IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 4,443 matching records.
AUTO-POLL // 2026-10-04 18:00 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P5 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 4

RANSOMWARE
P5
P5
COOL // 10 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
FRI
Oct 2

RANSOMWARE
P7
P7
COOL // 46 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
WED
Sep 30

RANSOMWARE
P10
P10
WARM // 59 ARTICLES
TUE
Sep 29

RANSOMWARE
P4
P4
COOL // 68 ARTICLES
MON
Sep 28

RANSOMWARE
P7
P7
COOL // 52 ARTICLES
RESET
2026-09-17 21:19 UTC
Vendor Research

Run open weight models on Amazon Bedrock in AWS European Sovereign Cloud

AWS Security Blog · Marta Taggart · indexed 2026-09-17 21:40 UTC

European organizations can run AI workloads on Amazon Web Services (AWS) while keeping data within the European Union (EU) and meeting regulatory requirements. You can now run generative AI workloads on open weight models on Amazon Bedrock in the AWS European Sovereign Cloud. We’re excited to announce the general availability of the first open weight […]

Cloud Security
P0
2026-09-17 21:13 UTC
Vendor Research

Cisco IOS XR Software Security Hardening Release: September 2026

Cisco Security Advisories · indexed 2026-09-02 16:10 UTC

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. These vulnerabilities were found during internal testing and are not known to be actively exploited. To assist customers in patching and streamline the disclosure process, Cisco has grouped these issues by …

AppleVulnerabilitiesCVE-2026-20274CVE-2026-20275CVE-2026-20276CVE-2026-20277CVE-2026-20278CVE-2026-20279CVE-2026-20280
P30
2026-09-17 19:18 UTC
Vendor Research

CVE-2026-92943 - Improper validation of certificate with host mismatch in AWS IoT Device SDK for Python

AWS Security Bulletins · aws@amazon.com · indexed 2026-09-17 19:25 UTC

Bulletin ID: 2026-115-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/17/2026 12:00 PM PDT Description: AWS IoT Device SDK for Python (AWSIoTPythonSDK) is an open source SDK that lets IoT devices and gateways connect to AWS IoT Core over MQTT. We identified CVE-2026-92943 in the MQTT client TLS connection layer, where the client did not validate that the server certificate matched the AWS IoT Core endpoint hostname. On Python 3.7 and later, an adversary-in-the-m…

Cloud SecurityVulnerabilitiesCVE-2026-92943
P5
2026-09-17 18:55 UTC
Security Journalism

OpenAI details more cases of AI agents taking unauthorized actions

BleepingComputer · Bill Toulas · indexed 2026-09-17 19:00 UTC

OpenAI has presented new examples of what they call "AI model misalignment" from the past six months, including unauthorized file uploads, following self-generated instructions, hiding mistakes, and leveraging exposed API keys. [...]

AI Security
P0
2026-09-17 18:08 UTC
Security Journalism

Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-18 03:55 UTC

A critical vulnerability in Check Point's Security Management and Log Servers could allow an attacker without login credentials to run code as root on those servers over the network. The Security Management Server is the system that controls firewall policy and administrator access. Check Point has released a fix through its LivePatch update channel and says it has no indication that the flaw

Network SecurityVulnerabilities
P10
2026-09-17 18:06 UTC
Other

Cyberattacks on Oil Tankers Put Maritime Critical Infrastructure at Risk

Security Affairs · Pierluigi Paganini · indexed 2026-09-17 18:45 UTC

Cyberattacks on oil tankers show how connected ships can expose navigation and critical systems, threatening safety, ports and global trade. U.S. Coast Guard personnel and FBI agents boarded two Texas‑bound energy tankers last month after cyberattacks hit the vessels while they were underway, according to U.S. officials. One of the ships was the VL Prosperity, […]

Law Enforcement
P0
2026-09-17 18:00 UTC
Vendor Research

Should you care about an “AI slowdown?”

Cisco Talos Intelligence Blog · David J. Bianco · indexed 2026-09-17 18:20 UTC

In this week's Threat Source, David talks about why focusing on your security basics is still your best bet, even in a world with rapid AI advancements.

P0
2026-09-17 17:32 UTC
Security Journalism

ThreatsDay: Self-Rewriting Agents, 800+ Flaws Patched, Insider SIM Swaps and 22 More New Stories

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-18 03:55 UTC

Attackers keep finding new keys. The funny part is that defenders keep inventing where to store them. This week, those keys sit in AI tools, exposed services, old bugs, weak logins, and software sold like a monthly subscription. Some attacks use new tricks. Others just reuse what was already lying around. Both work often enough. So the threat landscape is not getting cleaner. It is just

Cloud SecurityMicrosoft
P0
2026-09-17 17:11 UTC
Security Journalism

Brevo supply-chain attack injected ClickFix scripts on customer sites

BleepingComputer · Bill Toulas · indexed 2026-09-17 17:20 UTC

Brevo confirmed that attackers stole a Cloudflare API key and used it to inject malicious ClickFix scripts into its websites and JavaScript files embedded on customer sites to distribute malware. [...]

Malware
P0
2026-09-17 17:09 UTC
Security Journalism

Cyberattacks on Two Oil Tankers Prompt Coast Guard, FBI to Board Vessels

Security Week · Eduard Kovacs · indexed 2026-09-17 17:10 UTC

The Coast Guard confirmed evidence of malicious cyber activity on the VL Prosperity, but has not attributed the attack to Iran. The post Cyberattacks on Two Oil Tankers Prompt Coast Guard, FBI to Board Vessels appeared first on SecurityWeek.

Law Enforcement
P0
2026-09-17 17:00 UTC
Vendor Research

From guidance to action: Security fundamentals that materially reduce risk

Microsoft Security Blog · Ron Pessner · indexed 2026-09-17 18:45 UTC

AI has made fundamental changes to the operating environment for cybersecurity. Explore exposure management guidance on recommended controls and take action and stay ahead of cyberthreats. The post From guidance to action: Security fundamentals that materially reduce risk appeared first on Microsoft Security Blog.

Microsoft
P0
2026-09-17 16:47 UTC
Vendor Research

Cisco Secure Email Gateway SQL Injection Vulnerability

Cisco Security Advisories · indexed 2026-09-14 16:20 UTC

A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. This vulnerability is due to insufficient validation in the email parsing logic. An attacker could exploit this vulnerability by sending a crafted email message that contains malicious SQL statements through an affected device. A successful exploit could allow the attac…

VulnerabilitiesCVE-2026-76461
P5
2026-09-17 16:00 UTC
Vendor Research

Improving email security outcomes with real-world Microsoft Defender insights

Microsoft Security Blog · Rob Lefferts · indexed 2026-09-17 18:05 UTC

The latest email security benchmarking reports show strong Microsoft Defender performance across pre-delivery and post-delivery scenarios and reveal where threats and defenses continue to evolve. The post Improving email security outcomes with real-world Microsoft Defender insights appeared first on Microsoft Security Blog.

AppleMicrosoft
P0
2026-09-17 15:45 UTC
Security Journalism

OpenAI Says Its Models Searched GitHub for Leaked API Keys During Training

Security Week · Eduard Kovacs · indexed 2026-09-17 15:50 UTC

OpenAI published a framework for disclosing model misalignment alongside six reports describing problematic behavior. The post OpenAI Says Its Models Searched GitHub for Leaked API Keys During Training appeared first on SecurityWeek.

P0
2026-09-17 15:37 UTC
Security Journalism

Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-18 03:55 UTC

Malicious code running inside a Docker Sandboxes virtual machine on macOS could escape the project directory shared into it and read or change files anywhere else on the host, Docker warns in a security announcement on September 15. The escape runs with the rights of the host account that runs the virtual machine. The flaw, CVE-2026-77179, is rated Critical, affects versions

AppleVulnerabilitiesCVE-2026-77179
P5
2026-09-17 14:41 UTC
Other

AI Threat Landscape Digest: July–August 2026

Check Point Research · matthewsu@checkpoint.com · indexed 2026-09-17 15:10 UTC

The defining development of the period came not from attackers but from the AI labs themselves, whose models broke out of controlled evaluations and reached real systems. In the wild, the criminal and state use of AI continued to mature along the lines tracked in earlier editions: models now act as attack operators, an underground […] The post AI Threat Landscape Digest: July–August 2026 appeared first on Check Point Research.

P20
2026-09-17 14:28 UTC
Security Journalism

CISA Retires Weekly Vulnerability Bulletin in Risk-Based Pivot

Security Week · Eduard Kovacs · indexed 2026-09-17 14:30 UTC

The decision follows BOD 26-04, which directs federal organizations to prioritize vulnerabilities based on real-world risk. The post CISA Retires Weekly Vulnerability Bulletin in Risk-Based Pivot appeared first on SecurityWeek.

Vulnerabilities
P0
2026-09-17 14:16 UTC
Other

SilkParasite Infrastructure Links SpiceRAT to Central Asian Targets

Security Affairs · Pierluigi Paganini · indexed 2026-09-17 14:30 UTC

Hunt.io links SpiceRAT, NodeEdgeRAT and NomadRAT to a four-year SilkParasite campaign targeting governments and critical sectors in Central Asia. Hunt.io and researcher Guy Yasur have traced a tight cluster of SpiceRAT command‑and‑control servers that predate and extend Bitdefender’s August 2026 SilkParasite report. The work doesn’t dissect malware samples; it maps the network side of the […]

MalwareMicrosoft
P0
2026-09-17 14:03 UTC
Security Journalism

Iran-Linked Handala Hack Tied to HEAVYGRAM Telegram Backdoor That Can Steal Passwords

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-18 03:55 UTC

The Iran-linked "hacktivist" persona known as Handala Hack has been attributed to a Telegram-based surveillance backdoor called HEAVYGRAM and a Delphi-based utility known as CRUDEEXCLUDE. "HEAVYGRAM offers builtin commands supporting remote command execution, system, network and process information discovery, data and Telegram session files exfiltration, screenshot capture, DLL sideloading,

Malware
P0
2026-09-17 14:01 UTC
Security Journalism

What Recent AI-Powered Attacks Mean for Your Identity Security

BleepingComputer · Sponsored by Specops Software · indexed 2026-09-17 14:10 UTC

AI is making credential theft faster and easier to scale, giving attackers more opportunities to abuse valid identities. Specops explains why identity security must go beyond successful authentication by verifying that both the user and the device requesting access can be trusted. [...]

Phishing
P0
2026-09-17 13:57 UTC
Security Journalism

Revolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M Ransom

Security Week · Ionut Arghire · indexed 2026-09-17 14:10 UTC

Revolut allegedly fed customer information to hackers impersonating an Italian government agency for five months. The post Revolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M Ransom appeared first on SecurityWeek.

Data Breaches
P0
2026-09-17 13:32 UTC
Security Journalism

Congress eyes new support for Cyber Command after recent suicide deaths

The Record · indexed 2026-09-17 13:55 UTC

Congressional sources say they view the deaths of U.S. Cyber Command personnel as an inflection point, especially as the Pentagon’s appetite for cyber capabilities grows following successful contributions to high-profile missions against Iran and Venezuela.

P0
26 27 28 29 30