026 10:00 AM PDT Description: An issue exists in the the EventStream header decoder in AWS SDK for Go v2 in versions predating 2026-03-23. An actor can send a malformed EventStream response frame containing a crafted header value type byte outside the valid range, which can cause the host process to terminate. Impacted versions: < 2026-03-23 Please refer to the article below for the most u…

Cloud SecurityVulnerabilitiesCVE-2026-89090
P5
2026-09-11 16:37 UTC
Vendor Research

CVE-2026-18061 - XML External Entity (XXE) in AWS Advanced JDBC Wrapper RemoteQueryCachePlugin

AWS Security Bulletins · aws@amazon.com · indexed 2026-09-11 16:40 UTC

Bulletin ID: 2026-109-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/11/2026 09:30 AM PDT Description: The AWS Advanced JDBC Wrapper is an open-source library that enhances existing JDBC drivers with AWS-specific capabilities such as Aurora failover, IAM authentication, and automated SQL query caching for applications connecting to Amazon Aurora, RDS MySQL, and RDS MariaDB. We identified CVE-2026-18061, an improper restriction of XML external entity (XXE) refer…

Cloud SecurityVulnerabilitiesCVE-2026-18061
P5
2026-09-11 16:30 UTC
Security Journalism

GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-11 17:25 UTC

GitLab has released patches to address multiple flaws, including a maximum-severity security vulnerability that has witnessed in-the-wild probes within hours of public disclosure. The vulnerability in question is CVE-2026-85706 (CVSS score: 10.0), a path traversal issue in the repository commits API that could allow an unauthenticated user to read arbitrary files from the GitLab server under

Cloud SecurityVulnerabilitiesCVE-2026-85706
P5
2026-09-11 16:11 UTC
Security Journalism

GitLab Vulnerability Exploited One Day After Disclosure

Security Week · Ionut Arghire · indexed 2026-09-11 16:30 UTC

The critical-severity path traversal flaw allows unauthenticated attackers to read arbitrary files from the GitLab server. The post GitLab Vulnerability Exploited One Day After Disclosure appeared first on SecurityWeek.

Vulnerabilities
P0
12 13 14 15 16