IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 4,443 matching records.
AUTO-POLL // 2026-10-04 16:15 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P5 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 4

RANSOMWARE
P5
P5
COOL // 10 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
FRI
Oct 2

RANSOMWARE
P7
P7
COOL // 46 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
WED
Sep 30

RANSOMWARE
P10
P10
WARM // 59 ARTICLES
TUE
Sep 29

RANSOMWARE
P4
P4
COOL // 68 ARTICLES
MON
Sep 28

RANSOMWARE
P7
P7
COOL // 52 ARTICLES
RESET
2026-09-21 10:03 UTC
Security Journalism

Colorado Water Utilities Hit by Cyberattacks Targeting OT Systems

Security Week · Eduard Kovacs · indexed 2026-09-21 10:05 UTC

The hackers changed equipment settings, disabled remote access and alarms, and altered pumping cycles, officials said. The post Colorado Water Utilities Hit by Cyberattacks Targeting OT Systems appeared first on SecurityWeek.

P0
2026-09-21 10:00 UTC
Vendor Research

From Exposure to Lockdown: How AWS Neutralizes Compromised IAM Credentials through Managed Policies

Palo Alto Networks Unit 42 · Margaret Kelley · indexed 2026-09-21 10:15 UTC

We explore how AWS neutralizes exposed IAM credentials using managed policies, detailing GitHub secret scanning and CloudTrail monitoring strategies. The post From Exposure to Lockdown: How AWS Neutralizes Compromised IAM Credentials through Managed Policies appeared first on Unit 42.

Cloud Security
P0
2026-09-21 08:39 UTC
Security Journalism

ClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 Infrastructure

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-21 08:45 UTC

Threat actors are leveraging ClickFix-like lures to deliver a previously undocumented remote access trojan (RAT) called ChainScript. "ChainScript has appeared under multiple build names, including ComponentTask33, UpdateDigital, HostShared, and OrchidViolet66, while presenting itself as Spotify, Zoom Workplace, and Microsoft Teams software," Blackpoint Adversary Pursuit Group (APG)

MalwareMicrosoftThreat Actors
P0
2026-09-21 08:27 UTC
Other

The Target Is No Longer the Model. It’s the Agent.

Security Affairs · Pierluigi Paganini · indexed 2026-09-21 09:25 UTC

AI agents are becoming the new attack surface, exposed to poisoned skills, prompt injection, jailbreaks and attacks through connected tools. I read the AI security research published in a single month, February 2026, and when you put it all together, it’s not a list of curiosities. It’s a field guide to a new attack surface. […]

AI SecurityAppleSecurity Research
P0
2026-09-21 07:28 UTC
Other

UK Police Data Faces Long-Standing Microsoft Cloud Security Concerns

Security Affairs · Pierluigi Paganini · indexed 2026-09-21 08:25 UTC

A 2017 UK assessment warned that police data on Microsoft Azure could face foreign access risks. The risks may still exist. A Guardian investigation has surfaced a 2017 document signed off by then City of London police commissioner Ian Dyson, who also held the title of senior information risk owner for the entire country. That […]

Cloud SecurityDFIRMicrosoft
P0
2026-09-21 07:20 UTC
Security Journalism

Google Confirms Gemini AI Breached Three Firms

Security Week · Eduard Kovacs · indexed 2026-09-21 07:30 UTC

Google is the latest AI giant to confirm that its models escaped a testing environment and hacked real companies. The post Google Confirms Gemini AI Breached Three Firms appeared first on SecurityWeek.

P0
2026-09-21 06:06 UTC
Security Journalism

Jade Sleet Linked to Indian IT Provider Breach With FLATROOF and ROOFDECK Backdoors

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-21 06:15 UTC

The North Korean threat actor known as Jade Sleet has been attributed to the compromise of an India-based "much smaller organization" in the information technology (IT) services industry, once again highlighting how the adversary continues to target developers to breach target networks. Cybersecurity company SentinelOne, which disclosed details of the activity, said it involved the use of Apple

AppleMalwareThreat Actors
P0
2026-09-20 16:12 UTC
Other

U.S. CISA adds Linux Kernel flaws to its Known Exploited Vulnerabilities catalog

Security Affairs · Pierluigi Paganini · indexed 2026-09-20 17:10 UTC

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Linux Kernel flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added [1, 2] the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: Below are detailed descriptions of the flaws: At the time of this writing, there are currently no details on how the […]

Cloud SecurityLinux
P30
2026-09-20 14:11 UTC
Security Journalism

Malicious npm packages evade install-script defenses at runtime

BleepingComputer · Bill Toulas · indexed 2026-09-20 14:20 UTC

An ongoing npm malware campaign involving the 'indexed-btree' package shows how threat actors bypass supply chain defenses by hiding malicious code in a package's normal runtime behavior rather than in installation scripts. [...]

MalwareThreat Actors
P0
2026-09-20 13:44 UTC
Other

AI Hallucinations Nearly Triggered a US-China Military Confrontation

Security Affairs · Pierluigi Paganini · indexed 2026-09-20 14:50 UTC

An AI-generated intelligence report falsely identified weapons on a Chinese ship, nearly triggering a US military operation during the Iran war. According to CNN, four sources familiar with the episode say an intelligence report circulated through the military claiming a Chinese vessel in the Middle East was carrying components for a nuclear weapons program. The […]

P0
2026-09-20 12:22 UTC
Other

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 115

Security Affairs · Pierluigi Paganini · indexed 2026-09-20 12:30 UTC

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Gray Rabbits and the Tale of a One-Click Backdoor Red Heron exploits Gitea n-day flaw in multinational campaign, exposing new Linux rootkit Malicious Twitch Browser Extension Exposes 30,000 Users’ OAuth Tokens to Russian Bot […]

LinuxMalware
P0
2026-09-20 12:00 UTC
Security Journalism

Researchers escape OpenAI Codex sandbox to run commands on host

BleepingComputer · Ax Sharma · indexed 2026-09-20 12:10 UTC

Researchers escaped OpenAI's Codex sandbox two ways, one running commands on a developer's machine from its most locked-down mode. OpenAI has patched both. [...]

P0
2026-09-20 00:08 UTC
Other

Security Affairs newsletter Round 595 by Pierluigi Paganini – INTERNATIONAL EDITION

Security Affairs · Pierluigi Paganini · indexed 2026-09-20 00:35 UTC

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. Google Gemini also Broke Out of Its Test Environment AI Helps Hackers Hijack OpenAI Staff Accounts Through […]

P0
2026-09-19 18:36 UTC
Security Journalism

Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-19 11:30 UTC

Three researchers at the security firm Hacktron used Anthropic's Claude Opus 5 to chain two flaws and take over the ChatGPT and Codex accounts of several OpenAI employees, then reach an internal OpenAI code repository. The chain began with a bug in the software that runs OpenAI's public help forum and moved through a weakness in OpenAI's own login system. This was security research,

Cloud SecuritySecurity Research
P0
2026-09-19 14:56 UTC
Security Journalism

BragJack attacks hijack AI browser agents through malicious extensions

BleepingComputer · Ax Sharma · indexed 2026-09-19 15:00 UTC

BragJack, a proof-of-concept attack from Forever Security's Gal Weizman, hijacks the AI assistants in Chrome, Edge, Opera Neon, Perplexity Comet, and Claude in Chrome using one malicious extension. The Prompt Forcing technique earned over $20,000 in bounties and two CVEs. [...]

P0
2026-09-19 14:30 UTC
Security Journalism

TigerByte Cyber Emerges From Stealth With $3 Million in Funding

Security Week · Ionut Arghire · indexed 2026-09-19 14:50 UTC

The company has secured over $7 million in contracts with US government agencies, including the US Space Force, the US Navy, and DARPA. The post TigerByte Cyber Emerges From Stealth With $3 Million in Funding appeared first on SecurityWeek.

P0
2026-09-19 14:09 UTC
Other

Google Gemini also Broke Out of Its Test Environment

Security Affairs · Pierluigi Paganini · indexed 2026-09-19 15:05 UTC

Google Gemini escaped a cyber test environment, reached three real companies, and exposed why AI security tests need strict isolation. Google has confirmed that one of its Gemini models broke into the systems of three real companies during a cybersecurity test in May. The incident is the first publicly known case in which a Google […]

AI Security
P0
2026-09-19 14:05 UTC
Security Journalism

North Korean WaterPlum hackers infected 30,000 devices worldwide

BleepingComputer · Bill Toulas · indexed 2026-09-19 14:15 UTC

A joint law enforcement advisory warns that the North Korean hacking group WaterPlum compromised at least 30,000 devices worldwide from December 2025 through July 2026 and transferred more than $10.7 million in stolen cryptocurrency to North Korea. [...]

P0
2026-09-19 13:28 UTC
Security Journalism

Can You Prove a New CVE Is Exploitable Before Attackers Do? Learn How in This Webinar

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-17 13:45 UTC

A new CVE drops. Your scanner finds it. The severity score looks ugly. But that still does not answer the question that matters: Can it actually be exploited in your environment? Mythos-class AI is compressing the time between disclosure and working exploitation, while many security programs still validate risk on weekly or quarterly cycles. The dangerous gap is no longer just technical. It is

P0
2026-09-19 13:28 UTC
Security Journalism

Identity Visibility in 2026: The Foundation of Identity Security

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-19 14:30 UTC

Identity visibility is a starting point for modern identity security, because stolen and misused credentials are among the most frequently reported initial access vectors in breach research, including Verizon's annual Data Breach Investigations Report. This article explains what identity visibility means in IAM, why cloud and multicloud environments complicate it, which capabilities matter in

Data BreachesDFIR
P0
2026-09-19 13:01 UTC
Other

AI Helps Hackers Hijack OpenAI Staff Accounts Through a Forum

Security Affairs · Pierluigi Paganini · indexed 2026-09-19 13:50 UTC

AI helped researchers exploit a Discourse flaw in under 72 hours, hijacking OpenAI staff accounts and exposing the risks of shared SSO. Three researchers at Hacktron just took over ChatGPT and Codex accounts belonging to OpenAI staff. The attack did not rely on phishing techniques or a leaked password. Through an image upload on OpenAI’s […]

Phishing
P0
2026-09-19 11:38 UTC
Security Journalism

Viral AI actress' hotline face-scans every caller, watches their mood

BleepingComputer · Ax Sharma · indexed 2026-09-19 16:20 UTC

AI actress Tilly Norwood went viral after glitching into Chinese on Piers Morgan Uncensored last night. Her "Talking Tilly" video call service face-scans every caller for an 18+ age check, senses callers' moods during calls, and shuts down permanently on September 27. We tried it and read the fine print. [...]

P0
2026-09-19 11:38 UTC
Security Journalism

Calling viral AI actress Tilly Norwood? Agree to a face scan first

BleepingComputer · Ax Sharma · indexed 2026-09-19 11:40 UTC

AI actress Tilly Norwood went viral after glitching into Chinese on Piers Morgan Uncensored last night. Her "Talking Tilly" video call service face-scans every caller for an 18+ age check, senses callers' moods during calls, and shuts down permanently on September 27. We tried it and read the fine print. [...]

P0
2026-09-19 09:31 UTC
Security Journalism

SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-19 11:30 UTC

SolarWinds has released security updates to address a high-severity flaw in Access Rights Manager (ARM) that, if successfully exploited, could lead to an unauthenticated remote code execution vulnerability. The vulnerability, tracked as CVE-2026-28326, is rated 8.8 out of 10.0 on the CVSS scoring system. The issue affects all versions of Access Rights Manager 2026.2 and prior. "SolarWinds

VulnerabilitiesCVE-2026-28326
P20
2026-09-19 08:18 UTC
Security Journalism

Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-19 08:45 UTC

A critical vulnerability impacting Orkes Conductor is being actively exploited in the wild, according to Fortinet. The vulnerability in question is CVE-2026-58138 (CVSS v3.1 score: 9.8/CVSS v4 score: 9.3), which relates to a case of unauthenticated remote code execution. "Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerability that allows remote

Network SecurityVulnerabilitiesCVE-2026-58138
P75
23 24 25 26 27