IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 1,373 matching records.
AUTO-POLL // 2026-10-04 17:05 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P5 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 4

RANSOMWARE
P5
P5
COOL // 10 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
FRI
Oct 2

RANSOMWARE
P7
P7
COOL // 46 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
WED
Sep 30

RANSOMWARE
P10
P10
WARM // 59 ARTICLES
TUE
Sep 29

RANSOMWARE
P4
P4
COOL // 68 ARTICLES
MON
Sep 28

RANSOMWARE
P7
P7
COOL // 52 ARTICLES
RESET
2026-08-30 11:26 UTC
Other

Hackers Are Probing PaperCut Servers, and 47% Still Have No Patch

Security Affairs · Pierluigi Paganini · indexed 2026-08-30 11:40 UTC

PaperCut servers are under active attack, while 47% of tracked installations still run unpatched versions vulnerable to remote code execution. PaperCut, the print management software running in schools, hospitals, and offices worldwide, confirmed on August 27 that a pre-authentication remote code execution flaw is being actively exploited against real customers. Researchers at Huntress found evidence […]

Vulnerabilities
P40
2026-08-29 16:25 UTC
Security Journalism

Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-29 17:20 UTC

Multiple critical security flaws have been disclosed in WordPress plugins and themes, including WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP, that could lead to authentication bypass, account takeover, and arbitrary code execution. The vulnerabilities, according to Wordfence and Patchstack, are listed below - CVE-2026-76581 (CVSS score: 9.8) - An authentication bypass flaw in

Cloud SecurityVulnerabilitiesCVE-2026-76581
P30
2026-08-28 20:38 UTC
Security Journalism

Cosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was Vulnerable

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-28 21:00 UTC

Cosmos Labs has warned that a critical balance-handling flaw in the shared Cosmos EVM module was exploited to drain funds from six blockchains between August 20 and August 25, 2026. The vulnerability, designated GHSA-7g4w-cg88-2cq2, is rated Critical by Cosmos Labs and was published without a CVE identifier, a weakness classification, or a CVSS score. Affected versions are < 0.6.2 and >=

Vulnerabilities
P0
2026-08-28 17:12 UTC
Security Journalism

Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-28 18:30 UTC

Malicious actors are exploiting a newly patched security flaw in PaperCut NG and MF to execute arbitrary code on susceptible instances, as the company released a fresh emergency fix with additional hardening. "This vulnerability gives an unauthenticated attacker remote control over PaperCut's trusted configuration, which could be used to execute arbitrary Java code inside the application's

Cloud SecurityVulnerabilities
P0
2026-08-28 15:56 UTC
Security Journalism

ownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research Body

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-28 18:30 UTC

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a critical security flaw impacting ownCloud to its Known Exploited Vulnerabilities (KEV) catalog following reports that a Chinese-speaking threat actor weaponized the vulnerability to target a nuclear research body in the Philippines. The vulnerability, tracked as CVE-2023-49105 (CVSS score: 9.8), is a case of

Threat ActorsVulnerabilitiesCVE-2023-49105
P35
2026-08-28 14:01 UTC
Vendor Research

Why a cryptographic inventory is key for addressing the quantum computing threat

Tenable Blog · Christopher Day · indexed 2026-08-28 14:20 UTC

When quantum computers become generally available, they’ll be able to crack current public-key cryptographic algorithms, putting digitally stored and transmitted data at risk. But the threat already exists, as attackers use the "harvest now, decrypt later" tactic. Discover why building a comprehensive cryptographic inventory and executing a phased operational strategy are critical for protecting your data against quantum computing attacks.Key takeawaysQuantum computing risks are an operational …

APT / Nation-StateMicrosoftVulnerabilities
P0
2026-08-28 14:00 UTC
Security Journalism

AI Is Accelerating Vulnerability Discovery. Can Defenders Keep Up?

BleepingComputer · Sponsored by Action1 · indexed 2026-08-28 14:20 UTC

AI is accelerating vulnerability discovery, putting pressure on systems built to enrich, prioritize, and remediate flaws at a slower pace. Action1 explains why defenders increasingly need to correlate multiple intelligence sources and turn vulnerability data into faster remediation. [...]

Cloud SecurityMicrosoftVulnerabilities
P0
2026-08-28 13:54 UTC
Other

U.S. CISA adds ownCloud, Linux Kernel, and JFrog Artifactory flaws to its Known Exploited Vulnerabilities catalog

Security Affairs · Pierluigi Paganini · indexed 2026-08-28 14:40 UTC

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds ownCloud, Linux Kernel, and JFrog Artifactory flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2023-49105 (CVSS score of 9.8) is an improper-authentication flaw in ownCloud Server’s WebDAV functionality. An unauthenticated attacker who […]

Cloud SecurityLinuxVulnerabilitiesCVE-2023-49105
P35
2026-08-28 12:58 UTC
Security Journalism

Over 8,300 Gitea servers vulnerable to code execution attacks

BleepingComputer · Sergiu Gatlan · indexed 2026-08-28 13:00 UTC

Over 8,300 Internet-exposed Gitea instances are still unpatched against a critical security flaw exploited in ongoing remote code execution attacks, according to cybersecurity watchdog Shadowserver. [...]

Vulnerabilities
P15
2026-08-28 12:07 UTC
Security Journalism

Two Unitree G1 EDU Humanoid Robot Flaws Enable Root RCE, One Starts Over Bluetooth

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-28 13:15 UTC

Security researcher Olivier Laflamme has disclosed two independent root remote code execution (RCE) chains affecting the Unitree G1 EDU, including a Bluetooth Low Energy (BLE) path that can reach root on the robot's Locomotion PC. The flaws are tracked as CVE-2026-76639 and CVE-2026-76640, with the first involving a network-adjacent path through chat_go and bashrunner and the

Cloud SecuritySecurity ResearchVulnerabilitiesCVE-2026-76639CVE-2026-76640
P20
2026-08-28 11:20 UTC
Security Journalism

Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-28 11:40 UTC

ServiceNow has released patches for four security flaws impacting the ServiceNow AI Platform, three of them rated 10.0 on the CVSS scoring system and exploitable, in certain circumstances, by an unauthenticated attacker. The company said it deployed a security update to hosted instances and provided the update to its partners and self-hosted customers, which leaves organizations that run their

Cloud SecurityVulnerabilities
P5
2026-08-28 10:58 UTC
Security Journalism

China-Made ZBT Routers Ship With Two Implants Giving Unauthenticated Attackers Root Access

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-28 11:40 UTC

VulnCheck has disclosed two previously undocumented factory implants in firmware for routers built by Shenzhen Zhibotong Electronics (ZBT), each of which gives an unauthenticated remote attacker the ability to run commands as root on affected devices. The implants, named SPEAKINGSTONE and DARKLANTERN by the company's zero-day research team, are tracked as CVE-2026-74232 and CVE-2026-74233.

Network SecurityVulnerabilitiesCVE-2026-74232CVE-2026-74233
P30
2026-08-28 10:09 UTC
Vendor Research

PaperCut NG/MF Critical Zero-Day Exploited in the Wild

Rapid7 · Rapid7 · indexed 2026-08-28 10:30 UTC

Overview On August 27, 2026, PaperCut Software published an urgent security advisory stating that it is investigating active exploitation of a vulnerability affecting PaperCut NG and PaperCut MF. PaperCut has confirmed customer incidents and is treating the issue as a security emergency. At the initial time of disclosure, the vulnerability had not been assigned a CVE identifier, and PaperCut had not publicly disclosed a CVSS score, vulnerability class, authentication requirements, or the techni…

DFIRNetwork SecurityRansomwareThreat IntelligenceVulnerabilitiesCVE-2023-27350CVE-2026-81578CVE-2026-82078
P100
2026-08-28 09:45 UTC
Security Journalism

Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-28 10:25 UTC

cPanel has released patches for a security flaw affecting domain parking and addon domain functionality in cPanel and WebHost Manager (WHM), which could allow code execution as the root user. The vulnerability, assigned the CVE identifier CVE-2026-65643, impacts all supported versions of cPanel & WHM. cPanel described the issue as a critical security vulnerability and said that an

VulnerabilitiesCVE-2026-65643
P5
2026-08-28 09:43 UTC
Other

PaperCut Zero-Day Under Active Attack: Emergency Patch Released

Security Affairs · Pierluigi Paganini · indexed 2026-08-29 21:40 UTC

PaperCut warns that a zero-day in NG and MF is being exploited. The company already release emergency patches to address it. PaperCut Software warns that attackers are actively exploiting a zero-day in its NG and MF print management products. The flaw has no CVE yet, and the company has not released technical details. PaperCut issued […]

Vulnerabilities
P25
2026-08-28 09:43 UTC
Other

PaperCut Zero-Day Under Active Attack: Emergency Patch Released

Security Affairs · Pierluigi Paganini · indexed 2026-08-28 10:30 UTC

PaperCut warns that a zero-day in NG and MF is being exploited. The company already release emergency patches to address it. PaperCut Software warns that attackers are actively exploiting a zero-day in its NG and MF print management products. The flaw has no CVE yet, and the company has not released technical details. PaperCut issued […]

Vulnerabilities
P25
2026-08-28 09:07 UTC
Other

U.S. CISA adds Red Hat, Linux Kernel, Ajax.NET Professional, Microsoft SQL Server, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog

Security Affairs · Pierluigi Paganini · indexed 2026-08-28 09:30 UTC

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Red Hat, Linux Kernel, Ajax.NET Professional, Microsoft SQL Server, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2015-3246 is a race condition in Red Hat libuser that could let […]

Cloud SecurityLinuxMicrosoftVulnerabilitiesCVE-2015-3246
P35
2026-08-28 08:25 UTC
Security Journalism

PaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF Versions

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-28 08:40 UTC

PaperCut has alerted customers that bad actors are actively exploiting a vulnerability impacting all versions of its PaperCut NG and PaperCut MF print management software in zero-day attacks. The company has released an emergency patch for v25 and v26 to address the issue. It said it's "aware of confirmed customer incidents and is treating this matter with the highest priority." An

Vulnerabilities
P45
2026-08-28 06:39 UTC
Vendor Research

WordPress Loops & Logic - Reflected XSS

Tenable Research Advisories · Joshua Martinelle · indexed 2026-08-28 07:15 UTC

WordPress Loops & Logic - Reflected XSS A Reflected Cross-Site Scripting vulnerability exists in the Wordpress plugin 'Loops & Logic' The ‘name’ parameter of the ‘tangible_fields_fetch’ and ‘tangible_fields_store’ actions is used in the response without any filtering, resulting in a reflected XSS vulnerability. curl http://WORDPRESS/wp-admin/admin-ajax.php?action=tangible_fields_fetch&name=%3cimg+src%3dx+onerror%3dalert%28document.domain%29%3eAll of the vulnerable code is located in 'vendor/tan…

Vulnerabilities
P0
2026-08-27 18:36 UTC
Security Journalism

OpenAI Says Reward Hacking Drove AI Agents to Exploit Zero-Days and Breach Hugging Face

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-27 20:30 UTC

OpenAI on Wednesday revealed that reward hacking was a key driver behind the artificial intelligence (AI)-powered hack of Hugging Face last month, adding that it found evidence of misaligned behavior as early as late May. The incident, the company said, took place during cybersecurity evaluations of several OpenAI models, and that it was mainly fueled by what it described as a "highly capable

AI SecurityVulnerabilities
P25
2026-08-27 15:13 UTC
Security Journalism

Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-27 17:00 UTC

Credit: Hacktron Vercel has released security patches for two critical-severity vulnerabilities in the Next.js web framework, both of which allow unauthenticated remote code execution, one exploitable via specially crafted AVIF image files and the other through a path traversal flaw affecting servers that use a Windows filesystem. The Windows path traversal, tracked as CVE-2026-75604&

Cloud SecurityMicrosoftVulnerabilitiesCVE-2026-75604
P20
2026-08-27 15:12 UTC
Security Journalism

ThreatsDay: 296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New Stories

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-27 17:00 UTC

A fake login page. A fake security scan. A fake productivity app. Apparently, pretending to be useful is still one of the easier ways into a machine. The rest of the week gets stranger: botnets borrowing AI, command traffic hiding in public infrastructure, malicious tools waiting before showing their real behavior, exposed systems getting scanned, and exploit windows shrinking again. Different

MalwareMicrosoftVulnerabilities
P15
2026-08-27 14:30 UTC
Vendor Research

How to build an exposure management program the business trusts: Lessons from Tenable’s CSO

Tenable Blog · Robert Huber · indexed 2026-08-27 14:40 UTC

Discover how Tenable’s shift to an AI-driven exposure management program helped Tenable’s CSO, Robert Huber, overcome tool sprawl, unify data silos, mitigate the risk of rapid AI adoption, and shift from presenting granular, technical metrics to communicating business risk that the C-suite and the board can understand.Key takeawaysSecurity tool sprawl and data silos make it difficult for CISOs to holistically and accurately assess their organizations’ cyber risk.An exposure management program c…

AI SecurityAppleCloud SecurityMicrosoftVulnerabilities
P0
2026-08-27 13:39 UTC
Security Journalism

Amazon Kiro Prompt Injection Can Exfiltrate Sensitive Data Through Kiro Powers

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-27 15:05 UTC

Cybersecurity researchers have disclosed details of a vulnerability in Amazon Kiro, an artificial intelligence (AI)-powered, agentic integrated development environment (IDE), that could facilitate data exfiltration via prompt injection and Kiro Powers. The security flaw, which does not have a CVE identifier, works against Kiro IDE 0.7.45 on Windows, according to Mindgard. The latest version of

AI SecurityMicrosoftSecurity ResearchVulnerabilities
P0
21 22 23 24 25