IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 1,056 matching records.
AUTO-POLL // 2026-08-30 09:15 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P0 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Aug 30

CLEAR
P0
P0
COOL // 2 ARTICLES
SAT
Aug 29

RANSOMWARE
P9
P9
COOL // 8 ARTICLES
FRI
Aug 28

RANSOMWARE
P8
P8
COOL // 47 ARTICLES
THU
Aug 27

RANSOMWARE
P4
P4
COOL // 48 ARTICLES
WED
Aug 26

RANSOMWARE
P4
P4
COOL // 46 ARTICLES
TUE
Aug 25

ACTIVE EXPLOITATION
P4
P4
COOL // 40 ARTICLES
MON
Aug 24

RANSOMWARE
P4
P4
COOL // 34 ARTICLES
RESET
2026-08-30 07:36 UTC
Security Journalism

TerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-30 08:50 UTC

Microsoft has disclosed details of a new ClickFix variant, dubbed TerminalFix, that aims to trick users into running a malicious command in Windows Terminal or PowerShell. "While traditional ClickFix campaigns direct victims to the Windows Run dialog, TerminalFix campaigns apply the same technique but direct users to Windows Terminal or PowerShell instead, increasing the likelihood that complex

MalwareMicrosoft
P0
2026-08-30 07:14 UTC
Community

YARA-X 1.20.0 Release, (Sun, Aug 30th)

SANS Internet Storm Center · indexed 2026-08-30 07:30 UTC

YARA-X's 1.20.0 release brings 14 improvements and 13 bugfixes.

P0
2026-08-29 23:11 UTC
Security Journalism

Anthropic is cutting Claude Code's current weekly limits by 17%

BleepingComputer · Mayank Parmar · indexed 2026-08-29 23:20 UTC

Anthropic is permanently increasing Claude Code's standard weekly usage limits by 25% for Pro, Max, Team, and seat-based Enterprise plans, but it's not as good as it sounds. [...]

P0
2026-08-29 16:25 UTC
Security Journalism

Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-29 17:20 UTC

Multiple critical security flaws have been disclosed in WordPress plugins and themes, including WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP, that could lead to authentication bypass, account takeover, and arbitrary code execution. The vulnerabilities, according to Wordfence and Patchstack, are listed below - CVE-2026-76581 (CVSS score: 9.8) - An authentication bypass flaw in

Cloud SecurityVulnerabilitiesCVE-2026-76581
P30
2026-08-29 14:19 UTC
Security Journalism

Brave browser adds email aliases to help users evade tracking

BleepingComputer · Bill Toulas · indexed 2026-08-29 14:40 UTC

The latest version of the Brave browser, 1.94, introduces a feature called 'Email Aliases' that allows users to generate disposable email addresses when signing up to a new service. [...]

P0
2026-08-29 11:55 UTC
Other

Hack One Robot, Reach the Next: Unitree G1 Security Flaws

Security Affairs · Pierluigi Paganini · indexed 2026-08-29 12:50 UTC

A researcher chained two Unitree G1 flaws to gain root access remotely and showed how a compromised robot could attack others nearby. Security researcher Olivier Laflamme spent about three months digging into the Unitree G1 humanoid robot and eventually found a way to fully compromise it without plugging in a single cable. In his technical […]

Cloud SecuritySecurity Research
P0
2026-08-29 10:55 UTC
Other

Rhysida Ransomware Group Targets Berlin Government Ahead of Vote

Security Affairs · Pierluigi Paganini · indexed 2026-08-29 11:35 UTC

Berlin ‘s government faces a Rhysida ransomware attack weeks before elections, with officials refusing to pay despite a claimed 5.79 TB data theft. Berlin’s state government confirmed this week it’s dealing with an extortion attempt following an August cyberattack on the city-state’s administrative network, and officials have already refused the requested ransom. The ransomware group […]

Ransomware
P15
2026-08-29 09:16 UTC
Other

Philippine Nuclear and Naval Targets Hit by Suspected Chinese Operator

Security Affairs · Pierluigi Paganini · indexed 2026-08-29 09:40 UTC

An alleged Chinese-speaking actor breached Philippine nuclear and naval targets by exploiting known flaws, stealing sensitive data. A suspected Chinese-speaking operator targeted a Philippine nuclear research body and a marine engineering company that supports the Philippine Navy, using well-known vulnerabilities in internet-facing ownCloud and WordPress systems. The activity was uncovered after Hunt.io found an exposed […]

Cloud Security
P0
2026-08-29 03:43 UTC
Vendor Research

TerminalFix campaign deploys a reverse tunnel through multistage intrusion

Microsoft Security Blog · Microsoft Security Research, Sagar Patil, Suriyaraj Natarajan and Parasharan Raghavan · indexed 2026-08-29 05:20 UTC

Microsoft Threat Intelligence provides analysis of a ClickFix campaign that uses fake CAPTCHA prompts, DLL sideloading, and a reverse tunnel, with detections and hunting guidance. The post TerminalFix campaign deploys a reverse tunnel through multistage intrusion appeared first on Microsoft Security Blog.

MicrosoftThreat Intelligence
P0
2026-08-28 22:40 UTC
Security Journalism

McKesson discloses breach after ShinyHunters claims patient data theft

BleepingComputer · Lawrence Abrams · indexed 2026-08-28 22:50 UTC

Healthcare and pharmaceutical distribution giant McKesson has disclosed a cybersecurity incident involving unauthorized access to third-party applications and data theft, with the ShinyHunters extortion group claiming it stole 284 million patient data records. [...]

P0
2026-08-28 22:00 UTC
Vendor Research

Perturbation Probing: A New Diagnostic for the Fragility of LLM Safety

Palo Alto Networks Unit 42 · Tony Li, Hongliang Liu and Yuhao Wu · indexed 2026-08-28 22:10 UTC

New research reveals that AI safety refusal lives in a thin neural layer, highlighting the critical need for external, multi-layered security. The post Perturbation Probing: A New Diagnostic for the Fragility of LLM Safety appeared first on Unit 42.

AI Security
P0
2026-08-28 21:30 UTC
Security Journalism

Berlin Refuses to Pay Hackers Who Stole Data From the City's State Network

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-28 22:10 UTC

Berlin's state government has confirmed that it is the target of an extortion attempt following the August compromise of the city's state administrative network, and said it will not meet the extortionists' demands. The same statement disclosed that forensic work had found further data outflows in the portfolio of the Senate Department for Mobility, Transport, Climate Protection and Environment

P0
2026-08-28 20:38 UTC
Security Journalism

Cosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was Vulnerable

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-28 21:00 UTC

Cosmos Labs has warned that a critical balance-handling flaw in the shared Cosmos EVM module was exploited to drain funds from six blockchains between August 20 and August 25, 2026. The vulnerability, designated GHSA-7g4w-cg88-2cq2, is rated Critical by Cosmos Labs and was published without a CVE identifier, a weakness classification, or a CVSS score. Affected versions are < 0.6.2 and >=

Vulnerabilities
P0
2026-08-28 20:19 UTC
Security Journalism

Hundreds of OpenAI Agents Invaded Hugging Face Servers

Dark Reading · Nate Nelson · indexed 2026-08-28 20:45 UTC

The Hugging Face incident was bigger and worse than previously thought, with approximately 700 agents collaborating on a sophisticated, multistage attack.

AI Security
P0
2026-08-28 20:14 UTC
Other

Love Electric Breach: 877,000 Driver Records Offered for $600

Security Affairs · Pierluigi Paganini · indexed 2026-08-28 21:15 UTC

Love Electric’s alleged data breach exposes sensitive driver data and highlights the identity risks created by third-party salary sacrifice providers. A seller on an English-language data-breach forum claimed on August 26 that they had obtained the driver database of Love Electric, a UK broker that runs electric-vehicle salary sacrifice schemes. The seller, operating under the […]

Data Breaches
P0
2026-08-28 18:53 UTC
Vendor Research

Extend your data perimeter to the AWS Management Console with Private Access

AWS Security Blog · Madhur Kulkarni · indexed 2026-08-28 19:15 UTC

Organizations in regulated industries such as financial services, government, defense, and healthcare restrict their sensitive workloads to isolated network environments with no access to the public internet. Until now, customers could restrict AWS Management Console access to authorized AWS accounts and corporate networks, but the console itself required internet connectivity. This was creating tension between […]

Cloud Security
P0
2026-08-28 18:25 UTC
Security Journalism

Offensive Security Investments Surge as AI Threats Increase

Dark Reading · indexed 2026-08-28 18:30 UTC

Omdia's Theresa Lanowitz talks with the Dark Reading News Desk about the potential — and risks — of using agentic AI for penetration testing, red teaming, and other practices.

P0
2026-08-28 18:06 UTC
Vendor Research

CVE-2026-81849 - Path traversal in the aws:downloadContent plugin in amazon-ssm-agent

AWS Security Bulletins · aws@amazon.com · indexed 2026-08-28 18:20 UTC

Bulletin ID: 2026-091-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/28/2026 11:00 AM PDT Description: AWS Systems Manager Agent (amazon-ssm-agent) is Amazon software that runs on Amazon Elastic Compute Cloud (Amazon EC2) instances, edge devices, on-premises servers, and virtual machines (VMs). Amazon-ssm-agent makes it possible for Systems Manager to update, manage, and configure these resources. We identified CVE-2026-81849, where an improper limitation of a …

Cloud SecurityVulnerabilitiesCVE-2026-81849
P5
2026-08-28 18:00 UTC
Other

Trump Targets Foreign Technology in New U.S. Power Grid Security Order

Security Affairs · Pierluigi Paganini · indexed 2026-08-28 19:20 UTC

Trump targets foreign-made power grid equipment, citing cyber, sabotage and supply-chain risks to U.S. national security. Executive Order 14420, signed on August 26, targets equipment and technologies that could expose the power grid to sabotage, unauthorized access, malicious remote activity or supply-chain disruption. The timing matters. The White House points to the rapid expansion of […]

P0
2026-08-28 17:12 UTC
Security Journalism

Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-28 18:30 UTC

Malicious actors are exploiting a newly patched security flaw in PaperCut NG and MF to execute arbitrary code on susceptible instances, as the company released a fresh emergency fix with additional hardening. "This vulnerability gives an unauthenticated attacker remote control over PaperCut's trusted configuration, which could be used to execute arbitrary Java code inside the application's

Cloud SecurityVulnerabilities
P0
2026-08-28 16:50 UTC
Vendor Research

CVE-2026-81838 - Zip Slip path traversal in awsdac (diagram-as-code)

AWS Security Bulletins · aws@amazon.com · indexed 2026-08-28 17:05 UTC

Bulletin ID: 2026-090-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/27/2026 13:00 PM PDT Description: awsdac (diagram-as-code) is a CLI tool that generates AWS architecture diagrams from YAML definitions, enabling version-controlled, code-driven diagramming. We identified CVE-2026-81838, a Zip Slip (path traversal) issue. When awsdac extracts a zip archive referenced by a ZipFile resource in a definition file, a crafted archive can write files outside the inte…

Cloud SecurityVulnerabilitiesCVE-2026-81838
P5
2026-08-28 16:36 UTC
Security Journalism

68-year-old imprisoned after making $1.3 million by pirating IPTV services

BleepingComputer · Bill Toulas · indexed 2026-08-28 16:50 UTC

A 68-year-old has been sentenced in the U.K. to more than six years in prison for operating an illegal IPTV (Internet Protocol Television) service that generated £980,812 ($1.3 million) over three years. [...]

P0
2026-08-28 16:20 UTC
Security Journalism

Android 17 Adds OS-Wide ECH to Hide Website Visits From Network Providers

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-28 18:30 UTC

Google on Thursday announced new network security protections in Android 17 to bolster connection privacy, address cellular vulnerabilities, and safeguard the privacy of users' home networks. Topping the list is support for Encrypted Client Hello (ECH), a privacy standard that prevents networks from eavesdropping on which websites a user is visiting. "This new privacy standard works in tandem

Mobile SecurityNetwork Security
P0
2026-08-28 15:56 UTC
Security Journalism

ownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research Body

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-28 18:30 UTC

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a critical security flaw impacting ownCloud to its Known Exploited Vulnerabilities (KEV) catalog following reports that a Chinese-speaking threat actor weaponized the vulnerability to target a nuclear research body in the Philippines. The vulnerability, tracked as CVE-2023-49105 (CVSS score: 9.8), is a case of

Threat ActorsVulnerabilitiesCVE-2023-49105
P35
2026-08-28 15:27 UTC
Security Journalism

19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-28 15:45 UTC

Cybersecurity researchers have discovered a cluster of 18 Google Chrome and one Microsoft Edge extensions that were published over the last six months and harbored wallet secret stealing and cryptocurrency draining capabilities. The extensions, per Socket security researcher Karlo Zanki, share similarities in code and tradecraft, with evidence indicating that the campaign may have been active

MicrosoftSecurity Research
P0
1 2 3