IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 4,438 matching records.
AUTO-POLL // 2026-10-04 09:05 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P9 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 4

RANSOMWARE
P9
P9
COOL // 5 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
FRI
Oct 2

RANSOMWARE
P7
P7
COOL // 46 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
WED
Sep 30

RANSOMWARE
P10
P10
WARM // 59 ARTICLES
TUE
Sep 29

RANSOMWARE
P4
P4
COOL // 68 ARTICLES
MON
Sep 28

RANSOMWARE
P7
P7
COOL // 52 ARTICLES
RESET
2026-09-30 13:16 UTC
Security Journalism

WatchGuard Patches Critical Fireware OS Code Injection Vulnerability

Security Week · Ionut Arghire · indexed 2026-09-30 13:30 UTC

WatchGuard has rolled out patches for 15 code execution, DoS, authorization, and path traversal bugs in Fireware OS. The post WatchGuard Patches Critical Fireware OS Code Injection Vulnerability appeared first on SecurityWeek.

Vulnerabilities
P0
2026-09-30 12:16 UTC
Security Journalism

Chrome, Firefox Updates Patch Over 100 Vulnerabilities

Security Week · Ionut Arghire · indexed 2026-09-30 12:30 UTC

Some of the flaws could allow remote attackers to execute arbitrary code or escape the browser sandbox. The post Chrome, Firefox Updates Patch Over 100 Vulnerabilities appeared first on SecurityWeek.

Cloud Security
P0
2026-09-30 11:58 UTC
Security Journalism

Know Your Enemy: Browser-Based Attack Techniques in 2026

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-30 13:00 UTC

Given that the browser is where business apps are accessed and used, it makes sense that attacks are happening there too. Most breaches today begin in a browser session. Often, they never leave it, with the entire attack chain from initial access to exfiltration playing out in the browser. Here are the six most dangerous techniques that should be on every security team's radar in 2026. 1.

P0
2026-09-30 11:30 UTC
Security Journalism

AI Coding Agents Exposed 13,000 Internal Images, Including Billing Records, on GitHub

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-30 11:45 UTC

AI coding agents asked to share screenshots of code changes for review have put internal company images in public GitHub repositories, security company Glow said. Its researchers found more than 13,000 internal images from developers at over 300 organizations, including customer billing records and screens of features not yet released. In most cases, they sat under developers' personal accounts

P0
2026-09-30 10:45 UTC
Security Journalism

US-Focused CSuite Phishing Steals Microsoft 365 Sessions and Deploys RMM Tools for Remote Access

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-30 11:45 UTC

ANY.RUN researchers traced a US-focused CSuite phishing campaign across 351 sandbox analyses, with 51% of submissions coming from the United States. Technology, manufacturing, government, and consulting organizations showed the highest exposure. By combining Microsoft 365 session theft with remote-access tool deployment, CSuite can turn a phishing incident into broader account compromise, fraud

CybercrimeMicrosoftPhishing
P0
2026-09-30 10:20 UTC
Security Journalism

ShinyHunters Defiant After FBI Calls on Members to Come Forward

Security Week · Ionut Arghire · indexed 2026-09-30 10:30 UTC

In the wake of a suspected leader’s arrest, ShinyHunters says it never intended to publish data stolen from the FBI. The post ShinyHunters Defiant After FBI Calls on Members to Come Forward appeared first on SecurityWeek.

Law Enforcement
P0
2026-09-30 10:00 UTC
Vendor Research

China-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoor

Cisco Talos Intelligence Blog · Ashley Shen · indexed 2026-09-30 10:10 UTC

Cisco Talos uncovered a cluster of activity we track as UAT-11587 targeting government and policy organizations across Asia, including in Taiwan, India, the Philippines, and Cambodia, to deliver a previously undocumented backdoor referred to as “Antino” in developer artifacts.

Malware
P0
2026-09-30 09:14 UTC
Other

Attackers Abuse ChatGPT Custom GPTs to Deploy a Full-Featured RAT

Security Affairs · Pierluigi Paganini · indexed 2026-09-30 10:10 UTC

Threat actors abused fake ChatGPT Custom GPTs and ClickFix to deliver a multi-stage RAT. ChatGPT’s Custom GPT feature is the latest legitimate surface being turned into a delivery mechanism, and Huntress researchers caught it in action across at least 40 incidents. A Custom GPT (now simply called a GPT) is essentially a version of ChatGPT […]

Threat Actors
P0
2026-09-30 08:24 UTC
Security Journalism

Attackers Exploit NetScaler Flaw for Root Access, Deploy WHIPSHOT and SLAPSHOT

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-30 09:55 UTC

Unknown threat actors have been observed exploiting a newly patched security flaw in Citrix NetScaler ADC and NetScaler Gateway appliances to target organizations in North America and Europe. The activity, observed by Mandiant Consulting and Google Threat Intelligence Group (GTIG) in September 2026, has targeted government, financial services, technology, education, and legal and professional

Threat ActorsThreat Intelligence
P0
2026-09-30 08:09 UTC
Security Journalism

OpenSSL Fixes High-Severity DTLS Flaw That Can Leak Heap Memory Unencrypted

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-30 09:55 UTC

A High-severity OpenSSL flaw can leak heap memory to the other side of a DTLS connection or crash the program, OpenSSL said on September 29 as it released fixes. DTLS, the TLS variant used for UDP traffic, resends a handshake message if no reply arrives before the timer expires. The leak or crash can happen when such a resend starts while a larger handshake message is stuck part-way

P0
2026-09-30 08:04 UTC
Other

U.S. CISA adds Apple Multiple Products flaw to its Known Exploited Vulnerabilities catalog

Security Affairs · Pierluigi Paganini · indexed 2026-09-30 09:10 UTC

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Apple Multiple Products flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added an Apple Multiple Products flaw, tracked as CVE-2026-86950 (CVSS score of 8.8), to its Known Exploited Vulnerabilities (KEV) catalog. This week, Apple has released security updates for iOS, iPadOS […]

AppleVulnerabilitiesCVE-2026-86950
P35
2026-09-30 07:25 UTC
Other

WHIPSHOT and SLAPSHOT: the tools behind an active Citrix NetScaler campaign

Security Affairs · Pierluigi Paganini · indexed 2026-09-30 07:50 UTC

Mandiant and GTIG detail active exploitation of a Citrix NetScaler zero-day, deploying custom web shells WHIPSHOT and SLAPSHOT for root access. Mandiant and Google Threat Intelligence Group caught active exploitation of a zero-day in Citrix NetScaler ADC and Gateway appliances in late September 2026. The bug, tracked as CVE-2026-88772 (CVSS score of 9.5), has been […]

Threat IntelligenceVulnerabilitiesCVE-2026-88772
P30
2026-09-30 06:55 UTC
Security Journalism

High-Severity Vulnerabilities Patched in OpenSSL, WolfSSL

Security Week · Eduard Kovacs · indexed 2026-09-30 07:15 UTC

Roughly a dozen vulnerabilities have been patched in each of the open source cryptographic libraries. The post High-Severity Vulnerabilities Patched in OpenSSL, WolfSSL appeared first on SecurityWeek.

P0
2026-09-30 05:30 UTC
Security Journalism

Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-30 07:00 UTC

Cybersecurity researchers have disclosed technical details of a recently patched critical security flaw in Citrix NetScaler ADC and Gateway that has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-88772 (CVSS score: 9.5), has been described as a memory overflow bug in the Datagram Transport Layer Security (DTLS) protocol handling that's rooted in the NetScaler

Security ResearchVulnerabilitiesCVE-2026-88772
P25
2026-09-30 05:00 UTC
Other

ZDI-26-750: WatchGuard FireWare OS spamd statushdlr Stack-based Buffer Overflow Remote Code Execution Vulnerability

Zero Day Initiative · indexed 2026-09-30 21:10 UTC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of WatchGuard FireWare OS. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-18145.

VulnerabilitiesCVE-2026-18145
P20
2026-09-30 05:00 UTC
Other

ZDI-26-749: WatchGuard FireWare OS samld SAMLSession Deserialization of Untrusted Data Remote Code Execution Vulnerability

Zero Day Initiative · indexed 2026-09-30 21:10 UTC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of WatchGuard FireWare OS. An attacker must first obtain the ability to write to the samld session directory on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-13046.

VulnerabilitiesCVE-2026-13046
P20
2026-09-30 01:48 UTC
Security Journalism

Trump Says Top Tech Firms Have Signed Accord to ‘Self-Police’ AI Development

Security Week · Associated Press · indexed 2026-09-30 02:00 UTC

The accord opened the door to future regulation but focused on four voluntary steps for the companies to take. The post Trump Says Top Tech Firms Have Signed Accord to ‘Self-Police’ AI Development appeared first on SecurityWeek.

P0
2026-09-29 21:39 UTC
Vendor Research

Phishing Abuses RMM Tools for Persistent Access

Microsoft Security Blog · Microsoft Security Research, Parasharan Raghavan, Deva Kanna Kannan, Sai Chakri and Microsoft Defender Experts · indexed 2026-09-29 22:40 UTC

Microsoft observed phishing campaigns that abused MSP360 RMM to deploy ScreenConnect, creating redundant remote-access channels for follow-on activity The post Phishing Abuses RMM Tools for Persistent Access appeared first on Microsoft Security Blog.

MicrosoftPhishing
P0
5 6 7 8 9