IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 1,252 matching records.
AUTO-POLL // 2026-09-04 14:40 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
WARM
COOL WARM ELEVATED HOT CRITICAL
P11 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Sep 4

ACTIVE EXPLOITATION
P11
P11
WARM // 18 ARTICLES
THU
Sep 3

RANSOMWARE
P5
P5
COOL // 44 ARTICLES
WED
Sep 2

RANSOMWARE
P11
P11
WARM // 47 ARTICLES
TUE
Sep 1

RANSOMWARE
P6
P6
COOL // 43 ARTICLES
MON
Aug 31

RANSOMWARE
P1
P1
COOL // 37 ARTICLES
SUN
Aug 30

RANSOMWARE
P6
P6
COOL // 9 ARTICLES
SAT
Aug 29

RANSOMWARE
P9
P9
COOL // 8 ARTICLES
RESET
2026-08-25 15:52 UTC
Security Journalism

Massive DDoS attack disrupts Norway’s government digital services

BleepingComputer · Bill Toulas · indexed 2026-08-25 16:00 UTC

A large distributed denial-of-service (DDoS) attack has disrupted Norway's shared government digital infrastructure since Monday, affecting services used by the public sector. [...]

P0
2026-08-25 15:03 UTC
Community

Obfuscating IP Addresses as Hostnames, (Tue, Aug 25th)

SANS Internet Storm Center · indexed 2026-08-25 15:10 UTC

It is pretty obvious that hostnames can replace IP addresses. Pretty much any software accepting an IP address will also accept a hostname as an argument. Last week, I wrote about scans for the cloud metadata service listening at 169.254.169.254. These scans attempted to exploit Server Side Request Forgery (SSRF) vulnerability. One way to prevent these types of exploits is to filter requests that contain the string "169.254.169.254" or to add this IP to a blocklist of URLs that should not be ac…

Vulnerabilities
P0
2026-08-25 14:53 UTC
Security Journalism

Is Cyber Facing an Affordability Crisis?

Dark Reading · Arielle Waldman · indexed 2026-08-25 15:15 UTC

As breach costs reach record highs and defense spending nears $240 billion, small businesses are dangerously exposed, threatening supply chain security.

P0
2026-08-25 14:07 UTC
Security Journalism

A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-25 15:10 UTC

Oasis Security has disclosed a weakness in NVIDIA NemoClaw that could let an attacker-controlled webpage take unauthenticated control of the local Ollama instance serving an AI agent and plant hidden instructions inside the model itself. The findings were shared with The Hacker News ahead of publication, and the report says Oasis Security reported them to NVIDIA's Product Security Incident

AI Security
P0
2026-08-25 14:01 UTC
Security Journalism

From Fake Workers to Account Recovery: The Growing Identity Verification Risk

BleepingComputer · Sponsored by Specops Software · indexed 2026-08-25 14:15 UTC

Attackers are increasingly targeting the processes used to establish or recover identity rather than attacking the login itself. Specops explains how stronger identity verification can help organizations prevent fake workers and social engineering attacks from gaining legitimate access. [...]

P0
2026-08-25 14:00 UTC
Security Journalism

Ukraine to give Britain access to battlefield data to train AI

The Record · indexed 2026-08-25 14:15 UTC

Ukraine will give Britain access to a vast trove of battlefield data collected during the war with Russia, allowing U.K. companies and researchers to use it to train and test artificial intelligence systems.

AI Security
P0
2026-08-25 13:19 UTC
Security Journalism

WhatsApp Adds Multiple Passkeys for Phishing-Resistant Sign-Ins Across iOS and Android

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-25 13:45 UTC

Meta on Tuesday announced a set of WhatsApp account security features, including support for multiple passkeys to a single account to help users with both iOS and Android devices sign into their accounts using the phishing-resistant method. The tech giant said more than 1 billion people use a passkey to log into WhatsApp. Support for passkeys was first introduced in Android in October 2023,

AppleMobile SecurityPhishing
P0
2026-08-25 13:00 UTC
Security Journalism

WhatsApp adds stronger two-step verification, multiple passkeys

BleepingComputer · Sergiu Gatlan · indexed 2026-08-25 13:20 UTC

WhatsApp has started rolling out several new account security features, including support for multiple passkeys and stronger two-step verification. [...]

P0
2026-08-25 12:45 UTC
Security Journalism

UK government seeks powers to secretly block risky tech suppliers

The Record · indexed 2026-08-25 12:50 UTC

The British government is seeking new powers to ban certain technology vendors from supplying companies working in the country’s critical sectors — and to potentially do so in secret.

P0
2026-08-25 12:43 UTC
Security Journalism

Marimo Notebook Flaw Could Run MCP Commands Before Cells Execute in Edit Mode

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-25 13:45 UTC

Marimo has addressed a high-severity security flaw in its notebook software that allowed an attacker to execute an attacker-supplied Model Context Protocol (MCP) command in a specially crafted notebook, according to VulnCheck's CVE Numbering Authority (CNA) record. The CNA record says the command can run as a local subprocess when the notebook is opened in edit mode. The vulnerability, tracked

Vulnerabilities
P0
2026-08-25 11:56 UTC
Security Journalism

Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-25 12:45 UTC

Thousands of companies have been affected by the Mirage2FA campaign from 2024 to 2026. The commercial phishing-as-a-service toolkit targets Microsoft 365 accounts by abusing legitimate login flows and bypassing two-factor authentication. According to ANY.RUN research, 48% of targeted email addresses were potentially compromised. Most of the affected companies are US-based. Mirage2FA Campaign

MicrosoftPhishing
P0
2026-08-25 11:52 UTC
Security Journalism

24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-25 12:45 UTC

Cybersecurity researchers have disclosed details of a new campaign that uses a cluster of 24 npm packages as free phishing infrastructure for redirecting to ClickFix-style fake CAPTCHA pages. "While the malware is simply a single HTML page inside the npm package, and while downloading it wouldn't do harm, the threat actor’s use of npm isn't to infect developers who install it, but to use the

MalwarePhishingSecurity ResearchThreat Actors
P0
2026-08-25 11:45 UTC
Security Journalism

Large DDoS attack knocks Norwegian public services offline

The Record · indexed 2026-08-25 11:55 UTC

The Norwegian Digitalisation Agency said it was working with its IT partner to stabilize systems affected by a distributed denial-of-service attack, with some services gradually coming back online.

P0
2026-08-25 11:33 UTC
Security Journalism

E4del and PINHOLE RATs Turn FTP Banners Into Dead Drops for Malware Commands

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-25 12:45 UTC

Cybersecurity researchers are calling attention to a new campaign that employs FTP banners as dead drop resolvers (DDRs) to deliver two previously unreported remote access trojans (RATs) tracked as E4del and PINHOLE. While threat actors are known to abuse legitimate services to point to additional command-and-control (C2) infrastructure and blend in with regular network traffic, the development

MalwareSecurity ResearchThreat Actors
P0
2026-08-25 11:14 UTC
Security Journalism

Frontier AI: Vulnerability Management's Systemic Revolution

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-25 12:45 UTC

Vulnerability management has been a staple of security programs since the dawn of the cybersecurity discipline. The symbiotic relationship between vulnerability and patch management teams has also existed for that time and has gone through waves of contention and thankfulness. While this relationship required thoughtful care and feeding from both sides, both sides were aiming to work toward a

Vulnerabilities
P0
2026-08-25 10:00 UTC
Vendor Research

The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution

Palo Alto Networks Unit 42 · Sara McBroom · indexed 2026-08-25 10:20 UTC

Explore Unit 42 research on AI-enabled malware. Learn how existing behavioral detection and endpoint analytics stop AI-authored code before execution. The post The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution appeared first on Unit 42.

Malware
P0
2026-08-25 10:00 UTC
Vendor Research

The safety penalty: Reclaiming operational sovereignty in the age of AI

Cisco Talos Intelligence Blog · David J. Bianco · indexed 2026-08-25 10:15 UTC

As frontier AI models become increasingly restrictive, security teams are facing a "safety penalty" that hampers real-time incident response. Discover how organizations can move toward operational sovereignty to ensure their defensive AI keeps pace with unconstrained adversaries.

DFIR
P0
2026-08-25 08:48 UTC
Other

U.S. CISA adds maximum-severity Oracle flaw to its Known Exploited Vulnerabilities catalog

Security Affairs · Pierluigi Paganini · indexed 2026-08-25 09:40 UTC

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Oracle flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added an Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in flaw, tracked as CVE-2026-21962 (CVSS score of 10,0), to its Known Exploited Vulnerabilities (KEV) catalog. CVE-2026-21962 is a critical, unauthenticated vulnerability […]

VulnerabilitiesCVE-2026-21962
P35
2026-08-25 08:34 UTC
Security Journalism

Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-25 09:40 UTC

Bad actors are attempting to exploit two severe unauthenticated authentication bypasses in the Xecurify miniOrange SAML 2.0 Single Sign On plugin that make it possible for an attacker to sign in as any WordPress user, including administrators. The vulnerabilities, as disclosed by Patchstack, are listed below - CVE-2026-61979 (CVSS score: 8.1) - An unauthenticated privilege escalation

Cloud SecurityVulnerabilitiesCVE-2026-61979
P15
2026-08-25 07:15 UTC
Other

Fake Minecraft Sites Are Still Spreading WeedHack After C2 Takedown

Security Affairs · Pierluigi Paganini · indexed 2026-08-25 07:25 UTC

WeedHack Minecraft Malware Survives C2 Takedown: Fake Client Sites Still Active, SEO Poisoning Puts Malicious Downloads at the Top of Google McAfee Labs published a follow-up report on the WeedHack Malware-as-a-Service campaign this week, documenting ten active malicious sites and multiple file-hosting accounts that are still spreading the infostealer despite a disruption to its command-and-control […]

Malware
P0
2026-08-25 06:12 UTC
Security Journalism

Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-25 06:55 UTC

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a maximum-severity security flaw impacting Oracle HTTP Server and Oracle WebLogic Server to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability, tracked as CVE-2026-21962 (CVSS score: 10.0), allows an unauthenticated attacker with network access via HTTP to

VulnerabilitiesCVE-2026-21962
P60
2026-08-24 23:00 UTC
Security Journalism

US sanctions Iranian cyber actors as UK discloses power plant attack

The Record · indexed 2026-08-24 23:00 UTC

The U.S. sanctioned several Iranian nationals for cyberattacks on critical infrastructure just days after reports emerged of a cyber intrusion on a small power plant in the United Kingdom.

P0
11 12 13 14 15