IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 4,492 matching records.
AUTO-POLL // 2026-10-05 22:50 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P5 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
FRI
Oct 2

RANSOMWARE
P7
P7
COOL // 46 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
WED
Sep 30

RANSOMWARE
P10
P10
WARM // 59 ARTICLES
TUE
Sep 29

RANSOMWARE
P4
P4
COOL // 68 ARTICLES
RESET
2026-09-14 13:00 UTC
Security Journalism

The Race to Control AI and Protect What Makes Us Human

Security Week · Kevin Townsend · indexed 2026-09-14 13:10 UTC

As researchers warn that misaligned AI could threaten human survival, even beneficial systems may erode the critical thinking that defines our humanity. The post The Race to Control AI and Protect What Makes Us Human appeared first on SecurityWeek.

P0
2026-09-14 12:22 UTC
Other

14th September – Threat Intelligence Report

Check Point Research · urias@checkpoint.com · indexed 2026-09-14 12:30 UTC

For the latest discoveries in cyber research for the week of 14th Setpember, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES IDScan.net, a US identity verification provider, has disclosed a data breach after detecting unauthorized access on September 1. Exposed data included names and government identification numbers, while a criminal marketplace advertised a […] The post 14th September – Threat Intelligence Report appeared first on Check Point Research.

Data BreachesThreat Intelligence
P0
2026-09-14 12:15 UTC
Security Journalism

Webinar: How malicious OAuth apps can lead to Google Workspace breaches

BleepingComputer · BleepingComputer · indexed 2026-09-14 12:25 UTC

Attackers can combine social engineering with malicious OAuth applications to gain access to Google Workspace data without relying solely on stolen passwords. This webinar examines two attacks to show how these breaches unfold and which security controls can help stop them. [...]

P0
2026-09-14 11:58 UTC
Security Journalism

AI Changed the Exposure Problem. Validation Needs to Change With It.

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-14 12:25 UTC

There's a lot of noise around AI and cybersecurity right now. What’s actually important is far simpler, if often lost in the hubbub. Vulnerability discovery is getting faster and happening at a much greater scale, while defenders still have to work out which findings actually deserve their action. In the first half of 2026, a whopping 35,853 CVEs were published, roughly 49% more than in the

MicrosoftVulnerabilities
P0
2026-09-14 10:30 UTC
Security Journalism

CISOs Race to Control AI Agents Without Destroying Their Value

Security Week · Kevin Townsend · indexed 2026-09-14 10:50 UTC

Security leaders are struggling to modernize cyber hygiene and prevent over-privileged agents from causing unintended harm. The post CISOs Race to Control AI Agents Without Destroying Their Value appeared first on SecurityWeek.

AI Security
P0
2026-09-14 10:02 UTC
Vendor Research

CVE-2026-85706: Critical GitLab Path Traversal Exploited in the Wild

Rapid7 · Rapid7 · indexed 2026-09-14 10:50 UTC

OverviewOn September 10, 2026, GitLab published a critical patch release for GitLab Community Edition (CE) and Enterprise Edition (EE). The release addresses CVE-2026-85706, a critical path traversal vulnerability (CWE-22) in the repository commits API with a CVSSv3.1 score of 10.0. According to GitLab, improper path confinement and missing authentication enforcement could allow an unauthenticated user to read arbitrary files from an affected GitLab server under certain conditions.On September …

VulnerabilitiesCVE-2026-85706CVE-2026-87719
P55
2026-09-14 10:00 UTC
Vendor Research

Unmasking Cloud Identities: From Behavioral Clustering to Automated Detection

Palo Alto Networks Unit 42 · Osher Jacob · indexed 2026-09-14 10:10 UTC

We designed a behavioral clustering model to map cloud identity roles from audit logs, enabling continuous threat detection using standard SQL queries. The post Unmasking Cloud Identities: From Behavioral Clustering to Automated Detection appeared first on Unit 42.

P0
2026-09-14 09:56 UTC
Security Journalism

Telus Warns Customers of Account Breaches

Security Week · Eduard Kovacs · indexed 2026-09-14 10:10 UTC

Stolen credentials were used in a multi-month campaign to access subscriber personal data and billing records. The post Telus Warns Customers of Account Breaches appeared first on SecurityWeek.

Cybercrime
P0
2026-09-14 09:43 UTC
Other

Dutch NCSC Warns: Critical Check Point VPN Flaws Put Networks at Risk

Security Affairs · Pierluigi Paganini · indexed 2026-09-14 09:50 UTC

Two critical Check Point VPN flaws score 9.8 and could enable remote code execution. Patch now and restrict VPN access before exploitation begins. The Dutch NCSC warns that two critical vulnerabilities in Check Point VPN products, both rated CVSS score of 9.8, could soon be actively exploited. If you use Check Point VPN, you should […]

Cloud SecurityNetwork SecurityVulnerabilities
P45
2026-09-14 07:57 UTC
Other

Smish. Click. Drained: Inside the Smishing Triad’s Phishing Cockpit

Group-IB · indexed 2026-09-14 08:30 UTC

A deep technical analysis of the Smishing Triad’s JWR phishing kit and Outsider operator cluster, revealing its real-time victim control, encrypted WebSocket communications, multi-stage credential theft, AES-256-CTR implementation, infrastructure, and actionable indicators for defenders.

MicrosoftPhishing
P0
2026-09-14 07:24 UTC
Security Journalism

Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-14 08:30 UTC

A malicious cross-store Twitch browser extension has leaked OAuth tokens associated with nearly 31,000 users to proxy servers operated by a Russian commercial bot service. The extension, named "Twitch Enhanced Viewer | JeetBot," lists HISHIMIRO/jeetbot.cc as its developer and has the following identifiers on the Google Chrome Web Store and Mozilla Firefox Add-Ons store - Chrome -

P0
2026-09-14 06:40 UTC
Other

Anthropic CEO Calls for an AI Slowdown. Is It Possible?

Security Affairs · Pierluigi Paganini · indexed 2026-09-14 07:35 UTC

Anthropic CEO calls for AI slowdown, proposes embedded evaluators and global coordination. Geopolitical competition with China makes a voluntary pause structurally fragile. Dario Amodei published “We Must Pace the Frontier“, calling on the AI industry, governments, and international bodies to slow the pace of AI capability development before safety research can catch up. It’s the […]

P0
2026-09-14 05:00 UTC
Other

ZDI-26-701: Linux Kernel TLS Protocol Out-Of-Bounds Read Information Disclosure Vulnerability

Zero Day Initiative · indexed 2026-09-14 15:10 UTC

This vulnerability allows local attackers to disclose sensitive information on affected installations of Linux Kernel. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.7. The following CVEs are assigned: CVE-2026-64046.

LinuxVulnerabilitiesCVE-2026-64046
P5
2026-09-14 05:00 UTC
Other

ZDI-26-700: Linux Kernel QFQ Plus Scheduler Use-After-Free Local Privilege Escalation Vulnerability

Zero Day Initiative · indexed 2026-09-14 15:10 UTC

This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-22999.

LinuxVulnerabilitiesCVE-2026-22999
P15
2026-09-14 05:00 UTC
Other

ZDI-26-696: Linux Kernel NTFS3 Journal Heap-based Buffer Overflow Code Execution Vulnerability

Zero Day Initiative · indexed 2026-09-14 15:10 UTC

This vulnerability allows local attackers to execute arbitrary code on affected installations of Linux Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-72196.

LinuxVulnerabilitiesCVE-2026-72196
P5
2026-09-14 05:00 UTC
Other

ZDI-26-695: Linux Kernel NFSv4 Server Race Condition Remote Code Execution Vulnerability

Zero Day Initiative · indexed 2026-09-14 15:10 UTC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Linux Kernel. Authentication is required to exploit this vulnerability. Furthermore, only systems with nfsd enabled are vulnerable. The ZDI has assigned a CVSS rating of 8.5. The following CVEs are assigned: CVE-2026-89688.

LinuxVulnerabilitiesCVE-2026-89688
P20
2026-09-14 05:00 UTC
Other

ZDI-26-694: Linux Kernel Net Scheduler Clsact Qdisc Use-After-Free Local Privilege Escalation Vulnerability

Zero Day Initiative · indexed 2026-09-14 15:10 UTC

This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.2. The following CVEs are assigned: CVE-2026-23413.

LinuxVulnerabilitiesCVE-2026-23413
P15
36 37 38 39 40