IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 4,488 matching records.
AUTO-POLL // 2026-10-05 21:15 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P6 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 5

RANSOMWARE
P6
P6
COOL // 44 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
FRI
Oct 2

RANSOMWARE
P7
P7
COOL // 46 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
WED
Sep 30

RANSOMWARE
P10
P10
WARM // 59 ARTICLES
TUE
Sep 29

RANSOMWARE
P4
P4
COOL // 68 ARTICLES
RESET
2026-09-15 20:36 UTC
Vendor Research

Cisco Integrated Management Controller Argument Injection Vulnerabilities

Cisco Security Advisories · indexed 2026-08-15 14:33 UTC

Multiple vulnerabilities in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected system and elevate privileges to root. For more information about these vulnerabilities, see the Details section of this advisory. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities…

VulnerabilitiesCVE-2026-20200CVE-2026-20288
P5
2026-09-15 20:34 UTC
Vendor Research

Cisco UCS and UCS-Based Appliances UEFI Shell Secure Boot Bypass Vulnerability

Cisco Security Advisories · indexed 2026-09-08 16:35 UTC

A vulnerability in the Unified Extensible Firmware Interface (UEFI) Shell implementation of Cisco UCS Servers and UCS-based appliances could allow an authenticated attacker with valid credentials for a user account with the role of user or admin or an unauthenticated attacker with physical access to an affected device to bypass UEFI Secure Boot validation checks and execute unauthorized software. This vulnerability is due to the availability of memory write commands in the UEFI Shell while UEFI…

VulnerabilitiesCVE-2026-20293
P5
2026-09-15 19:30 UTC
Security Journalism

“We Think the Security Control Is Working” Is No Longer Good Enough

Security Week · Sravish Sridhar · indexed 2026-09-15 19:40 UTC

Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today. The post “We Think the Security Control Is Working” Is No Longer Good Enough appeared first on SecurityWeek.

P0
2026-09-15 19:00 UTC
Vendor Research

Architecting resilient authentication with Amazon Cognito multi-Region replication

AWS Security Blog · Abrom Douglas · indexed 2026-09-15 19:30 UTC

Your consumer identity and access management (CIAM) system is the foundation of your customer experience. It’s how users sign in, access services, and engage with your applications. As your business scales across geographies, ensuring authentication is always available becomes a core architectural requirement. However, building multi-Region authentication has traditionally required complex custom replication solutions that […]

P0
2026-09-15 18:54 UTC
Security Journalism

KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-15 19:10 UTC

Cybersecurity researchers have shed light on a previously undocumented Brazilian banking malware operation that delivers a toolkit called KREMLIN. Elastic Security Labs is tracking the activity under the moniker REF9334. Active since at least May 2025, the threat actor has used lures that impersonate a dozen Brazilian banks and install a malicious browser extension on Google Chrome and

MalwareSecurity ResearchThreat Actors
P0
2026-09-15 16:40 UTC
Security Journalism

CenterPoint Energy confirms customer data stolen in cyberattack

BleepingComputer · Bill Toulas · indexed 2026-09-15 16:45 UTC

CenterPoint Energy disclosed a breach compromising some customers' personal information after an attacker leaked data allegedly stolen from the utility company. [...]

P0
2026-09-15 16:29 UTC
Security Journalism

Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journalists

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-15 17:45 UTC

Cybersecurity agencies in the United States, the United Kingdom, and the Netherlands have detailed a Windows malware that they say Iran's intelligence service uses to spy on dissidents, journalists, and activists around the world. The malware is controlled via the Telegram messaging app and can copy a target's emails and chat messages, take screenshots, and activate the microphone to record

MalwareMicrosoft
P0
2026-09-15 16:28 UTC
Security Journalism

Iranian cyber spies used fake MRI scan results to hack ‘enemy of regime’

The Record · indexed 2026-09-15 16:35 UTC

According to the United Kingdom’s National Cyber Security Centre (NCSC), Iran has used this and similar cyber activity to “support the repression of individuals who are seen as a threat to the regime, such as dissidents, activists and journalists.”

P0
2026-09-15 15:53 UTC
Vendor Research

Operationalizing least privilege: Automate IAM remediation through your CI/CD pipeline

AWS Security Blog · Luis Pastor · indexed 2026-09-15 16:05 UTC

The principle of least privilege is straightforward to articulate but challenging to maintain at scale. When teams first deploy applications to AWS, they often grant broader permissions than strictly necessary; it’s faster to get things working, and the plan is always to tighten permissions later. But later rarely comes. Permissions accumulate, AWS Identity and Access […]

Cloud Security
P0
2026-09-15 15:45 UTC
Security Journalism

Exein Secures $270M at $1.7B Valuation for Physical AI Security

Security Week · Ionut Arghire · indexed 2026-09-15 16:00 UTC

The cybersecurity startup is building a proprietary foundation model and plans to accelerate global expansion. The post Exein Secures $270M at $1.7B Valuation for Physical AI Security appeared first on SecurityWeek.

AI Security
P0
2026-09-15 15:30 UTC
Security Journalism

Texas Utility CenterPoint Energy Confirms Breach After Hacker Leaks Data

Security Week · Eduard Kovacs · indexed 2026-09-15 15:40 UTC

A hacker claims to have stolen 7.5 million customer records after breaching the company’s systems. The post Texas Utility CenterPoint Energy Confirms Breach After Hacker Leaks Data appeared first on SecurityWeek.

P0
2026-09-15 15:23 UTC
Community

MacOS 27 - First Boot, (Tue, Sep 15th)

SANS Internet Storm Center · indexed 2026-09-15 15:40 UTC

I have not done this type of diary in a while: What traffic will you see from a system on boot, before a user logs in? I just took a quick look at macOS 27 "Golden Gate" to see what traffic you should expect. Here are some of the highlights:

Apple
P0
2026-09-15 15:23 UTC
Security Journalism

BambooToken Malware Uses MQTT to Control Windows and Linux Systems

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-15 15:50 UTC

Cybersecurity researchers have disclosed details of a multi-platform campaign that uses the Message Queueing Telemetry Transport (MQTT) protocol as a communication channel to control Windows and Linux systems. The emerging malware family, codenamed BambooToken, is assessed to be active since at least February 2023 and put to use in attacks targeting organizations across Asia and South America.

LinuxMalwareMicrosoftSecurity Research
P0
2026-09-15 13:45 UTC
Security Journalism

What Zero-Day Response Should Be in the Post-Mythos Era

BleepingComputer · Sponsored by Picus Security · indexed 2026-09-15 14:05 UTC

AI is shrinking the time between vulnerability disclosure and exploitation, leaving defenders less time to wait for patches or public exploits. Picus Security explains how exploitability validation, security control testing, and autonomous pentesting can help teams close exposure gaps before attackers arrive. [...]

MicrosoftVulnerabilities
P25
2026-09-15 13:32 UTC
Vendor Research

Australia is replacing the Essential Eight with a new cyber framework. Here’s how exposure management can help you get ahead of it.

Tenable Blog · Ben Mudie · indexed 2026-09-15 13:40 UTC

Australia’s move from the Essential Eight to an outcomes-based cybersecurity model will push organizations from conducting periodic point-in-time, checklist compliance assessments to having continuous evidence of a solid security posture.Key takeawaysThe Australian Signals Directorate (ASD) is moving from the Essential Eight cybersecurity framework to a new outcomes-focused Essentials series covering enterprise IT, cloud, operational technology (OT), and potentially agentic AI.The Essential Eig…

Cloud SecurityICS / OTMicrosoftNetwork SecurityVulnerabilities
P0
2026-09-15 13:00 UTC
Other

Cisco Warns of Ongoing Exploitation of Critical Email Gateway Zero-Day

Security Affairs · Pierluigi Paganini · indexed 2026-09-15 13:45 UTC

Cisco warns of a critical zero-day in Secure Email Gateway, exploited in the wild to gain root access through malicious emails. Cisco disclosed a critical zero-day, tracked as CVE-2026-76461 (CVSS score of 9.8), affecting Secure Email Gateway appliances. The flaw can be exploited remotely without authentication. Attackers can send specially crafted emails containing malicious SQL […]

VulnerabilitiesCVE-2026-76461
P50
33 34 35 36 37