IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 4,496 matching records.
AUTO-POLL // 2026-10-06 07:25 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P4 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 6

ADVISORY
P4
P4
COOL // 4 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
FRI
Oct 2

RANSOMWARE
P7
P7
COOL // 46 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
WED
Sep 30

RANSOMWARE
P10
P10
WARM // 59 ARTICLES
RESET
2026-08-31 20:47 UTC
Security Journalism

Cronos blockchain restarts after $74 million Tectonic exploit

BleepingComputer · Bill Toulas · indexed 2026-08-31 21:00 UTC

The Cronos blockchain network has resumed trading activity after a price-manipulation attack on the Tectonic cryptocurrency lending platform allowed an attacker to borrow $74 million. [...]

P0
2026-08-31 20:00 UTC
Community

The Coding-Agent Trap: When a "Free" LLM Endpoint Is the Adversary, (Mon, Aug 31st)

SANS Internet Storm Center · indexed 2026-08-31 20:10 UTC

One of my internet-exposed inference honeypots was discovered, relabeled with sought-after model names, and incorporated into infrastructure apparently used to provide "free" LLM backends. It then received a real coding-agent session — history, filesystem output, working paths, and the agent's local tool manifest. The honeypot did not request or cause any tool execution; what the request exposed is what a malicious operator in that position could do.

AI Security
P0
2026-08-31 19:45 UTC
Other

ValleyRAT: When Legitimate Software Becomes a Malware Delivery Tool

Security Affairs · Pierluigi Paganini · indexed 2026-08-31 20:50 UTC

ValleyRAT hides behind legitimate adware, using DLL sideloading to evade detection, steal data and give Silver Fox control of infected systems. ValleyRAT doesn’t always need to disguise itself as a cracked game or a fake browser update. It can also hide behind something much more ordinary: an application that looks like adware and appears to […]

Malware
P0
2026-08-31 19:00 UTC
Vendor Research

We invited a direct competitor into Security Hub Extended. Here’s why.

AWS Security Blog · Michael Fuller · indexed 2026-08-31 19:05 UTC

When customers keep pointing you to a solution that overlaps with parts of your own offering, you have a choice to make. This post is about the choice we made with Upwind, and why we’d make it again. AWS Security Hub Extended exists because customers told us what was working for them in enterprise security […]

Cloud Security
P0
2026-08-31 18:51 UTC
Security Journalism

Microsoft warns of TerminalFix attacks deploying reverse tunnels

BleepingComputer · Bill Toulas · indexed 2026-08-31 19:05 UTC

A new ClickFix variant dubbed TerminalFix uses fake Cloudflare CAPTCHA prompts on compromised websites to trick victims into running malicious PowerShell commands in Windows Terminal. [...]

Microsoft
P0
2026-08-31 17:34 UTC
Security Journalism

AI Model Rules Are Not Security Controls

Dark Reading · Jacob Krell · indexed 2026-08-31 17:55 UTC

OpenAI's Hugging Face attack postmortem shows agents don't care about rules — they need strong controls.

P0
2026-08-31 17:24 UTC
Security Journalism

North Korean Job Fraud Expands Beyond IT Into Healthcare and Sales

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-31 18:05 UTC

Threat actors with ties to the Democratic People's Republic of Korea (aka DPRK or North Korea) have been observed seeking job opportunities beyond the information technology (IT) sector, with recent investigations identifying suspected workers employed in sales and marketing and the medical profession. The ongoing insider threat is part of what has been described as the IT worker scheme,

CybercrimeDFIRThreat Actors
P0
2026-08-31 17:18 UTC
Vendor Research

Automate IAM Identity Center governance with continuous discovery and reporting

AWS Security Blog · Jonathan Nguyen · indexed 2026-08-31 17:20 UTC

AWS IAM Identity Center integrates with external identity provider (IdP) to provide customers with a centralized authentication and authorization solution for AWS resources across AWS Organizations. AWS continues to invest into IAM Identity Center with a growing number of AWS services that natively integrate with IAM Identity Center. As your AWS organization scales, maintaining visibility […]

Cloud SecurityMicrosoft
P0
2026-08-31 17:07 UTC
Vendor Research

GCP Apigee PE to Service Agent with API Proxy

Tenable Research Advisories · Joshua Martinelle · indexed 2026-08-31 19:05 UTC

GCP Apigee PE to Service Agent with API Proxy Tenable Research has identified and responsibly disclosed a privilege escalation vulnerability in Google Cloud Apigee. This vulnerability allowed an attacker with restricted Apigee permissions to exfiltrate the OAuth access token of the privileged Apigee Core Service Agent.The vulnerability stems from Apigee API Proxies' ability to execute custom JavaScript policy scripts that can access the underlying Instance Metadata Service (IMDS).An attacker wi…

Cloud SecuritySecurity ResearchVulnerabilities
P10
2026-08-31 16:50 UTC
Security Journalism

OpenAI confirms ChatGPT outage as users report errors

BleepingComputer · Mayank Parmar · indexed 2026-08-31 17:00 UTC

ChatGPT Work is experiencing a partial outage, and users across multiple subscription plans may be unable to start or continue tasks. [...]

P0
2026-08-31 15:42 UTC
Vendor Research

WordPress - Kubio AI Website Builder DoS

Tenable Research Advisories · Joshua Martinelle · indexed 2026-08-31 19:05 UTC

WordPress - Kubio AI Website Builder DoS The REST endpoint `GET /wp-json/kubio/v1/enable-theme` passes the client-supplied `name` parameter directly and without validation into WordPress core's `switch_theme()`:// lib/api/colibri.php function kubio_enable_theme( WP_REST_Request $data ) { switch_theme( $data['name'] ); // $data['name'] ) ); }Because `$data['name']` is not type-checked, an authorized request can supply `name` as an array instead of a string. `switch_theme()` persists that value i…

Network Security
P0
2026-08-31 14:00 UTC
Security Journalism

File servers are here to stay. Here’s how to manage them securely

BleepingComputer · Sponsored by Tenfold Software · indexed 2026-08-31 14:20 UTC

File servers remain a critical part of many IT environments, but managing access securely can become complex as permissions accumulate. tenfold Software outlines five best practices for simplifying file server administration and maintaining least-privilege access. [...]

P0
2026-08-31 14:00 UTC
Security Journalism

Huntress API Update: New Endpoints, Webhooks, and Automation

Huntress · indexed 2026-09-07 17:30 UTC

The Huntress API has grown from six read-only endpoints into a full integration and automation platform. See what’s new, including webhooks and MCP support.

P0
2026-08-31 13:50 UTC
Security Journalism

⚡ Weekly Recap: Chinese Spy Proxy, AI Agents Go Off-Task, Router Backdoors and More

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-31 14:30 UTC

The boring parts caused most of the trouble. A router shipped ready to listen. A fake check turned the user into the installer. Trusted systems collected traffic and passwords, then cleaned the logs. Old bugs formed new attack chains. Even an AI agent decided its assigned task was optional. Elsewhere, fake apps, helpful support calls, cheap banking kits, exposed systems, and weak defaults kept

AI SecurityMalwareNetwork Security
P0
2026-08-31 13:38 UTC
Other

Breaking the Seal: Static Deobfuscation of JSCeal’s Compiled V8 Bytecode

Check Point Research · shlomoo@checkpoint.com · indexed 2026-09-07 17:30 UTC

Research by: hasherezade Key Points Introduction JSCeal is a stealer delivered as compiled V8 bytecode (.jsc) and executed by a bundled Node.js runtime, targeting cryptocurrency applications (other vendors also tag it with the names WEEVILPROXY or MeadowLocust). Its campaign activity dates back to March 2024 [1]; Check Point Research has been tracking the malware since early […] The post Breaking the Seal: Static Deobfuscation of JSCeal’s Compiled V8 Bytecode appeared first on Check Point Resea…

Malware
P0
2026-08-31 12:58 UTC
Other

31st August – Threat Intelligence Report

Check Point Research · urias@checkpoint.com · indexed 2026-09-07 17:30 UTC

For the latest discoveries in cyber research for the week of 31st August, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Manchester Airports Group, the UK operator of Manchester, London Stansted, and East Midlands airports, has disclosed a cyberattack that exposed data belonging to about 8.7 million customers. The compromised information includes contact details, […] The post 31st August – Threat Intelligence Report appeared first on Check Point Research.

Threat Intelligence
P0
2026-08-31 12:14 UTC
Security Journalism

ValleyRAT Backdoor Hides in Signed Adware That Users Add to Antivirus Exclusions

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-31 12:30 UTC

The threat actor known as Silver Fox has been observed distributing the ValleyRAT backdoor disguised as a signed Chinese adware application, running the malware under a trusted process to slip past users who add such software to their antivirus exclusions. Russian cybersecurity vendor Kaspersky said the attackers built the disguise around QN Wallpaper, a genuine Chinese desktop-wallpaper tool

MalwareThreat Actors
P0
2026-08-31 11:47 UTC
Security Journalism

Aurora Ransomware Operators Use Cursor AI in Attacks Against 10 Targets

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-31 12:30 UTC

Threat actors associated with Aurora (aka Aur0ra) ransomware have been observed using SpaceX's artificial intelligence (AI)-powered coding assistant Cursor to break into target networks, according to findings from CloudSEK and Gambit Security. The two independent analyses are based on exposed infrastructure associated with the Russian-speaking cybercrime group, leading to the discovery of its

AI SecurityCybercrimeRansomwareThreat Actors
P15
58 59 60 61 62