IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 4,443 matching records.
AUTO-POLL // 2026-10-04 16:20 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P5 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 4

RANSOMWARE
P5
P5
COOL // 10 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
FRI
Oct 2

RANSOMWARE
P7
P7
COOL // 46 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
WED
Sep 30

RANSOMWARE
P10
P10
WARM // 59 ARTICLES
TUE
Sep 29

RANSOMWARE
P4
P4
COOL // 68 ARTICLES
MON
Sep 28

RANSOMWARE
P7
P7
COOL // 52 ARTICLES
RESET
2026-09-21 17:31 UTC
Security Journalism

Fake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus and EDR

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-21 18:15 UTC

A fake LastPass Authenticator installer offered on GitHub installs a Windows kernel driver that shuts off antivirus and other security software before a password stealer runs if a victim downloads and runs it, researchers at LastPass and Delphos Labs said on September 17. Microsoft's own hardware-compatibility program signs the driver, scored zero detections on VirusTotal when researchers

LinuxMalwareMicrosoft
P0
2026-09-21 17:19 UTC
Security Journalism

Google Hit With $463 Million Fine for EU Location Data Rule Breach

Security Week · Associated Press · indexed 2026-09-21 17:30 UTC

Google has been fined 403 million euros ($463 million) for breaching the European Union’s strict privacy rules because it mishandled users’ location data. The post Google Hit With $463 Million Fine for EU Location Data Rule Breach appeared first on SecurityWeek.

P0
2026-09-21 17:19 UTC
Security Journalism

Contagious Interview Campaign Compromises 30,000 Devices, Steals $10.71M in Crypto

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-21 18:15 UTC

The North Korean threat actors behind the Contagious Interview campaign have compromised at least 30,000 devices located in more than 100 countries and siphoned funds or account credentials from over 7,000 cryptocurrency wallets, according to a new joint cybersecurity advisory. The primary targets of the campaign are individual web designers, engineers, and specialists in cryptocurrency,

AppleThreat Actors
P0
2026-09-21 16:57 UTC
Security Journalism

Google Fined €403 Million Over GDPR Violations Tied to Location Data

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-21 18:15 UTC

Google has been fined €403 million for breaking the EU's data protection law, the GDPR, in the way three of its features handled people's location data from May 2018 to February 2020. Ireland's Data Protection Commission (DPC), Google's lead regulator in the EU, also ordered the company to make its processing comply with the law within 6 months. The DPC has not said publicly which

P0
2026-09-21 15:41 UTC
Security Journalism

Google fined €403 million over location data privacy violations

BleepingComputer · Bill Toulas · indexed 2026-09-21 15:55 UTC

Ireland's Data Protection Commission (DPC) has fined Google €403 million ($463M) for multiple GDPR violations related to processing users' location data. [...]

P0
2026-09-21 15:33 UTC
Vendor Research

Transforming Bedrock Guardrails events into OCSF with CloudWatch

AWS Security Blog · Dhananjay Karanjkar · indexed 2026-09-21 16:00 UTC

Security teams investigating possible AI-related security events need guardrail intervention data alongside their existing security telemetry. When a guardrail identifies or blocks a prompt injection attempt or redacts sensitive data, that intervention carries additional investigative value comparable to a failed sign-in or a network intrusion alert. AWS Bedrock publishes this telemetry to AWS CloudWatch metrics […]

AI SecurityCloud Security
P0
2026-09-21 14:47 UTC
Security Journalism

Rogue Behavior: OpenAI Reveals More Model Misalignment Incidents

Dark Reading · Elizabeth Montalbano · indexed 2026-09-21 15:15 UTC

The AI giant disclosed six examples of concerning model activity and published a new framework for investigating and disclosing such incidents.

P0
2026-09-21 14:30 UTC
Security Journalism

CISO Conversations: Noopur Davis – The Accidental Global CISO at Comcast

Security Week · Kevin Townsend · indexed 2026-09-21 14:35 UTC

Noopur Davis never planned a career in cybersecurity. She was a developer at Intergraph, and for many years that was all she wanted to be. The post CISO Conversations: Noopur Davis – The Accidental Global CISO at Comcast appeared first on SecurityWeek.

P0
2026-09-21 14:24 UTC
Security Journalism

⚡ Weekly Recap: Cisco 0-Day, AI Agent RCE, ClickFix Attacks, ClickFix Surge, and Browser Hijacks

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-21 14:45 UTC

A browser. A plugin. A package. A login screen. Normal stuff. That is basically the problem this week. The trouble keeps showing up inside things people already trust: code that takes a bad turn, old payloads coming back, exposed systems, weak checks, fake fixes, and attack paths that look almost too easy. Even the research side is getting messy, with more findings, more automation, and not

AI SecurityVulnerabilities
P25
2026-09-21 14:15 UTC
Security Journalism

TASK#STOMP PowerShell Backdoor Steals Documents, Wi-Fi Passwords, and Clipboard Data

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-21 14:45 UTC

Cybersecurity researchers have disclosed details of a new campaign dubbed TASK#STOMP that delivers a PowerShell backdoor designed to harvest sensitive data from compromised hosts. The backdoor "automatically harvests and exfiltrates business documents, watches the filesystem for new files in real time, steals Wi-Fi passwords and clipboard contents, takes screenshots, and accepts arbitrary

MalwareSecurity Research
P0
2026-09-21 14:02 UTC
Security Journalism

FBI's CJIS v6.1: What Security Teams Need to Know.

BleepingComputer · Sponsored by Specops Software · indexed 2026-09-21 14:15 UTC

The FBI's CJIS Security Policy v6.1 strengthens requirements around encryption and vulnerability scanning while continuing the shift toward more continuous security assessment. Specops explains what changed and how agencies can address password, MFA, and identity requirements as they prepare for upcoming audits. [...]

Law EnforcementVulnerabilities
P0
2026-09-21 14:00 UTC
Security Journalism

Dragos Completes NetRise and runZero Acquisitions Following Accenture Deal

Security Week · Eduard Kovacs · indexed 2026-09-21 14:15 UTC

The transaction is part of the $4.1 billion deal in which Accenture acquired a majority stake in Dragos in an OT cybersecurity push. The post Dragos Completes NetRise and runZero Acquisitions Following Accenture Deal appeared first on SecurityWeek.

P0
2026-09-21 13:32 UTC
Other

ChainScript: the RAT that hides its command server inside a blockchain contract

Security Affairs · Pierluigi Paganini · indexed 2026-09-21 13:50 UTC

Blackpoint uncovers ChainScript, a Node.js RAT that queries a Polygon smart contract to find and rotate its command server. Blackpoint’s Adversary Pursuit Group was chasing a ClickFix campaign spreading an unknown RAT namend ChainScript. The malicious code is a previously undocumented Node.js remote access trojan that hides its command server on a public blockchain. The […]

Malware
P0
2026-09-21 13:16 UTC
Security Journalism

Microsoft reminds admins to migrate Entra ID users to passkeys

BleepingComputer · Sergiu Gatlan · indexed 2026-09-21 13:30 UTC

Microsoft has reminded admins to migrate Entra ID users to phishing-resistant authentication methods to avoid sign-in disruptions after it retires SMS first-factor sign-in starting in February 2027. [...]

MicrosoftPhishing
P0
2026-09-21 12:55 UTC
Security Journalism

LinkedIn wins court order blocking mass scraping of user data

The Record · indexed 2026-09-21 13:00 UTC

The agreement between LinkedIn, ProAPIs and joint business operator Netswift also requires the firms to stop selling and transferring the data, no longer access LinkedIn through fake accounts and delete the data that was scraped, according to a senior LinkedIn executive.

P0
2026-09-21 12:51 UTC
Security Journalism

RatHat Android Trojan Uses AI for Automation

Security Week · Ionut Arghire · indexed 2026-09-21 12:55 UTC

The malware relies on AI for real-time device navigation and control, increasing adaptability and evasion. The post RatHat Android Trojan Uses AI for Automation appeared first on SecurityWeek.

MalwareMobile Security
P0
2026-09-21 12:30 UTC
Security Journalism

Google says Gemini breached three companies during security test

The Record · indexed 2026-09-21 12:45 UTC

Google’s artificial intelligence model Gemini accessed computer systems belonging to three real companies without authorization during a cybersecurity test in May — the latest in a string of similar incidents.

AI Security
P0
2026-09-21 11:57 UTC
Security Journalism

Rust Team Members and Popular Crate Owners Targeted via Video Calls

Security Week · Eduard Kovacs · indexed 2026-09-21 12:15 UTC

It’s unclear if the attacks are part of previous campaigns against Rust, but the techniques used by the attackers match those used by North Korea. The post Rust Team Members and Popular Crate Owners Targeted via Video Calls appeared first on SecurityWeek.

P0
2026-09-21 10:55 UTC
Security Journalism

CrowdSec Confirms Source Code Stolen in Supply Chain Attack

Security Week · Ionut Arghire · indexed 2026-09-21 11:00 UTC

The cybersecurity firm believes the data breach was the result of the May 2026 TanStack supply chain attack. The post CrowdSec Confirms Source Code Stolen in Supply Chain Attack appeared first on SecurityWeek.

Data Breaches
P0
2026-09-21 10:33 UTC
Community

TerminalFix: PNG Steganography, (Mon, Sep 21st)

SANS Internet Storm Center · indexed 2026-09-21 10:30 UTC

Microsoft Security Research published an interesting blog post "TerminalFix campaign deploys a reverse tunnel through multistage intrusion" about a malware campaign. The aspect that I want to take a closer look at, is the fact that the threat actors used PNG files with steganography. I reached out to the researchers and they kindly shared the IOCs for the PNG files with me.

MalwareMicrosoftSecurity ResearchThreat ActorsThreat Intelligence
P0
2026-09-21 10:32 UTC
Other

A BYD Shark 6 Hack Shows the Risks of Connected Cars

Security Affairs · Pierluigi Paganini · indexed 2026-09-21 11:35 UTC

A BYD Shark 6 was remotely hacked, exposing vehicle controls, location tracking and cabin audio, raising serious connected-car security concerns. A journalist drove a BYD Shark 6 down a country road outside Canberra while a hacker sitting on the shoulder killed the headlights with a keystroke. That’s not a hypothetical. It’s what happened during a […]

P0
22 23 24 25 26