IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 4,553 matching records.
AUTO-POLL // 2026-10-06 22:55 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P3 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 6

RANSOMWARE
P3
P3
COOL // 61 ARTICLES
MON
Oct 5

RANSOMWARE
P5
P5
COOL // 48 ARTICLES
SUN
Oct 4

RANSOMWARE
P10
P10
WARM // 11 ARTICLES
SAT
Oct 3

RANSOMWARE
P4
P4
COOL // 14 ARTICLES
FRI
Oct 2

RANSOMWARE
P7
P7
COOL // 46 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
WED
Sep 30

RANSOMWARE
P10
P10
WARM // 59 ARTICLES
RESET
2026-07-21 14:00 UTC
Security Journalism

What Are Initial Access Brokers?

Huntress · indexed 2026-09-07 17:30 UTC

Discover what initial access brokers (IABs) are, how they compromise networks to sell their access to other attackers, and how to protect your business.

Cybercrime
P0
2026-07-21 05:00 UTC
Other

ZDI-26-446: Microsoft Windows WMI Providers Incorrect Authorization Local Privilege Escalation Vulnerability

Zero Day Initiative · indexed 2026-09-07 17:35 UTC

This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.0. The following CVEs are assigned: CVE-2026-50297.

MicrosoftVulnerabilitiesCVE-2026-50297
P15
2026-07-21 05:00 UTC
Other

ZDI-26-445: Microsoft Windows WMI Providers Incorrect Authorization Local Privilege Escalation Vulnerability

Zero Day Initiative · indexed 2026-09-07 17:35 UTC

This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.0. The following CVEs are assigned: CVE-2026-50325.

MicrosoftVulnerabilitiesCVE-2026-50325
P15
2026-07-20 15:47 UTC
Vendor Research

Cisco Identity Services Engine Stored Cross-Site Scripting Vulnerabilities

Cisco Security Advisories · indexed 2026-08-15 14:33 UTC

Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) guest portals could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management interface of an affected system. An attacker could exploit these vulnerabilities by injecting malicious code into specific pages of the interface. A …

VulnerabilitiesCVE-2025-20204CVE-2025-20205
P5
2026-07-20 14:00 UTC
Security Journalism

How We Cut Noise Before It Hits the Analyst

Huntress · indexed 2026-09-07 17:30 UTC

Learn how Huntress' AI signal triage and AI-powered SOC triage cut noise before it reaches human analysts. And discover why that matters for response times.

P0
2026-07-20 12:18 UTC
Other

20th July – Threat Intelligence Report

Check Point Research · urias · indexed 2026-09-07 17:30 UTC

For the latest discoveries in cyber research for the week of 20th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Ernst & Young, a global accounting and professional services company, has disclosed a data breach involving a compromised third-party IT support platform. The exposed support tickets may have contained client documents, tax information, […] The post 20th July – Threat Intelligence Report appeared first on Check Point Research.

Data BreachesThreat Intelligence
P0
2026-07-20 09:36 UTC
Vendor Research

wp2shell (CVE-2026-63030, CVE-2026-60137): Frequently asked questions about remote code execution chain in WordPress Core

Tenable Cyber Exposure Alerts · Satnam Narang · indexed 2026-08-15 18:55 UTC

An unauthenticated attacker can chain two WordPress Core vulnerabilities, CVE-2026-63030 and CVE-2026-60137, to achieve remote code execution against affected WordPress installations. Multiple security firms have confirmed active in-the-wild exploitation within days of public disclosure, and public proof-of-concept exploits are circulating.Key takeaways:Two WordPress Core vulnerabilities, CVE-2026-63030 and CVE-2026-60137, can be chained together to achieve pre-authentication remote code execut…

Cloud SecurityDFIRMicrosoftNetwork SecurityRansomwareSecurity ResearchThreat ActorsThreat IntelligenceVulnerabilitiesCVE-2026-60137CVE-2026-601377CVE-2026-63030
P70
2026-07-17 18:00 UTC
Security Journalism

It’s Not Safe To Pay SafePa

Huntress · indexed 2026-09-07 17:30 UTC

Huntress has observed Akira ransomware affiliates in action, as well as ReadText34 and INC ransomware being deployed.

Ransomware
P15
2026-07-17 10:00 UTC
Vendor Research

Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy

Palo Alto Networks Unit 42 · Emmanuel Zhou, Adam Robbie, Rick Wyble and Miguel Pereira · indexed 2026-08-15 18:55 UTC

A technical analysis of three chained zero-day vulnerabilities in Siemens ROX II OT switches that allow privilege escalation and persistent root access. The post Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy appeared first on Unit 42.

Network SecurityVulnerabilities
P35
2026-07-16 23:00 UTC
Vendor Research

AI, Automation and Attacks: Unpacking the Unit 42 2026 Global Incident Response Report

Palo Alto Networks Unit 42 · Ria Bhatia · indexed 2026-08-15 18:55 UTC

Explore Unit 42's perspectives on AI's impact on cybersecurity, including key updates since the 2026 Incident Response Report. The post AI, Automation and Attacks: Unpacking the Unit 42 2026 Global Incident Response Report appeared first on Unit 42.

DFIR
P0
2026-07-16 18:00 UTC
Vendor Research

Begun, the Patch Wars have

Cisco Talos Intelligence Blog · Joe Marshall · indexed 2026-08-15 14:33 UTC

Long foretold, the Great Patching has begun and it’s a doozy. Buckle in as Joe takes you through the story.

P0
2026-07-16 14:00 UTC
Vendor Research

Demystifying AI Exploits: A Blueprint for AI-Assisted Vulnerability Management

Google Threat Intelligence / Mandiant · Mandiant · indexed 2026-08-15 18:55 UTC

Written by: Jules Czarniak Introduction As highlighted in the Mandiant M-Trends 2026 report, the mean time-to-exploit (TTE) has dropped to -7 days, meaning vulnerabilities are often exploited a week before a patch even exists. To keep pace, many security teams are exploring how to integrate large language model (LLM) agents into their codebases, development environments and continuous integration and continuous delivery (CI/CD) pipelines for automated vulnerability discovery and remediation. Ho…

AI SecurityAppleMicrosoftThreat ActorsThreat IntelligenceVulnerabilities
P10
2026-07-16 12:00 UTC
Vendor Research

CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions About Active Exploitation of Microsoft SharePoint Server Vulnerabilities

Tenable Cyber Exposure Alerts · Research Special Operations · indexed 2026-08-15 18:55 UTC

Four Microsoft SharePoint Server vulnerabilities are under active exploitation, prompting CISA to issue a hardening alert. An additional high-severity flaw recently patched adds pressure for organizations running on-premises deployments.Key TakeawaysCISA confirmed active exploitation of three on-premises SharePoint Server vulnerabilities (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164), used to gain unauthorized access, establish remote code execution, steal IIS machine keys and deploy malware …

Cloud SecurityMalwareMicrosoftRansomwareThreat ActorsVulnerabilitiesCVE-2026-32201CVE-2026-45659CVE-2026-55040CVE-2026-56164CVE-2026-58644
P95
2026-07-16 10:00 UTC
Vendor Research

The Hunter's Paradox: Is it time to embrace automated threat hunting?

Cisco Talos Intelligence Blog · David J. Bianco · indexed 2026-08-15 14:33 UTC

Humans can no longer keep up with the volume and velocity of security data on their own, but AI can't be fully trusted. David discusses the merits of both and muses on what the future might look like.

P0
2026-07-15 23:00 UTC
Vendor Research

The npm Threat Landscape: Attack Surface and Mitigations (Updated July 15)

Palo Alto Networks Unit 42 · Unit 42 · indexed 2026-08-15 18:55 UTC

Unit 42 analyzes npm supply chain evolution post-Shai Hulud. Discover wormable malware, CI/CD persistence, multi-stage attacks and more. The post The npm Threat Landscape: Attack Surface and Mitigations (Updated July 15) appeared first on Unit 42.

Malware
P15
2026-07-15 16:01 UTC
Vendor Research

Cisco Advance Notification for Publication of July 15, 2026, Security Advisories

Cisco Security Advisories · indexed 2026-08-15 14:33 UTC

On July 15, 2026, the Cisco Product Security Incident Response Team (PSIRT) published the following advisories: Cisco Security Advisory CVE ID Security Impact Rating CVSS Base Score Cisco RoomOS Security Hardening Release: July 2026 CVE-2026-20150CVE-2026-20153CVE-2026-20156CVE-2026-20157CVE-2026-20158CVE-2026-20187 High 8.8 Cisco Identity Services Engine Path Traversal Vulnerability CVE-2026-20146 Medium 5.5 To fully remediate the vulnerabilities that were disclosed on July 15, 2026, Cisco str…

DFIRVulnerabilitiesCVE-2026-20146
P5
2026-07-15 16:00 UTC
Vendor Research

Cisco RoomOS Security Hardening Release: July 2026

Cisco Security Advisories · indexed 2026-08-15 14:33 UTC

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. These vulnerabilities were found during internal testing and are not known to be actively exploited. To assist customers in patching and to streamline the disclosure process, Cisco has grouped these issues by the…

VulnerabilitiesCVE-2026-20150CVE-2026-20153CVE-2026-20156CVE-2026-20157CVE-2026-20158CVE-2026-20187
P30
2026-07-15 16:00 UTC
Vendor Research

Cisco Identity Services Engine Path Traversal Vulnerability

Cisco Security Advisories · indexed 2026-08-15 14:33 UTC

A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to perform path traversal attacks on the underlying operating system to either read or delete arbitrary files. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP req…

VulnerabilitiesCVE-2026-20146
P5
2026-07-15 14:00 UTC
Vendor Research

The Risk of Exposed Cloud Functions and How to Harden

Google Threat Intelligence / Mandiant · Mandiant · indexed 2026-08-15 18:55 UTC

Written by: Corné de Jong Introduction Mandiant security assessments frequently identify publicly exposed serverless applications that lack authentication, often as a result of specific business requirements. Serverless deployments typically run custom-developed code that incorporates third-party packages, making them targets for a wide range of application-level attacks, including: Local and Remote File Inclusion (LFI/RFI) Command Injection Successful exploitation of these vulnerabilities can …

AI SecurityAppleCloud SecurityMalwareThreat ActorsVulnerabilities
P15
2026-07-15 13:14 UTC
Vendor Research

CVE-2026-15409, CVE-2026-15410: SonicWall SMA 1000 zero-day vulnerabilities exploited in the wild

Tenable Cyber Exposure Alerts · Scott Caveza · indexed 2026-08-15 18:55 UTC

SonicWall patched two recently exploited zero-day vulnerabilities in its SMA 1000 Series secure remote access appliances which may have been chained for unauthenticated remote code execution.Key takeawaysCVE-2026-15409 and CVE-2026-15410 are a pair of exploited vulnerabilities that may have been chained together to allow for code execution on SonicWall SMA1000 series appliances. Zero-day exploitation of these vulnerabilities has been observed and confirmed by SonicWall. Patches and indicators o…

Cloud SecurityNetwork SecurityRansomwareSecurity ResearchThreat ActorsThreat IntelligenceVulnerabilitiesCVE-2026-15409CVE-2026-15410
P100
2026-07-15 13:00 UTC
Security Journalism

Every Ransomware Attack Has a Backstory

Huntress · indexed 2026-09-07 17:30 UTC

Ransomware is the final act, not the first move. Learn how attackers use access brokers and trusted tools to infiltrate your environment—and how to stop them early.

Ransomware
P15
2026-07-15 10:00 UTC
Vendor Research

TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development

Palo Alto Networks Unit 42 · Chris Navarrete, Doel Santos and Asher Davila · indexed 2026-08-15 18:55 UTC

TuxBot v3 Evolution, an IoT botnet framework built with LLMs. Read our analysis of its cross-compiled binaries, C2 architecture and bugs. The post TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development appeared first on Unit 42.

AI SecurityMalware
P0
95 96 97 98 99