IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 4,438 matching records.
AUTO-POLL // 2026-10-04 10:30 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P9 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 4

RANSOMWARE
P9
P9
COOL // 5 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
FRI
Oct 2

RANSOMWARE
P7
P7
COOL // 46 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
WED
Sep 30

RANSOMWARE
P10
P10
WARM // 59 ARTICLES
TUE
Sep 29

RANSOMWARE
P4
P4
COOL // 68 ARTICLES
MON
Sep 28

RANSOMWARE
P7
P7
COOL // 52 ARTICLES
RESET
2026-09-28 15:08 UTC
Independent Research

Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation

Krebs on Security · BrianKrebs · indexed 2026-09-28 15:15 UTC

Authorities in the Netherlands have arrested a 23-year-old convicted cybercriminal on suspicion of aiding in data thefts and extortions by the prolific hacker group ShinyHunters. In the days immediately following the suspect's arrest, remaining ShinyHunters members dramatically escalated their attacks, stealing highly sensitive data from the FBI and extorting the Russian ransomware group Cl0p.

DFIRLaw EnforcementRansomwareThreat Actors
P15
2026-09-28 15:00 UTC
Vendor Research

NeedyMantis: Unpacking a post-compromise malware family used in targeted operations

Microsoft Security Blog · Microsoft Threat Intelligence · indexed 2026-09-28 16:30 UTC

Microsoft Threat Intelligence identified NeedyMantis, a modular post-compromise malware framework used in targeted intrusions that combines custom loaders, encrypted archives, and extensible components to maintain long-term access and support follow-on operations. The post NeedyMantis: Unpacking a post-compromise malware family used in targeted operations appeared first on Microsoft Security Blog.

MalwareMicrosoftThreat Intelligence
P0
2026-09-28 14:08 UTC
Other

Nearly 400,000 Medicaid Beneficiaries Caught in Medicaid and DC Healthcare Alliance Data Exposure

Security Affairs · Pierluigi Paganini · indexed 2026-09-28 14:30 UTC

Nearly 400,000 DC Medicaid and Healthcare Alliance beneficiaries may have had personal data exposed through reports published on a public website. The District of Columbia Department of Health Care Finance is notifying nearly 400,000 Medicaid and DC Healthcare Alliance beneficiaries that their personal information may have been exposed. The incident affects people who enrolled between […]

P0
2026-09-28 14:00 UTC
Security Journalism

⚡ Weekly Recap: $387M Crypto Hack, Citrix Exploits, AI Agents Go Off-Script, and More Threats

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-28 14:10 UTC

A domain used as harmless placeholder text showed up in roughly 1,700 repositories. Then somebody registered it and started serving malicious lures. That is the kind of week this was: forgotten assumptions turning into live attack surface. Elsewhere, weak service accounts, old bugs, exposed systems, phishing kits, and strangely easy exploit paths kept doing useful work for attackers. Nothing

AI SecurityPhishing
P0
2026-09-28 14:00 UTC
Security Journalism

80,000+ Organizations Had AI Logins Stolen: From Shadow AI to LLMjacking

BleepingComputer · Sponsored by SOCRadar · indexed 2026-09-28 14:10 UTC

Infostealer logs exposed AI account credentials and sessions tied to more than 80,000 corporate domains, creating risks ranging from stolen conversations to LLMjacking. SOCRadar examines the growing market for stolen AI logins and how organizations can identify their exposure. [...]

AI SecurityMalware
P0
2026-09-28 13:55 UTC
Other

28th September – Threat Intelligence Report

Check Point Research · urias@checkpoint.com · indexed 2026-09-28 14:15 UTC

For the latest discoveries in cyber research for the week of 28th September, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES The FBI has confirmed unauthorized activity affecting FBIjobs.gov after the ShinyHunters group defaced the website. The group claimed to have stolen employee and applicant information and shared samples of purported FBI personnel […] The post 28th September – Threat Intelligence Report appeared first on Check Point Research.

Law EnforcementThreat Intelligence
P0
2026-09-28 12:36 UTC
Security Journalism

Prison Sentence for Former US Soldier Who Hacked AT&T and Verizon

Security Week · Ionut Arghire · indexed 2026-09-28 12:40 UTC

Cameron John Wagenius was sentenced to 70 months in prison for stealing information from the wireless carriers. The post Prison Sentence for Former US Soldier Who Hacked AT&T and Verizon appeared first on SecurityWeek.

P0
2026-09-28 11:58 UTC
Security Journalism

Webinar: How to Govern AI Agents, Reduce Excessive Access, and Control Shadow AI

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-28 12:40 UTC

AI agents are moving into production faster than security teams can govern them. They are connecting to apps, handling data, calling APIs, and acting across business systems—often without the same controls applied to human users. According to Okta’s Global CISO Insights 2026 report, only 47% of CISOs are confident they can identify every AI agent in their environment. Even among those who feel

AI Security
P0
2026-09-28 11:46 UTC
Security Journalism

Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-28 12:40 UTC

Cybersecurity researchers have disclosed details of a new botnet malware called Carbonato that's targeting exposed Docker daemons to deploy an open-source artificial intelligence (AI) agent framework called Hermes Agent. "The implant installs the framework unchanged, then overwrites its SOUL.md persona file," ThreatDown said. "The 39-line prompt directs it to execute tasks received through

AI SecurityMalwareSecurity Research
P0
2026-09-28 11:29 UTC
Security Journalism

DC Health Agency Exposes 400,000 Beneficiary Records

Security Week · Ionut Arghire · indexed 2026-09-28 11:40 UTC

The Medicaid IDs and other information of Medicaid and DC Healthcare Alliance beneficiaries were exposed. The post DC Health Agency Exposes 400,000 Beneficiary Records appeared first on SecurityWeek.

P0
2026-09-28 10:46 UTC
Other

Storm-3168, Linked to JADEPUFFER, Abused Stolen Azure Identities

Security Affairs · Pierluigi Paganini · indexed 2026-09-28 11:00 UTC

Microsoft details Storm-3168, the JADEPUFFER-linked actor that used stolen service principals to delete Azure storage in minutes and harvest keys. Microsoft just published the first detailed look at what JADEPUFFER does inside Azure. Sysdig first spotted the group’s activity in July 2026 and called it the first documented agentic ransomware operation. Microsoft tracks the same […]

Cloud SecurityMicrosoftRansomware
P15
2026-09-28 10:40 UTC
Security Journalism

New Mexico Jury Finds Facebook Liable for Deceiving Users About Privacy Protections

Security Week · Associated Press · indexed 2026-09-28 10:40 UTC

A New Mexico jury has found Facebook liable for deceiving users about privacy protections on the platform. The post New Mexico Jury Finds Facebook Liable for Deceiving Users About Privacy Protections appeared first on SecurityWeek.

P0
2026-09-28 10:27 UTC
Security Journalism

Nvidia Unveils AI Agent Safety Platform With Hardware-Based Watchdog

Security Week · Eduard Kovacs · indexed 2026-09-28 10:40 UTC

The platform combines open source software and a reference system design to keep AI agents within set boundaries. The post Nvidia Unveils AI Agent Safety Platform With Hardware-Based Watchdog appeared first on SecurityWeek.

AI Security
P0
2026-09-28 10:05 UTC
Vendor Research

Zero-Day Exploitation of Citrix NetScaler ADC and Gateway: CVE-2026-88771 and CVE-2026-88772

Rapid7 · Rapid7 · indexed 2026-09-28 10:25 UTC

OverviewOn September 27, 2026, Citrix disclosed eight new vulnerabilities affecting NetScaler ADC and NetScaler Gateway, including two critical remote code execution (RCE) vulnerabilities: CVE-2026-88771 and CVE-2026-88772. Both of these RCE vulnerabilities carry a critical CVSSv4 score of 9.5, and both have been confirmed as being actively exploited in the wild as zero-days prior to the vendor disclosure. CVE-2026-88771 affects vulnerable NetScaler deployments in their default configuration, w…

Network SecurityThreat IntelligenceVulnerabilitiesCVE-2026-88771CVE-2026-88772CVE-2026-887729CVE-2026-887739
P95
2026-09-28 09:44 UTC
Security Journalism

Kiteworks Urges Server Shutdown, Finds Advanced Forms Vulnerability

Security Week · Ionut Arghire · indexed 2026-09-28 10:00 UTC

The company says the measure was precautionary and that it has no evidence of Kiteworks or customer systems being compromised. The post Kiteworks Urges Server Shutdown, Finds Advanced Forms Vulnerability appeared first on SecurityWeek.

Vulnerabilities
P0
2026-09-28 09:08 UTC
Security Journalism

JADEPUFFER-Linked Attackers Used Compromised Service Principals to Delete Azure Resources

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-28 10:25 UTC

The threat actor known as JADEPUFFER has been observed orchestrating destructive actions within a Microsoft Azure environment using compromised service principals. Microsoft, which is tracking the activity under the name Storm-3168, has called it an evolution of the threat actor's tradecraft. The attack took place in early June 2026 over a period of about 18 hours. "The destructive operations

Cloud SecurityMicrosoftThreat Actors
P0
2026-09-28 08:55 UTC
Other

U.S. CISA adds Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog

Security Affairs · Pierluigi Paganini · indexed 2026-09-28 09:40 UTC

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2026-88771 (CVSS score: 9.5) is a remote code execution vulnerability caused by improper input validation that could allow an unauthenticated remote […]

Cloud SecurityVulnerabilitiesCVE-2026-88771
P50
2026-09-28 07:30 UTC
Security Journalism

US soldier gets 70 months in prison for extorting 10 tech, telecom firms

BleepingComputer · Sergiu Gatlan · indexed 2026-09-28 07:45 UTC

A former U.S. Army soldier has been sentenced to 70 months in prison for hacking and extorting at least 10 U.S. technology and telecommunications companies between April 2023 and December 2024. [...]

P0
2026-09-28 07:21 UTC
Security Journalism

CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-28 10:25 UTC

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Sunday added two critical Citrix NetScaler ADC and Gateway flaws to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation. The vulnerabilities are listed below - CVE-2026-88771 (CVSS score: 9.5) - An improper input validation vulnerability that could allow an unauthenticated attacker to

Cloud SecurityVulnerabilitiesCVE-2026-88771
P35
2026-09-28 06:24 UTC
Security Journalism

CISA orders feds to patch exploited Citrix flaws by Wednesday

BleepingComputer · Sergiu Gatlan · indexed 2026-09-28 06:35 UTC

The Cybersecurity and Infrastructure Security Agency (CISA) has ordered U.S. government agencies over the weekend to secure their systems against attacks exploiting two critical Citrix NetScaler vulnerabilities. [...]

Cloud Security
P0
2026-09-28 05:50 UTC
Other

Roundcube SQL injection CVE-2026-48842 is now being exploited in the wild

Security Affairs · Pierluigi Paganini · indexed 2026-09-28 06:30 UTC

Roundcube SQL injection CVE-2026-48842 is now being exploited in the wild, putting unpatched webmail servers at risk of database compromise. A Roundcube Webmail vulnerability, tracked as CVE-2026-48842 (CVSS score of 8.1) and patched four months ago, is now being exploited in the wild. The Canadian Centre for Cyber Security added the warning to its advisory […]

VulnerabilitiesCVE-2026-48842
P25
9 10 11 12 13