IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 4,439 matching records.
AUTO-POLL // 2026-10-04 13:55 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P8 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 4

RANSOMWARE
P8
P8
COOL // 6 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
FRI
Oct 2

RANSOMWARE
P7
P7
COOL // 46 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
WED
Sep 30

RANSOMWARE
P10
P10
WARM // 59 ARTICLES
TUE
Sep 29

RANSOMWARE
P4
P4
COOL // 68 ARTICLES
MON
Sep 28

RANSOMWARE
P7
P7
COOL // 52 ARTICLES
RESET
2026-09-23 12:17 UTC
Security Journalism

Honeywell: OT Security Teams Embrace AI, but Autonomy Still Rare

Security Week · Eduard Kovacs · indexed 2026-09-23 12:30 UTC

Only 21% of industrial security leaders report a complete OT asset inventory, even as 88% call their programs mature. The post Honeywell: OT Security Teams Embrace AI, but Autonomy Still Rare appeared first on SecurityWeek.

P0
2026-09-23 12:16 UTC
Security Journalism

New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-23 12:40 UTC

A flaw in cPanel's CalDAV and CardDAV service lets anyone with a cPanel hosting account run code as root and take "full control of the server," the company said on September 22. A second bug in the WP Toolkit plugin, used to install and manage WordPress sites, allows an account holder to change databases that belong to other accounts. cPanel has released fixed versions for both,

P0
2026-09-23 11:47 UTC
Security Journalism

545 Hackers Tested It First. Now XRanges for AI Scores Your Security Agent

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-23 12:40 UTC

Autonomous security agents are getting good at finding bugs. Nobody has a good way to measure how good. Point one at a realistic target and what comes back is a report the agent wrote about itself: confident prose, a list of findings, and no way to tell which of them happened. Someone with a security background then sits down and checks every claim against the target. Which findings are real,

P0
2026-09-23 11:47 UTC
Security Journalism

Anthropic and OpenAI Models Still Attempt Restricted Actions in Safety Tests

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-23 12:40 UTC

Anthropic and OpenAI on Tuesday announced new models, with both artificial intelligence (AI) companies noting that they are continuing to invest in improving alignment to combat risky behavior. Opus 5.5, per Anthropic, is a "major step up from Opus 5," and "achieves the best scores of any model to date on our automated behavioral audit, our alignment suite that tests Claude across thousands

AI Security
P0
2026-09-23 11:12 UTC
Security Journalism

Exploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container Escape

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-23 12:40 UTC

A use-after-free in the Linux kernel's AF_UNIX socket subsystem can be used to escape a container and gain root on the host, security firm DepthFirst said in research published September 22. The flaw, tracked as CVE-2026-80521 (CVSS score: 7.8), was fixed upstream on August 6, but Ubuntu has not shipped the patch for its 26.04, 24.04, or 22.04 LTS releases. DepthFirst

LinuxVulnerabilitiesCVE-2026-80521
P5
2026-09-23 11:00 UTC
Other

EvilTokens made phishing-as-a-service look easy. Then it got taken down

Security Affairs · Pierluigi Paganini · indexed 2026-09-23 11:10 UTC

Microsoft, Coinbase and law enforcement took down EvilTokens, a phishing kit that compromised 12,000 inboxes through device-code phishing and AI. EvilTokens showed up in February 2026 and moved fast. Within months it had compromised more than 12,000 inboxes across over 10,000 organizations. Microsoft says the EvilTokens platform, operated by Storm-2992, is a phishing-as-a-service kit sold […]

MicrosoftPhishing
P0
2026-09-23 10:36 UTC
Security Journalism

Chrome 154 Patches 108 Vulnerabilities

Security Week · Ionut Arghire · indexed 2026-09-23 10:50 UTC

The browser update resolves several critical-severity memory safety and memory corruption flaws. The post Chrome 154 Patches 108 Vulnerabilities appeared first on SecurityWeek.

Cloud Security
P0
2026-09-23 10:20 UTC
Security Journalism

A Look at AI Doomsday Scenarios That Researchers Say Could Put Humanity at Risk

Security Week · Associated Press · indexed 2026-09-23 10:30 UTC

Debates over the plausibility of these doomsday scenarios have heated up since several executives endorsed slowing the technology’s development for safety reasons. The post A Look at AI Doomsday Scenarios That Researchers Say Could Put Humanity at Risk appeared first on SecurityWeek.

Apple
P0
2026-09-23 10:00 UTC
Security Journalism

Outerlimit Raises $16 Million to Stop Rogue AI Agents From Causing Harm

Security Week · Kevin Townsend · indexed 2026-09-23 10:10 UTC

Emerging from stealth with $16 million in pre-seed funding, Outerlimit offers a decentralized authorization layer designed to discover, observe, and block harmful autonomous AI actions. The post Outerlimit Raises $16 Million to Stop Rogue AI Agents From Causing Harm appeared first on SecurityWeek.

AI SecurityMicrosoft
P0
2026-09-23 08:43 UTC
Vendor Research

CVE-2026-94127: Critical Unauthenticated RCE in F5 BIG-IP APM

Rapid7 · Rapid7 · indexed 2026-09-23 09:30 UTC

OverviewOn September 22, 2026, F5 published a security advisory for CVE-2026-94127, a critical heap-based buffer overflow vulnerability affecting F5 BIG-IP Access Policy Manager (APM). The vulnerability has a CVSS v3.1 score of 9.8. An unauthenticated attacker with network access to an affected virtual server may be able to achieve remote code execution (RCE) by sending specifically crafted traffic.BIG-IP APM provides identity-aware access control for applications and other corporate resources …

Security ResearchVulnerabilitiesCVE-2026-94127
P50
2026-09-23 08:33 UTC
Security Journalism

Arista Urges Immediate Patching of Exploited VCO Zero-Day

Security Week · Ionut Arghire · indexed 2026-09-23 08:50 UTC

Remote attackers could trigger the critical-severity flaw to access privileged internal functionality. The post Arista Urges Immediate Patching of Exploited VCO Zero-Day appeared first on SecurityWeek.

Vulnerabilities
P25
2026-09-23 08:29 UTC
Security Journalism

F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-23 08:45 UTC

Attackers are exploiting a critical flaw in F5 BIG-IP Access Policy Manager (APM) that lets them run code on a BIG-IP system without logging in, F5 says. The flaw, CVE-2026-94127, affects only systems in which APM serves as an OAuth authorization server, issuing access tokens to applications. F5 disclosed it in an advisory on September 22 and has released engineering hotfixes.

VulnerabilitiesCVE-2026-94127
P55
2026-09-23 08:29 UTC
Security Journalism

Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-23 08:45 UTC

A Chinese threat actor codenamed UTA0565 has been observed exploiting the recently disclosed Google Chrome-Microsoft Windows exploit chain as zero-days through fake websites. The attacks, detected on September 3 and 4, 2026, involved the chaining of two vulnerabilities in Chrome (CVE-2026-85046, CVE-2026-87491) and one impacting Windows Advanced Local Procedure Call (CVE-2026-85880) to break

MalwareMicrosoftThreat ActorsVulnerabilitiesCVE-2026-85046CVE-2026-85880CVE-2026-87491
P30
2026-09-23 08:25 UTC
Other

Fake LastPass on GitHub Led to an Infostealer That Killed 145 Security Tools

Security Affairs · Pierluigi Paganini · indexed 2026-09-23 08:50 UTC

Attackers spoofed LastPass on GitHub, used a Microsoft-signed driver to disable 145 security products, then deployed an infostealer. Someone impersonated LastPass on GitHub, got users to download a fake authenticator, and ended up killing 145 different antivirus and EDR products using a driver that Microsoft itself had signed. That last part is the one worth […]

MalwareMicrosoft
P0
2026-09-23 08:20 UTC
Security Journalism

Ryuk ransomware member sentenced to 24 months in prison

BleepingComputer · Sergiu Gatlan · indexed 2026-09-23 08:30 UTC

An Armenian man was sentenced to 24 months in prison and 3 years of supervised release for hacking U.S. companies and encrypting their systems in Ryuk ransomware attacks. [...]

Ransomware
P15
2026-09-23 07:36 UTC
Other

CVE-2026-87902: how close is your WordPress to remote code execution?

Security Affairs · Pierluigi Paganini · indexed 2026-09-23 07:50 UTC

WordPress 7.1.2 fixes an unauthenticated file inclusion bug active since version 4.7, patchable but exploitable into remote code execution. WordPress 7.1.2 shipped on September 22 address an unauthenticated local file inclusion, tracked as CVE-2026-87902 (CVSS score of 9.2), which stems of how the CMS resolves page templates, with a real path to remote code execution. […]

VulnerabilitiesCVE-2026-87902
P20
2026-09-23 07:34 UTC
Security Journalism

Critical F5 BIG-IP Vulnerability Exploited as Zero-Day

Security Week · Ionut Arghire · indexed 2026-09-23 07:50 UTC

Unauthenticated attackers could send malicious traffic to BIG-IP to achieve remote code execution. The post Critical F5 BIG-IP Vulnerability Exploited as Zero-Day appeared first on SecurityWeek.

Vulnerabilities
P40
2026-09-23 07:04 UTC
Security Journalism

Critical Next.js ImageResponse Flaw Can Lead to Server Code Execution via Crafted SVG Input

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-23 07:35 UTC

A new security vulnerability in Next.js could allow attackers to run code on a server via ImageResponse, the feature that generates Open Graph and other social preview images, Vercel said. The risk applies when an app puts values an attacker controls, such as text read from the request URL, into the image. Vercel, which develops Next.js, fixed the flaw on September 22 in version

Vulnerabilities
P0
2026-09-23 06:14 UTC
Security Journalism

Check Point Patches Exploited Management Server Zero-Day

Security Week · Ionut Arghire · indexed 2026-09-23 06:15 UTC

The critical-severity flaw could allow unauthenticated attackers to upload and execute arbitrary scripts. The post Check Point Patches Exploited Management Server Zero-Day appeared first on SecurityWeek.

Vulnerabilities
P25
2026-09-23 05:30 UTC
Security Journalism

ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-23 06:40 UTC

The cyber extortion group known as ShinyHunters on Tuesday claimed it had breached the U.S. Federal Bureau of Investigation and stolen data belonging to current and former employees at the agency. "We have compromised the FBI. We hold very sensitive data on almost ALL FBI Agents and individuals who filed an application with the FBI for a job," the group said in a statement posted on their dark

Data BreachesDFIRLaw Enforcement
P0
2026-09-23 05:00 UTC
Other

ZDI-26-748: Luxion KeyShot BIP File Parsing Uncontrolled Search Path Element Remote Code Execution Vulnerability

Zero Day Initiative · indexed 2026-09-23 22:30 UTC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Luxion KeyShot. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-92202.

VulnerabilitiesCVE-2026-92202
P20
2026-09-23 05:00 UTC
Other

ZDI-26-747: Wireshark RF4CE Packet Parsing Buffer Overflow Remote Code Execution Vulnerability

Zero Day Initiative · indexed 2026-09-23 22:30 UTC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Wireshark. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-96417.

VulnerabilitiesCVE-2026-96417
P20
16 17 18 19 20