IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 4,553 matching records.
AUTO-POLL // 2026-10-06 22:50 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P3 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
FRI
Oct 2

RANSOMWARE
P7
P7
COOL // 46 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
WED
Sep 30

RANSOMWARE
P10
P10
WARM // 59 ARTICLES
RESET
2026-07-24 14:00 UTC
Security Journalism

CMMC Updates: DoW Pause and Huntress Hits 50% of Requirements

Huntress · indexed 2026-09-07 17:30 UTC

DoW paused the CMMC Phase II deadline in July, but the underlying compliance obligations didn't move. Meanwhile, Huntress Managed ISPM pushes our NIST SP 800-171 coverage to 55 of 110 requirements. Here's what changed, what didn't, and why we're not slowing down.

P0
2026-07-24 14:00 UTC
Vendor Research

Updated Cyber Threat Actor Naming System

Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-08-15 18:55 UTC

Update (July 30): A table listing the new names of select prominent threat actors was appended to this post. Introduction Today, Google Threat Intelligence Group (GTIG) will begin rolling out a unified naming schema for tracking threat actors. This new naming taxonomy represents an effort to standardize tracking across platforms and public reporting. Why are we Adopting a Different Naming System? Historically, Mandiant and Google’s Threat Analysis Group (TAG) maintained distinct tracking system…

AppleAPT / Nation-StateDFIRMicrosoftThreat ActorsThreat Intelligence
P0
2026-07-23 18:00 UTC
Vendor Research

Don’t swing at everything

Cisco Talos Intelligence Blog · Thorsten Rosendahl · indexed 2026-08-15 14:33 UTC

Thorsten explores Q2 2026 stats, the artificial buffer zone of 2026, and why smart, prioritized patching is more critical than ever.

P0
2026-07-23 14:10 UTC
Vendor Research

Russian Global Webmail Espionage

Palo Alto Networks Unit 42 · Unit 42 · indexed 2026-08-15 18:55 UTC

Unit 42 details a Russian cyberespionage campaign targeting Zimbra webmail servers using JavaScript injection to steal credentials. The post Russian Global Webmail Espionage appeared first on Unit 42.

APT / Nation-State
P0
2026-07-23 14:00 UTC
Security Journalism

Employee Spotlight: Andrew Schlemmer

Huntress · indexed 2026-09-07 17:30 UTC

Meet Channel Account Manager Andrew Schlemmer, and learn how his personal experience with cybercrime fueled his mission to make enterprise-grade security attainable and accessible for businesses of all sizes.

Cybercrime
P0
2026-07-23 10:00 UTC
Vendor Research

Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel

Cisco Talos Intelligence Blog · Jordyn Dunk · indexed 2026-08-15 14:33 UTC

The Chaos ransomware group uses new malware "msaRAT" that hijacks browsers. The malware doesn't communicate directly with C2 but connects through the browser. It enables arbitrary command execution while hiding the attacker's IP from victims via WebRTC over TURN.

MalwareRansomware
P15
2026-07-23 10:00 UTC
Vendor Research

Preview: Cisco Talos at Black Hat USA 2026

Cisco Talos Intelligence Blog · Mitch Neff · indexed 2026-08-15 14:33 UTC

Here’s some of the ways Talos is showing up at Black Hat, alongside our friends at Cisco and Splunk.

P0
2026-07-23 07:13 UTC
Government

2026-009: Critical Vulnerabilities in Microsoft SharePoint

CERT-EU Security Advisories · indexed 2026-08-15 18:50 UTC

[UPDATED] On 14 July 2026, Microsoft released security updates addressing critical remote code execution (RCE) vulnerabilities in Microsoft SharePoint Server. On 20 July 2026, WatchTowr identified a proof-of-concept exploit code and subsequently observed active exploitation of CVE-2026-50522, a vulnerability part of an ongoing series of actively exploited flaws affecting on-premise SharePoint Server instances, including CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, and CVE-2026-58644. CERT-EU…

Cloud SecurityMicrosoftVulnerabilitiesCVE-2026-32201CVE-2026-45659CVE-2026-50522CVE-2026-56164CVE-2026-58644
P45
2026-07-23 05:00 UTC
Other

ZDI-26-452: Dify AI Workflow oauth_redirect_url Open Redirect Vulnerability

Zero Day Initiative · indexed 2026-09-07 17:35 UTC

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Dify. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 5.4. The following CVEs are assigned: CVE-2026-18266.

VulnerabilitiesCVE-2026-18266
P5
2026-07-23 05:00 UTC
Other

ZDI-26-451: Docker Desktop for macOS Inference Server Permissive Allow List Sandbox Escape Vulnerability

Zero Day Initiative · indexed 2026-09-07 17:35 UTC

This vulnerability allows local attackers to escape the model runner sandbox on affected installations of Docker Desktop for macOS. An attacker must first obtain the ability to execute low-privileged code within the sandbox in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8.

AppleVulnerabilities
P0
2026-07-23 05:00 UTC
Other

ZDI-26-450: AzeoTech DAQFactory CTL File Parsing Use-After-Free Remote Code Execution Vulnerability

Zero Day Initiative · indexed 2026-09-07 17:35 UTC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of AzeoTech DAQFactory. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-12921.

VulnerabilitiesCVE-2026-12921
P20
2026-07-23 05:00 UTC
Other

ZDI-26-449: AzeoTech DAQFactory CTL File Parsing Type Confusion Remote Code Execution Vulnerability

Zero Day Initiative · indexed 2026-09-07 17:35 UTC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of AzeoTech DAQFactory. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-12390.

VulnerabilitiesCVE-2026-12390
P20
2026-07-23 05:00 UTC
Other

ZDI-26-448: Bitdefender Total Security Shredder Link Following Local Privilege Escalation Vulnerability

Zero Day Initiative · indexed 2026-09-07 17:35 UTC

This vulnerability allows local attackers to escalate privileges on affected installations of Bitdefender Total Security. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.3. The following CVEs are assigned: CVE-2026-6851.

MicrosoftVulnerabilitiesCVE-2026-6851
P15
2026-07-23 05:00 UTC
Other

ZDI-26-447: Heimdall Data Database Proxy generateFileContent CRLF Injection Remote Code Execution Vulnerability

Zero Day Initiative · indexed 2026-09-07 17:35 UTC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Heimdall Data Database Proxy. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-12357.

VulnerabilitiesCVE-2026-12357
P20
2026-07-22 01:10 UTC
Independent Research

LG to Ban Residential Proxies from Smart TV Apps

Krebs on Security · BrianKrebs · indexed 2026-08-15 14:33 UTC

The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one's television into an always-on residential proxy node. The move comes less than a month after researchers found that more than 42 percent of games and other apps available for download on LG's webOS store allow unknown third-parties to route their Internet traffic through a user's TV.

P0
2026-07-22 00:00 UTC
Government

Multiples vulnérabilités dans Microsoft Sharepoint (22 juillet 2026)

CERT-FR Alerts · indexed 2026-09-07 17:35 UTC

Le 14 juillet 2026, à l'occasion de sa mise à jour mensuelle, Microsoft a publié, entre autres, des correctifs pour deux vulnérabilités critiques affectant SharePoint. Les vulnérabilités CVE-2026-50522 et CVE-2026-58644 permettent à un attaquant non authentifié d'exécuter du code arbitraire à...

MicrosoftVulnerabilitiesCVE-2026-50522CVE-2026-58644
P5
2026-07-21 17:07 UTC
Vendor Research

Oracle July 2026 Critical Patch Update Addresses 1235 CVEs

Tenable Blog · Research Special Operations · indexed 2026-08-15 18:55 UTC

Oracle addresses 1235 CVEs in its third quarterly update of 2026 with 1449 patches, including 261 critical updates.Key TakeawaysThe third Critical Patch Update (CPU) for 2026 contains fixes for 1235 unique CVEs in 1449 security updates, the largest CPU release.261 issues (18% of all patches) were assigned a critical severity ratingOracle E-Business Suite received the highest number of patches at 410, accounting for 28.3% of all patchesBackgroundOn July 21, Oracle released its Critical Patch Upd…

P5
2026-07-21 16:01 UTC
Vendor Research

Cisco Catalyst SD-WAN Controller, Catalyst SD-WAN Manager, and Catalyst SD-WAN Validator Authenticated Privilege Escalation Vulnerability

Cisco Security Advisories · indexed 2026-08-15 14:33 UTC

A vulnerability in the CLI of Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an authenticated, local attacker to execute arbitrary commands as root by supplying a crafted file to the affected system. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by uploading a crafted file to the aff…

VulnerabilitiesCVE-2026-20127CVE-2026-20182CVE-2026-20245
P15
94 95 96 97 98