IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 1,254 matching records.
AUTO-POLL // 2026-09-04 15:25 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
WARM
COOL WARM ELEVATED HOT CRITICAL
P10 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Sep 4

ACTIVE EXPLOITATION
P10
P10
WARM // 20 ARTICLES
THU
Sep 3

RANSOMWARE
P5
P5
COOL // 44 ARTICLES
WED
Sep 2

RANSOMWARE
P11
P11
WARM // 47 ARTICLES
TUE
Sep 1

RANSOMWARE
P6
P6
COOL // 43 ARTICLES
MON
Aug 31

RANSOMWARE
P1
P1
COOL // 37 ARTICLES
SUN
Aug 30

RANSOMWARE
P6
P6
COOL // 9 ARTICLES
SAT
Aug 29

RANSOMWARE
P9
P9
COOL // 8 ARTICLES
RESET
2026-08-24 20:36 UTC
Security Journalism

New Zealand to pursue social media ban for children under 16

The Record · indexed 2026-08-24 20:45 UTC

The legislation would mandate that high-risk social media platforms such as Instagram, TikTok, Snapchat and Facebook take “reasonable steps” to ensure users are over age 16 by using tools like facial age estimation, digital ID services, formal IDs and existing account information for verification.

P0
2026-08-24 19:26 UTC
Security Journalism

Hackers target WordPress sites in miniOrange auth bypass attacks

BleepingComputer · Bill Toulas · indexed 2026-08-24 19:35 UTC

Hackers are attempting to exploit two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress that can be used to forge SAML responses and log in as administrators. [...]

P10
2026-08-24 17:56 UTC
Security Journalism

TikTok reaches $400M settlement with US over COPPA violations

BleepingComputer · Bill Toulas · indexed 2026-08-24 18:10 UTC

The U.S. Department of Justice announced a $400 million settlement with TikTok, ByteDance, and affiliated companies over allegations that they violated the Children's Online Privacy Protection Act (COPPA). [...]

Law Enforcement
P0
2026-08-24 17:41 UTC
Security Journalism

Shipping More AI Code Than You Can Secure? Watch How to Control Remediation Debt

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-24 12:10 UTC

If your developers are using AI coding tools, you are probably already seeing the upside: faster development, more code, and less time spent on routine work. The harder part is what comes after. AI can also introduce open-source packages at a pace your security team was never built to handle. More dependencies mean more vulnerabilities to review, more remediation work, and a backlog that can

P0
2026-08-24 17:41 UTC
Security Journalism

Weedhack Malware Spreads via Fake Minecraft Clients and SEO Poisoning

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-24 23:15 UTC

Cybersecurity researchers have found that several websites are still actively distributing a malware family known as Weedhack to gamers by masquerading as Minecraft clients. McAfee Labs said it detected and blocked more than 6,300 attempts to access malicious sites, adding that it found lookalike gaming websites designed to mimic legitimate projects, including branding, feature lists, FAQs,

MalwareSecurity Research
P0
2026-08-24 17:27 UTC
Other

Cybercriminals Turn GTA VI Leaks Into Malware Bait

Security Affairs · Pierluigi Paganini · indexed 2026-08-24 18:10 UTC

A fake 113GB GTA VI build is packed with malware, using massive empty files to hide a tiny malicious payload. GTA VI hype has reached the point where people are volunteering to infect their own computers just to check if a leak is real. Someone on X asked their followers to “take one for the […]

Malware
P0
2026-08-24 15:17 UTC
Security Journalism

ReliaQuest confirms failed data-theft attack after ShinyHunters breach

BleepingComputer · Bill Toulas · indexed 2026-08-24 15:30 UTC

Cybersecurity company ReliaQuest has confirmed that one of its employees was targeted in a social engineering attack after hackers impersonated a member of the security team. [...]

P0
2026-08-24 15:02 UTC
Security Journalism

Tricky 'SynkLoader' Multitool May Herald Ransomware

Dark Reading · Nate Nelson · indexed 2026-08-24 15:50 UTC

An advanced, multilingual malware family brings back a trick from yesteryear — screen hijacking — for effective password theft, along with a slew of novel features.

MalwareRansomware
P15
2026-08-24 14:32 UTC
Security Journalism

⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-24 16:05 UTC

A package gets installed. A login prompt opens. A box sits exposed to the internet. Nothing looks unusual yet. That’s roughly the mood this week. Trusted tools turn hostile, old weak spots get fresh attention, AI makes exploit work cheaper, and researchers keep finding attacks that sound harder than they actually are. Plenty to clean up. Here’s the short version. ⚡ Threat of the Week U.S.

ICS / OT
P0
2026-08-24 14:00 UTC
Security Journalism

South Korean startup platform breach exposes key management failures

BleepingComputer · Sponsored by Penta Security · indexed 2026-08-24 14:05 UTC

A breach at South Korea's government-backed startup platform exposed encrypted personal data after an encryption key was included in an API. Penta Security explains why encryption keys must be securely managed and kept separate from the data they protect. [...]

P0
2026-08-24 14:00 UTC
Security Journalism

The Vulnerability Gap: Why Discovery Is Outrunning Repair

Dark Reading · Christopher Robinson · indexed 2026-08-24 17:05 UTC

The combination of AI both discovering more vulnerabilities at a faster pace and the tightening regulatory environment is making this an all-hands-on-deck moment for the cybersecurity community.

Vulnerabilities
P0
2026-08-24 12:35 UTC
Security Journalism

WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-24 14:05 UTC

Cybersecurity researchers have flagged two new malware families called WordlistLoader and SynkLoader that's used to deliver next-stage payloads and likely sell access to ransomware groups. According to findings from Gen Digital, WordlistLoader is being used to deliver Amatera Stealer (aka ACR Stealer or AcridRain Stealer) via ClearFake campaigns, which employ the ClickFix (aka FakeCaptcha)

MalwareMicrosoftPhishingRansomwareSecurity Research
P15
2026-08-24 11:56 UTC
Security Journalism

Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-24 12:10 UTC

Red Hat and the Keycloak project have released patches to address a critical security flaw in the open-source identity and access management server that could allow an unauthenticated remote attacker to take over any user account by forcing a password reset. The vulnerability, assigned the CVE identifier CVE-2026-18963, is rated 9.1 on the CVSS scoring system by Red Hat, which acts as

LinuxVulnerabilitiesCVE-2026-18963
P5
2026-08-24 11:51 UTC
Security Journalism

Operation QUICSILVER Targets Myanmar Government and IT with QUICAgent Backdoor

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-24 12:10 UTC

Cybersecurity researchers have flagged a cyber espionage campaign targeting Myanmar that uses graduation ceremony invitation lures to deliver a Go backdoor called QUICAgent. The campaign, codenamed Operation QUICSILVER, has been found to target government and information technology sectors, per Seqrite Labs. The activity is assessed to be the work of a China-nexus threat actor with moderate

APT / Nation-StateMalwareSecurity ResearchThreat Actors
P0
2026-08-24 11:30 UTC
Security Journalism

The Outsized Shadow: Why 5% of AI Users Are Your Biggest Security Risk

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-24 12:10 UTC

Big security risks come in small packages. While enterprise security teams focus on policing the proliferation of employees using ChatGPT and Claude for quick drafting tasks, a more urgent threat is posed by a handful of AI super-adopters who are quietly hardcoding unvetted tools into critical business operations. According to new research published by Akamai, the top 5% of enterprise power

P0
2026-08-24 10:45 UTC
Security Journalism

CISA orders urgent patching of actively exploited Zimbra flaw

BleepingComputer · Sergiu Gatlan · indexed 2026-08-24 10:50 UTC

The Cybersecurity and Infrastructure Security Agency (CISA) has ordered U.S. government agencies to patch an actively exploited vulnerability in Zimbra Collaboration Suite (ZCS) within three days. [...]

Vulnerabilities
P25
2026-08-24 08:52 UTC
Other

Slovakia Warns of Cyber Risks in Road Speed Cameras

Security Affairs · Pierluigi Paganini · indexed 2026-08-24 10:00 UTC

Slovakia warns that vulnerable speed cameras could expose vehicle data, enable remote access and provide attackers with a foothold into public networks. Slovakia’s National Security Authority, NBÚ, recently issued a warning about several road speed cameras, calling them a significant cyber threat. The alert is not about someone deleting a speeding ticket. It is about […]

P0
2026-08-24 08:08 UTC
Security Journalism

UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-24 08:45 UTC

Cybersecurity researchers have disclosed details of a Chinese-speaking cybercrime group dubbed UAT-10147 that's targeting Windows and Linux web servers globally across the education, media, technology, and gaming sectors. The vast majority of the targets are located in Brazil, Bolivia, China, Canada, and Vietnam. Details of the threat activity came to light following the discovery of an open

CybercrimeLinuxMalwareMicrosoftSecurity Research
P0
2026-08-24 07:23 UTC
Other

TikTok Settles U.S. Child Privacy Case for $400 Million

Security Affairs · Pierluigi Paganini · indexed 2026-08-24 07:35 UTC

TikTok will pay $400 million to settle U.S. claims that it violated child privacy laws by collecting data from users under 13. The U.S. Department of Justice announced that TikTok will pay $400 million to settle a 2024 lawsuit over children’s privacy. “Today, the Department of Justice announced a $400 million settlement with TikTok, ByteDance, […]

Cloud SecurityLaw Enforcement
P0
2026-08-24 07:23 UTC
Community

DOUBLECUP's PNG Payload, (Mon, Aug 24th)

SANS Internet Storm Center · indexed 2026-08-24 07:35 UTC

New malware that uses steganography always gets my attention, but I was disappointed when I looked at the latest DOUBLECUP write-up. It doesn't use real steganography:

Malware
P0
2026-08-24 07:17 UTC
Other

iAuthFlow v2: The $10,000 Phishing Toolkit That Survives Your Password Reset

Security Affairs · Pierluigi Paganini · indexed 2026-08-24 07:35 UTC

iAuthFlow v2 phishing toolkit uses a phished Google session to enroll an attacker-controlled passkey that survives password resets. Abnormal Security researchers have published an analysis of iAuthFlow v2, a phishing toolkit sold on a Russian-language cybercrime forum for $10,000 base price. The author also offers for sale additional capability modules separately. The headline feature is […]

CybercrimePhishingSecurity Research
P0
12 13 14 15 16