IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 1,373 matching records.
AUTO-POLL // 2026-10-04 17:30 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P5 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 4

RANSOMWARE
P5
P5
COOL // 10 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
FRI
Oct 2

RANSOMWARE
P7
P7
COOL // 46 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
WED
Sep 30

RANSOMWARE
P10
P10
WARM // 59 ARTICLES
TUE
Sep 29

RANSOMWARE
P4
P4
COOL // 68 ARTICLES
MON
Sep 28

RANSOMWARE
P7
P7
COOL // 52 ARTICLES
RESET
2026-08-27 11:56 UTC
Security Journalism

Learn How to Build Security Operations Ready for AI-Powered Attacks

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-27 12:55 UTC

Security teams have spent years trying to detect threats faster. AI is changing the harder part: how much time defenders have left to act. Advanced AI models can now help attackers discover vulnerabilities, generate exploit code, and move through weaknesses faster than traditional security processes were built to handle. The challenge is no longer just finding another vulnerability or

MicrosoftVulnerabilities
P0
2026-08-27 08:13 UTC
Security Journalism

New GPUThor Rowhammer Defeats ECC on NVIDIA RTX A6000 to Gain Host Root Access

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-27 08:50 UTC

Academic researchers have disclosed a Rowhammer attack impacting NVIDIA workstation GPUs with GDDR6 memory that defeats error correction codes (ECC), the mitigation NVIDIA recommends against GPU Rowhammer, and enables denial-of-service (DoS) and privilege escalation to a root shell. Dubbed GPUThor, the attack was developed by researchers at the University of Toronto, who hammered four DRAM

Vulnerabilities
P10
2026-08-27 07:05 UTC
Security Journalism

CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-27 07:15 UTC

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added six flaws to its Known Exploited Vulnerabilities (KEV) catalog, including a high-severity security vulnerability impacting Citrix NetScaler ADC and NetScaler Gateway, citing evidence of active exploitation. The vulnerabilities are listed below - CVE-2019-1068 - A remote code execution vulnerability in

Cloud SecurityLinuxVulnerabilitiesCVE-2019-1068
P50
2026-08-26 11:55 UTC
Security Journalism

Unpatched Kaltura mwEmbed Flaws Could Let Remote Attackers Read Files and Run Code

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-26 13:10 UTC

The CERT Coordination Center (CERT/CC) has disclosed two unpatched vulnerabilities in Kaltura's HTML5 video player library that allow a remote, unauthenticated attacker to read arbitrary files from a server and execute code on it. The flaws, tracked as CVE-2026-19913 and CVE-2026-19912, both stem from the same unsafe deserialization in the mwEmbedLoader.php endpoint of the mwEmbed player

Cloud SecurityVulnerabilitiesCVE-2026-19912CVE-2026-19913
P5
2026-08-26 09:00 UTC
Vendor Research

Edge infrastructure under siege: what two independent datasets reveal about who's exploiting your perimeter

Tenable Cyber Exposure Alerts · Research Special Operations · indexed 2026-08-26 13:15 UTC

A joint Tenable-SentinelOne analysis of 93 CVE-actor attribution pairs reveals that both state-sponsored actors and cybercriminals independently converge on the same edge infrastructure. Special thanks to SentinelOne® Incident Readiness & Response for their contributions to this publication.It is the shared attack surface where state-sponsored threat actors and financially motivated criminal groups independently converge — not the province of a single adversary category, and not exclusively a n…

APT / Nation-StateData BreachesDFIRMicrosoftNetwork SecurityPhishingRansomwareThreat ActorsThreat IntelligenceVulnerabilities
P45
2026-08-26 08:44 UTC
Other

U.S. CISA adds Gitea flaw to its Known Exploited Vulnerabilities catalog

Security Affairs · Pierluigi Paganini · indexed 2026-08-26 10:00 UTC

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Gitea flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added an Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in flaw, tracked as CVE-2026-60004 (CVSS score of 9,8), to its Known Exploited Vulnerabilities (KEV) catalog. Gitea is an open-source platform for […]

VulnerabilitiesCVE-2026-60004
P35
2026-08-26 06:27 UTC
Security Journalism

Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-26 07:10 UTC

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday warned of active exploitation efforts targeting a recently patched critical security flaw impacting Gitea. The vulnerability in question is CVE-2026-60004 (CVSS score: 9.8), a case of remote code execution that allows an attacker with ordinary write access to a repository to execute arbitrary shell commands as the

VulnerabilitiesCVE-2026-60004
P45
2026-08-25 16:43 UTC
Other

Two CVSS 9.8 Auth Bypasses in miniOrange SAML WordPress Plugin Were Exploited Before Any Database Even Listed the Paid Editions as Vulnerable

Security Affairs · Pierluigi Paganini · indexed 2026-08-25 17:30 UTC

Two CVSS 9.8 miniOrange SAML WordPress plugin auth bypasses were exploited while paid editions never appeared in any vulnerability database. Manual patch required. Two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On WordPress plugin, both rated CVSS 9.8, are under active exploitation. Both CVE-2026-61979 and CVE-2026-15981 allow an unauthenticated attacker to […]

VulnerabilitiesCVE-2026-15981CVE-2026-61979
P15
2026-08-25 15:03 UTC
Community

Obfuscating IP Addresses as Hostnames, (Tue, Aug 25th)

SANS Internet Storm Center · indexed 2026-08-25 15:10 UTC

It is pretty obvious that hostnames can replace IP addresses. Pretty much any software accepting an IP address will also accept a hostname as an argument. Last week, I wrote about scans for the cloud metadata service listening at 169.254.169.254. These scans attempted to exploit Server Side Request Forgery (SSRF) vulnerability. One way to prevent these types of exploits is to filter requests that contain the string "169.254.169.254" or to add this IP to a blocklist of URLs that should not be ac…

Vulnerabilities
P0
2026-08-25 12:43 UTC
Security Journalism

Marimo Notebook Flaw Could Run MCP Commands Before Cells Execute in Edit Mode

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-25 13:45 UTC

Marimo has addressed a high-severity security flaw in its notebook software that allowed an attacker to execute an attacker-supplied Model Context Protocol (MCP) command in a specially crafted notebook, according to VulnCheck's CVE Numbering Authority (CNA) record. The CNA record says the command can run as a local subprocess when the notebook is opened in edit mode. The vulnerability, tracked

Vulnerabilities
P0
2026-08-25 11:14 UTC
Security Journalism

Frontier AI: Vulnerability Management's Systemic Revolution

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-25 12:45 UTC

Vulnerability management has been a staple of security programs since the dawn of the cybersecurity discipline. The symbiotic relationship between vulnerability and patch management teams has also existed for that time and has gone through waves of contention and thankfulness. While this relationship required thoughtful care and feeding from both sides, both sides were aiming to work toward a

Vulnerabilities
P0
2026-08-25 08:48 UTC
Other

U.S. CISA adds maximum-severity Oracle flaw to its Known Exploited Vulnerabilities catalog

Security Affairs · Pierluigi Paganini · indexed 2026-08-25 09:40 UTC

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Oracle flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added an Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in flaw, tracked as CVE-2026-21962 (CVSS score of 10,0), to its Known Exploited Vulnerabilities (KEV) catalog. CVE-2026-21962 is a critical, unauthenticated vulnerability […]

VulnerabilitiesCVE-2026-21962
P35
2026-08-25 08:34 UTC
Security Journalism

Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-25 09:40 UTC

Bad actors are attempting to exploit two severe unauthenticated authentication bypasses in the Xecurify miniOrange SAML 2.0 Single Sign On plugin that make it possible for an attacker to sign in as any WordPress user, including administrators. The vulnerabilities, as disclosed by Patchstack, are listed below - CVE-2026-61979 (CVSS score: 8.1) - An unauthenticated privilege escalation

Cloud SecurityVulnerabilitiesCVE-2026-61979
P15
2026-08-25 06:12 UTC
Security Journalism

Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-25 06:55 UTC

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a maximum-severity security flaw impacting Oracle HTTP Server and Oracle WebLogic Server to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability, tracked as CVE-2026-21962 (CVSS score: 10.0), allows an unauthenticated attacker with network access via HTTP to

VulnerabilitiesCVE-2026-21962
P60
2026-08-24 14:00 UTC
Security Journalism

The Vulnerability Gap: Why Discovery Is Outrunning Repair

Dark Reading · Christopher Robinson · indexed 2026-08-24 17:05 UTC

The combination of AI both discovering more vulnerabilities at a faster pace and the tightening regulatory environment is making this an all-hands-on-deck moment for the cybersecurity community.

Vulnerabilities
P0
2026-08-24 11:56 UTC
Security Journalism

Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-24 12:10 UTC

Red Hat and the Keycloak project have released patches to address a critical security flaw in the open-source identity and access management server that could allow an unauthenticated remote attacker to take over any user account by forcing a password reset. The vulnerability, assigned the CVE identifier CVE-2026-18963, is rated 9.1 on the CVSS scoring system by Red Hat, which acts as

LinuxVulnerabilitiesCVE-2026-18963
P5
2026-08-24 10:45 UTC
Security Journalism

CISA orders urgent patching of actively exploited Zimbra flaw

BleepingComputer · Sergiu Gatlan · indexed 2026-08-24 10:50 UTC

The Cybersecurity and Infrastructure Security Agency (CISA) has ordered U.S. government agencies to patch an actively exploited vulnerability in Zimbra Collaboration Suite (ZCS) within three days. [...]

Vulnerabilities
P25
2026-08-24 05:00 UTC
Other

ZDI-26-610: Apple Safari JavaScriptCore B3 ReduceStrength Phase Use-After-Free Remote Code Execution Vulnerability

Zero Day Initiative · indexed 2026-09-07 17:35 UTC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Apple Safari. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-64715.

AppleVulnerabilitiesCVE-2026-64715
P20
2026-08-24 05:00 UTC
Other

ZDI-26-609: Linux Kernel Net Scheduler Packet Classifier Use-After-Free Local Privilege Escalation Vulnerability

Zero Day Initiative · indexed 2026-09-07 17:35 UTC

This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8.

LinuxVulnerabilities
P10
22 23 24 25 26