IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 4,492 matching records.
AUTO-POLL // 2026-10-06 03:05 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
NO DATA
NO INTELLIGENCE AGGREGATED TODAY
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 6
NO DATA
--
NO INTEL
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
FRI
Oct 2

RANSOMWARE
P7
P7
COOL // 46 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
WED
Sep 30

RANSOMWARE
P10
P10
WARM // 59 ARTICLES
RESET
2026-09-08 18:49 UTC
Security Journalism

Microsoft releases Windows 10 KB5122878 extended security update

BleepingComputer · Lawrence Abrams · indexed 2026-09-08 19:00 UTC

Microsoft has released the Windows 10 KB5122878 extended security update, which includes this month's record-breaking September 2026 Patch Tuesday fixes, along with a few bug fixes. [...]

Microsoft
P5
2026-09-08 18:09 UTC
Other

WeChat Worm Can Hijack Accounts Without Victims Answering Calls

Security Affairs · Pierluigi Paganini · indexed 2026-09-08 18:50 UTC

Researchers built a WeChat worm that spreads through incoming calls without user action. Tencent has blocked the exploit. Researchers at Calif created a WeChat worm that can take over an account through an incoming call, even if the victim never answers or touches the phone. The attack works only when the caller already appears in […]

P0
2026-09-08 18:07 UTC
Vendor Research

Microsoft’s September 2026 Patch Tuesday addresses 964 CVEs (CVE-2026-81963, CVE-2026-85880)

Tenable Cyber Exposure Alerts · Research Special Operations · indexed 2026-09-08 18:20 UTC

104Critical860Important0Moderate0LowMicrosoft addresses 964 CVEs, smashing July’s release as the largest Patch Tuesday release. This month’s updates include patches for two zero-days that were exploited in the wild.Microsoft patched a record 964 CVEs in its September 2026 Patch Tuesday release, with 104 rated critical and 860 rated as important.This month’s update includes patches for:.NET.NET and Visual StudioASP.NET CoreActive Directory Certificate Services (AD CS)Active Directory Domain Serv…

Cloud SecurityLinuxMicrosoftMobile SecurityNetwork SecurityVulnerabilitiesCVE-2023-21674CVE-2026-81963CVE-2026-85880
P65
2026-09-08 17:57 UTC
Security Journalism

Windows 11 cumulative updates KB5124008 & KB5122880 released

BleepingComputer · Mayank Parmar · indexed 2026-09-08 18:05 UTC

Microsoft has released Windows 11 KB5124008 and KB5122880 cumulative updates for versions 25H2/24H2 and 23H2 to fix security vulnerabilities, bugs, and add new features. [...]

Microsoft
P0
2026-09-08 17:21 UTC
Vendor Research

Claude Mythos 5 is coming to Tenable One, powering the new “Adversary View”

Tenable Blog · Eric Doerr · indexed 2026-09-08 17:30 UTC

Tenable is bringing Anthropic’s Claude Mythos 5 into our enterprise security offerings. Adding frontier adversarial reasoning to the Tenable One Exposure Management Platform will help customers better anticipate how attackers could breach their environments and stay ahead of AI-fueled risk. Tenable One Adversary View, the first innovation planned from this work, will debut in the coming weeks.Key takeawaysClaude Mythos 5 is coming to Tenable One. In addition to using Claude Mythos 5 for researc…

AI SecurityICS / OTMicrosoftVulnerabilities
P0
2026-09-08 17:00 UTC
Security Journalism

The Hidden Instructions That Can Hijack AI Agents

Security Week · Kevin Townsend · indexed 2026-09-08 17:15 UTC

Malicious prompts concealed in documents, metadata, emails, images and code can manipulate autonomous agents into taking dangerous actions. The post The Hidden Instructions That Can Hijack AI Agents appeared first on SecurityWeek.

AI Security
P0
2026-09-08 16:35 UTC
Security Journalism

Hackers Return $263 Million Stolen From Liquid Network

Security Week · Ionut Arghire · indexed 2026-09-08 16:40 UTC

Alleged ‘white-hat’ hackers drained $320 million from Liquid’s federation wallet, demanding a bug fix. The post Hackers Return $263 Million Stolen From Liquid Network appeared first on SecurityWeek.

P0
2026-09-08 16:35 UTC
Security Journalism

ShinyHunters hackers claim breach of Florida "DAVID" DMV database

BleepingComputer · Lawrence Abrams · indexed 2026-09-08 17:10 UTC

The ShinyHunters extortion gang claims it breached an online platform for the Florida Department of Motor Vehicles database known as "DAVID" and stole over 200,000 records about drivers in the state. [...]

P0
2026-09-08 16:28 UTC
Security Journalism

OpenAI says ChatGPT outage causes image generation errors

BleepingComputer · Sergiu Gatlan · indexed 2026-09-08 16:40 UTC

OpenAI is investigating an ongoing incident causing ChatGPT image generation failures and delays when uploading files. [...]

P0
2026-09-08 16:20 UTC
Security Journalism

Slim Spider Steals Crypto Custody Secrets From Brazilian Financial Institution

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-08 16:50 UTC

A previously undocumented financially motivated threat actor has been linked to attacks targeting Brazilian financial institutions since at least March 2026. Cybersecurity company CrowdStrike is tracking the Brazil-based activity cluster under the name Slim Spider. "The adversary demonstrates deep operational knowledge of Brazilian financial infrastructure, including the instant payment

Threat Actors
P0
2026-09-08 15:22 UTC
Security Journalism

August updates trigger 0xc0000409 errors on Windows Server 2016

BleepingComputer · Sergiu Gatlan · indexed 2026-09-08 15:40 UTC

Microsoft says the August 2026 security update may trigger 0xc0000409 errors on Windows Server 2016 systems where the Compatibility Appraiser diagnostic service is enabled. [...]

Microsoft
P5
2026-09-08 15:21 UTC
Security Journalism

Cylake Raises $245 Million Ahead of Cybersecurity Platform Beta

Security Week · Mike Lennon · indexed 2026-09-08 15:25 UTC

The startup founded by Palo Alto Networks’ Nir Zuk has raised $290 million to build an AI-native security platform for highly regulated organizations that cannot rely on the public cloud. The post Cylake Raises $245 Million Ahead of Cybersecurity Platform Beta appeared first on SecurityWeek.

Network Security
P0
2026-09-08 14:55 UTC
Security Journalism

SAP Patches Critical Extended Passport Processing Vulnerability

Security Week · Ionut Arghire · indexed 2026-09-08 15:05 UTC

Affecting the SAP kernel code, the flaw allows unauthenticated, remote attackers to run arbitrary commands, recover secrets, and modify data. The post SAP Patches Critical Extended Passport Processing Vulnerability appeared first on SecurityWeek.

LinuxVulnerabilities
P0
2026-09-08 14:54 UTC
Security Journalism

Liquid Hackers Return 3,400 Bitcoin Taken via Elements Bug, Still Holding $47M in BTC

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-08 15:20 UTC

Whoever took nearly 4,000 bitcoin from the Liquid Network on Sunday, September 6, returned 3,400 of it the next day, Bitcoin's public record shows. About 598.5 bitcoin has not come back. Liquid is a Bitcoin sidechain that holds real bitcoin to back a token called L-BTC. The network is still paused, so holders cannot turn that token back into bitcoin. The 3,400 bitcoin was sent to a&

P0
2026-09-08 14:19 UTC
Security Journalism

ChatGPT Flaw Let a Planted Prompt Send a Victim's Gmail Data to Another Account

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-08 15:20 UTC

Check Point Research said in a report published today that a single instruction planted in a ChatGPT conversation could cause ChatGPT to quietly work for an attacker while answering the user's question as usual. In the company's proof of concept, that hidden work read data from the user's connected Gmail account and passed it to a second ChatGPT account through a hidden channel

Security Research
P0
2026-09-08 14:00 UTC
Vendor Research

StyleSmuggler (CVE-2026-75650): Frequently asked questions about Adobe Commerce and Magento zero-day

Tenable Cyber Exposure Alerts · Satnam Narang · indexed 2026-09-08 14:20 UTC

A critical unauthenticated remote code execution (RCE) zero-day in Adobe Commerce and Magento Open Source, dubbed StyleSmuggler, has been actively exploited since September 4 with attacks observed three days before a vendor patch became available.Key takeawaysCVE-2026-75650 is a critical remote code execution vulnerability in Adobe Commerce, Adobe Commerce B2B and Magento Open Source that can be triggered without authentication.Active exploitation of CVE-2026-75650 began on September 4, 2026, t…

DFIRLinuxMalwareThreat ActorsThreat IntelligenceVulnerabilitiesCVE-2026-75650
P95
2026-09-08 14:00 UTC
Vendor Research

GTIG AI Threat Tracker: From Prompting to Autonomy – The Evolution of Adversarial AI

Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-09-08 13:45 UTC

Executive Summary Since the release of our May 2026 report detailing adversarial misuse of artificial intelligence (AI), Google Threat Intelligence Group (GTIG) has observed forward leaning adversaries transition from basic prompting to agentic AI workflows and AI-enabled automation. In these operations, human-in-the-loop latency is dramatically reduced, compressing the traditional window for defenders to respond. In Q2 2026, GTIG observed threat actors compromise a cloud resource, then plan, b…

AI SecurityAPT / Nation-StateCloud SecurityData BreachesDFIRMalwareMicrosoftPhishingRansomwareThreat ActorsThreat IntelligenceVulnerabilities
P35
2026-09-08 13:48 UTC
Security Journalism

Autonomous AI Agents Compromise Thousands of Credentials in Under Six Hours

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-08 15:20 UTC

Threat actors are continuing to leverage artificial intelligence (AI) to streamline their operations, with one financially motivated hacking group employing an autonomous, multi-agent attack framework to carry out a large-scale credential harvesting campaign within six hours. Google Threat Intelligence Group (GTIG) said it has observed attackers with diverse motivations targeting proprietary AI

AI SecurityPhishingThreat ActorsThreat Intelligence
P0
2026-09-08 13:00 UTC
Other

The Shared Clipboard Inside the Sandbox: Cross-Account Data Leakage in ChatGPT

Check Point Research · stcpresearch · indexed 2026-09-08 13:10 UTC

Research by: Alexey Bukhteyev Key Takeaways Introduction Over the past several years, AI assistants have moved far beyond text generation. Modern systems can execute code, install additional dependencies, analyze user files, and access data through connected services. These capabilities significantly increase the practical value of LLMs, but they also change the security model: protecting user […] The post The Shared Clipboard Inside the Sandbox: Cross-Account Data Leakage in ChatGPT appeared f…

AI SecurityData Breaches
P0
48 49 50 51 52