IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 4,555 matching records.
AUTO-POLL // 2026-10-07 02:40 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P0 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 7

CLEAR
P0
P0
COOL // 2 ARTICLES
TUE
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
FRI
Oct 2

RANSOMWARE
P7
P7
COOL // 46 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
RESET
2026-05-06 16:00 UTC
Vendor Research

Cisco Slido Insecure Direct Object Reference Vulnerability

Cisco Security Advisories · indexed 2026-08-15 14:33 UTC

A vulnerability in the REST API of Cisco Slido could have allowed an authenticated, remote attacker to access the social profile data of other users or affect quiz and poll results. Cisco has addressed this vulnerability in Cisco Slido and no customer action is needed. This vulnerability existed because of the presence of an insecure direct object reference. Prior to this vulnerability being addressed, an attacker could have exploited this vulnerability by sending a crafted request to the vulne…

VulnerabilitiesCVE-2026-20219
P5
2026-05-06 16:00 UTC
Vendor Research

Cisco IoT Field Network Director Vulnerabilities

Cisco Security Advisories · indexed 2026-08-15 14:33 UTC

Multiple vulnerabilities in the web-based management interface of Cisco IoT Field Network Director Software could allow an authenticated, remote attacker to access files, execute commands, and cause denial of service (DoS) conditions on managed routers. For more information about these vulnerabilities, see the Details section of this advisory. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities. This advisory is ava…

Network SecurityVulnerabilitiesCVE-2026-20167CVE-2026-20168CVE-2026-20169
P5
2026-05-06 16:00 UTC
Vendor Research

Cisco SG350 and SG350X Series Managed Switches SNMP Denial of Service Vulnerability

Cisco Security Advisories · indexed 2026-08-15 14:33 UTC

A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco 350 Series Managed Switches (SG350) and Cisco 350X Series Stackable Managed Switches (SG350X) firmware could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper error handling when parsing response data for a specific SNMP request. An attacker could exploit this vulnerability by sending a specific SNMP request to an aff…

DFIRNetwork SecurityVulnerabilitiesCVE-2026-20185
P5
2026-05-06 08:44 UTC
Government

2026-006: Critical Vulnerability in PAN-OS

CERT-EU Security Advisories · indexed 2026-08-15 18:50 UTC

On 6 May 2026, Palo Alto published a security advisory addressing a critical vulnerability affecting PAN-OS. This vulnerability allows an unauthenticated attacker to execute arbitrary code with root privileges. Palo Alto observed limited exploitation of this vulnerability. It is strongly recommended updating affected appliances as soon as patches will be available, and to apply workarounds and mitigation in the meantime.

Network SecurityVulnerabilities
P10
2026-05-04 15:00 UTC
Government

Cyber Brief 26-05 - April 2026

CERT-EU Threat Intelligence · indexed 2026-08-15 18:50 UTC

Cyber Briefs are monthly executive reports that aim to present an overview of the most relevant developments in cyber security, based exclusively on open sources, with a view to inform political leadership and senior management in its constituency. Additional information on any item in this Brief can be provided upon request. Cyber Briefs are TLP:CLEAR.

P0
2026-05-04 12:00 UTC
Government

Stronger Cybersecurity, Stronger Business: NIST Celebrates 2026 National Small Business Week

NIST Cybersecurity Insights · Daniel Eliot · indexed 2026-08-15 20:45 UTC

Happy National Small Business Week! For over 60 years, the U.S. Small Business Administration has led this initiative to acknowledge the critical contributions of America’s entrepreneurs and small business owners. Part of the U.S. Department of Commerce, NIST’s mission is to drive U.S. innovation and global competitiveness, and the small business community is central to this mission. In this year’s blog, we shine a spotlight on some new and upcoming NIST resources that are all focused on streng…

Microsoft
P0
2026-04-30 13:00 UTC
Security Journalism

ClickFix Removes Your Background but Leaves the Malware

Huntress · indexed 2026-09-07 17:30 UTC

Your background is gone, but malware is here. Huntress breaks down BackgroundFix, a new ClickFix social engineering tactic involving CastleLoader, NetSupport RAT, and CastleStealer. Read the analysis.

Malware
P0
2026-04-30 09:25 UTC
Government

2026-005: High Vulnerability in the Linux Kernel ("Copy Fail")

CERT-EU Security Advisories · indexed 2026-08-15 18:50 UTC

On 29 April 2026, a high local privilege escalation vulnerability in the Linux kernel, tracked as CVE-2026-31431 and named "Copy Fail", was publicly disclosed. The vulnerability affects every mainstream Linux distributions shipping a kernel built since 2017. A public proof-of-concept exploit has been released. As of the date of this advisory, no distribution has shipped a fixed kernel package. The mainline fix was committed on 1 April 2026, but vendor updates are still pending across all major …

Cloud SecurityLinuxVulnerabilitiesCVE-2026-31431
P15
2026-04-30 09:00 UTC
Other

This month in security with Tony Anscombe – April 2026 edition

ESET · indexed 2026-09-07 17:30 UTC

Warnings about helpdesk impersonation scams and Iran-linked hackers targeting critical sectors in the US, plus the most damaging scams of 2025 - here's some of what made the headlines this month

P0
2026-04-29 06:54 UTC
Other

Phoenix Rising: Exposing the PhaaS Kit Behind Global Mass Phishing Campaigns

Group-IB · indexed 2026-09-07 17:30 UTC

While analyzing global smishing operations spanning APAC, LATAM, Europe, and MEA, Group-IB researchers uncovered the 'Phoenix System' administrative panel, a centralized Phishing-as-a-Service (PhaaS) platform with real-time victim monitoring, geofencing, and live-phishing interventions to bypass multi-factor authentication.

MicrosoftPhishing
P0
2026-04-28 12:00 UTC
Government

From DMV to Wallet: Understanding Verifiable Digital Credential Issuance

NIST Cybersecurity Insights · Bill Fisher, Ryan Galluzzo, Heather Flanagan · indexed 2026-08-15 20:45 UTC

In our last post in this series, we compared two credential formats that shape the digital identity ecosystem: ISO/IEC 18013-5 and -7 mobile documents (mdocs) and W3C Verifiable Credentials (VCs). Both formats define how a credential is structured and shared, but neither can function without an issuance process. This blog post explores what it takes to issue verifiable digital credentials, with a focus on mobile driver’s licenses (mDLs). We’ll look at how issuance works today in practice, where…

P0
2026-04-23 21:38 UTC
Vendor Research

AI threats in the wild: The current state of prompt injections on the web

Google Online Security Blog · Kimberly Samra · indexed 2026-08-15 14:33 UTC

Posted by Thomas Brunner, Yu-Han Liu, Moni PandeAt Google, our Threat Intelligence teams are dedicated to staying ahead of real-world adversarial activity, proactively monitoring emerging threats before they can impact users. Right now, Indirect Prompt Injection (IPI) is a top priority for the security community, anticipating it as a primary attack vector for adversaries to target and compromise AI agents. But while the danger of IPI is widely discussed, are threat actors actually exploiting th…

AI SecurityMicrosoftSecurity ResearchThreat ActorsThreat Intelligence
P20
2026-04-23 14:00 UTC
Vendor Research

Snow Flurries: How UNC6692 Employed Social Engineering to Deploy a Custom Malware Suite

Google Threat Intelligence / Mandiant · Mandiant · indexed 2026-08-15 18:55 UTC

Written by: JP Glab, Tufail Ahmed, Josh Kelley, Muhammad Umair Introduction Google Threat Intelligence Group (GTIG) identified a multistage intrusion campaign by a newly tracked threat group, UNC6692, that leveraged persistent social engineering, a custom modular malware suite, and deft pivoting inside the victim’s environment to achieve deep network penetration. As with many other intrusions in recent years, UNC6692 relied heavily on impersonating IT helpdesk employees, convincing their victim…

Cloud SecurityMalwareMicrosoftPhishingThreat ActorsThreat Intelligence
P0
2026-04-22 20:00 UTC
Security Journalism

What Cybersecurity Leaders Must Prioritize in 2026

Huntress · indexed 2026-09-07 17:30 UTC

The threat landscape has shifted. Here's what cybersecurity leaders need to know about RMM abuse, AI-powered attacks, ransomware, and identity threats in 2026.

Ransomware
P15
104 105 106 107 108