Intel Free'd: A CYBERSECURITY INTELLIGENCE FEEDby: buf0rd

LATEST

Aggregated cybersecurity reporting, advisories and research. 5 matching records.
AUTO-POLL // 2026-08-18 20:55 UTC
RESET
2026-08-18 17:44 UTC
Security Journalism

Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-18 18:35 UTC

Two critical vulnerabilities impacting MLflow, an open-source artificial intelligence (AI) platform, and FUXA, an open-source, web-based SCADA / HMI software built for operational technology (OT) and industrial automation, are witnessing malicious scanning and exploitation efforts. According to independent reports from watchTowr and VulnCheck, the vulnerabilities in question are as follows -

AI SecurityICS / OT
P0
2026-08-18 12:49 UTC
Vendor Research

New Report: AI threats are here. Why Q2 2026 signals the end of traditional patch cycles

Rapid7 · Rapid7 Labs · indexed 2026-08-18 15:35 UTC

You can’t patch everything. So what do you fix first? Findings in Q2 2026 have changed traditional answers.The latest Quarterly Threat Landscape Report from Rapid7 Labs shows vulnerability disclosures still surging while attackers use automation and AI-assisted tooling to compress the time between disclosure and exploitation. The gap that patch cycles were built to fill is closing. Speed and volume are overwhelming security teams that have relied on traditional patch cycles and reactive program…

APT / Nation-StateCloud SecurityCybercrimeDFIRICS / OTMicrosoftPhishingRansomwareVulnerabilities
P15
2026-08-12 19:17 UTC
Vendor Research

ScadaLTS Multiple Vulnerabilities

Tenable Research Advisories · Ben Smith · indexed 2026-08-15 18:55 UTC

ScadaLTS Multiple Vulnerabilities ScadaLTS is an open-source, web-based SCADA/HMI application. Version 2.7.8.1 is affected by multiple vulnerabilities: CVE-2026-19656: Authenticated Remote Code Execution (AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)A server-side method is exposed without any authorization checks, allowing any authenticated user (including one holding only low-privilege, read-only permissions) to execute arbitrary operating-system commands on the underlying host. Successful exploitation…

ICS / OTVulnerabilitiesCVE-2026-19656CVE-2026-19657
P20
2026-07-30 16:05 UTC
Vendor Research

Canada’s Bill C-8 is here: Why the 72-hour reporting rule will redefine critical infrastructure security

Tenable Blog · Ashley Lukeeram · indexed 2026-08-15 18:55 UTC

Canada’s new Critical Cyber Systems Protection Act (Bill C-8) introduces a strict 72-hour cyber incident reporting mandate. Find out how Tenable is helping critical national infrastructure operators bridge the IT/OT divide to ensure full compliance.Key takeaways:Bill C-8 introduces stringent new cyber incident reporting requirements and heavy financial penalties for critical infrastructure operators. Eliminating network blind spots with a hybrid IT/OT discovery approach, including Safe Active Q…

Cloud SecurityDFIRICS / OTThreat ActorsThreat IntelligenceVulnerabilities
P10
2026-07-29 03:19 UTC
Vendor Research

Coordinated "cyberattack" on U.S. water utilities: What you need to know

Tenable Blog · Research Special Operations · indexed 2026-08-15 18:55 UTC

A coordinated cyber attack disrupted water and wastewater systems in at least 12 U.S. states, including more than 30 Minnesota communities. Here is what defenders need to know about the attack so far. This FAQ also details recent cyberactivity targeting internet-exposed PLCs, and how to protect exposed infrastructure.Change logUpdate August 10: Added Columbus Water Works as a second confirmed Georgia victim. Added a table summarizing publicly confirmed affected entities to date.This is an activ…

DFIRICS / OTLaw EnforcementMalwareMicrosoftThreat IntelligenceVulnerabilitiesCVE-2021-22681
P45