IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 1,061 matching records.
AUTO-POLL // 2026-08-30 14:40 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P8 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Aug 30

RANSOMWARE
P8
P8
COOL // 7 ARTICLES
SAT
Aug 29

RANSOMWARE
P9
P9
COOL // 8 ARTICLES
FRI
Aug 28

RANSOMWARE
P8
P8
COOL // 47 ARTICLES
THU
Aug 27

RANSOMWARE
P4
P4
COOL // 48 ARTICLES
WED
Aug 26

RANSOMWARE
P4
P4
COOL // 46 ARTICLES
TUE
Aug 25

ACTIVE EXPLOITATION
P4
P4
COOL // 40 ARTICLES
MON
Aug 24

RANSOMWARE
P4
P4
COOL // 34 ARTICLES
RESET
2026-08-20 21:35 UTC
Vendor Research

CVE-2026-7791 - Local Privilege Escalation via TOCTOU Race Condition in Amazon WorkSpaces Skylight Agent

AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC

Bulletin ID: 2026-025-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 2026/05/04 15:30 PM PDT Description: Amazon Skylight Workspace Config Service ( slwsconfigservice) is a critical background service within Amazon WorkSpaces that manages system configuration, monitors health, and updates components. We identified CVE-2026-7791 which allows a local non-admin authenticated user to escalate privileges to SYSTEM by exploiting a race condition in the Skylight Workspac…

Cloud SecurityMicrosoftVulnerabilitiesCVE-2026-7791
P15
2026-08-20 21:35 UTC
Vendor Research

CVE-2026-10740 - Excessive memory allocation in s2n-quic

AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC

Bulletin ID: 2026-042-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 06/10/2026 11:15 AM PDT Description: s2n-quic is a Rust implementation of the QUIC protocol. We identified CVE-2026-10740, an issue of unbounded memory allocation in the CRYPTO frame reassembler in s2n-quic before 1.82.0. An unauthenticated user can attempt to exhaust server memory on an s2n-quic endpoint by sending crafted CRYPTO frames with high offsets. The buffer used for processing CRYPTO fr…

Cloud SecurityVulnerabilitiesCVE-2026-10740
P5
2026-08-20 21:35 UTC
Vendor Research

Issue with FreeRTOS-Plus-TCP - IPv6 Router Advertisement Memory Safety Issues

AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC

Bulletin ID: 2026-023-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 2026/04/29 12:30 PM PDT Description: FreeRTOS-Plus-TCP is an open source TCP/IP stack implementation designed for FreeRTOS, providing a standard Berkeley sockets interface and support for essential networking protocols including IPv6, ARP, DHCP, DNS, and Router Advertisement (RA). We identified CVE-2026-7425 and CVE-2026-7426, one of them being out-of-bounds read and another one being out-of-boun…

Cloud SecurityNetwork SecurityVulnerabilitiesCVE-2026-7425CVE-2026-7426
P5
2026-08-20 21:35 UTC
Vendor Research

CVE-2026-18733 - Prompt injection bypasses shell tool consent gate in Strands Agents Tools

AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC

Bulletin ID: 2026-072-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/03/2026 13:30 PM PDT Description: Strands Agents is an open-source SDK for building AI agents. The strands-agents-tools package provides pre-built tools for use with the SDK, including the shell tool for executing operating system commands on the agent's host. We identified CVE-2026-18733. The shell tool includes a human consent gate that prompts the operator to approve commands before they ru…

AI SecurityCloud SecurityVulnerabilitiesCVE-2026-18733
P5
2026-08-20 21:35 UTC
Vendor Research

CVE-2026-9291 - Insecure Deserialization in Amazon Braket SDK Job Results Processing

AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC

Bulletin ID: 2026-036-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 05/22/2026 11:15 AM PDT Description: Amazon Braket SDK is an open-source Python library for interacting with the Amazon Braket quantum computing service, including managing hybrid quantum jobs and retrieving job results. We identified CVE-2026-9291, an insecure deserialization issue (CWE-502) in the job results processing component. The SDK's deserialize_values() function trusts the dataFormat fi…

Cloud SecurityVulnerabilitiesCVE-2026-9291
P5
2026-08-20 21:35 UTC
Vendor Research

CVE-2026-15738 - Issue with AWS Load Balancer Controller Cross-Namespace Traffic Interception via HTTPRoute/GRPCRoute Priority Ordering

AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC

Bulletin ID: 2026-055-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 07/14/2026 13:30 PM PDT Description: The AWS Load Balancer Controller is an open-source Kubernetes controller that manages AWS Elastic Load Balancing resources for Kubernetes clusters. We identified CVE-2026-15738, an incorrect rule precedence ordering issue in the Gateway API listener rule generation logic. When both an HTTPRoute and a GRPCRoute are attached to the same Application Load Balancer…

Cloud SecurityVulnerabilitiesCVE-2026-15738
P5
2026-08-20 21:35 UTC
Vendor Research

Issues in tough library and tuftool CLI utility

AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC

Bulletin ID: 2026-019-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 2026/04/24 13:30 AM PDT Description: Multiple security issues have been identified in the tough library and tuftool CLI utility. tough is a Rust library used for generating, signing, and managing TUF (The Update Framework) repositories, and tuftool is the command-line interface for repository management Operations. The following issues have been identified: - CVE-2026-6966 - CVE-2026-6967 - CVE-2…

Cloud SecurityVulnerabilitiesCVE-2026-6966CVE-2026-6967CVE-2026-6968
P5
2026-08-20 21:35 UTC
Vendor Research

MariaDB Server Audit Plugin Comment Handling Bypass

AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC

Bulletin ID: 2026-006-AWS Scope: AWS Content Type: Informational Publication Date: 2026/03/03 10:15 AM PST Description: Amazon RDS/Aurora is a managed relational database service. We identified CVE-2026-3494. In MariaDB server version through 11.8.5, when server audit plugin is enabled with server_audit_events variable configured with QUERY_DCL, QUERY_DDL, or QUERY_DML filtering, if an authenticated database user invokes a SQL statement prefixed with double-hyphen (‐‐) or hash (#) style comment…

Cloud SecurityVulnerabilitiesCVE-2026-3494
P5
2026-08-20 20:22 UTC
Security Journalism

Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-20 22:00 UTC

The Rust Project has deleted malicious versions of three widely used Rust crates from crates.io after a compromised maintainer account published releases that added a typosquatted dependency whose build script downloaded and executed a remote payload during compilation. The affected releases are arrayref 0.3.10, internment 0.8.7, and append-only-vec 0.1.9, all published from the same owner

Malware
P0
2026-08-20 19:59 UTC
Security Journalism

Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-20 20:30 UTC

Three distinct suspected Russian cyber espionage threat clusters have been observed leveraging legitimate authentication flows to single out individuals working in academia, aerospace and defense, governments, and think tanks across Europe, as well as academia and think tanks within the U.S. These clusters include UNC6293, UNC7005, and UNC5976. "These clusters engage in persistent, adaptive

APT / Nation-State
P0
2026-08-20 19:11 UTC
Security Journalism

What We Missed: Delta Flight Disrupted With Wi-Fi Hack

Dark Reading · Rob Wright, Alexander Culafi · indexed 2026-08-20 19:45 UTC

In this video, Dark Reading editors discuss some of the news they didn't get a chance to cover, including some scary airplane security risks and the US government's newest "hack back" strategy.

P0
2026-08-20 18:40 UTC
Vendor Research

AWS Network Firewall now supports rule hit count

AWS Security Blog · Preetkumar Shah · indexed 2026-08-20 18:45 UTC

As firewall rule sets grow in complexity, security teams face a common challenge: manual log analysis is used to determine which rules are actively matching traffic and which are consuming capacity without being triggered. This lack of visibility creates operational and compliance gaps. Organizations with governance policies that require removal of dormant rules after a […]

Cloud SecurityNetwork Security
P0
2026-08-20 18:03 UTC
Other

Manic: The Android Malware That Exfiltrates Data Even When the Phone Is Offline

Security Affairs · Pierluigi Paganini · indexed 2026-08-20 18:35 UTC

Manic Android malware combines banking fraud and spyware, using a Bluetooth relay to steal data even when devices are offline. ThreatFabric’s Mobile Threat Intelligence team has identified a new Android malware, dubbed Manic, which has been active in the wild since at least February 2026. The researchers state that the malware is still under development […]

CybercrimeMalwareMobile SecurityThreat Intelligence
P20
2026-08-20 18:00 UTC
Vendor Research

Is Cyber missing the Marque?

Cisco Talos Intelligence Blog · Mick Baccio · indexed 2026-08-20 18:10 UTC

In this week's newsletter, new author Mick Baccio introduces himself and explores the operational and security implications of the new White House memorandum regarding private sector participation in government-authorized offensive cyber operations.

P0
2026-08-20 17:53 UTC
Security Journalism

Hackers poison arrayref Rust crate to push infostealer malware

BleepingComputer · Bill Toulas · indexed 2026-08-20 18:00 UTC

Hackers compromised the maintainer account behind the widely used Rust crate arrayref to introduce malware that executed on developers' systems during compilation. [...]

Malware
P0
2026-08-20 17:39 UTC
Security Journalism

N-able Bug Exposes Password Vault Master Keys

Dark Reading · Nate Nelson · indexed 2026-08-20 17:50 UTC

The popular "Passportal" password manager, favored by MSPs and SMBs, remains risky even after its patch, thanks to its cloud-based design. Should these products stay away from the cloud entirely?

P0
2026-08-20 17:36 UTC
Other

NSA, CISA, FBI, DOE, and EPA Warn of Active AI-Assisted Attacks on Siemens S7 PLCs

Security Affairs · Pierluigi Paganini · indexed 2026-08-20 18:35 UTC

NSA, CISA, FBI, DOE, and EPA warn of active AI-assisted attacks against Siemens S7 PLCs across US critical infrastructure sectors. Five U.S. federal agencies issued a joint advisory this week warning of an active hacking campaign against Siemens S7 Series programmable logic controllers. The advisory, CISA AA26-231A, is co-signed by NSA, FBI, DOE, and EPA […]

Law Enforcement
P0
2026-08-20 17:33 UTC
Security Journalism

Senators press TikTok over withholding of safety features for some users

The Record · indexed 2026-08-20 17:50 UTC

In a letter on Wednesday, Sens. Marsha Blackburn (R-TN) and Richard Blumenthal (D-CT) criticized the company for having “knowingly withheld a critical safety measure for millions of American users."

P0
2026-08-20 17:32 UTC
Security Journalism

Money and Mindset: The Two Biggest Roadblocks to Cyber Policing

Dark Reading · Arielle Waldman · indexed 2026-08-20 18:35 UTC

Law enforcement training is falling behind the volume and rapid evolution of cybercrimes. Officers really only need to learn the basics, but lack of focus and budget hinder progress.

Cybercrime
P0
2026-08-20 17:23 UTC
Security Journalism

ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit, and More

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-20 18:50 UTC

A lot of this week’s trouble starts with something trusted doing exactly what it was allowed to do. Signed drivers get turned against defenses. Legitimate apps help malware blend in. A weak header check opens a path to code execution. Elsewhere, exposed systems, old bugs, odd hiding tricks, and AI-assisted exploit research keep lowering the effort needed to cause damage. Nothing here needs

Malware
P0
2026-08-20 16:59 UTC
Security Journalism

AI-Generated Exploit Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructure

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-20 17:25 UTC

The U.S. government on Wednesday warned of an "active threat" targeting critical infrastructure organizations in the country using artificial intelligence (AI)-generated exploit scripts. The activity is targeting Siemens S7 SeriesProgrammable Logic Controllers (PLCs) to conduct reconnaissance and capability development using AI-generated scripts disguised as legitimate monitoring tools. That

AI Security
P0
2026-08-20 14:36 UTC
Security Journalism

New Cryptographic Context Injection Attack Could Let Web Pages Steal Grok Chat Data

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-20 16:10 UTC

Adversa AI has disclosed an attack technique that it says can cause xAI's Grok chatbot to send a user's name, approximate location, subscription tier, and the prompts from the ongoing conversation to an attacker-controlled server after the user asks it to summarize an ordinary web page. The AI security company, which has codenamed the technique "Cryptographic Context Injection," said the

AI Security
P0
2026-08-20 14:01 UTC
Security Journalism

How MSPs can catch phishing attacks email filters miss

BleepingComputer · Sponsored by Kaseya · indexed 2026-08-20 14:20 UTC

AI is making phishing attacks more personalized, convincing, and difficult for traditional email filters to detect. Kaseya explains how MSPs can monitor identity, email, and endpoint activity to detect and contain attacks that make it past the inbox. [...]

Phishing
P0
2026-08-20 14:00 UTC
Vendor Research

Going with the Flow(s): Distinct Clusters Target Individuals of Interest to Russia

Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-08-20 14:40 UTC

Written by: Gabby Roncone, Wesley Shields Overview Google Threat Intelligence Group (GTIG) is tracking three distinct suspected Russian cyber espionage threat clusters abusing legitimate authentication flows to target individuals working in academia, aerospace and defense, governments and think tanks across Europe, as well as academia and think tanks within the United States. Examples of these techniques can be found in our previous blog on UNC6293’s phishing operations. We now track an additio…

APT / Nation-StateMalwareMicrosoftPhishingThreat Intelligence
P0
2026-08-20 13:48 UTC
Security Journalism

Isolated-vm Flaw Lets Sandboxed JavaScript Escape to Host for Potential RCE

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-20 14:30 UTC

Cybersecurity researchers have disclosed a critical security flaw in isolated-vm, a popular open-source sandbox with more than 2,900 stars and 190 forks on GitHub, that could allow attackers to escape the confines of the isolated environment. The vulnerability ("GHSA-864f-rcv7-6rh4"), which has yet to be assigned a CVE identifier, impacts all versions of the library before and including 7.0.0.

Security ResearchVulnerabilities
P15
2026-08-20 13:35 UTC
Security Journalism

Critical NetScaler Flaw Can Bypass Authentication on Certain Gateway and AAA Servers

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-20 14:30 UTC

Citrix has released updates to address two security flaws impacting NetScaler ADC and NetScaler Gateway deployments, including a critical-severity authentication bypass vulnerability. According to the cloud computing and virtualization technology company, the issues affect customer-managed NetScaler ADC and NetScaler Gateway, including certain FIPS and NDcPP builds, as well as SecurAccess

Cloud SecurityVulnerabilities
P10
11 12 13 14 15