IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 4,442 matching records.
AUTO-POLL // 2026-10-04 15:40 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P5 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 4

RANSOMWARE
P5
P5
COOL // 9 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
FRI
Oct 2

RANSOMWARE
P7
P7
COOL // 46 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
WED
Sep 30

RANSOMWARE
P10
P10
WARM // 59 ARTICLES
TUE
Sep 29

RANSOMWARE
P4
P4
COOL // 68 ARTICLES
MON
Sep 28

RANSOMWARE
P7
P7
COOL // 52 ARTICLES
RESET
2026-09-22 17:10 UTC
Vendor Research

CVE-2026-94384 - Missing Authorization in AmazonConnectSalesforceLambda sfExecuteAWSService

AWS Security Bulletins · aws@amazon.com · indexed 2026-09-22 17:20 UTC

Bulletin ID: 2026-115-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/22/2026 10:00 AM PDT Description: Amazon Connect Salesforce Lambda (AmazonConnectSalesforceLambda) is a Serverless Application Repository application that provides Lambda functions for integrating Amazon Connect with Salesforce. We identified CVE-2026-94384, a missing authorization issue in the sfExecuteAWSService Lambda function, which is used only during initial setup. The function dispatche…

Cloud SecurityVulnerabilitiesCVE-2026-94384
P5
2026-09-22 17:03 UTC
Security Journalism

Microsoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox Compromises

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-22 17:55 UTC

Microsoft on Tuesday announced the takedown of the EvilTokens device code phishing service that it said used artificial intelligence (AI) "at every step of the attack chain." The action, carried out with authorization from the U.S. District Court for the Eastern District of Virginia, involved the efforts of Health-ISAC, alongside Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, The Shadowserver

AI SecurityMicrosoftPhishing
P0
2026-09-22 16:52 UTC
Government

2026-013: Critical Vulnerability in F5 BIG-IP APM

CERT-EU Security Advisories · indexed 2026-09-22 17:10 UTC

On 22 September 2026, F5 published an advisory addressing a critical vulnerability affecting its BIG-IP APM product. The vendor confirmed active exploitation in the wild. CERT-EU recommends taking appropriate actions as soon as possible.

Vulnerabilities
P30
2026-09-22 16:41 UTC
Security Journalism

Critical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-22 17:55 UTC

A critical vulnerability in Bifrost, an open-source AI gateway that routes requests to more than 20 LLM providers, allows an unauthenticated attacker to run arbitrary commands on the gateway server with a single HTTP request. The flaw, tracked as CVE-2026-90898 (CVSS score: 9.8), affects all versions of the Bifrost HTTP transport before 2.1.0 when management authentication is

AI SecurityVulnerabilitiesCVE-2026-90898
P15
2026-09-22 16:14 UTC
Security Journalism

Researcher Drops BigDiskBuster Zero-Day PoC That Blocks Microsoft Defender Updates

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-22 17:55 UTC

A zero-day proof-of-concept tool that stops Microsoft Defender from installing platform and signature updates by filling all available disk space was published on GitHub on September 19. The tool, called BigDiskBuster, has no patch, no CVE, and no Microsoft advisory. Its author, Abdelhamid Naceri, is a former Microsoft security researcher whose earlier Defender exploits were used in

MicrosoftSecurity ResearchVulnerabilities
P25
2026-09-22 15:51 UTC
Security Journalism

Two arrested in UK after Microsoft takedown of ‘Eviltokens’ AI-chatbot for cybercriminals

The Record · indexed 2026-09-22 16:00 UTC

Available on Telegram for a $1,500 initiation fee and a recurring monthly $500 subscription, EvilTokens provided cybercriminals with artificial intelligence tools enabling them to compromise accounts, analyze breached inboxes and find the best methods for monetizing their access through fraud.

AI SecurityCybercrimeLaw EnforcementMicrosoft
P0
2026-09-22 15:00 UTC
Vendor Research

Unmasking EvilTokens: Getting to the root of device code phishing

Microsoft Security Blog · Microsoft Threat Intelligence, Microsoft Defender Experts and Microsoft Security Research · indexed 2026-09-22 16:30 UTC

EvilTokens has quickly become one of the top PhaaS platforms, enabling device code phishing attacks through AI-assisted lures, automated infrastructure, and token theft. In collaboration with partners, Microsoft Digital Crimes Unit (DCU) facilitated a disruption of EvilTokens infrastructure and operations. The post Unmasking EvilTokens: Getting to the root of device code phishing appeared first on Microsoft Security Blog.

MicrosoftPhishing
P0
2026-09-22 14:29 UTC
Security Journalism

Cyera Raises $400 Million at $12+ Billion Valuation

Security Week · SecurityWeek News · indexed 2026-09-22 14:30 UTC

The data security company received the new investment from Goldman Sachs Alternatives, extending its Series G funding round. The post Cyera Raises $400 Million at $12+ Billion Valuation appeared first on SecurityWeek.

P0
2026-09-22 14:04 UTC
Other

Chaotic Eclipse Released BigDiskBuster, A PoC For Windows Defender Update DoS Zero-Day

Security Affairs · Pierluigi Paganini · indexed 2026-09-22 14:10 UTC

The researcher Chaotic Eclipse released BigDiskBuster, a PoC exploit for a Windows Defender Update DoS Zero-Day vulnerability. Security researcher Chaotic Eclipse, also known as INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse, released a new zero-day exploit targeting Microsoft Defender. The researcher named the exploit BigDiskBuster, it triggers a Denial of Service Vulnerability in Windows Defender Update. The security researcher […]

MicrosoftSecurity ResearchVulnerabilities
P25
2026-09-22 14:00 UTC
Security Journalism

AI Attacks Move Faster. Huntress’ Agentic SOC Keeps Up

Huntress · indexed 2026-09-22 21:10 UTC

AI hasn't changed attacker tradecraft, just the speed. See how Huntress built Athena, an agentic SOC partner, to help analysts keep pace.

P0
2026-09-22 13:10 UTC
Community

LausivLoader analysis, or how to pass data between malware stages, (Thu, Sep 17th)

SANS Internet Storm Center · indexed 2026-09-17 15:05 UTC

At the end of August, a malspam message was caught in the quarantine of a mail gateway operated by one of my customers. The message was not especially remarkable – it asked the recipient to review some attached requirements and provide a price quotation for a fiber optic system and appeared to impersonate an employee of a legitimate company.

Malware
P0
2026-09-22 12:57 UTC
Security Journalism

Webinar tomorrow: Inside real-world Google Workspace breaches

BleepingComputer · BleepingComputer · indexed 2026-09-22 13:10 UTC

Tomorrow's webinar examines real Google Workspace breaches involving social engineering and malicious OAuth applications, from initial access through the critical first hours of incident response. Learn which security controls and response decisions can make the greatest difference. [...]

DFIR
P0
2026-09-22 12:30 UTC
Security Journalism

AI Agents Are Rewriting the Rules of Lateral Movement

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-22 13:40 UTC

Security teams have spent decades asking whether an identity has too much access. AI agents raise a harder question: how can we determine which paths an autonomous system can discover, given the access it already has? A person may try several ways to complete a task. A deterministic application follows the flow its developer wrote. But an AI agent is relentless in its pursuit of done. In May

AI Security
P0
2026-09-22 12:29 UTC
Security Journalism

New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-22 13:40 UTC

Attackers are exploiting a new flaw in on-premises VeloCloud Orchestrator (VCO), the server that manages the Edge devices in a VeloCloud SD-WAN, Arista said on September 22. The flaw, tracked as CVE-2026-93952, may allow a remote attacker with no login access to privilege internal functions and affect the VCO host. Only orchestrators set up to authenticate their Edges with certificates are

VulnerabilitiesCVE-2026-93952
P30
2026-09-22 12:24 UTC
Security Journalism

Only 13% of OT Network Segments Are Fully Isolated: Analysis

Security Week · Eduard Kovacs · indexed 2026-09-22 12:30 UTC

Forescout’s new network segmentation research shows that OT and medical devices often share network segments with other enterprise assets. The post Only 13% of OT Network Segments Are Fully Isolated: Analysis appeared first on SecurityWeek.

P0
2026-09-22 11:45 UTC
Security Journalism

DORA Year Two: Can Your SOC Actually See the Attack?

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-22 12:10 UTC

When the Digital Operational Resilience Act (DORA) became enforceable across the European Union in January 2025, it triggered an administrative sprint. Financial entities spent the first year establishing risk governance, assessing third-party service providers, updating contract clauses, and documenting incident escalation workflows. Now in its second year, the harder part of DORA is

P0
2026-09-22 11:38 UTC
Security Journalism

New Linux Kernel Flaw Gives ARM64 KVM Guests Read-Write Access to Host Memory

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-22 12:10 UTC

A new flaw in the Linux kernel's KVM virtualization code for ARM64 processors can leave a freed piece of host memory exposed to a guest virtual machine on hosts with nested virtualization enabled. The bug, tracked as CVE-2026-89775, allows a guest to read and write host kernel memory, and the researcher who found it says it can be used to escape the guest and run code on the host machine.

LinuxVulnerabilitiesCVE-2026-89775
P5
2026-09-22 11:33 UTC
Security Journalism

Malicious B-tree NPM Package Accumulates Millions of Downloads

Security Week · Ionut Arghire · indexed 2026-09-22 11:50 UTC

Posing as the legitimate sorted-btree package, indexed-btree hides a malware trigger in its prototype method. The post Malicious B-tree NPM Package Accumulates Millions of Downloads appeared first on SecurityWeek.

Malware
P0
2026-09-22 11:17 UTC
Security Journalism

SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-22 12:10 UTC

A SharePoint Server vulnerability that Microsoft initially classified as a spoofing flaw with a CVSS score of 6.5 actually enables authenticated remote code execution, according to full technical details published today by Viettel Cyber Security researcher Dinh Ho Anh Khoa. The flaw, CVE-2026-65660, affects SharePoint Server 2016, 2019, and Subscription Edition. Patches have been

MicrosoftSecurity ResearchVulnerabilitiesCVE-2026-65660
P20
20 21 22 23 24