IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 4,541 matching records.
AUTO-POLL // 2026-10-06 17:15 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P3 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 6

RANSOMWARE
P3
P3
COOL // 49 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
FRI
Oct 2

RANSOMWARE
P7
P7
COOL // 46 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
WED
Sep 30

RANSOMWARE
P10
P10
WARM // 59 ARTICLES
RESET
2026-08-14 08:27 UTC
Security Journalism

Data analyst sent to prison for stealing data, extorting employer

BleepingComputer · Sergiu Gatlan · indexed 2026-08-15 14:33 UTC

A former data analyst contractor for Brightly Software has been sentenced to two years in prison for targeting his employer in a $2.5 million extortion scheme. [...]

P0
2026-08-14 07:54 UTC
Security Journalism

China-Linked Jewelbug Uses XG-Web for Government Espionage and Crypto Fraud

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-17 10:50 UTC

The China-linked threat actor known as Jewelbug has been observed carrying out cyber espionage operations targeting governments and militaries, while simultaneously engaging in cryptocurrency fraud. "Both missions are administered from a single control panel, XG-Web, a browser-centric remote-access and information-stealing framework that turns a victim's browser into a full remote-control

APT / Nation-StateCybercrimeThreat Actors
P0
2026-08-14 05:00 UTC
Other

ZDI-26-526: (0Day) PAX Technology Q80 Application Installer Signature Verification Bypass Remote Code Execution Vulnerability

Zero Day Initiative · indexed 2026-09-07 17:35 UTC

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of PAX Technology Q80. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-19910, CVE-2026-19911.

VulnerabilitiesCVE-2026-19910CVE-2026-19911
P20
2026-08-14 04:00 UTC
Security Journalism

10 Hacker Summer Camp Standouts at Black Hat and DEF CON

Huntress · indexed 2026-09-07 17:30 UTC

From the panels to the villages, Huntress researchers and SOC analysts were all over Hacker Summer Camp this year. Here’s what stood out at Black Hat and DEF CON.

P0
2026-08-13 21:23 UTC
Vendor Research

AWS Certificate Manager will discontinue email validation to prove domain validation for certificates

AWS Security Blog · Adam Aboudi · indexed 2026-08-15 18:55 UTC

Today, we’re announcing that AWS Certificate Manager (ACM) will discontinue support for email-validated public certificates by September 30, 2027. If you use email validation for your ACM public certificates, you need to migrate to DNS validation before that date. This change aligns with the Certification Authority/Browser (CA/B) Forum’s industry-wide deprecation of email-based domain validation and […]

Cloud Security
P0
2026-08-13 20:11 UTC
Vendor Research

ClamAV Vulnerabilities Affecting Cisco Products: August 2026

Cisco Security Advisories · indexed 2026-08-15 14:33 UTC

Multiple vulnerabilities in ClamAV could allow a remote attacker to cause a denial of service (DoS) condition, interrupting scanning operations. For more information about these vulnerabilities, see the Details section of this advisory. For additional information on these vulnerabilities in ClamAV, see the ClamAV blog. Cisco has released software updates that address these vulnerabilities in affected Cisco platforms. There are no workarounds that address these vulnerabilities. Notes: The Securi…

LinuxMicrosoftVulnerabilitiesCVE-2026-20337CVE-2026-20338CVE-2026-20339CVE-2026-20345CVE-2026-20346CVE-2026-20347CVE-2026-20348
P5
2026-08-13 18:45 UTC
Security Journalism

GeoServer Zero-Day Targeted in Active Exploitation Attempts, Can Lead to RCE

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-17 10:50 UTC

A newly disclosed zero-day flaw in GeoServer is seeing active exploitation efforts, per watchTowr. The vulnerability, which has yet to be assigned a CVE identifier, is an SQL injection vulnerability in the open-source platform that can lead to remote code execution (RCE). The security defect remains unpatched. It was first disclosed on August 12, 2026, at 10:46 UTC, by a researcher named @

Vulnerabilities
P40
2026-08-13 18:17 UTC
Security Journalism

ThreatsDay: GhostJacking AI Attacks, EtherHiding ClickFix, Cursor CLI Flaw + 17 More Stories

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-17 10:50 UTC

Some weeks have one big security story. Others bring many smaller updates that are easy to miss but still matter. This week has plenty of them, covering cloud services, AI tools, malware, data breaches, scams, and new attack methods. The latest ThreatsDay Bulletin puts all of these short updates in one place, so you can quickly catch up on what happened, what changed, and what security teams

Data BreachesMalware
P0
2026-08-13 18:00 UTC
Vendor Research

Curiouser and Curiouser

Cisco Talos Intelligence Blog · William Largent · indexed 2026-08-15 14:33 UTC

In this edition of the Threat Source newsletter, William reflects on the “Make Hazel a Hacker” segment in Beers with Talos, and how cybersecurity is a field where questions can lead to multiple correct answers.

P0
2026-08-13 17:33 UTC
Security Journalism

AI 'watermark removers' flood the web. Almost none can prove they work.

BleepingComputer · Ax Sharma · indexed 2026-08-15 14:33 UTC

Multiple 'watermark removers' have surfaced days after Anthropic began watermarking text generated by Claude, including an open source project with over 4,500 GitHub stars and paid AI detection evasion services. None of the tools' claims about defeating the text watermark can be verified, as Anthropic has not released a detector. [...]

P0
2026-08-13 16:47 UTC
Security Journalism

Flock tightens privacy controls amid scandals over officer abuse

The Record · indexed 2026-08-15 18:55 UTC

All Flock Safety customers will be required to adopt its "Audit Assistance" feature for tracking abnormal uses, and the company says it will hold license plate data for only seven days in most cases.

P0
2026-08-13 15:00 UTC
Security Journalism

New PATCHCORD Backdoor Targets Afghan Telecom and Indian Critical Infrastructure

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-17 10:50 UTC

Afghan telecom providers and South Asian critical infrastructure organizations have emerged as the target of a new ongoing campaign that delivers a previously undocumented backdoor called PATCHCORD. According to Acronis Threat Research Unit (TRU), the backdoor is a compiled C/C++ implant delivered by means of sector-specific lures, including fake VPN installers impersonating Afghan Telecom (

MalwareNetwork Security
P0
2026-08-13 13:43 UTC
Security Journalism

AmnesiaStealer Hijacks Chromium Sessions to Give Attackers Live Browser Control on macOS

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-17 10:50 UTC

Cybersecurity researchers have disclosed details of a new macOS-oriented, Rust-based information stealer called AmnesiaStealer that's capable of hijacking Chromium web browsers to steal session data. The multi-stage stealer is spread via a counterfeit GitHub download page titled "Download for macOS" and claims to be from a verified publisher. The page employs a ClickFix-style lure that

AppleMalwareSecurity Research
P0
2026-08-13 13:37 UTC
Security Journalism

Brazil orders Discord to suspend livestreaming after teen suicide

The Record · indexed 2026-08-15 18:55 UTC

Discord's Go Live feature contributed to a 13-year-old girl's death by suicide, according to Brazilian regulators, who told the company to suspend the streaming technology.

P0
2026-08-13 13:00 UTC
Security Journalism

Fake Refund Scam Hits Shopify Shop App Users

Huntress · indexed 2026-09-07 17:30 UTC

A Shopify fake refund scam has been making the rounds over the past few months, targeting Shopify’s Shop app users directly within the app. Here’s what to know.

P0
2026-08-13 12:54 UTC
Other

The State of Ransomware Q2 2026

Check Point Research · matthewsu@checkpoint.com · indexed 2026-09-07 17:30 UTC

For the past year, the ransomware conversation has centered on concentration: a handful of dominant RaaS operations controlling most of the damage, and a shrinking pool of active groups fighting over the same territory. The State of Ransomware Q2 2026 report from Check Point Research shows that picture starting to shift. The leaders are still winning, but […] The post The State of Ransomware Q2 2026 appeared first on Check Point Research.

MicrosoftRansomware
P15
2026-08-13 11:53 UTC
Security Journalism

WindRelay Android Malware Turns Victims' Phones Into NFC Relays for Payment Fraud

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-17 10:50 UTC

A previously unseen Android near field communication (NFC) relay malware family dubbed WindRelay is being deployed in conjunction with a known remote access trojan (RAT) called SpyNote as part of a contactless payment fraud scheme. The purpose-built malware, according to Group-IB, is designed to capture live card data via NFC and transmit it to fraudsters in real time. It was first detected in

CybercrimeMalwareMobile Security
P0
2026-08-13 11:45 UTC
Security Journalism

North Korean Remote Workers Are Infiltrating Government and Businesses: How to Expose Them Before Hiring

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-17 10:50 UTC

Companies are used to thinking about attackers as outsiders trying to break in. North Korean IT workers flip that model. They apply for jobs, pass interviews, receive legitimate credentials, and can end up inside the same systems companies spend millions trying to protect. That risk is no longer theoretical. The FBI is now investigating a North Korean remote IT worker who reportedly worked for

Law Enforcement
P0
2026-08-13 10:20 UTC
Vendor Research

The Evolving Role of the Red Team in the Era of Agentic Security

Google Security Blog · Daniel Fabian · indexed 2026-08-15 18:55 UTC

At Google, our Red Teams have always operated on the cutting edge of security. We’ve shared our journey in the past: from the high-stakes operations showcased in our Hac…

P0
80 81 82 83 84