IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 4,433 matching records.
AUTO-POLL // 2026-10-04 07:25 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
NO DATA
NO INTELLIGENCE AGGREGATED TODAY
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 4
NO DATA
--
NO INTEL
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
FRI
Oct 2

RANSOMWARE
P7
P7
COOL // 46 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
WED
Sep 30

RANSOMWARE
P10
P10
WARM // 59 ARTICLES
TUE
Sep 29

RANSOMWARE
P4
P4
COOL // 68 ARTICLES
MON
Sep 28

RANSOMWARE
P7
P7
COOL // 52 ARTICLES
RESET
2026-10-01 21:15 UTC
Vendor Research

CVE-2026-104002: Fail-open error handling in the data masking utility in Powertools for AWS Lambda (Python)

AWS Security Bulletins · aws@amazon.com · indexed 2026-10-01 21:35 UTC

Bulletin ID: 2026-123-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 10/01/2026 14:00 PM PDT Description: Powertools for AWS Lambda (Python) is a developer toolkit that implements serverless best practices and increases developer velocity. We identified CVE-2026-104002, a fail-open error handling issue within the data masking utility of Powertools for AWS Lambda (Python). This issue might allow actors to read sensitive field values that the application intended to…

Cloud SecurityVulnerabilitiesCVE-2026-104002
P5
2026-10-01 20:50 UTC
Vendor Research

CVE-2026-104020 - Uncontrolled recursion in the Ion reader in Amazon Ion Python

AWS Security Bulletins · aws@amazon.com · indexed 2026-10-01 21:00 UTC

Bulletin ID: 2026-122-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 10/01/2026 13:30 PM PDT Description: Amazon Ion Python is an open-source Python implementation of the Amazon Ion data notation. We identified CVE-2026-104020, an issue in the Ion reader in Amazon Ion Python before version 0.15.0 where a crafted, deeply nested Ion value could cause the application to raise an error or crash, resulting in a denial of service. Impacted versions: < 0.15.0 Please refe…

Cloud SecurityVulnerabilitiesCVE-2026-104020
P5
2026-10-01 18:16 UTC
Vendor Research

CVE-2026-97662 - Argument injection in AWS security-agent-mcp-server diff scan

AWS Security Bulletins · aws@amazon.com · indexed 2026-10-01 18:20 UTC

Bulletin ID: 2026-121-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 10/01/2026 10:30 AM PDT Description: security-agent-mcp-server is an open-source Model Context Protocol (MCP) server, published by AWS in the awslabs/mcp repository, that AI assistants use to run local security scans (including differential "diff" scans) over source code. We identified CVE-2026-97662, an argument injection issue in the diff scan operation: a crafted reference value supplied to th…

Cloud SecurityVulnerabilitiesCVE-2026-97662
P5
2026-10-01 18:08 UTC
Other

Operation KillSwitch: Police Dismantle KillSec Ransomware Group

Security Affairs · Pierluigi Paganini · indexed 2026-10-01 19:00 UTC

Operation KillSwitch: Europol says the KillSec ransomware group, allegedly led by a 16-year-old, was dismantled after attacks on about 1,000 victims. Law enforcement seized control of KillSec ‘s dark web leak site, the Tor website the group used to threaten victims with publishing stolen files unless they paid up. That single action locked down more […]

CybercrimeLaw EnforcementNetwork SecurityRansomware
P15
2026-10-01 18:00 UTC
Vendor Research

Give yourself room to be human

Cisco Talos Intelligence Blog · Amy Ciminnisi · indexed 2026-10-01 18:05 UTC

In this week’s edition, Amy reflects on the importance of prioritizing family and personal well-being over the pressure to remain constantly productive.

P0
2026-10-01 18:00 UTC
Security Journalism

Zero Trust Creator Says Model Holds Firm Against AI-Assisted Attacks

Security Week · Kevin Townsend · indexed 2026-10-01 18:20 UTC

Fifteen years after coining the framework, John Kindervag insists zero trust still works in the AI era—if you get the implementation right. The post Zero Trust Creator Says Model Holds Firm Against AI-Assisted Attacks appeared first on SecurityWeek.

P0
2026-10-01 17:16 UTC
Security Journalism

Osavul Lands $10 Million to Spot Hostile Intent Across Cyber, Physical Domains

Security Week · SecurityWeek News · indexed 2026-10-01 17:20 UTC

Hybrid risk intelligence company Osavul has raised $10 million in a Series A funding round led by 33N Ventures. The post Osavul Lands $10 Million to Spot Hostile Intent Across Cyber, Physical Domains appeared first on SecurityWeek.

P0
2026-10-01 16:55 UTC
Security Journalism

Police Arrest 16-Year-Old Suspected of Running KillSec, Seize Ransomware Leak Site and Servers

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-01 17:15 UTC

Police in Spain have arrested a 16-year-old whom investigators suspect of running the KillSec ransomware group. KillSec is accused of stealing data from organizations and threatening to publish it on its leak site unless they paid. The 16-year-old was one of 3 people arrested on September 30, when police also took control of that site. Investigators identified him as KillSec's suspected

Law EnforcementRansomware
P15
2026-10-01 16:45 UTC
Security Journalism

ThreatsDay: AI-Powered Zero-Day Chain, 543K Live Secrets, Model Inspection RCE and 13 More Stories

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-01 17:15 UTC

This week, the useful words are boring ones: inspect, cache, compile, store, trust. Each sounds harmless. Each can become an attack path when a system does a little more than people expect. A model check can run code. A cache can mix up requests. A public secret can stay useful for years. That is the lesson running through the list. Attackers do not always need a brilliant new trick. They can

Vulnerabilities
P40
2026-10-01 14:37 UTC
Security Journalism

WordPress Backdoor Rebuilds Itself After Cleanup Using Files, Database, and Shared Memory

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-01 14:50 UTC

Cybersecurity researchers have shed light on a WordPress compromise in which threat actors deployed multiple persistence mechanisms to ensure that the final payload kept returning without having to infect the site again. The backdoor has been codenamed SC after the "SC_" markers present in the injected content. Sucuri has described the malware as a "self-healing mesh" that's

MalwareSecurity ResearchThreat Actors
P0
2026-10-01 14:30 UTC
Security Journalism

Hacker Conversations: Rob Juncker, a Knock at the Door and a Moral Compass

Security Week · Kevin Townsend · indexed 2026-10-01 14:40 UTC

Rob Juncker is chief product and technology officer at Mimecast. Is he a hacker? “Unequivocally yes,” he says. The post Hacker Conversations: Rob Juncker, a Knock at the Door and a Moral Compass appeared first on SecurityWeek.

P0
2026-10-01 14:30 UTC
Security Journalism

Enterprises Struggle to Prepare for AI and Quantum Threats, PwC Says

Security Week · Kevin Townsend · indexed 2026-10-01 14:40 UTC

PwC’s survey found that only 22% of leaders would use fully autonomous AI for cyber defense, while just 21% are implementing quantum-resistant security measures. The post Enterprises Struggle to Prepare for AI and Quantum Threats, PwC Says appeared first on SecurityWeek.

P0
2026-10-01 14:17 UTC
Security Journalism

Police Shut Down KillSec Ransomware, Identify Alleged Teen Leader

Security Week · Eduard Kovacs · indexed 2026-10-01 14:20 UTC

Police took control of KillSec’s leak site and secured at least 110 terabytes of data stolen from victims. The post Police Shut Down KillSec Ransomware, Identify Alleged Teen Leader appeared first on SecurityWeek.

Ransomware
P15
2026-10-01 14:01 UTC
Security Journalism

The Day-One Hole in Zero Trust Architecture

BleepingComputer · Sponsored by Specops Software · indexed 2026-10-01 14:15 UTC

Zero Trust can verify users once they are established, but onboarding creates a gap where organizations must decide who to trust before strong authentication exists. Specops explains why identity verification should begin before credentials, MFA methods, and access are issued. [...]

P0
2026-10-01 14:00 UTC
Vendor Research

Preparing governments for an era of interconnected cyber risk

Microsoft Security Blog · Matthew Thomas · indexed 2026-10-01 14:40 UTC

According to this year’s Microsoft Digital Defense Report, government agencies and services were the sector most impacted by cyber threats in 2026, accounting for 27% of observed activity, up from 17% in 2025. The post Preparing governments for an era of interconnected cyber risk appeared first on Microsoft Security Blog.

Microsoft
P0
2026-10-01 14:00 UTC
Vendor Research

Insights from the 2026 Microsoft Digital Defense Report

Microsoft Security Blog · Terrell Cox · indexed 2026-10-01 14:40 UTC

Read highlights from the 2026 Microsoft Digital Defense Report, which reflects a security environment that continues to grow more interconnected. The post Insights from the 2026 Microsoft Digital Defense Report appeared first on Microsoft Security Blog.

Microsoft
P0
2026-10-01 13:51 UTC
Security Journalism

Kiteworks patches max severity code injection vulnerability

BleepingComputer · Sergiu Gatlan · indexed 2026-10-01 14:00 UTC

Secure file-sharing software company Kiteworks has released security updates to address 126 vulnerabilities, including a max-severity flaw affecting its Email Protection Gateway (EPG) security solution. [...]

Vulnerabilities
P5
2026-10-01 13:33 UTC
Other

Inside Gemini 4 Argon, the model Google is testing on its own infrastructure first

Security Affairs · Pierluigi Paganini · indexed 2026-10-02 07:20 UTC

Google unveils Gemini 4 Argon, a frontier AI model built for coding, enterprise work, and autonomous cybersecurity defense, rolling out to trusted testers. Google announced Gemini 4 Argon, and it’s not going straight to the public. It’s rolling out first to a set of trusted cyber defenders through what Google calls the Fairwind Program, which […]

Microsoft
P0
1 2 3 4 5