IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 4,492 matching records.
AUTO-POLL // 2026-10-06 04:50 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
NO DATA
NO INTELLIGENCE AGGREGATED TODAY
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 6
NO DATA
--
NO INTEL
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
FRI
Oct 2

RANSOMWARE
P7
P7
COOL // 46 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
WED
Sep 30

RANSOMWARE
P10
P10
WARM // 59 ARTICLES
RESET
2026-09-04 18:30 UTC
Other

Crooks Behind Manchester Airports Group Hack Leaked Data of 8.8 Million People

Security Affairs · Pierluigi Paganini · indexed 2026-09-04 18:55 UTC

Manchester Airports Group (MAG) data allegedly leaked by FulcrumSec exposes emails and phone numbers of 8.8 million people. Manchester Airports Group, which operates Manchester, London Stansted and East Midlands airports, has confirmed a data breach involving customer information held in a third-party database. The company says airport operations, passenger safety and aviation security were not […]

Data Breaches
P0
2026-09-04 18:13 UTC
Vendor Research

OSPAR 2026 report now available with 167 services in scope

AWS Security Blog · James Chang · indexed 2026-09-04 18:35 UTC

We’re pleased to confirm the successful completion of our annual Amazon Web Services (AWS) Outsourced Service Provider’s Audit Report (OSPAR) assessment on July 29, 2026, in line with the OSPAR version 2.0 framework. The Association of Banks in Singapore (ABS) established the Guidelines on Control Objectives and Procedures for Outsourced Service Providers (ABS Guidelines) to […]

Cloud Security
P0
2026-09-04 16:18 UTC
Security Journalism

In Other News: Microsoft’s Cloud Patches, Hacked Dropbox Accounts, Guardio’s $1.1B Valuation

Security Week · SecurityWeek News · indexed 2026-09-07 17:25 UTC

Noteworthy stories that might have slipped under the radar: Microsoft rolled out patches for cloud services, hackers compromised 5,000 Dropbox accounts, and Guardio is now valued at $1.1 billion. The post In Other News: Microsoft’s Cloud Patches, Hacked Dropbox Accounts, Guardio’s $1.1B Valuation appeared first on SecurityWeek.

Microsoft
P0
2026-09-04 16:11 UTC
Security Journalism

HPE Patches Critical RCE Vulnerabilities in AOS-CX

Security Week · Ionut Arghire · indexed 2026-09-07 17:25 UTC

Nearly two dozen issues, tracked collectively as CVE-2026-73749 (CVSS score of 9.8), were addressed with the updates. The post HPE Patches Critical RCE Vulnerabilities in AOS-CX appeared first on SecurityWeek.

VulnerabilitiesCVE-2026-73749
P20
2026-09-04 16:07 UTC
Security Journalism

OpenAI Pledges $1 Billion to Bring Frontier AI to Critical Infrastructure Defenders

Security Week · Kevin Townsend · indexed 2026-09-07 17:25 UTC

The Daybreak initiative will provide subsidized AI cyber capabilities, training and technical assistance, though OpenAI has disclosed few details about costs and eligibility. The post OpenAI Pledges $1 Billion to Bring Frontier AI to Critical Infrastructure Defenders appeared first on SecurityWeek.

Microsoft
P0
2026-09-04 15:57 UTC
Security Journalism

Companies Have 6 Months to Prepare for Automated Attacks

Dark Reading · Robert Lemos · indexed 2026-09-04 16:15 UTC

Frontier AI models have already demonstrated they can autonomously — and in some cases, inadvertently — conduct end-to-end compromises, but researchers warn the situation will become more urgent very soon.

P0
2026-09-04 15:57 UTC
Security Journalism

Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-04 16:10 UTC

Microsoft is alerting of a "high-volume phishing campaign" that's using invisible Unicode tag characters to bypass email filters. "Instead of using these characters to hide instructions from people while exposing them to AI models, the attacker used them to split financial lure words such as 'funding' to prevent email filters from parsing them," the Microsoft Security Research team said. The

MicrosoftPhishingSecurity Research
P0
2026-09-04 15:42 UTC
Security Journalism

US, Britain to coordinate on scam center takedowns

The Record · indexed 2026-09-04 16:00 UTC

The U.S. Department of Justice and the U.K.'s National Crime Agency and Crown Prosecutor signed a memorandum to cooperate on cases involving Southeast Asian scam operations.

Law Enforcement
P0
2026-09-04 15:20 UTC
Security Journalism

PostgreSQL Fixes 12-Year-Old Logical Decoding Flaw Enabling Replication-Role Code Execution

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-04 16:10 UTC

PostgreSQL has released updates to address a security flaw that allows an account with the REPLICATION attribute to run arbitrary code as the operating-system user running the database server. The flaw, tracked as CVE-2026-6471 (CVSS score: 7.2), has been present since logical decoding was introduced in PostgreSQL 9.4 in 2014. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are

VulnerabilitiesCVE-2026-6471
P5
2026-09-04 14:51 UTC
Security Journalism

New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-04 15:10 UTC

A previously undocumented Linux toolkit has been found compiled directly into the trojanized HAProxy load balancers of two South Korean organizations, where it intercepted web traffic and served altered pages to selected visitors. The attackers named the implant ted in debug strings left in the binary. It is not a HAProxy vulnerability, and installing it requires code execution on the host and

LinuxMalwareVulnerabilities
P0
2026-09-04 14:45 UTC
Security Journalism

UK account-hack losses surge as new reporting system exposes hidden cases

The Record · indexed 2026-09-04 15:00 UTC

In its first annual assessment, published Friday, the City of London Police said victims reported losing £6.3 million ($8.5 million) to account hacks in the year ending March 31, up from £1.2 million ($1.6 million) a year earlier.

P0
2026-09-04 14:01 UTC
Security Journalism

39 New Methods That Compromise Passkey Authentication

BleepingComputer · Sponsored by Token · indexed 2026-09-04 14:15 UTC

Passkeys eliminate many password-based attacks, but researchers have documented 39 methods for compromising authentication built around them. Token explains how attackers can abuse authentication prompts, synced credentials, enrollment, recovery, and other trust boundaries without breaking FIDO2 cryptography. [...]

P0
2026-09-04 13:41 UTC
Other

PostgreSQL Hit by 12-Year-Old Vulnerability Allowing Server Takeover

Security Affairs · Pierluigi Paganini · indexed 2026-09-04 14:25 UTC

PostGREShell (CVE-2026-6471) is a 12-year-old PostgreSQL flaw that lets low-privileged attackers execute code and take over servers. Cyera researchers found a severe PostgreSQL vulnerability, dubbed PostGREShell and tracked as CVE-2026-6471 (CVSS score of 7.2). Present in releases dating back to 2014, the flaw can be exploited by attackers with low-level replication access to execute code, […]

VulnerabilitiesCVE-2026-6471
P5
2026-09-04 12:34 UTC
Security Journalism

G7 urges organizations to prepare for quantum cyber threats

The Record · indexed 2026-09-04 12:55 UTC

In a joint advisory released Thursday, the G7 Cyber Security Working Group and the U.S. Cybersecurity and Infrastructure Security Agency, CISA, said organizations should begin moving to post-quantum cryptography now.

P0
2026-09-04 12:15 UTC
Security Journalism

Insurers Search for Answers to Rein in Rogue AI

Dark Reading · Robert Lemos · indexed 2026-09-04 21:40 UTC

As incidents of unintended harm caused by rogue AI agents mount, CISOs and insurance firms are figuring out how to handle the fallout.

AI Security
P0
2026-09-04 12:00 UTC
Vendor Research

DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors

Rapid7 · Rapid7 Intelligence · indexed 2026-09-04 12:25 UTC

OverviewA new Linux toolkit, identified by Rapid7 Labs, has been targeting organizations across South Korea’s automotive and media industries with minimal detection. The campaign made use of a HAProxy instance named “ted backdoor”, alongside trojanized versions of crond, agetty, atd, sshd, and polkitd. This previously undocumented framework enabled threat actors to execute remote commands on compromised servers, inject malicious scripts into web traffic, perform credential harvesting, and engag…

APT / Nation-StateLinuxMalwarePhishingThreat ActorsVulnerabilities
P15
2026-09-04 11:00 UTC
Other

Chinese Hackers Use AI Agents in Multi-Country Cyber Campaign

Security Affairs · Pierluigi Paganini · indexed 2026-09-04 11:10 UTC

Hunt.io uncovered a Chinese-speaking campaign using AI agents to automate cyberattacks against Asian government, education and industrial targets. Threat intelligence firm Hunt.io just documented a second, separate China-linked campaign wiring commercial AI models directly into live cyberespionage operations, this time hitting Taiwan’s Kuomintang Party archives, Indonesia’s Ministry of Foreign Affairs, government and education systems in […]

AI SecurityAPT / Nation-StateThreat Intelligence
P0
2026-09-04 08:48 UTC
Security Journalism

Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-04 09:40 UTC

Threat actors are exploiting two critical security flaws in WordPress plugins Super Forms and Elementor Pro, according to findings from Wordfence. The vulnerabilities in question are - CVE-2026-14894 (CVSS score: 9.8) - A missing file type validation vulnerability in Super Forms – Drag & Drop Form Builder that allows unauthenticated attackers to upload files of any type, including

Cloud SecurityThreat ActorsVulnerabilitiesCVE-2026-14894
P20
2026-09-04 08:24 UTC
Other

Google fixes the sixth actively exploited Chrome zero-day of 2026

Security Affairs · Pierluigi Paganini · indexed 2026-09-04 08:50 UTC

Google patched 12 Chrome flaws, including an actively exploited V8 zero-day that could enable remote code execution through a crafted webpage. Google released a Chrome security update fixing 12 vulnerabilities, including CVE-2026-85046 (CVSS score of 8.8), an actively exploited V8 type confusion flaw. The bug affects Chrome’s JavaScript and WebAssembly engine and could let a […]

Cloud SecurityVulnerabilitiesCVE-2026-85046
P45
2026-09-04 07:35 UTC
Security Journalism

Plex Urges Immediate Updates After Patching Multiple Undisclosed Security Flaws

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-04 08:40 UTC

Plex is urging users to update their instances to the latest version following the release of an update that patches multiple security flaws. The fixes are available in Plex Media Server 1.43.3 and Plex Desktop 1.115.0. The streaming media service did not elaborate on what those issues are, but said CVE identifiers have been requested for them. "We recommend all server owners and Desktop users

Cloud Security
P0
2026-09-04 07:18 UTC
Security Journalism

Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-04 08:40 UTC

Google on Thursday released security updates to patch 12 vulnerabilities, including one that has come under active exploitation in the wild. The high-severity vulnerability, tracked as CVE-2026-85046 (CVSS score: 8.8), has been described as a type confusion bug in V8, Chrome's JavaScript and WebAssembly engine. "Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote

VulnerabilitiesCVE-2026-85046
P50
52 53 54 55 56