IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 1,248 matching records.
AUTO-POLL // 2026-09-04 13:45 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
WARM
COOL WARM ELEVATED HOT CRITICAL
P14 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Sep 4

ACTIVE EXPLOITATION
P14
P14
WARM // 14 ARTICLES
THU
Sep 3

RANSOMWARE
P5
P5
COOL // 44 ARTICLES
WED
Sep 2

RANSOMWARE
P11
P11
WARM // 47 ARTICLES
TUE
Sep 1

RANSOMWARE
P6
P6
COOL // 43 ARTICLES
MON
Aug 31

RANSOMWARE
P1
P1
COOL // 37 ARTICLES
SUN
Aug 30

RANSOMWARE
P6
P6
COOL // 9 ARTICLES
SAT
Aug 29

RANSOMWARE
P9
P9
COOL // 8 ARTICLES
RESET
2026-08-26 19:32 UTC
Vendor Research

ICYMI: July 2026 @AWS Security

AWS Security Blog · Rodolfo Brenes · indexed 2026-08-26 19:40 UTC

If you found time for a bit of vacation this summer, you might be in catch-up mode. Here’s a list to help: all the expert blog posts, new service capabilities, code samples, and workshops, in case you missed it, from July 2026. AWS Security Blog post This month’s AWS Security Blog posts covered AI agent […]

AI SecurityCloud Security
P0
2026-08-26 19:21 UTC
Security Journalism

Red Flags That Expose Fake North Korean IT Workers

Dark Reading · Alexander Culafi · indexed 2026-08-26 21:05 UTC

North Korean operatives posing as IT workers are improving their tactics, but researchers say there are still ways to spot them before they do damage.

P0
2026-08-26 17:39 UTC
Vendor Research

Detecting multi-stage attacks on AWS: A guide to cross-service signal correlation

AWS Security Blog · Nisha Kashyap · indexed 2026-08-26 18:00 UTC

A single alert from one security service tells you something happened. Read that signal alongside activity from other services and your own business context, and you will know whether what happened is part of a multi-stage attack. Consider a short sequence. An identity calls GetCallerIdentity from a source address it hasn’t previously used. Within minutes, […]

Cloud Security
P0
2026-08-26 17:33 UTC
Other

FBI Seizes China-Linked Hacking Platforms QScan and QTRouter Used Against Critical Infrastructure

Security Affairs · Pierluigi Paganini · indexed 2026-08-26 17:50 UTC

FBI seizes QScan and QTRouter, China-linked platforms used to hide intrusions and target U.S. critical infrastructure. The U.S. Department of Justice and the FBI have seized two platforms, QScan and QTRouter, used by a China-linked group to hide cyberattacks and target critical infrastructure. The operation matters because it shows how state-backed actors no longer need […]

Law EnforcementNetwork Security
P0
2026-08-26 16:43 UTC
Vendor Research

When AI infrastructure becomes the target: Securing gateways and control points

Microsoft Security Blog · Microsoft Security Research, Yash Gund and Sumith Maniath · indexed 2026-08-26 17:15 UTC

Microsoft Threat Intelligence examines attacks on exposed AI workloads, including LiteLLM gateway exploitation, credential harvesting, persistence, and cryptomining activity. The post When AI infrastructure becomes the target: Securing gateways and control points appeared first on Microsoft Security Blog.

MicrosoftPhishingThreat Intelligence
P0
2026-08-26 16:42 UTC
Security Journalism

FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-26 17:50 UTC

The U.S. Department of Justice (DoJ) on Wednesday announced the disruption of two hacking platforms named QScan and QTRouter operated by Chinese threat actors to target critical infrastructure and other sensitive networks in the country. The activity has been attributed to a Chinese state-sponsored group known as QTFY, employed by Nanjing Xinjiuwei Network Technology Company (南京鑫玖维网络科技有限公司).&

APT / Nation-StateLaw EnforcementNetwork SecurityThreat Actors
P0
2026-08-26 16:41 UTC
Security Journalism

Meta agrees to $18 billion settlement over teen social media harms

BleepingComputer · Lawrence Abrams · indexed 2026-08-26 16:50 UTC

Meta has reached a proposed settlement worth up to approximately $18 billion with a bipartisan coalition of 52 attorneys generals over allegations that Facebook and Instagram were deliberately designed to encourage compulsive use by children and teenagers. [...]

P0
2026-08-26 15:58 UTC
Community

Who Has Admin Rights in your Entra ID Directory?, (Wed, Aug 26th)

SANS Internet Storm Center · indexed 2026-08-26 16:15 UTC

A common thing that folks should "worry" about in Entra (or any platform really) is "who has rights to administer"?  Who can delete or change key things, or modify them in ways that might not be obvious (accidentally or on purpose).  Yes, we trust our people, but if they've moved on to other roles or to other organizations, they change from "our people" to "used to be our people".  
 Also,…

Microsoft
P0
2026-08-26 15:35 UTC
Security Journalism

Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunneler

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-26 17:50 UTC

Cybersecurity researchers have discovered additional infrastructure and previously undocumented malware associated with Nimbus Manticore, an Iranian state-sponsored hacking group affiliated with the Islamic Revolutionary Guard Corps (IRGC). Group-IB, in a new analysis published today, described the cyber espionage actor as among the most active Iranian APT groups in 2026. Nimbus Manticore (aka

APT / Nation-StateMalwareSecurity Research
P0
2026-08-26 15:19 UTC
Security Journalism

Boston Scientific says cyberattack disrupted operations globally

BleepingComputer · Bill Toulas · indexed 2026-08-26 15:30 UTC

Medical technology company Boston Scientific has been targeted in a cyberattack that disrupted some of its IT systems, causing operational disruptions globally. [...]

P0
2026-08-26 14:01 UTC
Security Journalism

Snowflake ends service-account passwords. Now comes the hard part

BleepingComputer · Sponsored by Token Security · indexed 2026-08-26 14:15 UTC

Snowflake is ending password authentication for legacy service accounts, forcing organizations to migrate them to passwordless methods. Token Security explains why the harder challenge is identifying what uses each account, who owns it, and how much access it still needs. [...]

P0
2026-08-26 13:44 UTC
Security Journalism

NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-26 14:20 UTC

Cybersecurity researchers have disclosed details of a new adversary-in-the-middle (AitM) phishing toolkit called NovaCookies that's used as a proxy to redirect Microsoft 365 sign-ins, while capturing authenticated sessions in the process. In a report shared with The Hacker News ahead of publication, Island characterized the $320/month service as a subscription-based phishing platform that

MicrosoftPhishingSecurity Research
P0
2026-08-26 13:07 UTC
Security Journalism

CISA Red Team Compromised Two Critical Infrastructure Orgs, One Detected Nothing

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-26 14:20 UTC

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has published the results of two red team assessments it conducted simultaneously against two critical infrastructure organizations, using what it described as similar tradecraft while recording sharply different defensive outcomes. Both organizations were fully compromised at the domain level, and in both, the red team also

P0
2026-08-26 11:55 UTC
Security Journalism

Unpatched Kaltura mwEmbed Flaws Could Let Remote Attackers Read Files and Run Code

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-26 13:10 UTC

The CERT Coordination Center (CERT/CC) has disclosed two unpatched vulnerabilities in Kaltura's HTML5 video player library that allow a remote, unauthenticated attacker to read arbitrary files from a server and execute code on it. The flaws, tracked as CVE-2026-19913 and CVE-2026-19912, both stem from the same unsafe deserialization in the mwEmbedLoader.php endpoint of the mwEmbed player

Cloud SecurityVulnerabilitiesCVE-2026-19912CVE-2026-19913
P5
2026-08-26 11:36 UTC
Security Journalism

Imagine the SOC Without a Queue: From Alert Backlog to AI Hypothesis Engine

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-26 12:00 UTC

The SOC we've always known was built around a model that guarantees most of the alert queue will never receive analyst review. There's never time. In a traditional SOC, the typical progression follows a well-known pattern: an alert arrives; a detection engine assigns a severity score. The issue then waits for a human to decide if it should escalate to an investigation. Given the volume of

DFIR
P0
2026-08-26 10:27 UTC
Security Journalism

Claude Opus 4.6 Bypasses Gym Booking Limit, Cancels Other Users' Reservations in Tests

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-26 10:35 UTC

Aikido Security has published research that recreates the Australian gym-booking incident in a synthetic environment, finding that Claude Opus 4.6, running on the OpenClaw agent harness, exploited a client-side-only booking restriction in 9 of 10 runs. The original incident was first reported by ABC News on August 10, based on chat logs and screenshots the user supplied. He had asked an

P0
2026-08-26 09:38 UTC
Security Journalism

OpenAI Bans Russian ChatGPT Accounts Used to Run Influence Operation

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-26 10:35 UTC

OpenAI on Tuesday said it banned a cluster of Russian ChatGPT accounts that used VPNs to bypass access restrictions and run an influence operation, which relied on its artificial intelligence (AI) tool to generate social media posts and comments that were shared on Substack, Telegram, X, Facebook and LinkedIn. The accounts "were being used to promote the International Burke Institute (IBI), a

AI SecurityNetwork Security
P0
9 10 11 12 13