IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 4,492 matching records.
AUTO-POLL // 2026-10-06 04:00 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
NO DATA
NO INTELLIGENCE AGGREGATED TODAY
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 6
NO DATA
--
NO INTEL
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
FRI
Oct 2

RANSOMWARE
P7
P7
COOL // 46 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
WED
Sep 30

RANSOMWARE
P10
P10
WARM // 59 ARTICLES
RESET
2026-09-07 08:35 UTC
Other

Why AI Agent Sandboxes Are Failing Security Tests

Security Affairs · Pierluigi Paganini · indexed 2026-09-07 09:50 UTC

Autonomous AI agents escaped a sandbox and accessed Hugging Face via reward hacking, exposing serious architectural control and isolation flaws. The recent case involving OpenAI test agents and Hugging Face should concern security teams, but not for the reason implied by headlines about an imminent AI “takeover.” The documented issue is more concrete: autonomous agents, […]

AI SecurityCloud Security
P0
2026-09-07 08:31 UTC
Security Journalism

N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-07 09:45 UTC

Every on-premises N-central build below 2026.3.1.14 — including servers updated to Hotfix 3 a day earlier — needs Hotfix 4. N-able's incident notice says the flaw has been exploited in the wild; its release notes say that is unconfirmed. N-able has released its fourth hotfix in five weeks for the N-central remote monitoring and management (RMM) platform, this time for a

MicrosoftVulnerabilities
P35
2026-09-07 07:53 UTC
Security Journalism

JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-07 08:35 UTC

Cybersecurity researchers have unpacked JSCeal, a sophisticated compiled V8 JavaScript (JSC) malware with credential harvesting, surveillance, and traffic-interception capabilities. "The payloads are protected with javascript-obfuscator, using multiple techniques including RC4-protected strings, control-flow flattening, proxy functions, and operation wrappers," Check Point Research said in a

MalwarePhishingSecurity Research
P0
2026-09-07 07:19 UTC
Other

Berlin Ransomware Leak Exposes State Secrets

Security Affairs · Pierluigi Paganini · indexed 2026-09-07 08:30 UTC

Berlin refused a 30 Bitcoin ransom, leading hackers to leak 6TB of sensitive state administration and national defense data on the dark web. When a ransomware gang dumps nearly six terabytes of state administration files onto the dark web, ignoring them does not make the problem go away. The Rhysida ransomware group recently carried out […]

CybercrimeRansomware
P15
2026-09-07 01:15 UTC
Security Journalism

ChatGPT Astra is now rolling out to $20 Plus subscription

BleepingComputer · Mayank Parmar · indexed 2026-09-07 01:25 UTC

OpenAI is now rolling out ChatGPT Astra, its most powerful model to date, to those with a $20 Plus subscription, but there's no word on when free users will get access.. [...]

P0
2026-09-06 21:43 UTC
Community

Critical MikroTik Vulnerability - Patch Now, (Sun, Sep 6th)

SANS Internet Storm Center · indexed 2026-09-06 22:05 UTC

Mikrotik released a patch late last week for an already-exploited vulnerability. The vulnerability allows an SSH authentication bypass and is already being exploited. At this point, assume compromise. Attackers have been adding new accounts to affected devices to maintain access after a patch is installed.

Vulnerabilities
P15
2026-09-06 13:46 UTC
Other

Your MikroTik Router May Already Be Compromised: Look for SSH User “-2”

Security Affairs · Pierluigi Paganini · indexed 2026-09-06 14:45 UTC

MikroTik RouterOS SSH zero-day (MikroTrick chain) under active exploitation since Sept 2. Patch to 7.24.2, 7.23.5, or 6.49.21 immediately and check logs. Anyone running a MikroTik router with SSH exposed to the internet should treat it as compromised until proven otherwise. The popular cybersecurity expert Costin Raiu published a detailed technical breakdown of the active […]

Network SecurityVulnerabilities
P25
2026-09-06 11:43 UTC
Other

AI Agents Hijacked German Wiki to Cheat, OpenAI Delayed Disclosure

Security Affairs · Pierluigi Paganini · indexed 2026-09-06 12:10 UTC

AI agents secretly took over a 25-year-old German wiki for two months to cheat on tests, and OpenAI sat on the news until reporters found it first OpenAI finally admitted this weekend that a swarm of its own AI agents hijacked a German programming wiki earlier this year, turning it into a private message board […]

AI Security
P0
2026-09-06 09:32 UTC
Security Journalism

Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-06 10:00 UTC

Attackers are exploiting MikroTik routers with their Secure Shell (SSH) remote-access service, which is reachable from the internet, to gain full administrative control without authentication, according to CERT Polska's attack warning, published on September 5. Successful attacks date to at least September 2. The Hacker News’s September 6 review of the warning found no victim count or

Network Security
P0
2026-09-06 08:34 UTC
Security Journalism

Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-06 10:00 UTC

Elastic Security Labs has documented four previously unreported programs associated with REVSTEALER, an emerging Windows information stealer, that remain on an infected machine after the stealer deletes itself. One of them switches off Windows Update and Microsoft Defender before running a cryptocurrency miner. The company named the four programs ProManager, WinUpdate, SoftManager, and

MalwareMicrosoftNetwork Security
P0
2026-09-06 08:27 UTC
Other

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 113

Security Affairs · Pierluigi Paganini · indexed 2026-09-06 08:55 UTC

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Hackers Steal Claude Login Sessions With Infostealer Malware to Hijack Accounts Fire Ant Evolves: From Hypervisors to Trusted Infrastructure Gryxa: The AI-Built Toolkit That Watches How You Remove It ValleyRAT masquerading as adware […]

Malware
P0
2026-09-06 07:56 UTC
Other

Security Affairs newsletter Round 593 by Pierluigi Paganini – INTERNATIONAL EDITION

Security Affairs · Pierluigi Paganini · indexed 2026-09-06 08:55 UTC

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. PaperCut Flaws Exploited in Attacks on U.S. and European Schools Broadcom Patches Critical VMware Workstation and Fusion […]

Cloud Security
P20
2026-09-05 21:14 UTC
Other

OpenAI Announced $1B in Defensive Tools for Water Utilities

Security Affairs · Pierluigi Paganini · indexed 2026-09-05 21:50 UTC

OpenAI pledges $1B in subsidized Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. OpenAI announced Daybreak for Frontline Defenders on September 3, 2026, committing $1 billion in subsidized access to its Daybreak cyber models, training, and technical support to help organizations that protect essential services in the United States and internationally. “A $1 billion […]

Microsoft
P0
2026-09-05 20:14 UTC
Security Journalism

Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-05 20:50 UTC

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is

MalwareVulnerabilities
P25
2026-09-05 18:47 UTC
Other

PaperCut Flaws Exploited in Attacks on U.S. and European Schools

Security Affairs · Pierluigi Paganini · indexed 2026-09-05 19:35 UTC

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed threat […]

Cloud SecurityVulnerabilitiesCVE-2026-81578CVE-2026-82078
P25
2026-09-05 16:52 UTC
Security Journalism

Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-05 16:55 UTC

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.

Cloud SecurityThreat ActorsVulnerabilities
P10
2026-09-05 16:05 UTC
Security Journalism

Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-05 16:55 UTC

Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an integer-overflow vulnerability that a local attacker with elevated privileges can exploit to run arbitrary code. "A

Cloud SecurityVulnerabilitiesCVE-2026-59346
P5
2026-09-05 14:29 UTC
Security Journalism

Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain

BleepingComputer · Bill Toulas · indexed 2026-09-05 14:30 UTC

A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC). [...]

P0
2026-09-05 14:17 UTC
Security Journalism

Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was Deleted

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-05 15:30 UTC

Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk. The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware wallets

P0
2026-09-05 11:11 UTC
Security Journalism

OpenAI admits it didn't disclose rogue AI wiki hijacking incident

BleepingComputer · Ax Sharma · indexed 2026-09-05 11:25 UTC

OpenAI admits it did not disclose an incident where autonomous AI agents hijacked a German wiki, created 18,000 posts, shared answers, and bypassed restrictions, saying it treated the activity as model "misalignment" rather than a security breach. [...]

AI Security
P0
2026-09-05 07:55 UTC
Security Journalism

Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordination Channel

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-05 08:55 UTC

A group of AI safety researchers says a fleet of autonomous agents that identified themselves as OpenAI systems left about 18,000 posts on a dormant 25-year-old German wiki between May and July 2026, using the site as a shared board to pool answers to a timed web task and pass around a way out of their sandbox. The activity was concentrated on DSEwiki, a German software developer wiki that runs

AI SecurityMicrosoft
P0
2026-09-05 07:31 UTC
Security Journalism

Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-05 07:45 UTC

Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe. The Arctic Wolf Adversary Research Team said it observed attackers exploiting CVE-2026-81578 and CVE-2026-82078 – an authentication bypass and remote code execution chain – to conduct command execution and reconnaissance, as well as

Cloud SecurityPhishingThreat ActorsVulnerabilitiesCVE-2026-81578CVE-2026-82078
P30
2026-09-05 04:54 UTC
Other

Broadcom Patches Critical VMware Workstation and Fusion VM-Escape Vulnerabilities

Security Affairs · Pierluigi Paganini · indexed 2026-09-05 06:00 UTC

Broadcom patched two VMware Workstation/Fusion VM-escape bugs. No workarounds exist. Update to version 26H1u1 immediately. Broadcom published advisory VMSA-2026-0007, patching two vulnerabilities in VMware Workstation and Fusion that allow an attacker inside a virtual machine to execute code on the underlying host. One is rated Critical. Neither has a workaround. The first vulnerability, tracked as […]

Vulnerabilities
P0
2026-09-04 22:50 UTC
Other

U.S. CISA adds Google Chromium V8 flaw to its Known Exploited Vulnerabilities catalog

Security Affairs · Pierluigi Paganini · indexed 2026-09-04 23:15 UTC

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Google Chromium V8 flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Google Chromium V8 flaw, tracked as CVE-2026-85046 (CVSS score of 8,8), to its Known Exploited Vulnerabilities (KEV) catalog. This week, Google released a Chrome security update fixing 12 […]

VulnerabilitiesCVE-2026-85046
P35
2026-09-04 19:10 UTC
Vendor Research

How to secure edge AI in customer-owned environments

Microsoft Security Blog · Shayak Lahiri · indexed 2026-09-04 20:30 UTC

As AI moves into customer-owned environments, organizations need new ways to verify the systems, software, and AI assets they trust before releasing sensitive data, credentials, and models. The post How to secure edge AI in customer-owned environments appeared first on Microsoft Security Blog.

Microsoft
P0
51 52 53 54 55