IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 4,442 matching records.
AUTO-POLL // 2026-10-04 15:35 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P5 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 4

RANSOMWARE
P5
P5
COOL // 9 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
FRI
Oct 2

RANSOMWARE
P7
P7
COOL // 46 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
WED
Sep 30

RANSOMWARE
P10
P10
WARM // 59 ARTICLES
TUE
Sep 29

RANSOMWARE
P4
P4
COOL // 68 ARTICLES
MON
Sep 28

RANSOMWARE
P7
P7
COOL // 52 ARTICLES
RESET
2026-09-22 10:22 UTC
Security Journalism

Shai-Hulud Attack Nips Cyber-Firm CrowdSec's GitHub Data

Dark Reading · Elizabeth Montalbano · indexed 2026-09-22 17:55 UTC

Threat actors stole the contents of 170 private repositories using an OAuth token stolen from a former employee's computer through the TanStack npm supply chain attack.

Threat Actors
P0
2026-09-22 10:22 UTC
Security Journalism

WordPress Patches ‘Click2Shell’ Vulnerability

Security Week · Ionut Arghire · indexed 2026-09-22 10:35 UTC

The bug lets attackers automatically install and preview themes and could lead to remote code execution. The post WordPress Patches ‘Click2Shell’ Vulnerability appeared first on SecurityWeek.

Vulnerabilities
P15
2026-09-22 10:13 UTC
Other

Public PoC Exposes Critical Veeam Agent Privilege Escalation

Security Affairs · Pierluigi Paganini · indexed 2026-09-22 10:50 UTC

A Veeam Agent flaw lets local users gain SYSTEM privileges. A public PoC is available, raising the risk of exploitation on shared Windows systems. If you’re running Veeam Agent on a Windows endpoint with more than one local user, now’s the time to check the version, not tomorrow. On September 14, 2026, public technical details […]

MicrosoftVulnerabilities
P10
2026-09-22 10:00 UTC
Vendor Research

The Closed Quorum: Inside the first reported autonomous AI C2 implant

Cisco Talos Intelligence Blog · Ryan Fetterman · indexed 2026-09-22 10:05 UTC

CLOSEDQUORUM, a malware binary discovered through Cisco Talos’ CAIRN project, exhibits fully autonomous command and control (C2). It represents a shift in effort displacement for attackers, in which expanding portions of the attack chain can be executed without operator involvement.

Malware
P0
2026-09-22 09:38 UTC
Security Journalism

Malicious npm Package indexed-btree Hid Its Loader in Runtime Code Before Removal

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-22 10:50 UTC

A malicious npm package named "indexed-btree" has been observed hiding its malicious behavior within application code rather than using lifecycle scripts, indicating that threat actors are likely shifting tactics in response to recent security controls. "Indexed-btree is a malicious npm package mimicking the legit sorted-btree package, an ordinary B-tree/indexing utility," Checkmarx said. "

Threat Actors
P0
2026-09-22 09:13 UTC
Other

U.S. CISA adds Zyxel flaw to its Known Exploited Vulnerabilities catalog

Security Affairs · Pierluigi Paganini · indexed 2026-09-22 09:40 UTC

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Zyxel flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Zyxel GS1900 Series Switches flaw, tracked as CVE-2026-7273 (CVSS score of 8.8), to its Known Exploited Vulnerabilities (KEV) catalog. The flaw is a stack-based buffer overflow that could allow attackers […]

Network SecurityVulnerabilitiesCVE-2026-7273
P35
2026-09-22 08:37 UTC
Security Journalism

Japan Dismantles First North Korean Laptop Farm as US and Allies Detail Wider Scheme

Security Week · Eduard Kovacs · indexed 2026-09-22 08:40 UTC

The US, Japan, Germany and Australia have published a joint report detailing the scope of North Korea’s WaterPlum campaign. The post Japan Dismantles First North Korean Laptop Farm as US and Allies Detail Wider Scheme appeared first on SecurityWeek.

P0
2026-09-22 07:52 UTC
Security Journalism

SideCopy Broadens India Targeting to Academia With ReverseRAT Spear-Phishing

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-22 09:25 UTC

The threat actor known as SideCopy has been observed using spear-phishing lures to target academic institutions in India, expanding their strategic focus beyond government entities. "SideCopy campaign operations typically initiate through spear-phishing campaigns that leverage the abuse of mshta.exe to execute malicious scripts and circumvent standard security protocols," Trellix researchers

PhishingThreat Actors
P0
2026-09-22 06:44 UTC
Other

Contagious Interview: 30,000 devices infected by a fake job interview

Security Affairs · Pierluigi Paganini · indexed 2026-09-22 07:40 UTC

North Korea-linked WaterPlum runs the Contagious Interview campaign, infecting over 30,000 devices using a fake job interview. On September 18, Japan’s National Police Agency, the FBI, the US Department of Defense’s Cyber Crime Center, and intelligence agencies from Australia and Germany published a joint advisory about a group called WaterPlum, better known as Contagious Interview. […]

Law Enforcement
P0
2026-09-22 06:33 UTC
Security Journalism

One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-22 06:55 UTC

Malware already running on a Mac can quietly take over Meta's Muse assistant and use the broad access its owner granted the app, security researcher Patrick Wardle has shown in a proof-of-concept released on September 21. It works by changing a hidden setting so that when the user taps the microphone and dictates a prompt, the words go to the attacker instead of Meta. The flaw is in

MalwareSecurity Research
P0
2026-09-22 06:03 UTC
Security Journalism

WordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-22 06:55 UTC

A new flaw in WordPress core let an anonymous visitor leave a comment that planted a hidden script on the page. If a logged-in administrator later opened that page, the script could run code on the site's server. WordPress fixed the flaw, tracked as CVE-2026-93485 and called "Comment2Shell," on September 17 in version 7.1.1 and told site owners to update right away. There is

VulnerabilitiesCVE-2026-93485
P20
2026-09-22 05:31 UTC
Security Journalism

Zyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM Access

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-22 06:55 UTC

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a now-patched security flaw impacting Zyxel GS1900 series switches to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability, tracked as CVE-2026-7273 (CVSS score: 8.8), is a stack-based buffer overflow vulnerability that could result in arbitrary operating

Cloud SecurityNetwork SecurityVulnerabilitiesCVE-2026-7273
P35
2026-09-22 05:00 UTC
Other

ZDI-26-719: Cisco ThousandEyes Virtual Appliance DHCP Client Command Injection Remote Code Execution Vulnerability

Zero Day Initiative · indexed 2026-09-22 21:10 UTC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Cisco ThousandEyes Virtual Appliance. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-20350.

VulnerabilitiesCVE-2026-20350
P20
2026-09-22 02:01 UTC
Security Journalism

US Proposes AI Incident Alert System in Talks With China, Bessent Says

Security Week · Associated Press · indexed 2026-09-22 02:10 UTC

Trump has resisted calls to slow down AI development, saying that would help China catch up to U.S. companies. The post US Proposes AI Incident Alert System in Talks With China, Bessent Says appeared first on SecurityWeek.

P0
2026-09-21 23:13 UTC
Other

21st September – Threat Intelligence Report

Check Point Research · urias@checkpoint.com · indexed 2026-09-21 23:20 UTC

For the latest discoveries in cyber research for the week of 21st September, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Japan’s Digital Agency, which operates the Government Solution Service used by multiple ministries, has confirmed a data breach after attackers exploited a vulnerability in a VPN appliance. Approximately 246,000 records were exposed, […] The post 21st September – Threat Intelligence Report appeared first on Check Point Research.

Data BreachesNetwork SecurityThreat IntelligenceVulnerabilities
P0
2026-09-21 21:18 UTC
Security Journalism

BigCommerce alerts merchants of data breach linked to Ribon apps

BleepingComputer · Bill Toulas · indexed 2026-09-21 21:20 UTC

Ecommerce platform BigCommerce has alerted multiple merchants to data breaches after attackers compromised credentials for third-party Ribon applications and used them to inject malicious scripts into online stores. [...]

Data Breaches
P0
2026-09-21 20:20 UTC
Other

Google Fined €403 Million Over Location Data Practices

Security Affairs · Pierluigi Paganini · indexed 2026-09-21 21:20 UTC

Ireland’s DPC fined Google €403 million over GDPR violations involving location data, transparency, retention and user control. Ireland’s Data Protection Commission (DPC) just fined Google €403 million, and the case behind it goes back six years, to a set of complaints that never really went away. The DPC launched the investigation in February 2020 after […]

DFIR
P0
2026-09-21 20:07 UTC
Security Journalism

ShinyHunters Hacked Cl0p. Now What About Cl0p's Victims?

Dark Reading · Alexander Culafi · indexed 2026-09-21 20:30 UTC

ShinyHunters defaced Cl0p's Dark Web site and claims to have stolen victim data, potentially exposing organizations that paid ransoms to renewed extortion attempts.

Cybercrime
P0
2026-09-21 18:09 UTC
Other

Foreign Hackers Target Two Colorado Water Utilities

Security Affairs · Pierluigi Paganini · indexed 2026-09-21 19:10 UTC

Hackers targeted two Colorado water utilities, changing OT settings and disabling alarms, but causing no impact on water services or safety. Foreign hackers targeted the operational technology (OT) systems of two small private water utilities in Colorado in late August, apparently trying to disrupt operations. Local authorities haven’t identified the affected utilities or the attackers. […]

ICS / OT
P0
21 22 23 24 25