IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 4,487 matching records.
AUTO-POLL // 2026-10-05 19:45 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P6 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 5

RANSOMWARE
P6
P6
COOL // 43 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
FRI
Oct 2

RANSOMWARE
P7
P7
COOL // 46 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
WED
Sep 30

RANSOMWARE
P10
P10
WARM // 59 ARTICLES
TUE
Sep 29

RANSOMWARE
P4
P4
COOL // 68 ARTICLES
RESET
2026-09-17 16:00 UTC
Vendor Research

Improving email security outcomes with real-world Microsoft Defender insights

Microsoft Security Blog · Rob Lefferts · indexed 2026-09-17 18:05 UTC

The latest email security benchmarking reports show strong Microsoft Defender performance across pre-delivery and post-delivery scenarios and reveal where threats and defenses continue to evolve. The post Improving email security outcomes with real-world Microsoft Defender insights appeared first on Microsoft Security Blog.

AppleMicrosoft
P0
2026-09-17 15:45 UTC
Security Journalism

OpenAI Says Its Models Searched GitHub for Leaked API Keys During Training

Security Week · Eduard Kovacs · indexed 2026-09-17 15:50 UTC

OpenAI published a framework for disclosing model misalignment alongside six reports describing problematic behavior. The post OpenAI Says Its Models Searched GitHub for Leaked API Keys During Training appeared first on SecurityWeek.

P0
2026-09-17 15:37 UTC
Security Journalism

Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-18 03:55 UTC

Malicious code running inside a Docker Sandboxes virtual machine on macOS could escape the project directory shared into it and read or change files anywhere else on the host, Docker warns in a security announcement on September 15. The escape runs with the rights of the host account that runs the virtual machine. The flaw, CVE-2026-77179, is rated Critical, affects versions

AppleVulnerabilitiesCVE-2026-77179
P5
2026-09-17 14:41 UTC
Other

AI Threat Landscape Digest: July–August 2026

Check Point Research · matthewsu@checkpoint.com · indexed 2026-09-17 15:10 UTC

The defining development of the period came not from attackers but from the AI labs themselves, whose models broke out of controlled evaluations and reached real systems. In the wild, the criminal and state use of AI continued to mature along the lines tracked in earlier editions: models now act as attack operators, an underground […] The post AI Threat Landscape Digest: July–August 2026 appeared first on Check Point Research.

P20
2026-09-17 14:28 UTC
Security Journalism

CISA Retires Weekly Vulnerability Bulletin in Risk-Based Pivot

Security Week · Eduard Kovacs · indexed 2026-09-17 14:30 UTC

The decision follows BOD 26-04, which directs federal organizations to prioritize vulnerabilities based on real-world risk. The post CISA Retires Weekly Vulnerability Bulletin in Risk-Based Pivot appeared first on SecurityWeek.

Vulnerabilities
P0
2026-09-17 14:16 UTC
Other

SilkParasite Infrastructure Links SpiceRAT to Central Asian Targets

Security Affairs · Pierluigi Paganini · indexed 2026-09-17 14:30 UTC

Hunt.io links SpiceRAT, NodeEdgeRAT and NomadRAT to a four-year SilkParasite campaign targeting governments and critical sectors in Central Asia. Hunt.io and researcher Guy Yasur have traced a tight cluster of SpiceRAT command‑and‑control servers that predate and extend Bitdefender’s August 2026 SilkParasite report. The work doesn’t dissect malware samples; it maps the network side of the […]

MalwareMicrosoft
P0
2026-09-17 14:03 UTC
Security Journalism

Iran-Linked Handala Hack Tied to HEAVYGRAM Telegram Backdoor That Can Steal Passwords

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-18 03:55 UTC

The Iran-linked "hacktivist" persona known as Handala Hack has been attributed to a Telegram-based surveillance backdoor called HEAVYGRAM and a Delphi-based utility known as CRUDEEXCLUDE. "HEAVYGRAM offers builtin commands supporting remote command execution, system, network and process information discovery, data and Telegram session files exfiltration, screenshot capture, DLL sideloading,

Malware
P0
2026-09-17 14:01 UTC
Security Journalism

What Recent AI-Powered Attacks Mean for Your Identity Security

BleepingComputer · Sponsored by Specops Software · indexed 2026-09-17 14:10 UTC

AI is making credential theft faster and easier to scale, giving attackers more opportunities to abuse valid identities. Specops explains why identity security must go beyond successful authentication by verifying that both the user and the device requesting access can be trusted. [...]

Phishing
P0
2026-09-17 13:57 UTC
Security Journalism

Revolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M Ransom

Security Week · Ionut Arghire · indexed 2026-09-17 14:10 UTC

Revolut allegedly fed customer information to hackers impersonating an Italian government agency for five months. The post Revolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M Ransom appeared first on SecurityWeek.

Data Breaches
P0
2026-09-17 13:32 UTC
Security Journalism

Congress eyes new support for Cyber Command after recent suicide deaths

The Record · indexed 2026-09-17 13:55 UTC

Congressional sources say they view the deaths of U.S. Cyber Command personnel as an inflection point, especially as the Pentagon’s appetite for cyber capabilities grows following successful contributions to high-profile missions against Iran and Venezuela.

P0
2026-09-17 13:00 UTC
Security Journalism

Comp AI Raises $34 Million for AI-Native Compliance and Security

Security Week · Ionut Arghire · indexed 2026-09-17 13:10 UTC

The company plans to expand into continuous cybersecurity, offering security testing across applications and infrastructure. The post Comp AI Raises $34 Million for AI-Native Compliance and Security appeared first on SecurityWeek.

P0
2026-09-17 12:39 UTC
Security Journalism

ISC Patches 14 Vulnerabilities in BIND 9 Security Update

Security Week · Ionut Arghire · indexed 2026-09-17 12:50 UTC

Attackers could exploit the flaws to increase resource usage, trigger an unexpected program exit, or terminate the named process. The post ISC Patches 14 Vulnerabilities in BIND 9 Security Update appeared first on SecurityWeek.

Cloud Security
P5
2026-09-17 12:30 UTC
Security Journalism

Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-17 13:45 UTC

Every release of the Unbound DNS resolver before 1.26.1 has a critical heap overflow in its DNSSEC validator, maintainer NLnet Labs said in an advisory on Wednesday. An attacker who controls a malicious zone and queries a vulnerable resolver can trigger it, enabling remote code execution. Unbound 1.26.1, released the same day, fixes the bug, tracked as CVE-2026-81642, along with

VulnerabilitiesCVE-2026-81642
P20
2026-09-17 12:29 UTC
Security Journalism

Ransomware Attacks on Manufacturers Surge as Supply Chain Risk Grows

Security Week · Kevin Townsend · indexed 2026-09-17 12:30 UTC

Research shows attacks on manufacturers rose 40% in early 2026, as ransomware groups increasingly exploit the supply-chain disruption caused by operational shutdowns. The post Ransomware Attacks on Manufacturers Surge as Supply Chain Risk Grows appeared first on SecurityWeek.

Ransomware
P15
2026-09-17 11:35 UTC
Other

NightmareStresser Goes Offline in Global DDoS-for-Hire Crackdown

Security Affairs · Pierluigi Paganini · indexed 2026-09-17 12:15 UTC

The DOJ seized domains behind NightmareStresser, a DDoS-for-hire service tied to hundreds of thousands of attacks since 2022, as part of Operation PowerOFF. Renting a DDoS attack used to be as easy as renting a movie. Pick a target, pay a few dollars, watch the site go dark. The Justice Department just made that a […]

Law Enforcement
P0
2026-09-17 11:33 UTC
Security Journalism

US takes down NightmareStresser DDoS-for-hire platform

BleepingComputer · Sergiu Gatlan · indexed 2026-09-17 11:40 UTC

The U.S. Federal Bureau of Investigation (FBI) seized the domains used by NightmareStresser, one of the world's longest-running distributed denial-of-service (DDoS) platforms. [...]

DFIRLaw Enforcement
P0
2026-09-17 10:50 UTC
Security Journalism

CISO's Expert Guide to Agentic Pentesting for Websites

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-17 13:45 UTC

Attackers now weaponize new vulnerabilities in about five days (Mandiant, part of Google Cloud). The median organization takes 43 days to patch one (Verizon DBIR 2026). A new free guide explains how autonomous AI agents are closing that gap, and what security leaders must demand before pointing one at production. TL;DR Exploitation is now the front door. It starts 31% of breaches (Verizon DBIR

AI SecurityCloud Security
P0
2026-09-17 10:05 UTC
Security Journalism

China-Aligned FamousSparrow Deploys SparroWocky Backdoor Across Latin America

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-17 13:45 UTC

The China-aligned state-sponsored threat actor known as FamousSparrow has been observed deploying a previously unreported backdoor called SparroWocky in attacks targeting multiple countries in Latin America since at least August 2025. "SparroWocky is a modular, C++ backdoor," ESET security researchers Alexandre Côté Cyr and Romain Dumont said in a technical report shared with The Hacker News

APT / Nation-StateMalwareSecurity ResearchThreat Actors
P0
2026-09-17 10:00 UTC
Vendor Research

Ransomware incidents in Japan in the first half of 2026: Investigation of The Gentlemen’s infrastructure and evidence of Qilin's AI use

Cisco Talos Intelligence Blog · Takahiro Takeda · indexed 2026-09-17 10:15 UTC

Ransomware incidents in Japan rose 4.7% year over year. The Gentlemen was the most active group, with leak-site listings more than doubling from January to July. Qilin ranked second and appeared to use AI, while SMEs with capital under JPY 1 billion represented 80% of victims.

DFIRRansomware
P15
2026-09-17 09:53 UTC
Security Journalism

OpenAI Reveals Six Model Incidents Involving Hidden Failures and Unauthorized Uploads

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-17 13:45 UTC

OpenAI on Wednesday disclosed six new instances of "unexpected or concerning model behavior" that took place over the past six months, while sharing a new framework for reporting, tracking, investigating, and disclosing model misalignment in a bid to improve transparency. "As AI systems grow more advanced and more widely deployed, we need to build a broader and better-informed consensus on the

P0
2026-09-17 09:26 UTC
Other

U.S. CISA adds Acronis Backup, Cisco ISE, and Google Pixel flaws to its Known Exploited Vulnerabilities catalog

Security Affairs · Pierluigi Paganini · indexed 2026-09-17 10:20 UTC

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Acronis Backup, Cisco ISE, and Google Pixel flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added [1, 2] the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2026-76460 is an authentication bypass vulnerability affecting an API in Cisco Identity Services Engine (ISE). The flaw […]

Cloud SecurityVulnerabilitiesCVE-2026-76460
P45
28 29 30 31 32