IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 4,443 matching records.
AUTO-POLL // 2026-10-04 17:05 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P5 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 4

RANSOMWARE
P5
P5
COOL // 10 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
FRI
Oct 2

RANSOMWARE
P7
P7
COOL // 46 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
WED
Sep 30

RANSOMWARE
P10
P10
WARM // 59 ARTICLES
TUE
Sep 29

RANSOMWARE
P4
P4
COOL // 68 ARTICLES
MON
Sep 28

RANSOMWARE
P7
P7
COOL // 52 ARTICLES
RESET
2026-09-18 11:01 UTC
Security Journalism

An Abandoned CDN Domain Was Re-Registered. Thousands of Sites Still Call It.

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-18 13:55 UTC

In July 2025, someone registered a domain that used to belong to a content delivery network. The CDN had been wound down years earlier, and the domain it served assets from was allowed to expire. What it had not lost were its callers. Thousands of websites, code repositories, and documentation pages still carry hard-coded references to hostnames beneath it. The new owner holds

P0
2026-09-18 11:01 UTC
Security Journalism

Plugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding Agents

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-18 13:55 UTC

A flaw in four widely used AI coding agents lets someone who controls a plugin's code repository swap the plugin an agent installs for a malicious one, even when the agent locked that plugin to a specific reviewed version, security firm Air Security said on Thursday. The firm said Anthropic has patched the flaw in Claude Code 2.1.179 and OpenAI in Codex 0.146.0, that GitHub Copilot has no

P0
2026-09-18 10:40 UTC
Security Journalism

WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storage

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-18 11:00 UTC

Cybersecurity researchers have discovered a cluster of 13 npm packages that have been found to deliver a previously undocumented JavaScript stealer codenamed WeaselBiscuit. The new malware family, per OpenSourceMalware, exhibits functional overlaps with two malware strains associated with the Democratic People's Republic of Korea's (DPRK) Contagious Interview campaign: BeaverTail and

MalwareSecurity Research
P0
2026-09-18 10:12 UTC
Security Journalism

NightmareStresser DDoS Service Disrupted in International Operation

Security Week · Ionut Arghire · indexed 2026-09-18 10:30 UTC

Active since at least 2022, NightmareStresser was one of the longest-running DDoS-for-hire services in the world. The post NightmareStresser DDoS Service Disrupted in International Operation appeared first on SecurityWeek.

P0
2026-09-18 10:04 UTC
Other

RatHat Turns Android Accessibility Into an Attack Weapon

Security Affairs · Pierluigi Paganini · indexed 2026-09-18 10:50 UTC

RatHat combines AI-driven screen control, Android debugging abuse and advanced credential theft to give attackers deep control of infected phones. RatHat is the new Android trojan you should know about. Zimperium researchers just published a breakdown of a strain they’ve traced to China-based operators, and what makes it different isn’t the credential theft, which is […]

MalwareMobile SecurityPhishing
P0
2026-09-18 10:00 UTC
Vendor Research

A Vault with a Heap-View: The Uncomfortable Space Between AgentCore Harness and Identity

Palo Alto Networks Unit 42 · Niv Rabin · indexed 2026-09-18 10:10 UTC

Analysis of how default configurations in AWS AgentCore Harness allow prompt injection to exfiltrate credentials, and key steps to secure your agents. The post A Vault with a Heap-View: The Uncomfortable Space Between AgentCore Harness and Identity appeared first on Unit 42.

AI SecurityCloud Security
P0
2026-09-18 09:46 UTC
Security Journalism

Brevo Supply Chain Attack Injects Malware Into 100,000 Websites

Security Week · Ionut Arghire · indexed 2026-09-18 09:50 UTC

Hackers used a compromised API key to deploy a Cloudflare worker that injected malicious scripts. The post Brevo Supply Chain Attack Injects Malware Into 100,000 Websites appeared first on SecurityWeek.

Malware
P0
2026-09-18 09:18 UTC
Security Journalism

Claimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm Stealer

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-18 09:30 UTC

A financially motivated threat actor has been linked to the development and distribution of a JavaScript (JS)-based information stealer known as PhantomRaven via the npm package registry. "The developer likely wrote the malware using a large language model (LLM), an assessment made with high confidence based on verbose comments, placeholder code, and statistical token-analysis patterns,"

AI SecurityMalwareThreat Actors
P0
2026-09-18 07:52 UTC
Other

Check Point Fixes Critical CVE-2026-91843 Allowing Root Code Execution

Security Affairs · Pierluigi Paganini · indexed 2026-09-18 08:10 UTC

Check Point fixed CVE-2026-91843, a critical flaw that could let attackers run code as root on Security Management and Log Servers with no login needed. Check Point addressed CVE-2026-91843 (CVSS score of 9.8), a critical vulnerability in its Security Management and Log Servers. The flaw could let an attacker with no account run code as […]

VulnerabilitiesCVE-2026-91843
P15
2026-09-18 07:35 UTC
Security Journalism

Microsoft fixes broken copy and paste for Excel 2016 users

BleepingComputer · Sergiu Gatlan · indexed 2026-09-18 07:45 UTC

Microsoft has fixed a known issue that causes copy-and-paste failures for some Excel users after installing the September 2026 KB5002914 security update. [...]

Microsoft
P5
2026-09-18 07:25 UTC
Security Journalism

MIND Secures $72 Million for AI-Powered DLP

Security Week · Ionut Arghire · indexed 2026-09-18 07:30 UTC

The company will use the funding to accelerate platform development and expand its presence in key enterprise markets. The post MIND Secures $72 Million for AI-Powered DLP appeared first on SecurityWeek.

P0
2026-09-18 07:14 UTC
Security Journalism

Check Point, Kaspersky, Tanium Patch Product Vulnerabilities

Security Week · Eduard Kovacs · indexed 2026-09-18 07:30 UTC

Check Point Security Management and Log Servers are affected by a critical vulnerability that can allow remote code execution with root privileges. The post Check Point, Kaspersky, Tanium Patch Product Vulnerabilities appeared first on SecurityWeek.

Vulnerabilities
P25
2026-09-18 06:17 UTC
Security Journalism

RatHat Android Malware Abuses ADB to Retain Shell Access After Uninstall

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-18 06:30 UTC

Cybersecurity researchers have flagged a new Android malware called RatHat that's assessed to be operated by China-based threat actors and features an artificial intelligence (AI)-powered system to navigate and control compromised devices. "Distributed primarily via targeted smishing (SMS/text phishing) and malvertising campaigns leading to deceptive third-party download portals, RatHat uses

AI SecurityMalwareMobile SecurityPhishingSecurity ResearchThreat Actors
P0
2026-09-18 05:00 UTC
Other

ZDI-26-718: Cisco Identity Services Engine MnTRESTLivelogService XML External Entity Processing Information Disclosure Vulnerability

Zero Day Initiative · indexed 2026-09-18 14:35 UTC

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Cisco Identity Services Engine. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 4.9. The following CVEs are assigned: CVE-2026-20235.

VulnerabilitiesCVE-2026-20235
P5
2026-09-18 05:00 UTC
Other

ZDI-26-717: Cisco Identity Services Engine AlarmMessageDiskQueue Deserialization of Untrusted Data Remote Code Execution Vulnerability

Zero Day Initiative · indexed 2026-09-18 14:35 UTC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Cisco Identity Services Engine. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-20211.

VulnerabilitiesCVE-2026-20211
P20
2026-09-18 05:00 UTC
Other

ZDI-26-716: Cisco Identity Services Engine createDBLink Command Injection Remote Code Execution Vulnerability

Zero Day Initiative · indexed 2026-09-18 14:35 UTC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Cisco Identity Services Engine. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-20176.

VulnerabilitiesCVE-2026-20176
P20
2026-09-18 05:00 UTC
Other

ZDI-26-715: Linux Mint Xreader PDF File Parsing Type Confusion Remote Code Execution Vulnerability

Zero Day Initiative · indexed 2026-09-18 14:35 UTC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Linux Mint Xreader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-19772.

LinuxVulnerabilitiesCVE-2026-19772
P20
2026-09-18 04:00 UTC
Security Journalism

North Korean hackers infect thousands of devices across 100 countries as part of ‘WaterPlum’ campaign

The Record · indexed 2026-09-18 19:10 UTC

The FBI and Defense Department partnered with Japan’s National Police Agency and law enforcement agencies in Australia and Germany on a new advisory about “WaterPlum” — a group of cyber actors allegedly stealing cryptocurrency from job applicants by posing as AI or blockchain companies.

Law Enforcement
P0
2026-09-17 23:07 UTC
Other

OpenAI admits its models lie to cover their own mistakes

Security Affairs · Pierluigi Paganini · indexed 2026-09-18 00:20 UTC

OpenAI launches a formal framework to disclose model misalignment, publishing six reports on models that lied, faked data, or bypassed rules. Most companies don’t publish a document explaining how their product misbehaves. OpenAI just did. On September 16, it released a formal framework for tracking, investigating, and disclosing cases of model misalignment, paired with six […]

P0
2026-09-17 22:00 UTC
Vendor Research

Inside the Modern SOC: Defending the Cross-Environment Pivot

Palo Alto Networks Unit 42 · Sharon Maydar · indexed 2026-09-17 22:20 UTC

Cross-environment attacks demand a new approach to security operations. Learn how Unit 42 Managed XSIAM helps SOC teams investigate complete attack paths. The post Inside the Modern SOC: Defending the Cross-Environment Pivot appeared first on Unit 42.

P0
25 26 27 28 29