IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 1,373 matching records.
AUTO-POLL // 2026-10-04 15:55 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P5 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 4

RANSOMWARE
P5
P5
COOL // 10 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
FRI
Oct 2

RANSOMWARE
P7
P7
COOL // 46 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
WED
Sep 30

RANSOMWARE
P10
P10
WARM // 59 ARTICLES
TUE
Sep 29

RANSOMWARE
P4
P4
COOL // 68 ARTICLES
MON
Sep 28

RANSOMWARE
P7
P7
COOL // 52 ARTICLES
RESET
2026-09-08 11:22 UTC
Vendor Research

Cisco Secure Email Secure/Multipurpose Internet Mail Extensions Ciphertext Decryption Vulnerabilities

Cisco Security Advisories · indexed 2026-09-02 16:10 UTC

Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption functionality of Cisco Secure Email could allow an unauthenticated, remote attacker to recover plain text from encrypted email messages. These vulnerabilities are due to insufficient validation of message integrity. An attacker could exploit these vulnerabilities by using a machine-in-the-middle technique to intercept and modify traffic between email gateways. A successful exploit could allow the at…

VulnerabilitiesCVE-2026-20354CVE-2026-20355
P5
2026-09-08 11:01 UTC
Vendor Research

CVE-2026-86206, CVE-2026-86207: N-able N-central Authentication Bypass (FIXED)

Rapid7 · Stephen Fewer · indexed 2026-09-08 12:25 UTC

OverviewWhile conducting research into a recent N-able N-central authentication bypass vulnerability (CVE-2026-18577), Rapid7 Labs discovered two new vulnerabilities affecting the latest version of N-central. When chained together, these two vulnerabilities allow a remote unauthenticated attacker to bypass authentication and create a new attacker-controlled System administrator account on an affected server.CVE IDDescriptionCWECVSSv4CVE-2026-86206Semicolon/Forwarded access-control bypassCWE-791…

MicrosoftSecurity ResearchVulnerabilitiesCVE-2026-18577CVE-2026-86206CVE-2026-86207
P15
2026-09-08 10:37 UTC
Security Journalism

N-able Patches Critical Zero-Day in N-central

Security Week · Ionut Arghire · indexed 2026-09-08 10:50 UTC

Administrators are advised to check their deployments for newly created user accounts they don’t recognize. The post N-able Patches Critical Zero-Day in N-central appeared first on SecurityWeek.

MicrosoftVulnerabilities
P25
2026-09-08 10:00 UTC
Vendor Research

StyleSmuggler (CVE-2026-75650): Frequently asked questions about Adobe Commerce and Magento zero-day

Tenable Cyber Exposure Alerts · Satnam Narang · indexed 2026-09-08 14:20 UTC

A critical unauthenticated remote code execution (RCE) zero-day in Adobe Commerce and Magento Open Source, dubbed StyleSmuggler, has been actively exploited since September 4 with attacks observed three days before a vendor patch became available.Key takeawaysCVE-2026-75650 is a critical remote code execution vulnerability in Adobe Commerce, Adobe Commerce B2B and Magento Open Source that can be triggered without authentication.Active exploitation of CVE-2026-75650 began on September 4, 2026, t…

DFIRLinuxMalwareThreat ActorsThreat IntelligenceVulnerabilitiesCVE-2026-75650
P95
2026-09-08 09:13 UTC
Security Journalism

Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-08 10:00 UTC

Adobe on Monday released security patches to address a maximum-severity flaw impacting Adobe Commerce and Magento Open Source that has come under active exploitation in the wild. The vulnerability, now tracked as CVE-2026-75650 (CVSS score: 10.0), has been codenamed StyleSmuggler by Sansec, which discovered zero-day exploitation starting September 4, 2026. "This update resolves a critical

MalwareVulnerabilitiesCVE-2026-75650
P50
2026-09-08 05:00 UTC
Other

ZDI-26-622: Microsoft Windows IKEv2 AES-GCM Decryption Integer Underflow Remote Code Execution Vulnerability

Zero Day Initiative · indexed 2026-09-08 21:50 UTC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Windows. Authentication is not required to exploit this vulnerability, but only systems with specific IPsec configurations are vulnerable. The ZDI has assigned a CVSS rating of 8.1. The following CVEs are assigned: CVE-2026-50696.

MicrosoftVulnerabilitiesCVE-2026-50696
P20
2026-09-08 05:00 UTC
Other

ZDI-26-621: Microsoft Windows UMPDDrvRealizeBrush Improper Object Management Local Privilege Escalation Vulnerability

Zero Day Initiative · indexed 2026-09-08 21:50 UTC

This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-62712.

MicrosoftVulnerabilitiesCVE-2026-62712
P15
2026-09-08 05:00 UTC
Other

ZDI-26-620: Microsoft Windows UMPDDrvPlgBlt Improper Object Management Local Privilege Escalation Vulnerability

Zero Day Initiative · indexed 2026-09-08 21:50 UTC

This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-62712.

MicrosoftVulnerabilitiesCVE-2026-62712
P15
2026-09-08 05:00 UTC
Other

ZDI-26-619: Microsoft Windows UMPDDrvStretchBltROP Improper Object Management Local Privilege Escalation Vulnerability

Zero Day Initiative · indexed 2026-09-08 21:50 UTC

This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-62712.

MicrosoftVulnerabilitiesCVE-2026-62712
P15
2026-09-08 05:00 UTC
Other

ZDI-26-618: Microsoft Windows UMPDDrvStretchBlt Improper Object Management Local Privilege Escalation Vulnerability

Zero Day Initiative · indexed 2026-09-08 21:50 UTC

This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-62712.

MicrosoftVulnerabilitiesCVE-2026-62712
P15
2026-09-08 05:00 UTC
Other

ZDI-26-617: Microsoft Windows MIDI Service Incorrect Permission Assignment Local Privilege Escalation Vulnerability

Zero Day Initiative · indexed 2026-09-08 21:50 UTC

This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-66804.

MicrosoftVulnerabilitiesCVE-2026-66804
P15
2026-09-07 17:49 UTC
Other

StyleSmuggler: The Magento Zero-Day Behind New Store Attacks

Security Affairs · Pierluigi Paganini · indexed 2026-09-07 18:00 UTC

StyleSmuggler Magento zero-day is under active attack, letting unauthenticated attackers execute code and install backdoors on stores that may already be patched. A new zero-day flaw, dubbed StyleSmuggler, in Magento and Adobe Commerce is under active attack, giving unauthenticated attackers a path to run code on vulnerable online stores. Sansec researchers say it affects current […]

MalwareVulnerabilities
P25
2026-09-07 14:36 UTC
Security Journalism

⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-07 16:10 UTC

Turning off email images should at least stop the pictures. This week, attackers had a workaround: a scannable QR code built out of text. It still appears, even with images blocked. A small detail, but an annoying one if that was a precaution you were counting on. Elsewhere, a trusted software source delivered code that stole credentials, and a protocol designed for secure network management

Network SecurityVulnerabilities
P25
2026-09-07 13:42 UTC
Other

Chaotic Eclipse Released GreenSection, A PoC For NVIDIA Memory Corruption Zero-Day

Security Affairs · Pierluigi Paganini · indexed 2026-09-09 08:30 UTC

Chaotic Eclipse released GreenSection, a PoC exploit for an Nvidia Memory Corruption Zero-Day Security researcher Chaotic Eclipse, also known as INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse, released a new zero-day exploit targeting Nvidia. The researcher named the exploit GreenSection, it triggers a Memory Corruption flaw. The researcher disclosed a potential security vulnerability in NVIDIA’s Windows user-mode components. […]

MicrosoftSecurity ResearchVulnerabilities
P25
2026-09-07 13:42 UTC
Other

Chaotic Eclipse Released A PoC For NVIDIA GreenSection Memory Corruption Zero-Day

Security Affairs · Pierluigi Paganini · indexed 2026-09-07 14:40 UTC

Chaotic Eclipse released GreenSection, a PoC exploit for an Nvidia GreenSection Memory Corruption Zero-Day Security researcher Chaotic Eclipse, also known as INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse, released a new zero-day exploit targeting Nvidia. The researcher named the exploit GreenSection, it triggers a Memory Corruption flaw. The researcher disclosed a potential security vulnerability in NVIDIA’s Windows user-mode […]

MicrosoftSecurity ResearchVulnerabilities
P25
2026-09-07 11:58 UTC
Security Journalism

Adobe Commerce Zero-Day Exploited to Backdoor Online Stores

Security Week · Ionut Arghire · indexed 2026-09-07 17:25 UTC

The StyleSmuggler zero-day allows attackers to execute code and deploy a stealthy backdoor on Adobe Commerce and Magento stores. The post Adobe Commerce Zero-Day Exploited to Backdoor Online Stores appeared first on SecurityWeek.

MalwareVulnerabilities
P25
2026-09-07 11:20 UTC
Security Journalism

Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-07 13:00 UTC

A TantoSec proof-of-concept turns an AES-CBC "padding oracle" in Telerik UI for ASP.NET AJAX into unauthenticated remote code execution — but only against applications in a specific non-default configuration, and Progress patched the chain in July. There are no confirmed reports of exploitation in the wild. Security firm TantoSec has published a working exploit chain targeting vulnerabilities

Vulnerabilities
P35
2026-09-07 08:31 UTC
Security Journalism

N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-07 09:45 UTC

Every on-premises N-central build below 2026.3.1.14 — including servers updated to Hotfix 3 a day earlier — needs Hotfix 4. N-able's incident notice says the flaw has been exploited in the wild; its release notes say that is unconfirmed. N-able has released its fourth hotfix in five weeks for the N-central remote monitoring and management (RMM) platform, this time for a

MicrosoftVulnerabilities
P35
2026-09-06 21:43 UTC
Community

Critical MikroTik Vulnerability - Patch Now, (Sun, Sep 6th)

SANS Internet Storm Center · indexed 2026-09-06 22:05 UTC

Mikrotik released a patch late last week for an already-exploited vulnerability. The vulnerability allows an SSH authentication bypass and is already being exploited. At this point, assume compromise. Attackers have been adding new accounts to affected devices to maintain access after a patch is installed.

Vulnerabilities
P15
2026-09-06 13:46 UTC
Other

Your MikroTik Router May Already Be Compromised: Look for SSH User “-2”

Security Affairs · Pierluigi Paganini · indexed 2026-09-06 14:45 UTC

MikroTik RouterOS SSH zero-day (MikroTrick chain) under active exploitation since Sept 2. Patch to 7.24.2, 7.23.5, or 6.49.21 immediately and check logs. Anyone running a MikroTik router with SSH exposed to the internet should treat it as compromised until proven otherwise. The popular cybersecurity expert Costin Raiu published a detailed technical breakdown of the active […]

Network SecurityVulnerabilities
P25
2026-09-05 20:14 UTC
Security Journalism

Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-05 20:50 UTC

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is

MalwareVulnerabilities
P25
2026-09-05 18:47 UTC
Other

PaperCut Flaws Exploited in Attacks on U.S. and European Schools

Security Affairs · Pierluigi Paganini · indexed 2026-09-05 19:35 UTC

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed threat […]

Cloud SecurityVulnerabilitiesCVE-2026-81578CVE-2026-82078
P25
2026-09-05 16:52 UTC
Security Journalism

Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-05 16:55 UTC

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.

Cloud SecurityThreat ActorsVulnerabilities
P10
2026-09-05 16:05 UTC
Security Journalism

Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-05 16:55 UTC

Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an integer-overflow vulnerability that a local attacker with elevated privileges can exploit to run arbitrary code. "A

Cloud SecurityVulnerabilitiesCVE-2026-59346
P5
18 19 20 21 22