IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 4,433 matching records.
AUTO-POLL // 2026-10-04 07:25 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
NO DATA
NO INTELLIGENCE AGGREGATED TODAY
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 4
NO DATA
--
NO INTEL
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
FRI
Oct 2

RANSOMWARE
P7
P7
COOL // 46 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
WED
Sep 30

RANSOMWARE
P10
P10
WARM // 59 ARTICLES
TUE
Sep 29

RANSOMWARE
P4
P4
COOL // 68 ARTICLES
MON
Sep 28

RANSOMWARE
P7
P7
COOL // 52 ARTICLES
RESET
2026-10-02 15:51 UTC
Security Journalism

Is It Fair to Blame 'Rogue' AI for Security Failures?

Dark Reading · Alexander Culafi · indexed 2026-10-02 16:00 UTC

"Rogue AI" terminology anthropomorphizes LLMs and shifts risk responsibility from vendors. Defenders should treat agents as untrusted, nondeterministic software systems, not sentient beings with malicious intent.

AI SecurityMicrosoft
P0
2026-10-02 15:20 UTC
Security Journalism

US sanctions Tren de Aragua gang members in ATM hacks crackdown

BleepingComputer · Sergiu Gatlan · indexed 2026-10-02 15:25 UTC

The U.S. Treasury Department has sanctioned eight members of the Venezuelan gang Tren de Aragua (TdA) for their role in the theft of millions of dollars in ATM jackpotting attacks across the United States. [...]

P0
2026-10-02 15:00 UTC
Government

Cyber Brief 26-10 - September 2026

CERT-EU Threat Intelligence · indexed 2026-10-02 13:15 UTC

Cyber Briefs are monthly executive reports that aim to present an overview of the most relevant developments in cyber security, based exclusively on open sources, with a view to inform political leadership and senior management in its constituency. Additional information on any item in this Brief can be provided upon request. Cyber Briefs are TLP:CLEAR.

P0
2026-10-02 14:30 UTC
Security Journalism

In Other News: $15K iCloud Spoofing Bugs, AI Policy Experts Phished, Adblocker Spies on AI Chats

Security Week · SecurityWeek News · indexed 2026-10-02 14:30 UTC

Noteworthy stories that might have slipped under the radar: Kiteworks patches over 100 vulnerabilities, Microsoft publishes 2026 Digital Defense Report, AI finds 24 Android app flaws. The post In Other News: $15K iCloud Spoofing Bugs, AI Policy Experts Phished, Adblocker Spies on AI Chats appeared first on SecurityWeek.

Cloud SecurityMicrosoftMobile SecurityPhishing
P0
2026-10-02 14:19 UTC
Other

AI Agents Attempt SQL Injection While Searching Government Data

Security Affairs · Pierluigi Paganini · indexed 2026-10-02 15:10 UTC

AI agents probing US and Canadian government sites made SQL injection attempts while seeking data, but investigators found no evidence of compromise. Autonomous AI agents, working on what looks like ordinary data retrieval tasks, ended up throwing basic hacking attempts at a U.S. Department of Education site and Library and Archives Canada. Nobody told them […]

AI Security
P0
2026-10-02 14:00 UTC
Security Journalism

The EDR blind spot: 3 ways browser attacks evade endpoint telemetry

BleepingComputer · Sponsored by NordLayer Browser · indexed 2026-10-02 14:15 UTC

Browser-based attacks can steal sessions, abuse extensions, or manipulate users without creating the endpoint artifacts EDR is designed to detect. NordLayer explains three ways attacks can evade endpoint telemetry and why browser-level controls can help close the gap. [...]

P0
2026-10-02 14:00 UTC
Security Journalism

Vulnerability Backlogs Are an Ownership Problem

Dark Reading · Nishant Sharma · indexed 2026-10-02 14:05 UTC

Organizations don't need better vulnerability scanners; they need to know who owns their assets and has the authority and capacity to actually fix them.

Vulnerabilities
P0
2026-10-02 13:15 UTC
Security Journalism

macOS Users Targeted by Fake Zoom Installer Carrying CloudSyncD Backdoor

Security Week · Kevin Townsend · indexed 2026-10-02 13:30 UTC

The dropper “carries a complete universal Mach-O inside itself, roughly 756 KB in the development build, and extracts it at runtime. The post macOS Users Targeted by Fake Zoom Installer Carrying CloudSyncD Backdoor appeared first on SecurityWeek.

AppleMalware
P0
2026-10-02 13:00 UTC
Vendor Research

Follow the thread: a new dashboard to investigate account abuse

Cloudflare Security · Nicole Justus · indexed 2026-10-02 13:30 UTC

Fraudsters are increasingly using AI to bypass stateless security checks. Cloudflare's new Account Abuse Protection dashboard uses stateful analysis and edge-generated Hashed User IDs to help teams investigate and block account abuse.

Cybercrime
P0
2026-10-02 13:00 UTC
Vendor Research

SMTP is the key: BPFDoor and AVERAT hitting the network edge

Rapid7 · Rapid7 Intelligence · indexed 2026-10-02 13:30 UTC

OverviewRapid7 tracked a set of Linux samples that blend into the software and device conventions of the telecom environments they target. The set spans a newly observed BPFDoor variant, a BPF Rekoobe build seen against South Korean targets, a dropper, and six builds of a Linux implant we track as AVERAT, deployed against Taiwanese appliances. Additionally, we provide source code details of the Rapid7 BPFDoor controller introduced in our April 2026 blog, Stealthy BPFDoor Variants are a Needle T…

LinuxMalwareNetwork Security
P0
2026-10-02 12:23 UTC
Security Journalism

OpenAI Parts Ways With Three Safety Researchers Over Sensitive Information Mishandling

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-02 12:45 UTC

OpenAI has parted ways with three members of its safety team after they leaked private information in violation of company policies, The Wall Street Journal reported. "We have parted ways with three individuals for violating our policies on accessing and handling sensitive company information," a spokesperson for the company was quoted as saying. "Our investigation confirmed that these

DFIR
P0
2026-10-02 11:46 UTC
Security Journalism

Crypto Scammers Hijack Microsoft’s Official X Account

Security Week · Eduard Kovacs · indexed 2026-10-02 12:00 UTC

Hackers used the account, which has 13 million followers, to amplify a Clippy-themed cryptocurrency account. The post Crypto Scammers Hijack Microsoft’s Official X Account appeared first on SecurityWeek.

Microsoft
P0
2026-10-02 11:30 UTC
Security Journalism

Why CISOs Struggle to Answer the Board's Three Hardest Questions, and How to Fix the Report

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-02 11:45 UTC

The quarterly board meeting is two weeks out. The security team is pulling exports from the identity provider, the cloud posture tool, the vulnerability scanner, the SIEM and the EDR console. Someone is building a spreadsheet to reconcile them. Someone else is turning that spreadsheet into slides. Then a board member asks three questions: How secure is the organization, overall? What is

Vulnerabilities
P0
2026-10-02 11:14 UTC
Security Journalism

In Rare Move, Alleged Iranian State Hacker Extradited to US

Security Week · Ionut Arghire · indexed 2026-10-02 11:20 UTC

Amir Barati, an alleged member of the Mabna Institute, was indicted for targeting universities, private organizations, and government entities in the US and abroad. The post In Rare Move, Alleged Iranian State Hacker Extradited to US appeared first on SecurityWeek.

Law Enforcement
P0
2026-10-02 09:29 UTC
Security Journalism

Microsoft’s X account hacked in crypto pump-and-dump scheme

BleepingComputer · Sergiu Gatlan · indexed 2026-10-02 09:30 UTC

On Thursday, unknown attackers hijacked the official Microsoft account on X, which has over 13 million followers, in what appeared to be a pump-and-dump scheme promoting a crypto token. [...]

Microsoft
P0
2026-10-02 08:38 UTC
Security Journalism

AI Agents Aimed SQL Injection at US and Canadian Government Sites

Security Week · Eduard Kovacs · indexed 2026-10-02 08:40 UTC

The attacks targeted the US Department of Education and Library and Archives Canada, and researchers linked some agents to OpenAI. The post AI Agents Aimed SQL Injection at US and Canadian Government Sites appeared first on SecurityWeek.

AI Security
P0
2026-10-02 08:01 UTC
Security Journalism

Android 17 Advanced Protection Locks Accessibility Services to Verified Accessibility Tools

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-02 08:20 UTC

Google has announced a new security measure that limits access to Android's accessibility services to verified applications classified as Accessibility Tools when Advanced Protection is enabled. With malicious Android applications abusing the API serving as the main conduit for malware and financial fraud, the tech giant said the move would block a major attack pathway. Advanced Protection is a

CybercrimeMalwareMobile Security
P0
2026-10-02 06:05 UTC
Other

Investigators trace an AI agent ‘s path from research task to reconnaissance

Security Affairs · Pierluigi Paganini · indexed 2026-10-02 07:20 UTC

Asymmetric Security traces rogue OpenAI AI agent activity that probed government sites, accessed staging servers, and evaded sandbox limits. Researchers at Asymmetric Security spent 48 hours over the last weekend reconstructing reported rogue OpenAI AI agent activity that hit the Australian government and other organizations between March and September this year. They worked from public […]

AI Security
P0
2026-10-02 05:50 UTC
Other

U.S. CISA adds Fortinet FortiMail flaw to its Known Exploited Vulnerabilities catalog

Security Affairs · Pierluigi Paganini · indexed 2026-10-02 06:00 UTC

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Fortinet FortiMail flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Fortinet FortiMail flaw, tracked as CVE-2026-104286 (CVSS score of 9.8), to its Known Exploited Vulnerabilities (KEV) catalog. The flaw is a path traversal vulnerability that can be triggered through […]

Network SecurityVulnerabilitiesCVE-2026-104286
P35
2026-10-02 05:49 UTC
Security Journalism

Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-02 06:25 UTC

The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added a critical security flaw impacting Fortinet FortiMail to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation. The vulnerability, tracked as CVE-2026-104286 (CVSS score: 9.8), allows unauthenticated attackers to write arbitrary files on the underlying system. "An improper

Network SecurityVulnerabilitiesCVE-2026-104286
P80
1 2 3 4