IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 4,521 matching records.
AUTO-POLL // 2026-10-06 14:40 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P3 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 6

RANSOMWARE
P3
P3
COOL // 29 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
FRI
Oct 2

RANSOMWARE
P7
P7
COOL // 46 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
WED
Sep 30

RANSOMWARE
P10
P10
WARM // 59 ARTICLES
RESET
2026-08-19 16:00 UTC
Vendor Research

Cisco Unified Intelligence Center SQL Injection Vulnerability

Cisco Security Advisories · indexed 2026-08-19 16:10 UTC

A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an authenticated, local attacker to perform a blind SQL injection attack against an affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted request to the web-based management interface. A successful exploit could allow the attacker to read the contents of the internal database of an affecte…

VulnerabilitiesCVE-2026-20327
P5
2026-08-19 16:00 UTC
Vendor Research

Cisco Industrial Ethernet 1000 Series Switches Denial of Service Vulnerability

Cisco Security Advisories · indexed 2026-08-19 16:10 UTC

A vulnerability in the handling of management plane packets by Cisco Industrial Ethernet (IE) 1000 Series Switches could allow an unauthenticated, remote attacker to cause the device manager, SSH, or API to become inaccessible.This vulnerability is due to insufficient protection against management plane flooding attacks. An attacker could exploit this vulnerability by sending a high rate of ICMP, SSH, or HTTP traffic to an affected device. A successful exploit could allow the attacker to cause …

Network SecurityVulnerabilitiesCVE-2026-20177
P5
2026-08-19 16:00 UTC
Vendor Research

Cisco RoomOS Stack Overflow Vulnerability

Cisco Security Advisories · indexed 2026-08-19 16:10 UTC

A vulnerability in the USB driver of Cisco RoomOS could allow an unauthenticated, local attacker with physical access to the USB port on an affected device to execute arbitrary code with root privileges. This vulnerability is due to insufficient boundary checks for specific data that is provided through the USB driver. An attacker could exploit this vulnerability by connecting a malicious USB device to an affected device. A successful exploit could allow the attacker to cause a buffer overflow …

VulnerabilitiesCVE-2026-20302
P5
2026-08-19 16:00 UTC
Vendor Research

Cisco BroadWorks Out-of-Band Blind XML External Entity Injection Vulnerability

Cisco Security Advisories · indexed 2026-08-19 16:10 UTC

A vulnerability in the Open Client Interface (OCI) XML Parser of Cisco BroadWorks could allow an unauthenticated, remote attacker to read sensitive configuration information on an affected system. This vulnerability exists because XML entries are improperly parsed due to external entity resolution being allowed by default. An attacker could exploit this vulnerability by sending a crafted XML message to the Open Client Interface – Provisioning (OCI-P) service. A successful exploit could allow th…

VulnerabilitiesCVE-2026-20320
P5
2026-08-19 15:56 UTC
Security Journalism

US charges Iranian hackers over $3.4 billion intellectual property theft

BleepingComputer · Bill Toulas · indexed 2026-08-19 16:10 UTC

The U.S. has charged 17 Iranians, alleged members of a hacking-for-hire company called Mabna Institute, involved in years-long operations that stole data from American organizations. [...]

P0
2026-08-19 14:24 UTC
Community

Simple Scans for Cloud Metadata Service, (Wed, Aug 19th)

SANS Internet Storm Center · indexed 2026-08-19 14:30 UTC

Cloud providers typically expose a REST API at 169.254.169.254 that allows code running on virtual machines to retrieve machine-specific data. Some of the data is more or less harmless, such as the region the machine is running in or its MAC and IP addresses. However, the service may also be used to retrieve credentials for IAM roles and service account tokens.

P0
2026-08-19 14:00 UTC
Security Journalism

Password spraying attacks surge 155x as hackers exploit MFA gaps

BleepingComputer · Sponsored by Huntress Labs · indexed 2026-08-19 14:05 UTC

Huntress observed a 155x increase in password spraying attacks in H1 2026, including a campaign that generated more than 81 million login attempts in two weeks. The attacks exploited legacy authentication and gaps in MFA policies that left some login flows unprotected. [...]

P0
2026-08-19 13:12 UTC
Security Journalism

SilkParasite Espionage Campaign Targets Central Asian Governments with Five New RATs

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-19 13:35 UTC

A previously unreported cyber espionage operation dubbed SilkParasite has been observed targeting government bodies in Central Asia. The intrusion set makes use of seven remote access tool (RAT) families, five of which have never been previously documented: DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT. SilkParasite, first discovered in late 2025, is assessed to be a

APT / Nation-StateMicrosoft
P0
2026-08-19 12:00 UTC
Vendor Research

Rapid7 and Licencias OnLine Partner to Accelerate Cybersecurity Maturity across Latin America

Rapid7 · Cássio De Alcântara · indexed 2026-08-19 14:20 UTC

Cássio De Alcântara is Director, LATAM Sales at Rapid7.Across Latin America, organizations are embracing cloud, AI, and digital transformation to drive innovation and business growth. These technologies create new opportunities, but also introduce greater complexity and expanding attack surfaces.In this environment, security leaders are being asked to understand where risk exists across increasingly distributed environments and quickly eliminate blind spots like Shadow IT and Shadow AI – all wi…

P0
2026-08-19 12:00 UTC
Government

NIST Releases Tips & Tactics for Building Automation & Control System Cybersecurity

NIST Cybersecurity Insights · Keith Stouffer, Michael Galler · indexed 2026-08-19 12:25 UTC

Recent cyberattacks highlight the growing threat to operational technology (OT) used in critical infrastructure. Whether you work for an infrastructure owner/operator or are a consumer of an infrastructure service, the events of the past few weeks have made it clear that cybersecurity is an important factor in ensuring the safe and reliable delivery of critical goods and services. For OT owners/operators, it can be challenging to address the range of cybersecurity threats, vulnerabilities and r…

ICS / OT
P0
2026-08-19 11:34 UTC
Security Journalism

Hackers Compromised 14,500+ Dahua Devices Using Credential Attacks, Auth Bypasses, and P2P

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-19 13:35 UTC

Cybersecurity researchers at Hunt.io have disclosed details of a campaign that they say compromised more than 14,530 Dahua devices between June 17 and July 22, 2026, using credential attacks, two authentication-bypass flaws, and a peer-to-peer (P2P) relay technique. The activity, codenamed Operation CameraSwarm, was reconstructed from a 407 MB exposed working directory containing 2,616 files

Cloud SecuritySecurity Research
P0
2026-08-19 11:30 UTC
Security Journalism

Phishing 3.0: The Fight Moves to Agent Versus Agent

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-19 13:35 UTC

Most email defenses still do the job they did a decade ago. Scan the message, look for something malicious, block it. That worked when the danger sat in the payload, a bad link or an attachment. It stopped working when the danger moved into the message's intent, and it is failing now that the sender is no longer a person. From Bad Content to Bad Intent to AI on Both Sides Phishing 1.0 was bad

Phishing
P0
2026-08-19 11:25 UTC
Security Journalism

StopAndProtect Uses Nearly 2,000 Hacked WordPress Sites to Spread Malware and Steal Data

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-19 11:35 UTC

Cybersecurity researchers have flagged a global cybercrime operation that abuses thousands of hacked WordPress websites as infrastructure to disseminate malware, commandeer infected hosts, store stolen documents, screenshots, and activity logs created to track the status of the activity. "The operation doesn't rely on a single piece of malware, but on a whole toolkit of criminal software

CybercrimeMalwareSecurity Research
P0
2026-08-19 11:14 UTC
Security Journalism

Microsoft fixes known issue causing Windows Defender crashes

BleepingComputer · Sergiu Gatlan · indexed 2026-08-19 11:35 UTC

Microsoft has resolved a bug that caused Windows Defender to crash after a recent security update, resulting in 0xc0000005 access violation errors on some affected systems. [...]

Microsoft
P5
2026-08-19 11:01 UTC
Security Journalism

Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-19 11:35 UTC

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added four critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, stating they are being exploited in the wild. The shortcomings added to the KEV catalog are listed below - CVE-2026-65400 (CVSS score: 9.8) - An improper authentication vulnerability impacting Apple macOS that could allow an

AppleCloud SecurityMicrosoftVulnerabilitiesCVE-2026-65400
P55
2026-08-19 10:00 UTC
Vendor Research

Describing attacks with crime script analysis

Cisco Talos Intelligence Blog · Martin Lee · indexed 2026-08-19 10:05 UTC

Martin explores how using crime script analysis to describe an attack with everyday language makes the situation accessible to non-technical audiences and identify points where the crime can be disrupted.

P0
2026-08-19 08:55 UTC
Other

Microsoft Tracks MacSync Stealer by Its Behavior, Not Its Domains

Security Affairs · Pierluigi Paganini · indexed 2026-08-19 09:50 UTC

Microsoft tracked over 30 MacSync Stealer domains by focusing on behavioral patterns, revealing a campaign targeting passwords, keys, wallets and other data. Domain blocking is a losing game when the thing you’re blocking can register a new domain faster than you can add it to a list. That’s the exact problem Microsoft Defender Experts ran […]

MalwareMicrosoft
P0
2026-08-19 08:33 UTC
Other

50,000 Stripe Secrets Leaked in Public Code

Security Affairs · Pierluigi Paganini · indexed 2026-08-19 09:50 UTC

Over 50,000 exposed Stripe API keys show how leaked secrets can enable fraud, data access and account abuse within hours. Ransomnews researchers have documented a large-scale leak of Stripe merchant API keys found exposed in public code repositories, GitHub Actions logs, and misconfigured web servers, with over 50,000 unique keys identified in total. The research […]

Cybercrime
P0
2026-08-19 07:19 UTC
Other

U.S. CISA adds Apple macOS, Microsoft SharePoint, Broadcom VMware vCenter, and Microsoft IKE flaws to its Known Exploited Vulnerabilities catalog

Security Affairs · Pierluigi Paganini · indexed 2026-08-19 07:35 UTC

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Apple macOS, Microsoft SharePoint, Broadcom VMware vCenter, and Microsoft IKE flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2026-33824 is a Windows Internet Key Exchange (IKE) Service Extensions Remote Code Execution […]

AppleCloud SecurityMicrosoftVulnerabilitiesCVE-2026-33824
P50
2026-08-19 06:01 UTC
Security Journalism

Microsoft Links 30+ Rotating Domains to MacSync Stealer Infrastructure

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-19 09:45 UTC

Microsoft Defender Experts have linked more than 30 web domains to MacSync Stealer, a macOS-focused information stealer, after correlating recurring endpoint and network behaviors across changing infrastructure, tracing the malware from payload retrieval through data collection, staging, and exfiltration. The tech giant said it required multiple endpoint and network behaviors to align before

AppleMalwareMicrosoft
P0
2026-08-19 05:39 UTC
Security Journalism

Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-19 09:45 UTC

A JavaServer Pages (JSP) web shell deployed following the exploitation of a critical security flaw in PTC Windchill and FlexPLM servers is specifically designed for the enterprise Product Lifecycle Management (PLM) software, according to new findings from ReliaQuest. The cybersecurity company characterized the web shell as a fully equipped extortion platform capable of mapping sensitive vault

P0
2026-08-19 04:00 UTC
Security Journalism

A Detection Engineer's Guide for Delegating Work to AI

Huntress · indexed 2026-09-07 17:30 UTC

Before delegating work to AI, ask one question: can you check the output? A detection engineer on why verification, not trust, decides what tasks you hand over.

P0
74 75 76 77 78