IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 4,433 matching records.
AUTO-POLL // 2026-10-04 07:25 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
NO DATA
NO INTELLIGENCE AGGREGATED TODAY
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 4
NO DATA
--
NO INTEL
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
FRI
Oct 2

RANSOMWARE
P7
P7
COOL // 46 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
WED
Sep 30

RANSOMWARE
P10
P10
WARM // 59 ARTICLES
TUE
Sep 29

RANSOMWARE
P4
P4
COOL // 68 ARTICLES
MON
Sep 28

RANSOMWARE
P7
P7
COOL // 52 ARTICLES
RESET
2026-10-03 19:09 UTC
Security Journalism

ShinyHunters hacker reportedly detained in Jordan, aiding FBI

BleepingComputer · Lawrence Abrams · indexed 2026-10-03 19:20 UTC

A suspected ShinyHunters hacking group member known online as "Rey" has reportedly been detained in Jordan and is cooperating with the FBI to help locate other members of the extortion group. [...]

Law Enforcement
P0
2026-10-03 15:11 UTC
Other

Fake Zoom installer hides macOS backdoor CloudSyncD

Security Affairs · Pierluigi Paganini · indexed 2026-10-03 15:30 UTC

Jamf Threat Labs details CloudSyncD, a fake macOS Zoom installer that hides a phished password using invisible zero-width Unicode characters. Jamf Threat Labs found CloudSyncD while doing routine scanning on VirusTotal, buried inside a disguised Zoom client. They first spotted it on September 15, clearly still under construction, and within two days watched it move […]

AppleMalwarePhishing
P0
2026-10-03 14:40 UTC
Community

YARA-X 1.21.0 Release, (Sat, Oct 3rd)

SANS Internet Storm Center · indexed 2026-10-03 14:50 UTC

YARA-X's 1.21.0 release brings 5 improvements and 4 bugfixes.

P0
2026-10-03 14:38 UTC
Security Journalism

MI5 Says China’s MSS Funded Research Involving 100+ U.K.-Linked Academics

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-03 15:25 UTC

The U.K.'s domestic intelligence and security agency has warned that more than 100 academics have helped China boost its intelligence gathering efforts on behalf of Beijing's state security service. In a "Security Service Espionage Alert" issued on September 30, 2026, MI5 said the "primary purpose of the China General Technology Research Institute (CGTRI) 中国通用技术研究院 is to fund research that

APT / Nation-State
P0
2026-10-03 14:36 UTC
Security Journalism

Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-03 15:25 UTC

The suspected China-linked threat actor known as Warlock is still continuing to weaponize Microsoft SharePoint vulnerabilities, likely both old and new, in attacks targeting organizations in Portuguese- and Spanish-speaking countries. The activity, observed by the Symantec and Carbon Black Threat Hunter Team, has hit critical infrastructure, government, and education organizations. "In the

Cloud SecurityMicrosoftRansomwareThreat Actors
P15
2026-10-03 14:35 UTC
Security Journalism

Danish university DTU breach exposes data of up to 200,000 people

BleepingComputer · Ionut Ilascu · indexed 2026-10-03 14:45 UTC

The Technical University of Denmark (DTU) says information belonging to up to 200,000 users may have been exposed after hackers accessed its identity and access management system and downloaded a large amount of data. [...]

P0
2026-10-03 11:34 UTC
Security Journalism

Fortra Patches Critical Vulnerabilities in BoKS

Security Week · Ionut Arghire · indexed 2026-10-03 11:40 UTC

The bugs could lead to authentication bypass, shell command execution, and memory corruption. The post Fortra Patches Critical Vulnerabilities in BoKS appeared first on SecurityWeek.

P10
2026-10-03 11:00 UTC
Security Journalism

The State of Cybersecurity in 2026: Key Segments, Insights, and Innovations

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-03 11:10 UTC

Featuring: Cybersecurity is being reshaped by the expansion of cloud infrastructure, AI, distributed systems, and increasingly complex digital environments. As organizations manage more identities, devices, data, and internet-facing infrastructure, security is shifting toward continuous visibility, control, and the ability to respond to risk at scale. This report examines how core areas of

P0
2026-10-03 10:43 UTC
Other

CVE-2026-90970: Critical GitLab AI Gateway Flaw Fixed

Security Affairs · Pierluigi Paganini · indexed 2026-10-03 11:00 UTC

GitLab fixes critical AI Gateway flaw that could let authenticated Duo users escape a prompt sandbox and execute commands on self-hosted gateways. GitLab has released patches for a critical vulnerability in its AI Gateway, tracked as CVE-2026-90970 (CVSS score of 9.9), that could allow an authenticated user with access to the Duo Agent Platform to […]

VulnerabilitiesCVE-2026-90970
P15
2026-10-03 09:26 UTC
Other

Antino Backdoor Lets China-Linked UAT-11587 Turn Microsoft 365 Into a C2 Channel

Security Affairs · Pierluigi Paganini · indexed 2026-10-03 10:00 UTC

Cisco Talos details UAT-11587, a China-linked group using the Antino backdoor and Microsoft 365 as cover to spy on Asian governments. Cisco Talos has been tracking a cluster of espionage activity since September 2025 that it calls UAT-11587, and by July 2026 the group had hit at least 16 government and policy organizations across eight […]

APT / Nation-StateMalwareMicrosoft
P0
2026-10-02 23:18 UTC
Vendor Research

Cisco Catalyst SD-WAN Manager API Authentication Bypass Vulnerability

Cisco Security Advisories · indexed 2026-09-30 13:10 UTC

A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user. This vulnerability is due to improper handling of URI encoding in an HTTP request, which allows the request to bypass an authentication rule that is intended to restrict access to a specific API endpoint. An attacker could exploit this vulnerability by sending a crafted HTTP request to …

Network SecurityVulnerabilitiesCVE-2026-76504
P15
2026-10-02 22:46 UTC
Other

U.S. CISA adds Zammad GmbH Zammad flaws to its Known Exploited Vulnerabilities catalog

Security Affairs · Pierluigi Paganini · indexed 2026-10-02 23:35 UTC

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Zammad GmbH Zammad flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: The first flaw, CVE-2026-102489, is a session hijacking vulnerability in Zammad that can lead to remote code execution as the […]

Cloud SecurityVulnerabilitiesCVE-2026-102489
P50
2026-10-02 20:25 UTC
Vendor Research

CVE-2026-104019 - OS command injection in the Studio Space startup script in Amazon SageMaker Distribution

AWS Security Bulletins · aws@amazon.com · indexed 2026-10-02 20:40 UTC

Bulletin ID: 2026-125-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 10/02/2026 13:00 PM PDT Description: Amazon SageMaker Unified Studio is an AWS service that unifies data, analytics, and AI development. It lets you find and access your organization's data and act on it with integrated, purpose-built tools. We identified CVE-2026-104019, an issue with the startup of SageMaker Spaces in SageMaker Unified Studio. The startup script in a SageMaker Space performs a …

Cloud SecurityVulnerabilitiesCVE-2026-104019
P5
2026-10-02 19:30 UTC
Security Journalism

Bipartisan backlash to ALPRs grows as two high-profile bills are introduced

The Record · indexed 2026-10-02 19:45 UTC

Republican Sen. Josh Hawley has new legislation on limiting automated license plate readers (ALPRs), while Democratic Sens. Bernie Sanders and Jeff Merkley, with Rep. Alexandria Ocasio-Cortez, have teed up a broader bill.

P0
2026-10-02 19:21 UTC
Vendor Research

CVE-2026-103956, CVE-2026-103957, and CVE-2026-103958 - Issues in Loom for AWS

AWS Security Bulletins · aws@amazon.com · indexed 2026-10-02 19:25 UTC

Bulletin ID: 2026-124-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 10/02/2026 12:00 PM PDT Description: Loom is an AWS Labs open-source AI agent orchestration platform. We have identified and addressed three issues in Loom for AWS, described below. We recommend upgrading to the latest version (1.7.0) and ensuring any forked or derivative code is patched to incorporate the new fixes. - CVE-2026-103956 ‐ Authentication bypass in Loom for AWS (CWE-306, CWE-1188) An…

AI SecurityCloud SecurityVulnerabilitiesCVE-2026-103956CVE-2026-103957CVE-2026-103958
P15
2026-10-02 19:21 UTC
Vendor Research

Cisco IOS XE Software Security Hardening Release: August 2026

Cisco Security Advisories · indexed 2026-08-15 14:33 UTC

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. These vulnerabilities were found during internal testing and are not known to be actively exploited. To assist customers in patching and streamline the disclosure process, Cisco has grouped these issues by …

AppleVulnerabilitiesCVE-2026-20267CVE-2026-20268CVE-2026-20269CVE-2026-20270CVE-2026-20271CVE-2026-20272CVE-2026-20273
P30
2026-10-02 17:33 UTC
Security Journalism

GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-02 17:45 UTC

A critical flaw in GitLab's AI Gateway could let a logged-in user with Duo Agent Platform access run commands on the gateway under certain conditions, GitLab said in an advisory. The gateway is the service that connects a GitLab instance to AI models, and only organizations that host their own gateway need to act. The flaw is fixed in gateway versions 19.2.4, 19.3.2, and 19.4.1. The flaw

P10
2026-10-02 17:33 UTC
Security Journalism

Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-02 17:45 UTC

Government and policy organizations across Asia have become the target of a new campaign orchestrated by a China-nexus threat actor. The activity, which has targeted government and policy organizations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, and Myanmar, involves the deployment of a previously undocumented backdoor codenamed Antino. Cisco Talos is tracking the cluster

APT / Nation-StateMalwareThreat Actors
P0
2026-10-02 17:02 UTC
Security Journalism

Dell CSM Flaws Enable Unauthenticated Admin Access and Root on Kubernetes Nodes

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-02 17:45 UTC

Dell has released security updates to address multiple critical security flaws in Dell Container Storage Modules (CSM) that could be exploited by bad actors to take over susceptible systems. The vulnerabilities are listed below - CVE-2026-63688 (CVSS score: 10.0) - A missing authentication for critical function vulnerability in the csm-authorization-storage gRPC server that an

Cloud SecurityVulnerabilitiesCVE-2026-63688
P5
2026-10-02 16:38 UTC
Vendor Research

CVE-2026-103505 - Mount Option Injection in Amazon EFS CSI Driver

AWS Security Bulletins · aws@amazon.com · indexed 2026-10-02 16:50 UTC

Bulletin ID: 2026-120-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 10/01/2026 08:30 AM PDT Description: The Amazon EFS CSI Driver is a Container Storage Interface driver that allows Kubernetes clusters to use Amazon Elastic File System. We identified CVE-2026-103505, where an actor with PersistentVolume creation privileges can inject additional mount options through the mounttargetipmap volumeAttribute. Appending comma-separated values to a value inside that JSO…

Cloud SecurityVulnerabilitiesCVE-2026-103505
P5
2026-10-02 16:01 UTC
Security Journalism

Is Your Organization Ready for 2027's AI Accountability Era?

Dark Reading · Arielle Waldman · indexed 2026-10-02 16:15 UTC

Organizations may face an artificial intelligence (AI) reckoning over the next year. Omdia and Gartner weigh in on how to tackle the governance, security, and value challenges ahead.

AI Security
P0
1 2 3