IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 1,373 matching records.
AUTO-POLL // 2026-10-04 09:15 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P9 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 4

RANSOMWARE
P9
P9
COOL // 5 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
FRI
Oct 2

RANSOMWARE
P7
P7
COOL // 46 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
WED
Sep 30

RANSOMWARE
P10
P10
WARM // 59 ARTICLES
TUE
Sep 29

RANSOMWARE
P4
P4
COOL // 68 ARTICLES
MON
Sep 28

RANSOMWARE
P7
P7
COOL // 52 ARTICLES
RESET
2026-09-25 08:22 UTC
Other

U.S. CISA adds Adobe and WSO2 flaws to its Known Exploited Vulnerabilities catalog

Security Affairs · Pierluigi Paganini · indexed 2026-09-25 08:25 UTC

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Adobe and WSO2 flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: The first flaw added to the catalog, tracked as CVE-2026-5430 (CVSS score 10.0), is an authentication bypass in multiple WSO2 products […]

Cloud SecurityVulnerabilitiesCVE-2026-5430
P45
2026-09-25 04:46 UTC
Security Journalism

WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-25 06:35 UTC

The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added two critical security flaws impacting WSO2 and Adobe Commerce and Magento to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation. The vulnerabilities are listed below - CVE-2026-5430 (CVS score: 9.8) - A path traversal vulnerability in WSO2 API Control Plane,

Cloud SecurityVulnerabilitiesCVE-2026-5430
P55
2026-09-24 19:17 UTC
Vendor Research

CVE-2026-96883 - Type confusion in AWS pgcollection allows remote code execution

AWS Security Bulletins · aws@amazon.com · indexed 2026-09-24 19:35 UTC

Bulletin ID: 2026-118-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/24/2026 12:00 PM PDT Description: pgcollection is an open source extension to PostgreSQL. We identified CVE-2026-96883, an issue in pgcollection's type coercion logic. When requesting a stored icollection value as a type incompatible with how it was actually stored causes the extension to misinterprets the datum's representation, allowing an authenticated database user to crash the PostgreSQL …

Cloud SecurityVulnerabilitiesCVE-2026-96883
P20
2026-09-24 18:00 UTC
Vendor Research

Trust and the enticing consultancy offer

Cisco Talos Intelligence Blog · Martin Lee · indexed 2026-09-24 18:30 UTC

In this week’s newsletter Martin muses over a very suspicious elicitation over social media and the true value of trust within the cyber ecosystem. Hubris might be the real vulnerability that the cyber industry must worry about.

Vulnerabilities
P0
2026-09-24 17:21 UTC
Vendor Research

CVE-2026-95985 - Kiro IDE Allows Agentic Writes to Global Configurations While Working in Untrusted Workspaces

AWS Security Bulletins · aws@amazon.com · indexed 2026-09-24 18:00 UTC

Bulletin ID: 2026-117-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/24/2026 10:00 AM PDT Description: Kiro is an agentic IDE that users install on their desktop. We identified CVE-2026-95985. The file write tool in Kiro IDE before version 1.0.242 might allow remote unauthenticated actors to execute arbitrary commands and to inject crafted instructions into the agent's context. When a user runs the agent in a crafted repository as an untrusted workspace, sendin…

Cloud SecurityVulnerabilitiesCVE-2026-95985
P5
2026-09-24 17:16 UTC
Vendor Research

Cisco Identity Services Engine Authentication Bypass Vulnerabilities

Cisco Security Advisories · indexed 2026-09-16 16:40 UTC

Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow a remote attacker to access or manipulate data, obtain sensitive information, or cause a reload of certificate and key material on an affected device. For more information about these vulnerabilities, see the Details section of this advisory. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilit…

VulnerabilitiesCVE-2026-76439CVE-2026-76444CVE-2026-76446CVE-2026-76447
P15
2026-09-24 14:02 UTC
Security Journalism

FedRAMP VDR & VER: Daily Scans Are Only the Beginning

BleepingComputer · Sponsored by Anecdotes · indexed 2026-09-24 14:15 UTC

FedRAMP's new VDR and VER requirements make vulnerability management more continuous, with faster scanning, tighter remediation deadlines, and stronger evidence requirements. Anecdotes explains why the December 7 deadline is just the beginning of a broader shift toward continuous, automated compliance validation. [...]

Vulnerabilities
P0
2026-09-24 14:00 UTC
Vendor Research

Proactive Defense: Hardening Code Pipelines and CI/CD Infrastructure

Google Threat Intelligence / Mandiant · Mandiant · indexed 2026-09-24 15:25 UTC

Introduction The landscape of software supply chain security has undergone a significant shift. Recent campaigns demonstrate that sophisticated threat actors are systematically targeting the engineering lifecycle by compromising trusted security and programming tools. These intrusions reveal three key tactics: Attackers target trusted security scanners, utility libraries, and AI developer tools to exploit the elevated privileges granted to these systems within build pipelines. Adversaries targe…

AI SecurityMicrosoftPhishingThreat ActorsVulnerabilities
P0
2026-09-24 13:00 UTC
Vendor Research

When Business Email Compromise Starts Rewriting Reality

Rapid7 · Douglas McKee, Director, Vulnerability Intelligence · indexed 2026-09-24 13:20 UTC

Business Email Compromise (BEC) operates on a familiar playbook. Threat actors breach a mailbox, silently monitor operations, map approval chains, and ultimately exploit that access to divert funds or exfiltrate sensitive assets.This dynamic is central to our analysis as we kick off a series around Rapid7's collaborative research with Zimbra; upcoming installments will explore technical details and broader findings based within the Zimbra Collaboration Suite. Our investigation disrupted the tra…

CybercrimeDFIRMicrosoftPhishingThreat ActorsVulnerabilitiesCVE-2022-27925CVE-2022-37042CVE-2023-37580CVE-2024-45519CVE-2025-27915CVE-2026-73570
P70
2026-09-24 05:36 UTC
Security Journalism

Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-24 08:35 UTC

Threat actors have begun to actively exploit a critical security flaw in WordPress within hours of public disclosure. The vulnerability in question is CVE-2026-87902 (CVSS score: 9.2), which could allow an unauthenticated attacker to obtain remote code execution (RCE). "An unauthenticated attacker can make get_page_template() page-template resolution include a chosen readable local .php file

Threat ActorsVulnerabilitiesCVE-2026-87902
P20
2026-09-23 20:37 UTC
Other

U.S. CISA adds Check Point, Arista VeloCloud Orchestrator, and F5 BIG-IP APM flaws to its Known Exploited Vulnerabilities catalog

Security Affairs · Pierluigi Paganini · indexed 2026-09-23 21:00 UTC

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Check Point, Arista VeloCloud Orchestrator, and F5 BIG-IP APM flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2026-85102 resides in the VPN negotiation process and lets an unauthenticated attacker bypass security checks […]

Cloud SecurityNetwork SecurityVulnerabilitiesCVE-2026-85102
P35
2026-09-23 18:12 UTC
Other

F5 BIG-IP APM Zero-Day Exploited in Zero-Day RCE Attacks

Security Affairs · Pierluigi Paganini · indexed 2026-09-23 18:50 UTC

F5 warns of a critical BIG-IP APM zero-day, CVE-2026-94127, allowing remote code execution. Attackers are already exploiting it. F5 has released emergency security updates for a critical vulnerability, tracked as CVE-2026-94127 (CVSS score of 9.8), in BIG-IP Access Policy Manager (APM) that attackers are already exploiting in the wild. The flaw can allow an unauthenticated […]

VulnerabilitiesCVE-2026-94127
P75
2026-09-23 16:06 UTC
Security Journalism

MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-23 16:35 UTC

Two MikroTik RouterOS SSH vulnerabilities chained together let attackers take full administrative control of Internet-exposed routers without a password, SSH key, or completed authentication. The chain, which CERT Polska calls MikroTrick, combines an SSH state-machine flaw (CVE-2026-67279) with an argument-injection bug in the RouterOS login process (CVE-2026-86060). Attack logs date to at

Network SecurityVulnerabilitiesCVE-2026-67279CVE-2026-86060
P5
2026-09-23 14:01 UTC
Security Journalism

How One Kubernetes YAML Can Hand Over a GCP Organization

BleepingComputer · Sponsored by Varonis · indexed 2026-09-23 14:15 UTC

A Kubernetes user with limited permissions can potentially gain control of an entire Google Cloud organization by exploiting the authority granted to Google Kubernetes Config Connector. Varonis explains how this confused deputy problem can turn a single Kubernetes YAML file into a path to organization-wide privilege escalation. [...]

Cloud SecurityVulnerabilities
P10
2026-09-23 13:56 UTC
Other

ShinyHunters claims FBI breach after alleged PeopleSoft zero-day attack

Security Affairs · Pierluigi Paganini · indexed 2026-09-23 14:20 UTC

ShinyHunters claims FBI breach via PeopleSoft zero-day, steals staff data; FBI investigating, no confirmation yet. The popular cybercrime group ShinyHunters is claiming that it breached the U.S. Federal Bureau of Investigation (FBI) and stole sensitive information belonging to FBI employees and job applicants. The group says the operation was not financially motivated and was instead […]

CybercrimeDFIRLaw EnforcementVulnerabilities
P25
2026-09-23 13:26 UTC
Vendor Research

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software SSL VPN Denial of Service Vulnerability

Cisco Security Advisories · indexed 2026-09-16 16:40 UTC

Update for September 16, 2026: The original 1.0 version of this advisory was specific to the Cisco Adaptive Security Virtual Appliance (ASAv) and Cisco Secure Firewall Threat Defense Virtual (FTDv) models. However, it was later found that this vulnerability affects all Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software platforms. A vulnerability in the VPN and management web servers of the Cisco Secure Firewall ASA Software a…

Network SecurityVulnerabilitiesCVE-2024-20260
P5
2026-09-23 11:12 UTC
Security Journalism

Exploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container Escape

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-23 12:40 UTC

A use-after-free in the Linux kernel's AF_UNIX socket subsystem can be used to escape a container and gain root on the host, security firm DepthFirst said in research published September 22. The flaw, tracked as CVE-2026-80521 (CVSS score: 7.8), was fixed upstream on August 6, but Ubuntu has not shipped the patch for its 26.04, 24.04, or 22.04 LTS releases. DepthFirst

LinuxVulnerabilitiesCVE-2026-80521
P5
2026-09-23 08:43 UTC
Vendor Research

CVE-2026-94127: Critical Unauthenticated RCE in F5 BIG-IP APM

Rapid7 · Rapid7 · indexed 2026-09-23 09:30 UTC

OverviewOn September 22, 2026, F5 published a security advisory for CVE-2026-94127, a critical heap-based buffer overflow vulnerability affecting F5 BIG-IP Access Policy Manager (APM). The vulnerability has a CVSS v3.1 score of 9.8. An unauthenticated attacker with network access to an affected virtual server may be able to achieve remote code execution (RCE) by sending specifically crafted traffic.BIG-IP APM provides identity-aware access control for applications and other corporate resources …

Security ResearchVulnerabilitiesCVE-2026-94127
P50
3 4 5 6 7