IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 4,487 matching records.
AUTO-POLL // 2026-10-05 19:45 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P6 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 5

RANSOMWARE
P6
P6
COOL // 43 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
FRI
Oct 2

RANSOMWARE
P7
P7
COOL // 46 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
WED
Sep 30

RANSOMWARE
P10
P10
WARM // 59 ARTICLES
TUE
Sep 29

RANSOMWARE
P4
P4
COOL // 68 ARTICLES
RESET
2026-09-17 08:24 UTC
Security Journalism

Microsoft shares workaround for Windows domain login issues

BleepingComputer · Sergiu Gatlan · indexed 2026-09-17 08:30 UTC

Microsoft shared a temporary fix on Wednesday for a known issue that prevents Windows 11 users from logging in with valid domain credentials after installing the September 2026 security updates. [...]

Microsoft
P5
2026-09-17 08:00 UTC
Security Journalism

BIND 9 Update Fixes 14 Flaws, Including an Unauthenticated Crash Over DNS-over-HTTPS

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-17 13:45 UTC

The Internet Systems Consortium (ISC) has released BIND 9.20.29 and 9.21.26 to fix fourteen security flaws it disclosed on 16 September in BIND 9, its open-source DNS server software. One of them affects any BIND server that answers DNS-over-HTTPS (DoH). A sender with no credentials can crash the server process, named, with a single request that carries an invalid SIG

Cloud Security
P0
2026-09-17 07:53 UTC
Security Journalism

CISA Releases Cyber Decoy Guidance to Strengthen Critical Infrastructure Defenses

Security Week · Ionut Arghire · indexed 2026-09-17 07:55 UTC

Complementing Zero Trust models, decoys enable organizations to detect, observe, and block malicious activity in their environments. The post CISA Releases Cyber Decoy Guidance to Strengthen Critical Infrastructure Defenses appeared first on SecurityWeek.

P0
2026-09-17 07:41 UTC
Security Journalism

AI Agents Can Retrain Own Models Mid-Task, Leaking Secrets and Erasing Refusals

Security Week · Eduard Kovacs · indexed 2026-09-17 07:55 UTC

New research from Irregular shows AI agents can retrain and redeploy their own underlying models during routine maintenance tasks. The post AI Agents Can Retrain Own Models Mid-Task, Leaking Secrets and Erasing Refusals appeared first on SecurityWeek.

AI Security
P0
2026-09-17 07:30 UTC
Security Journalism

Gyazo Breach Exposes 23.62 Million User Records and 490 Million Image Metadata Records

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-17 13:45 UTC

A security breach at Gyazo, Helpfeel's image-sharing service, exposed about 23.62 million user records, including email addresses and password hashes, the Kyoto-based company said in a notice published Wednesday. It also exposed about 490 million image metadata records, mostly for images from January 2019 or earlier, including the IDs that make up Gyazo image links. Helpfeel said

P0
2026-09-17 07:25 UTC
Other

Chosen Brick, Iran’s Surveillance Malware

Security Affairs · Pierluigi Paganini · indexed 2026-09-17 08:00 UTC

UK, US, and Dutch agencies expose Chosen Brick, Iranian malware used to track and harass dissidents, journalists, and activists via Telegram. The UK, the US, and the Netherlands published a joint advisory warning about a Windows malware family, dubbed Chosen Brick, that Iran’s intelligence services use to track down dissidents, journalists, and activists, and the […]

MalwareMicrosoft
P0
2026-09-17 07:20 UTC
Other

HEAVYGRAM: A Telegram-based Surveillance Backdoor Linked to Handala Hack

Group-IB · indexed 2026-09-17 08:35 UTC

Group-IB Threat Intelligence analyzes HEAVYGRAM, a Telegram-based Windows backdoor attributed with moderate confidence to the Iran-linked threat actor Handala Hack. Active since Fall 2023, it has been used to surveil Iranian dissidents, journalists and government opponents, enabling remote command execution, data exfiltration, and persistence over Telegram command-and-control.

MalwareMicrosoftThreat ActorsThreat Intelligence
P0
2026-09-17 06:39 UTC
Security Journalism

Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-17 13:45 UTC

Cisco has warned of a fresh maximum-severity security flaw impacting Identity Services Engine (ISE) that has come under active exploitation. The vulnerability, tracked as CVE-2026-76460 (CVSS score: 10.0), could allow an unauthenticated, remote attacker to bypass authentication. "This vulnerability is due to insufficient authentication control on an API endpoint," Cisco said. "An attacker

VulnerabilitiesCVE-2026-76460
P30
2026-09-17 06:19 UTC
Security Journalism

Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day

Security Week · Ionut Arghire · indexed 2026-09-17 06:35 UTC

Remote, unauthenticated attackers can exploit the vulnerability to bypass authentication via crafted requests. The post Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day appeared first on SecurityWeek.

Vulnerabilities
P25
2026-09-17 05:59 UTC
Other

Top 5 Fraud Prevention Platforms for Banks and Fintechs in 2026

Group-IB · indexed 2026-09-17 08:35 UTC

Most fraud platforms only see a threat once it becomes a transaction. This guide compares the top 5 fraud prevention platforms for banks and fintechs in 2026, including Group-IB, Feedzai, Sift, DataVisor, and Kount, and what actually separates them.

Cybercrime
P0
2026-09-17 05:13 UTC
Security Journalism

U.S. Seizes NightmareStresser Domains Linked to Hundreds of Thousands of DDoS Attacks

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-17 13:45 UTC

The U.S. Department of Justice (DoJ) on Tuesday announced the court-authorized seizure of internet domains associated with a distributed denial-of-service (DDoS)-for-hire service known as NightmareStresser. The domains in question are: nightmare-stresser[.]com and nightmarestresser[.]org. Visitors to the sites are now greeted by a seizure banner that states - "This domain has been seized by

Law Enforcement
P0
2026-09-17 05:00 UTC
Other

ZDI-26-714: Samsung rlottie Stack-based Buffer Overflow Remote Code Execution Vulnerability

Zero Day Initiative · indexed 2026-09-17 14:55 UTC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Samsung rlottie. Interaction with the rlottie library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-91826.

VulnerabilitiesCVE-2026-91826
P20
2026-09-17 00:35 UTC
Security Journalism

Anthropic wants Claude to analyze your bank account and financial data

BleepingComputer · Mayank Parmar · indexed 2026-09-17 00:45 UTC

Anthropic is testing a new personal finance feature called "Claude Money" that will allow you to connect your bank accounts directly to Claude and "understand your money." [...]

P0
2026-09-16 21:20 UTC
Vendor Research

Architecting a secure landing zone in the AWS European Sovereign Cloud

AWS Security Blog · Pablo Pagani · indexed 2026-09-16 21:50 UTC

The AWS European Sovereign Cloud is a new, independent cloud for Europe, physically and logically separate from existing AWS Regions and operated within the European Union (EU). It provides the same services, features, and APIs as AWS commercial Regions, but runs as a distinct AWS partition (aws-eusc), with its own control plane, AWS Identity and […]

Cloud Security
P0
2026-09-16 20:39 UTC
Security Journalism

Windows 11 KB5124008 update breaks domain trust for some users

BleepingComputer · Lawrence Abrams · indexed 2026-09-16 20:50 UTC

Microsoft is investigating reports that the Windows 11 KB5124008 security update is breaking domain trust relationships on some enterprise systems, preventing users from logging in with valid domain credentials. [...]

Microsoft
P5
2026-09-16 20:20 UTC
Other

BambooToken: The Malware That Speaks MQTT to Stay Under the Radar

Security Affairs · Pierluigi Paganini · indexed 2026-09-16 21:00 UTC

Lumen exposes BambooToken, a stealthy malware family using MQTT and sideloading to quietly infect targets across Asia and beyond. BambooToken is a new malware family that uses MQTT, a lightweight messaging protocol commonly found in smart devices and industrial systems, to quietly control infected Windows and Linux machines. Most malware connects directly to a command-and-control […]

LinuxMalwareMicrosoft
P0
2026-09-16 20:16 UTC
Vendor Research

CVE-2026-86831: Improper validation of pod identifier uniqueness in aws-network-policy-agent in Amazon EKS

AWS Security Bulletins · aws@amazon.com · indexed 2026-09-16 20:20 UTC

Bulletin ID: 2026-113-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/16/2026 12:30 PM PDT Description: Network Policy Agent is an EKS Policy management feature. We identified CVE-2026-86831, a cross-namespace NetworkPolicy bypass in Amazon EKS Network Policy Agent (aws-network-policy-agent) before v1.4.0. Pod identifiers are constructed by concatenating the pod name and namespace with a hyphen delimiter, which is a legal character in both Kubernetes pod names a…

Cloud SecurityVulnerabilitiesCVE-2026-86831
P5
2026-09-16 18:28 UTC
Security Journalism

House passes bill to equip local law enforcement with scam-fighting tools

The Record · indexed 2026-09-16 18:35 UTC

The Guarding Unprotected Aging Retirees from Deception Act (GUARD) attempts to address a common complaint from the victims of online scams like pig butchering — that such cases typically do not rise to the level of a federal investigation but local law enforcement is unequipped to properly investigate them.

DFIR
P0
2026-09-16 18:14 UTC
Independent Research

Data Broker Radaris Loses Domains in Privacy Fight

Krebs on Security · BrianKrebs · indexed 2026-09-16 18:25 UTC

The consumer data broker Radaris.com has long had a reputation for ignoring requests to remove personal information from its vast empire of people-search services online. That reputation caught up with the company recently in a lawsuit alleging Radaris violated a New Jersey privacy law that provides for hefty fines against data brokers that publish personal information on state law enforcement officials. In the face of repeated stonewalling and prevarication by attorneys for Radaris, the judge …

Cloud Security
P0
2026-09-16 18:00 UTC
Security Journalism

Fighting Your Dragons Through Tough Tech Times

Dark Reading · Dark Reading Editorial Team · indexed 2026-09-16 18:20 UTC

Cybersecurity industry veteran Hal Pomeranz gives a pep talk on career anxiety and self-doubt and shares how to build meaningful connections during historical tech industry downturns.

P0
2026-09-16 17:26 UTC
Security Journalism

Spain reports first alleged AI-powered data theft attack

BleepingComputer · Bill Toulas · indexed 2026-09-16 17:30 UTC

The Spanish Data Protection Agency (AEPD) was notified of an attack allegedly carried out with an AI agent powered by a known large language model (LLM). [...]

AI Security
P0
29 30 31 32 33