IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 4,439 matching records.
AUTO-POLL // 2026-10-04 11:15 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P8 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 4

RANSOMWARE
P8
P8
COOL // 6 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
FRI
Oct 2

RANSOMWARE
P7
P7
COOL // 46 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
WED
Sep 30

RANSOMWARE
P10
P10
WARM // 59 ARTICLES
TUE
Sep 29

RANSOMWARE
P4
P4
COOL // 68 ARTICLES
MON
Sep 28

RANSOMWARE
P7
P7
COOL // 52 ARTICLES
RESET
2026-09-27 17:40 UTC
Government

2026-014: Critical Vulnerabilities in Citrix NetScaler ADC and Gateway

CERT-EU Security Advisories · indexed 2026-09-27 18:00 UTC

On 27 September 2026, Citrix published a security bulletin addressing 8 vulnerabilities affecting customer-managed Citrix NetScaler ADC and Citrix NetScaler Gateway, among which 2 critical unauthenticated Remote Code Execution (RCE) vulnerabilities. Citrix has confirmed active exploitation of these 2 critical vulnerabilities in the wild. CERT-EU recommends updating affected software and running a compromise assessment on those exposed on the internet.

Vulnerabilities
P35
2026-09-27 17:29 UTC
Other

Citrix Confirmed Two New NetScaler Flaws Exploited as Zero-Day

Security Affairs · Pierluigi Paganini · indexed 2026-09-27 18:10 UTC

Citrix confirmed two critical NetScaler zero-days were exploited before patches were available, with attackers able to remotely execute code. Citrix confirmed that two critical zero-day vulnerabilities in NetScaler ADC and NetScaler Gateway were exploited before the company released patches. The flaws allow remote code execution, meaning attackers can potentially take control of affected appliances. The […]

Cloud SecurityVulnerabilities
P40
2026-09-27 15:26 UTC
Other

SECURITY AFFAIRS AI-CYBERSECURITY NEWSLETTER ROUND 1

Security Affairs · Pierluigi Paganini · indexed 2026-09-27 15:35 UTC

Security Affairs AI-CYBERSECURITY newsletter includes a collection of the best articles and research on AI in the international landscape Artificial intelligence is rapidly changing cybersecurity, reshaping both the techniques used by attackers and the tools available to defenders. AI agents can automate tasks, analyze large amounts of data, discover vulnerabilities and accelerate offensive operations. At […]

AI SecurityMicrosoft
P0
2026-09-27 15:05 UTC
Other

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 116

Security Affairs · Pierluigi Paganini · indexed 2026-09-27 15:35 UTC

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Threat Intel | One Kit, Forty Companies: How a Malware-as-a-Service Platform Used GitHub as a Distribution Network for its Campaign Group Policy hijacked: PAYLOAD ransomware weaponizes Active Directory GPO ChainScript: Tracing a Node.js RAT […]

MalwareRansomware
P15
2026-09-27 13:40 UTC
Other

Security Affairs newsletter Round 597 by Pierluigi Paganini – INTERNATIONAL EDITION

Security Affairs · Pierluigi Paganini · indexed 2026-09-27 14:40 UTC

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. OpenAI Agents Accessed US Government Websites Without Authorization Exploit.in Database Reveals the Roots of Today’s Ransomware Ecosystem […]

AI SecurityRansomware
P15
2026-09-27 09:27 UTC
Other

Rydox Admin Faces 20 Years After Selling Stolen Data and Fraud Tools

Security Affairs · Pierluigi Paganini · indexed 2026-09-27 09:40 UTC

Kosovo national Ardit Kutleshi pleaded guilty to running Rydox, a cybercrime marketplace that sold stolen identities and credentials for years. Ardit Kutleshi, 28 years old and a citizen of Kosovo, pleaded guilty last week to building and running the cybercrime marketplace Rydox. The Rydox marketplace has been active since February 2016; it facilitated over 7,600 […]

CybercrimeData Breaches
P0
2026-09-27 07:47 UTC
Security Journalism

Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-27 08:15 UTC

Two critical vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway that allow remote code execution have been exploited in the wild, Citrix confirmed on September 27. It released fixes for both, along with six other flaws. One of the two affects every deployment on an affected version, including those in the default configuration. The bulletin came a day after security firm watchTowr

Cloud SecurityVulnerabilities
P60
2026-09-27 05:35 UTC
Vendor Research

Frequently asked questions about reported Citrix NetScaler zero-day vulnerabilities

Tenable Blog · Satnam Narang · indexed 2026-09-27 10:00 UTC

CVE-2026-88771 and CVE-2026-88772, two zero-day vulnerabilities in Citrix NetScaler, have been confirmed as exploited in the wild. Citrix released patches on September 27, 2026.Change logUpdate September 27: Citrix published security bulletin CTX697096, confirming CVE-2026-88771 and CVE-2026-88772 as the two zero-day RCE vulnerabilities and releasing patches. Post updated with CVE IDs, CVSS scores, patch versions, and IoC guidance.Click here to review the change log historyUpdate September 27: …

APT / Nation-StateCloud SecurityNetwork SecurityRansomwareThreat ActorsThreat IntelligenceVulnerabilitiesCVE-2023-6549CVE-2025-6543CVE-2026-19489CVE-2026-19490CVE-2026-88771CVE-2026-88772
P95
2026-09-26 18:22 UTC
Security Journalism

Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-26 19:05 UTC

The Psychedelic Stealer malware distributed via compromised Ukrainian websites using ClickFix-style Cloudflare verification checks is part of a wider malware-as-a-service (MaaS) platform called Lunex. The new findings come from Ontinue, which described the activity as a four-stage attack chain aimed at targeting Ukrainian-speaking users. "The attack chain begins with a fake CAPTCHA page and

Malware
P0
2026-09-26 16:26 UTC
Security Journalism

Claude Opus 5.5 uses 95% fewer em dashes, but its answers are getting longer

BleepingComputer · Mayank Parmar · indexed 2026-09-26 16:35 UTC

Anthropic's Claude Opus 5.5 appears to be changing how it writes, with new analysis showing fewer obvious AI writing patterns, shorter sentences, and simpler wording compared with Opus 5. [...]

P0
2026-09-26 15:50 UTC
Security Journalism

Microsoft pauses KB5002907 update after Office license deactivations

BleepingComputer · Lawrence Abrams · indexed 2026-09-26 15:55 UTC

Microsoft has paused the rollout of the KB5002907 Microsoft 365 update after users report that it deactivated, or in some cases completely removed, perpetual Office 2016 and Office 2019 installations. [...]

Microsoft
P0
2026-09-26 15:41 UTC
Other

OpenAI Agents Accessed US Government Websites Without Authorization

Security Affairs · Pierluigi Paganini · indexed 2026-09-26 17:00 UTC

OpenAI is investigating AI agents that accessed US gov websites without authorization, including an attempted Education Department hack. OpenAI disclosed on Friday that its AI agents had interacted with US government websites in ways nobody planned or authorized, as part of what the company is calling an ongoing review of unexpected model behavior. The affected […]

AI Security
P0
2026-09-26 14:34 UTC
Other

Exploit.in Database Reveals the Roots of Today’s Ransomware Ecosystem

Security Affairs · Pierluigi Paganini · indexed 2026-09-26 15:40 UTC

Exploit.in data shows how a 2005 cybercrime forum helped shape today’s ransomware ecosystem, with users and practices surviving for decades. Ransomnews researcher Dancho Danchev dug up a database dump of Exploit.in covering its first three years, from February 2005 to May 2008, and the numbers inside it tell a story about Russian cybercrime that enforcement […]

CybercrimeRansomware
P15
2026-09-26 14:19 UTC
Security Journalism

GitHub Actions re-enabled with Mini Shai-Hulud payload still active

BleepingComputer · Bill Toulas · indexed 2026-09-26 14:40 UTC

Two third-party GitHub Actions previously compromised in a Mini Shai-Hulud campaign were re-enabled by their maintainer and remained accessible for more than a week despite still pointing to malicious code. [...]

P0
2026-09-26 12:00 UTC
Security Journalism

New x47.c Windows Botnet Weaponizes xAI Grok, AI API Draining

Security Week · Ionut Arghire · indexed 2026-09-26 12:10 UTC

The Windows botnet relies on AI to maintain persistence, using xAI Grok to choose from predefined actions. The post New x47.c Windows Botnet Weaponizes xAI Grok, AI API Draining appeared first on SecurityWeek.

MalwareMicrosoft
P0
2026-09-26 11:46 UTC
Security Journalism

Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-26 14:20 UTC

Google is warning of renewed mass exploitation of a known security vulnerability in Oracle PeopleSoft as part of a campaign targeting multiple sectors globally. The ShinyHunters-linked activity involves the weaponization of CVE-2026-35273 (CVSS score: 9.8), a critical security flaw that could result in unauthenticated remote code execution. The vulnerability was first exploited as a zero-day

VulnerabilitiesCVE-2026-35273
P65
2026-09-26 10:30 UTC
Security Journalism

Zero Trust for AI Agents Starts With Fixing Zero Visibility

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-26 14:20 UTC

The way we talk about AI agents is shifting, and the way we implement them requires an even more fundamental shift. While earlier discourse focused on how quickly organizations could stand up agents and how much productivity they could promise, a string of recent incidents, including a widely discussed intrusion at Hugging Face during an evaluation of OpenAI agents, has spurred organizations to

AI Security
P0
2026-09-26 10:15 UTC
Security Journalism

OpenAI Says Its Models Engaged With US Government Websites in New Model Misbehavior Disclosure

Security Week · Associated Press · indexed 2026-09-26 10:30 UTC

OpenAI’s CEO said there is an “extensive and ongoing review related to our agents’ use of internet access during training and evaluation.” The post OpenAI Says Its Models Engaged With US Government Websites in New Model Misbehavior Disclosure appeared first on SecurityWeek.

P0
2026-09-26 09:55 UTC
Security Journalism

Elementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-26 10:05 UTC

Details have emerged about a high-severity security flaw in the Elementor Website Builder WordPress plugin that could be exploited by an unauthenticated attacker to create rogue administrator accounts and take control of a site. The cross-site request forgery (CSRF) vulnerability, which has yet to be assigned a CVE identifier, carries a CVSS score of 8.8 out of 10.0. It only affects versions

Vulnerabilities
P0
2026-09-26 08:49 UTC
Security Journalism

SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-26 10:05 UTC

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added two security flaws impacting Microsoft SharePoint and Mikrotik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerabilities in question are as follows - CVE-2026-65660 (CVSS score: 8.8) - A code injection vulnerability in Microsoft Office SharePoint

Cloud SecurityMicrosoftNetwork SecurityVulnerabilitiesCVE-2026-65660
P95
2026-09-26 07:48 UTC
Security Journalism

Kiteworks Urges Customers to Shut Down Systems for 9 Hours Over Possible Cyber Attack

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-26 10:05 UTC

Kiteworks (formerly Accellion) is urging customers to shut down their systems as a precautionary measure for nine hours over the weekend after it received threat intelligence about an imminent cyber attack. "Kiteworks received credible threat intelligence from federal intelligence authorities indicating that a threat actor may attempt to target some Kiteworks systems," said Frank Balonis, Chief

Threat ActorsThreat Intelligence
P0
10 11 12 13 14