IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 4,553 matching records.
AUTO-POLL // 2026-10-07 00:25 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
NO DATA
NO INTELLIGENCE AGGREGATED TODAY
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 7
NO DATA
--
NO INTEL
TUE
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
FRI
Oct 2

RANSOMWARE
P7
P7
COOL // 46 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
RESET
2026-06-24 12:00 UTC
Government

Advancing Product Security: New IoT Guidance and New Engagement

NIST Cybersecurity Insights · Michael Fagan · indexed 2026-08-15 20:45 UTC

It may be summertime, but the NIST Cybersecurity for the Internet of Things (IoT) Program isn’t hitting the hammock! Organizations are managing growing device complexity, evolving threats, and pressure to turn guidance into operational decisions…so we remain focused on helping stakeholders apply security guidance in ways that are practical and actionable. What’s Been Happening Lately? An initial public draft (IPD) of NIST SP 800-213 Revision 1, IoT Product Cybersecurity Guidelines for the Feder…

P0
2026-06-24 11:00 UTC
Vendor Research

Zero-Day Exploitation of Vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN Manager

Google Threat Intelligence / Mandiant · Mandiant · indexed 2026-08-15 18:55 UTC

Written by: Chester Sng, Pete Boonyakarn, Logeswaran Nadarajan, Lukasz Lamparski Introduction In early 2026, Mandiant identified a threat actor targeting SD-WAN infrastructure at a service provider. After gaining initial access, the threat actor exploited a zero-day vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN to escalate privileges from a compromised administrative account to root-level access. The vulnerability stems from the device’s file upload feature lacking the ability to prop…

MicrosoftNetwork SecurityThreat ActorsVulnerabilitiesCVE-2026-20127CVE-2026-20182CVE-2026-20245
P40
2026-06-24 06:00 UTC
Vendor Research

Unlocking the Cloudflare app ecosystem with OAuth for all

Cloudflare Security · Sam Cabell · indexed 2026-08-15 18:58 UTC

Self-Managed OAuth is now available to all developers on Cloudflare. Here's how we executed a zero-downtime migration of our core OAuth engine to make it happen.

P0
2026-06-23 16:12 UTC
Independent Research

Scattered Spider Hackers Plead Guilty on Day 1 of Trial

Krebs on Security · BrianKrebs · indexed 2026-08-15 14:33 UTC

Two men pleaded guilty in the United Kingdom this week to criminal charges stemming from an August 2024 cyberattack that crippled Transport for London, the entity responsible for the public transport network in the Greater London area. The duo were key members of a prolific cybercrime group known as Scattered Spider, and their guilty pleas came on the first day of what was expected to be a six-week trial.

Cybercrime
P0
2026-06-23 01:16 UTC
Other

10 Cybersecurity Priorities for E-Commerce Teams This Year

Group-IB · indexed 2026-09-07 17:30 UTC

E-commerce is the second most targeted sector for cyberattacks in 2026. Get the 10 priorities every security team must act on, with Group-IB intelligence behind each.

P0
2026-06-22 15:04 UTC
Vendor Research

Cisco Packaged Contact Center Enterprise and Cisco Unified Contact Center Enterprise Cross-Site Scripting Vulnerabilities

Cisco Security Advisories · indexed 2026-08-15 14:33 UTC

Multiple vulnerabilities in the web-based management interface of Cisco Packaged Contact Center Enterprise (Packaged CCE) and Cisco Unified Contact Center Enterprise (Unified CCE) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. These vulnerabilities exist because the web-based management interface does not properly validate user-supplied input. An attacker could exploit these…

VulnerabilitiesCVE-2026-20055CVE-2026-20109
P5
2026-06-19 06:41 UTC
Vendor Research

Gogs - Authentication Bypass via Unvalidated Reverse Proxy Headers

Tenable Research Advisories · Joshua Martinelle · indexed 2026-08-15 18:55 UTC

Gogs - Authentication Bypass via Unvalidated Reverse Proxy Headers When 'ENABLE_REVERSE_PROXY_AUTHENTICATION' is enabled, Gogs accepts the configured authentication header (default: 'X-WEBAUTH-USER') directly from client requests without validating that the request originated from a trusted reverse proxy.Any remote attacker who can reach the Gogs service can forge this header to impersonate any user or trigger automatic account creation, completely bypassing authentication. Joshua Martinelle Fr…

P10
2026-06-18 17:59 UTC
Vendor Research

Build your own vulnerability harness

Cloudflare Security · Dan Jones · indexed 2026-08-15 18:58 UTC

We break down the technical architecture behind our multi-stage vulnerability discovery harness and automated triage loop. Learn how we manage state controls, squash false positives through adversarial review, and route around LLM context limits.

AI SecurityVulnerabilities
P0
2026-06-18 05:23 UTC
Vendor Research

Oracle June 2026 Critical Security Patch Update Addresses 243 CVEs (CVE-2026-35273)

Tenable Cyber Exposure Alerts · Research Special Operations · indexed 2026-08-15 18:55 UTC

Oracle addresses 243 CVEs in its June 2026 Critical Security Patch Update with 245 patches, including 122 critical updates.Key TakeawaysThe June 2026 Critical Security Patch Update (CSPU) contains fixes for 243 unique CVEs in 245 security updates122 issues (49.8% of all patches) were assigned a critical severity ratingOracle Fusion Middleware received the highest number of patches at 106, accounting for 43.3% of all patchesBackgroundOn June 16, Oracle released its Critical Security Patch Update…

Threat IntelligenceVulnerabilitiesCVE-2026-35273
P65
2026-06-18 04:45 UTC
Other

GitBait: Phishing dirigido al sector financiero mexicano

Group-IB · indexed 2026-09-07 17:30 UTC

Se ha descubierto una infraestructura de phishing modular dirigida a múltiples bancos mexicanos, que abusa de GitHub Pages, emplea scripts ofuscados y centraliza la exfiltración de credenciales mediante la API de SheetBest, lo que indica una operación de phishing escalable y persistente de múltiples marcas.

MicrosoftPhishing
P0
2026-06-17 16:09 UTC
Vendor Research

iba ibaPDA / ibaDatCoordinator .NET Deserialization Remote Code Execution

Tenable Research Advisories · Ben Smith · indexed 2026-08-15 18:55 UTC

iba ibaPDA / ibaDatCoordinator .NET Deserialization Remote Code Execution A .NET deserialization vulnerability exists in iba ibaPDA, ibaDatCoordinator and ibaLogic. An unauthenticated remote attacker can exploit it to achieve remote code execution.The ibaPDA Server service (ibaPDAService.exe) listens on TCP port 9170 by default. Clients communicate with the server using GenuineChannels, which uses .NET Remoting. Messages sent to the server are deserialized using BinaryFormatter. GenuineChannels…

Vulnerabilities
P15
2026-06-17 16:00 UTC
Vendor Research

Cisco Umbrella Virtual Appliance Privilege Escalation Vulnerability

Cisco Security Advisories · indexed 2026-08-15 14:33 UTC

A vulnerability in the vmadmin CLI of Cisco Umbrella Virtual Appliance could allow an authenticated, local attacker to elevate privileges on an affected device. This vulnerability is due to insufficient validation of user-supplied commands. An attacker with vmadmin privileges could exploit this vulnerability by using certain commands at the CLI. A successful exploit could allow the attacker to elevate privileges to root. Cisco has released software updates that address this vulnerability. There…

VulnerabilitiesCVE-2026-20246
P15
2026-06-17 16:00 UTC
Vendor Research

Cisco Crosswork Network Controller Server-Side Template Injection Vulnerability

Cisco Security Advisories · indexed 2026-08-15 14:33 UTC

A vulnerability in the web-based management interface of Cisco Crosswork Network Controller could allow an authenticated, remote attacker to execute arbitrary commands on an affected device. This vulnerability is due to insufficient input validation in the configuration template engine of the web-based management interface. An attacker could exploit this vulnerability by sending a crafted request to the affected device. A successful exploit could allow the attacker to execute arbitrary commands…

VulnerabilitiesCVE-2026-20220
P5
2026-06-17 16:00 UTC
Vendor Research

Cisco Webex App Open Redirect Vulnerability

Cisco Security Advisories · indexed 2026-08-15 14:33 UTC

A vulnerability in the browser-based version of Cisco Webex App could have allowed an unauthenticated, remote attacker to redirect users to a malicious webpage. Cisco has addressed this vulnerability in the Cisco Webex App, and no customer action is needed. This vulnerability existed due to improper input validation of URL parameters in an HTTP request. Prior to this vulnerability being addressed, an attacker could have exploited this vulnerability by persuading a user to click a crafted URL. A…

VulnerabilitiesCVE-2026-20178
P5
2026-06-17 14:00 UTC
Security Journalism

Why Your Organization Needs ISPM

Huntress · indexed 2026-09-07 17:30 UTC

Huntress Managed ISPM finds and closes Microsoft 365 identity gaps before attackers do. Learn why visibility isn't enough and what real identity hardening takes.

Microsoft
P0
2026-06-17 06:57 UTC
Other

GitBait: Phishing the Mexican Financial Sector

Group-IB · indexed 2026-09-07 17:30 UTC

A modular phishing infrastructure targeting multiple Mexican banks has been uncovered, abusing GitHub-hosted Pages, employing obfuscated scripts, and featuring a centralized credential exfiltration via SheetBest API, indicating a scalable and persistent multi-brand phishing operation.

MicrosoftPhishing
P0
2026-06-16 17:39 UTC
Vendor Research

Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability

Cisco Security Advisories · indexed 2026-08-15 14:33 UTC

A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system. This vulnerability exists because the peering authentication mechanism in an affected system is not working properly. An attacker could exploit…

VulnerabilitiesCVE-2026-20127
P15
2026-06-16 17:39 UTC
Vendor Research

Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability

Cisco Security Advisories · indexed 2026-08-15 14:33 UTC

May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and fixed after the Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability was disclosed in February 2026. This new advisory is for a new vulnerability in the control connection handshaking. The Indicators of Compromise section of this advisory includes Show Control Connections guidance to help with system checks. A vulnerability in the peering authentication in Cisco …

VulnerabilitiesCVE-2026-20182
P15
2026-06-15 22:00 UTC
Vendor Research

Cisco Catalyst SD-WAN Manager Arbitrary File Write Vulnerability

Cisco Security Advisories · indexed 2026-08-15 14:33 UTC

A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system. This vulnerability exists because the affected software does not properly validate user-supplied input during a file upload process. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected API endpoint of the affected system. A successful exploit…

VulnerabilitiesCVE-2026-20262
P5
99 100 101 102 103