IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 4,443 matching records.
AUTO-POLL // 2026-10-04 18:05 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P5 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 4

RANSOMWARE
P5
P5
COOL // 10 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
FRI
Oct 2

RANSOMWARE
P7
P7
COOL // 46 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
WED
Sep 30

RANSOMWARE
P10
P10
WARM // 59 ARTICLES
TUE
Sep 29

RANSOMWARE
P4
P4
COOL // 68 ARTICLES
MON
Sep 28

RANSOMWARE
P7
P7
COOL // 52 ARTICLES
RESET
2026-09-17 13:00 UTC
Security Journalism

Comp AI Raises $34 Million for AI-Native Compliance and Security

Security Week · Ionut Arghire · indexed 2026-09-17 13:10 UTC

The company plans to expand into continuous cybersecurity, offering security testing across applications and infrastructure. The post Comp AI Raises $34 Million for AI-Native Compliance and Security appeared first on SecurityWeek.

P0
2026-09-17 12:39 UTC
Security Journalism

ISC Patches 14 Vulnerabilities in BIND 9 Security Update

Security Week · Ionut Arghire · indexed 2026-09-17 12:50 UTC

Attackers could exploit the flaws to increase resource usage, trigger an unexpected program exit, or terminate the named process. The post ISC Patches 14 Vulnerabilities in BIND 9 Security Update appeared first on SecurityWeek.

Cloud Security
P5
2026-09-17 12:30 UTC
Security Journalism

Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-17 13:45 UTC

Every release of the Unbound DNS resolver before 1.26.1 has a critical heap overflow in its DNSSEC validator, maintainer NLnet Labs said in an advisory on Wednesday. An attacker who controls a malicious zone and queries a vulnerable resolver can trigger it, enabling remote code execution. Unbound 1.26.1, released the same day, fixes the bug, tracked as CVE-2026-81642, along with

VulnerabilitiesCVE-2026-81642
P20
2026-09-17 12:29 UTC
Security Journalism

Ransomware Attacks on Manufacturers Surge as Supply Chain Risk Grows

Security Week · Kevin Townsend · indexed 2026-09-17 12:30 UTC

Research shows attacks on manufacturers rose 40% in early 2026, as ransomware groups increasingly exploit the supply-chain disruption caused by operational shutdowns. The post Ransomware Attacks on Manufacturers Surge as Supply Chain Risk Grows appeared first on SecurityWeek.

Ransomware
P15
2026-09-17 11:35 UTC
Other

NightmareStresser Goes Offline in Global DDoS-for-Hire Crackdown

Security Affairs · Pierluigi Paganini · indexed 2026-09-17 12:15 UTC

The DOJ seized domains behind NightmareStresser, a DDoS-for-hire service tied to hundreds of thousands of attacks since 2022, as part of Operation PowerOFF. Renting a DDoS attack used to be as easy as renting a movie. Pick a target, pay a few dollars, watch the site go dark. The Justice Department just made that a […]

Law Enforcement
P0
2026-09-17 11:33 UTC
Security Journalism

US takes down NightmareStresser DDoS-for-hire platform

BleepingComputer · Sergiu Gatlan · indexed 2026-09-17 11:40 UTC

The U.S. Federal Bureau of Investigation (FBI) seized the domains used by NightmareStresser, one of the world's longest-running distributed denial-of-service (DDoS) platforms. [...]

DFIRLaw Enforcement
P0
2026-09-17 10:50 UTC
Security Journalism

CISO's Expert Guide to Agentic Pentesting for Websites

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-17 13:45 UTC

Attackers now weaponize new vulnerabilities in about five days (Mandiant, part of Google Cloud). The median organization takes 43 days to patch one (Verizon DBIR 2026). A new free guide explains how autonomous AI agents are closing that gap, and what security leaders must demand before pointing one at production. TL;DR Exploitation is now the front door. It starts 31% of breaches (Verizon DBIR

AI SecurityCloud Security
P0
2026-09-17 10:05 UTC
Security Journalism

China-Aligned FamousSparrow Deploys SparroWocky Backdoor Across Latin America

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-17 13:45 UTC

The China-aligned state-sponsored threat actor known as FamousSparrow has been observed deploying a previously unreported backdoor called SparroWocky in attacks targeting multiple countries in Latin America since at least August 2025. "SparroWocky is a modular, C++ backdoor," ESET security researchers Alexandre Côté Cyr and Romain Dumont said in a technical report shared with The Hacker News

APT / Nation-StateMalwareSecurity ResearchThreat Actors
P0
2026-09-17 10:00 UTC
Vendor Research

Ransomware incidents in Japan in the first half of 2026: Investigation of The Gentlemen’s infrastructure and evidence of Qilin's AI use

Cisco Talos Intelligence Blog · Takahiro Takeda · indexed 2026-09-17 10:15 UTC

Ransomware incidents in Japan rose 4.7% year over year. The Gentlemen was the most active group, with leak-site listings more than doubling from January to July. Qilin ranked second and appeared to use AI, while SMEs with capital under JPY 1 billion represented 80% of victims.

DFIRRansomware
P15
2026-09-17 09:53 UTC
Security Journalism

OpenAI Reveals Six Model Incidents Involving Hidden Failures and Unauthorized Uploads

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-17 13:45 UTC

OpenAI on Wednesday disclosed six new instances of "unexpected or concerning model behavior" that took place over the past six months, while sharing a new framework for reporting, tracking, investigating, and disclosing model misalignment in a bid to improve transparency. "As AI systems grow more advanced and more widely deployed, we need to build a broader and better-informed consensus on the

P0
2026-09-17 09:26 UTC
Other

U.S. CISA adds Acronis Backup, Cisco ISE, and Google Pixel flaws to its Known Exploited Vulnerabilities catalog

Security Affairs · Pierluigi Paganini · indexed 2026-09-17 10:20 UTC

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Acronis Backup, Cisco ISE, and Google Pixel flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added [1, 2] the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2026-76460 is an authentication bypass vulnerability affecting an API in Cisco Identity Services Engine (ISE). The flaw […]

Cloud SecurityVulnerabilitiesCVE-2026-76460
P45
2026-09-17 08:24 UTC
Security Journalism

Microsoft shares workaround for Windows domain login issues

BleepingComputer · Sergiu Gatlan · indexed 2026-09-17 08:30 UTC

Microsoft shared a temporary fix on Wednesday for a known issue that prevents Windows 11 users from logging in with valid domain credentials after installing the September 2026 security updates. [...]

Microsoft
P5
2026-09-17 08:00 UTC
Security Journalism

BIND 9 Update Fixes 14 Flaws, Including an Unauthenticated Crash Over DNS-over-HTTPS

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-17 13:45 UTC

The Internet Systems Consortium (ISC) has released BIND 9.20.29 and 9.21.26 to fix fourteen security flaws it disclosed on 16 September in BIND 9, its open-source DNS server software. One of them affects any BIND server that answers DNS-over-HTTPS (DoH). A sender with no credentials can crash the server process, named, with a single request that carries an invalid SIG

Cloud Security
P0
2026-09-17 07:53 UTC
Security Journalism

CISA Releases Cyber Decoy Guidance to Strengthen Critical Infrastructure Defenses

Security Week · Ionut Arghire · indexed 2026-09-17 07:55 UTC

Complementing Zero Trust models, decoys enable organizations to detect, observe, and block malicious activity in their environments. The post CISA Releases Cyber Decoy Guidance to Strengthen Critical Infrastructure Defenses appeared first on SecurityWeek.

P0
2026-09-17 07:41 UTC
Security Journalism

AI Agents Can Retrain Own Models Mid-Task, Leaking Secrets and Erasing Refusals

Security Week · Eduard Kovacs · indexed 2026-09-17 07:55 UTC

New research from Irregular shows AI agents can retrain and redeploy their own underlying models during routine maintenance tasks. The post AI Agents Can Retrain Own Models Mid-Task, Leaking Secrets and Erasing Refusals appeared first on SecurityWeek.

AI Security
P0
2026-09-17 07:30 UTC
Security Journalism

Gyazo Breach Exposes 23.62 Million User Records and 490 Million Image Metadata Records

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-17 13:45 UTC

A security breach at Gyazo, Helpfeel's image-sharing service, exposed about 23.62 million user records, including email addresses and password hashes, the Kyoto-based company said in a notice published Wednesday. It also exposed about 490 million image metadata records, mostly for images from January 2019 or earlier, including the IDs that make up Gyazo image links. Helpfeel said

P0
2026-09-17 07:25 UTC
Other

Chosen Brick, Iran’s Surveillance Malware

Security Affairs · Pierluigi Paganini · indexed 2026-09-17 08:00 UTC

UK, US, and Dutch agencies expose Chosen Brick, Iranian malware used to track and harass dissidents, journalists, and activists via Telegram. The UK, the US, and the Netherlands published a joint advisory warning about a Windows malware family, dubbed Chosen Brick, that Iran’s intelligence services use to track down dissidents, journalists, and activists, and the […]

MalwareMicrosoft
P0
2026-09-17 07:20 UTC
Other

HEAVYGRAM: A Telegram-based Surveillance Backdoor Linked to Handala Hack

Group-IB · indexed 2026-09-17 08:35 UTC

Group-IB Threat Intelligence analyzes HEAVYGRAM, a Telegram-based Windows backdoor attributed with moderate confidence to the Iran-linked threat actor Handala Hack. Active since Fall 2023, it has been used to surveil Iranian dissidents, journalists and government opponents, enabling remote command execution, data exfiltration, and persistence over Telegram command-and-control.

MalwareMicrosoftThreat ActorsThreat Intelligence
P0
2026-09-17 06:39 UTC
Security Journalism

Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-17 13:45 UTC

Cisco has warned of a fresh maximum-severity security flaw impacting Identity Services Engine (ISE) that has come under active exploitation. The vulnerability, tracked as CVE-2026-76460 (CVSS score: 10.0), could allow an unauthenticated, remote attacker to bypass authentication. "This vulnerability is due to insufficient authentication control on an API endpoint," Cisco said. "An attacker

VulnerabilitiesCVE-2026-76460
P30
2026-09-17 06:19 UTC
Security Journalism

Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day

Security Week · Ionut Arghire · indexed 2026-09-17 06:35 UTC

Remote, unauthenticated attackers can exploit the vulnerability to bypass authentication via crafted requests. The post Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day appeared first on SecurityWeek.

Vulnerabilities
P25
2026-09-17 05:59 UTC
Other

Top 5 Fraud Prevention Platforms for Banks and Fintechs in 2026

Group-IB · indexed 2026-09-17 08:35 UTC

Most fraud platforms only see a threat once it becomes a transaction. This guide compares the top 5 fraud prevention platforms for banks and fintechs in 2026, including Group-IB, Feedzai, Sift, DataVisor, and Kount, and what actually separates them.

Cybercrime
P0
2026-09-17 05:13 UTC
Security Journalism

U.S. Seizes NightmareStresser Domains Linked to Hundreds of Thousands of DDoS Attacks

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-17 13:45 UTC

The U.S. Department of Justice (DoJ) on Tuesday announced the court-authorized seizure of internet domains associated with a distributed denial-of-service (DDoS)-for-hire service known as NightmareStresser. The domains in question are: nightmare-stresser[.]com and nightmarestresser[.]org. Visitors to the sites are now greeted by a seizure banner that states - "This domain has been seized by

Law Enforcement
P0
2026-09-17 05:00 UTC
Other

ZDI-26-714: Samsung rlottie Stack-based Buffer Overflow Remote Code Execution Vulnerability

Zero Day Initiative · indexed 2026-09-17 14:55 UTC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Samsung rlottie. Interaction with the rlottie library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-91826.

VulnerabilitiesCVE-2026-91826
P20
27 28 29 30 31