IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 4,441 matching records.
AUTO-POLL // 2026-10-04 14:45 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P6 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 4

RANSOMWARE
P6
P6
COOL // 8 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
FRI
Oct 2

RANSOMWARE
P7
P7
COOL // 46 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
WED
Sep 30

RANSOMWARE
P10
P10
WARM // 59 ARTICLES
TUE
Sep 29

RANSOMWARE
P4
P4
COOL // 68 ARTICLES
MON
Sep 28

RANSOMWARE
P7
P7
COOL // 52 ARTICLES
RESET
2026-09-22 19:31 UTC
Other

Check Point Fixes a New Actively Exploited Critical Security Flaw

Security Affairs · Pierluigi Paganini · indexed 2026-09-22 20:50 UTC

Check Point fixes an actively exploited flaw that lets unauthenticated attackers upload and run scripts on vulnerable Security Management Servers. Check Point has released emergency hotfixes for CVE-2026-93616, a critical path traversal flaw in its Security Management Server. Attackers can abuse the flaw without logging in to upload malicious scripts and execute them on vulnerable […]

VulnerabilitiesCVE-2026-93616
P30
2026-09-22 19:06 UTC
Community

The Truth about GET and HTTP Standards, (Tue, Sep 22nd)

SANS Internet Storm Center · indexed 2026-09-22 15:10 UTC

On Friday, Xavier talked about the newly introduced HTTP Query method. This new method was introduced to allow "GET" requests that include a body. The main reason for this was that GET requests typically do not contain a body. But what if they do?

P0
2026-09-22 18:29 UTC
Security Journalism

Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-22 19:25 UTC

Attackers exploited a previously unknown flaw in Check Point's Security Management Server in a handful of targeted attacks on July 23, the company said. The flaw, CVE-2026-93616, allows an attacker who can access the server's web service to run scripts on it without logging in. Check Point released a fix on September 22 for the server that controls firewall policies for the Check Point

Network SecurityVulnerabilitiesCVE-2026-93616
P30
2026-09-22 18:03 UTC
Security Journalism

WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-22 19:25 UTC

WordPress has fixed a critical flaw in its core software that lets an attacker with no account make a site load a PHP file from outside its theme folders. On some servers, that can go further, allowing the attacker to run their own code. The fix shipped on September 22 in WordPress 7.1.2, with fixes for every branch the project still supports, back to 4.7, and WordPress is telling site owners

P10
2026-09-22 17:58 UTC
Security Journalism

Malicious npm Package Poses as Twilio Bug-Bounty Probe, Can Exfiltrate Credentials

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-22 19:25 UTC

Cybersecurity researchers have disclosed details of a malicious npm package named "tw-pkgprobe-7731" that masquerades as a security tool targeting developers integrating Twilio into their applications, while stealthily attempting to harvest sensitive data. The package, named "tw-pkgprobe-7731," was first uploaded to the npm registry in mid-August 2026 by an npm account named "twdepprobe7731."

Security Research
P0
2026-09-22 17:58 UTC
Security Journalism

BigCommerce Data Stolen via Ribon Apps Hack

Security Week · Ionut Arghire · indexed 2026-09-22 18:00 UTC

The attackers used a compromised BigCommerce application key held by Ribon to access customer data. The post BigCommerce Data Stolen via Ribon Apps Hack appeared first on SecurityWeek.

P0
2026-09-22 17:17 UTC
Security Journalism

Reducing shadow IT visibility gaps with Wazuh

BleepingComputer · Sponsored by Wazuh · indexed 2026-09-22 17:20 UTC

Shadow IT can leave security teams unaware of unmanaged endpoints, unauthorized software, and other assets that fall outside existing monitoring. Wazuh explains how endpoint inventory, agentless monitoring, and centralized analysis can help organizations identify and reduce these visibility gaps. [...]

Microsoft
P0
2026-09-22 17:12 UTC
Security Journalism

Amid Ongoing Rogue Incidents, Debate Over AI Safety Gets Real

Dark Reading · Robert Lemos · indexed 2026-09-22 17:25 UTC

As more reports of misalignment incidents underscore AI risks, large AI labs, regular businesses, and even nations are searching for better ways to keep control and be secure.

P0
2026-09-22 17:10 UTC
Vendor Research

CVE-2026-94384 - Missing Authorization in AmazonConnectSalesforceLambda sfExecuteAWSService

AWS Security Bulletins · aws@amazon.com · indexed 2026-09-22 17:20 UTC

Bulletin ID: 2026-115-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/22/2026 10:00 AM PDT Description: Amazon Connect Salesforce Lambda (AmazonConnectSalesforceLambda) is a Serverless Application Repository application that provides Lambda functions for integrating Amazon Connect with Salesforce. We identified CVE-2026-94384, a missing authorization issue in the sfExecuteAWSService Lambda function, which is used only during initial setup. The function dispatche…

Cloud SecurityVulnerabilitiesCVE-2026-94384
P5
19 20 21 22 23