IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 4,438 matching records.
AUTO-POLL // 2026-10-04 09:50 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P9 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 4

RANSOMWARE
P9
P9
COOL // 5 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
FRI
Oct 2

RANSOMWARE
P7
P7
COOL // 46 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
WED
Sep 30

RANSOMWARE
P10
P10
WARM // 59 ARTICLES
TUE
Sep 29

RANSOMWARE
P4
P4
COOL // 68 ARTICLES
MON
Sep 28

RANSOMWARE
P7
P7
COOL // 52 ARTICLES
RESET
2026-09-29 20:59 UTC
Security Journalism

Custom ChatGPTs push ClickFix attacks to deploy RAT malware

BleepingComputer · Bill Toulas · indexed 2026-09-29 21:05 UTC

Custom variants of OpenAI's ChatGPT promoted in sponsored Google results are directing unsuspecting users to malicious sites that use ClickFix attacks to deliver malware. [...]

Malware
P0
2026-09-29 20:54 UTC
Other

Japanese railway operators Keio Corporation and Tokyo Metro disclose security breaches

Security Affairs · Pierluigi Paganini · indexed 2026-09-29 21:50 UTC

Keio, a major Japanese railway operator, was hit by ransomware, disrupting business systems and forcing the company to shut down its network. Keio Corporation, one of Japan’s major private railway operators, was hit by a ransomware attack over the weekend, disrupting some of its business systems. The company detected a system failure early Saturday and […]

Ransomware
P15
2026-09-29 18:09 UTC
Security Journalism

Former US Air Force members sent to prison over BEC attacks

BleepingComputer · Sergiu Gatlan · indexed 2026-09-29 18:10 UTC

Two former members of the United States Air Force were sentenced to a combined 189 months in federal prison for their roles in a multi-year series of business email compromise (BEC) scams and phishing campaigns. [...]

Phishing
P0
2026-09-29 17:47 UTC
Security Journalism

French Tax Data Theft Using Stolen Staff Passwords Went Undetected for Seven Weeks

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-29 18:35 UTC

An attacker used stolen passwords of staff at France's tax administration to take tax data on hundreds of thousands of taxpayers and businesses in June and July. Neither the tax administration nor France's national cybersecurity agency saw the data leave. The attack was not sophisticated, the agency, ANSSI, says in a report (in French) published on Tuesday: it worked because of weak

P0
2026-09-29 17:24 UTC
Security Journalism

DARPA Selects Xint to Use AI in Securing Military Messaging Apps

Security Week · Kevin Townsend · indexed 2026-09-29 17:35 UTC

The AIxCC competition winner will analyze messaging app code and compiled binaries for vulnerabilities, with technology that could also help commercial customers secure their software. The post DARPA Selects Xint to Use AI in Securing Military Messaging Apps appeared first on SecurityWeek.

P0
2026-09-29 17:20 UTC
Security Journalism

New Spectre-v2 BTR Attack Leaks Linux Memory Despite Existing Defenses

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-29 17:20 UTC

A group of academics from VUSec and Scuola Superiore Sant'Anna have disclosed details of a new Spectre CPU vulnerability variant that affects Just-In-Time (JIT) engines present in web browsers, language runtimes, and the operating system kernel, across multiple CPU vendors. The new Spectre v2 variant has been codenamed Branch Target Reuse (BTR). "The key insight is that, while modern CPUs

LinuxVulnerabilities
P0
2026-09-29 17:20 UTC
Security Journalism

Russia's Star Blizzard Targets 100+ Organizations With Fake Event Invites to Deliver Backdoor

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-29 18:35 UTC

Russian state hackers known as Star Blizzard have been using fake event invitations to trick people into installing a backdoor on their Windows computers, according to Microsoft. The campaigns, aimed at people and organizations tied to Ukraine, have affected more than 100 organizations since January, mostly in the U.S. and U.K. At least one computer was infected, but the number of breached

MalwareMicrosoft
P0
2026-09-29 17:00 UTC
Security Journalism

New Spectre v2 Variant Exposes Intel, AMD, Arm CPUs to Data Leaks

Security Week · Eduard Kovacs · indexed 2026-09-29 17:15 UTC

Branch Target Reuse (BTR) is a new Spectre v2 attack targeting JIT compilers in web browsers, language runtimes, and the operating system kernel The post New Spectre v2 Variant Exposes Intel, AMD, Arm CPUs to Data Leaks appeared first on SecurityWeek.

Data BreachesLinux
P0
2026-09-29 16:24 UTC
Security Journalism

Meet Athena: Huntress' Agentic SOC Analyst

Huntress · indexed 2026-09-07 17:30 UTC

Learn how Huntress' Athena brings agentic AI to the SOC, investigating signals end-to-end while human analysts own the final call.

P0
2026-09-29 16:00 UTC
Vendor Research

​​Beyond source code: A path to the keys to the kingdom

Microsoft Security Blog · Microsoft Defender Experts Cybersecurity Incident Response · indexed 2026-09-29 17:10 UTC

Explore how Storm-3068 turned a compromised identity into broader cloud access and the steps organizations can take to defend their identities, pipelines, and cloud infrastructure. The post ​​Beyond source code: A path to the keys to the kingdom appeared first on Microsoft Security Blog.

Microsoft
P0
2026-09-29 15:17 UTC
Vendor Research

CVE-2026-100308 - GluonTS arbitrary command execution during model deserialization

AWS Security Bulletins · aws@amazon.com · indexed 2026-09-29 15:35 UTC

Bulletin ID: 2026-119-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/29/2026 08:00 AM PDT Description: GluonTS is an open source library for deep learning based time series models. We identified CVE-2026-100308 that allows arbitrary command execution upon deserialization of untrusted model artifacts. Deserialization of untrusted data in the model loading component in Amazon GluonTS before 0.17.0 might allow context-dependent attackers to execute arbitrary opera…

Cloud SecurityVulnerabilitiesCVE-2026-100308
P5
2026-09-29 15:00 UTC
Vendor Research

Star Blizzard refines phishing and malware delivery with the RedFlick technique

Microsoft Security Blog · Microsoft Threat Intelligence · indexed 2026-09-29 15:35 UTC

Since January 2026, Microsoft has observed Russian state threat actor Star Blizzard evolve their detection evasion capabilities through large-scale phishing campaigns, the use of accounts on compromised websites, and a novel malware delivery technique, tracked by Microsoft as “RedFlick”. The post Star Blizzard refines phishing and malware delivery with the RedFlick technique appeared first on Microsoft Security Blog.

MalwareMicrosoftPhishingThreat Actors
P0
2026-09-29 14:38 UTC
Security Journalism

RemoteThreat Launches With $7 Million for Offensive Operations Platform

Security Week · SecurityWeek News · indexed 2026-09-29 14:40 UTC

The company emerged from stealth mode with pre-seed funding from Osage University Partners and DataTribe. The post RemoteThreat Launches With $7 Million for Offensive Operations Platform appeared first on SecurityWeek.

P0
2026-09-29 14:13 UTC
Security Journalism

Kiteworks Fixes Critical Flaw Found During Nine-Hour Precautionary Shutdown

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-29 15:25 UTC

Kiteworks on Monday said it worked with federal intelligence authorities over the weekend as it identified and addressed a critical security vulnerability during the scheduled precautionary shutdown. "During the shutdown, this activity led to the discovery of a previously unknown critical vulnerability confined to a capability that is enabled for less than 1% of the customer base," the company

Vulnerabilities
P10
2026-09-29 14:09 UTC
Other

Three Million Affected in Pentagon Personnel Agency Data Breach

Security Affairs · Pierluigi Paganini · indexed 2026-09-29 15:00 UTC

Pentagon personnel agency breach exposed data of 3 million people after attackers accessed a file-sharing server for about nine months. The U.S. Defense Manpower Data Center (DMDC), which maintains personnel records for the Department of Defense, is notifying people that their personal information was exposed in a data breach. According to the agency, unauthorized users […]

Data Breaches
P0
2026-09-29 14:01 UTC
Security Journalism

Catch threats before they escalate with real-time Identity Telemetry

BleepingComputer · Sponsored by tenfold Software · indexed 2026-09-29 14:15 UTC

Identity governance helps control who should have access, but periodic reviews alone may not reveal attacks as they happen. tenfold Software explains how real-time identity telemetry can help security teams investigate suspicious activity before it escalates. [...]

P0
6 7 8 9 10