IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 1,255 matching records.
AUTO-POLL // 2026-09-04 15:30 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
WARM
COOL WARM ELEVATED HOT CRITICAL
P11 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Sep 4

ACTIVE EXPLOITATION
P11
P11
WARM // 21 ARTICLES
THU
Sep 3

RANSOMWARE
P5
P5
COOL // 44 ARTICLES
WED
Sep 2

RANSOMWARE
P11
P11
WARM // 47 ARTICLES
TUE
Sep 1

RANSOMWARE
P6
P6
COOL // 43 ARTICLES
MON
Aug 31

RANSOMWARE
P1
P1
COOL // 37 ARTICLES
SUN
Aug 30

RANSOMWARE
P6
P6
COOL // 9 ARTICLES
SAT
Aug 29

RANSOMWARE
P9
P9
COOL // 8 ARTICLES
RESET
2026-08-24 07:17 UTC
Other

iAuthFlow v2: The $10,000 Phishing Toolkit That Survives Your Password Reset

Security Affairs · Pierluigi Paganini · indexed 2026-08-24 07:35 UTC

iAuthFlow v2 phishing toolkit uses a phished Google session to enroll an attacker-controlled passkey that survives password resets. Abnormal Security researchers have published an analysis of iAuthFlow v2, a phishing toolkit sold on a Russian-language cybercrime forum for $10,000 base price. The author also offers for sale additional capability modules separately. The headline feature is […]

CybercrimePhishingSecurity Research
P0
2026-08-23 17:04 UTC
Other

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 111

Security Affairs · Pierluigi Paganini · indexed 2026-08-23 18:20 UTC

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Akira Hits Safe Mode: Ransomware Rebooting Around EDR Multi-Functional Linux Botnet “Evooo1Bot” StubMaker RubyGems Campaign Delivers a Windows Infostealer Hunting MacSync Stealer infrastructure through behavioral pivots Manic: Blend between Banking Malware & Spyware […]

LinuxMalwareMicrosoftRansomware
P15
2026-08-23 08:48 UTC
Other

UK Power Plant Disabled for Four Days by Iran-Linked Hackers, Concurrent with US Water Attacks

Security Affairs · Pierluigi Paganini · indexed 2026-08-23 09:20 UTC

Iran-linked hackers shut down a UK power plant for four days in the first confirmed attack of its kind, concurrent with water infrastructure attacks across 12 US states. Iran-linked hackers shut down a British power plant for four days in what The Telegraph describes as the most successful cyberattack of its kind against UK energy […]

P0
2026-08-23 08:29 UTC
Other

Security Affairs newsletter Round 591 by Pierluigi Paganini – INTERNATIONAL EDITION

Security Affairs · Pierluigi Paganini · indexed 2026-08-23 09:20 UTC

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. ToxicPanda 2.0 Gets a Major Upgrade, Expanding Attacks Across 16 Countries Malware Hijacks Android Car Head Units […]

MalwareMobile Security
P0
2026-08-23 07:20 UTC
Other

Zero-Click Grok Chat History Theft: Adversa AI Demonstrates Cryptographic Context Injection

Security Affairs · Pierluigi Paganini · indexed 2026-08-23 08:20 UTC

New Cryptographic Context Injection technique bypasses AI guardrails via AES-encrypted payloads, leaking full Grok chat histories zero-click Adversa AI researcher Rony Utevsky devised a new attack technique, called Cryptographic Context Injection, that bypasses AI safety filters by sending instructions as AES-encrypted ciphertext and tricking the model into decrypting them inside its own code execution runtime. […]

P0
2026-08-22 16:50 UTC
Other

ToxicPanda 2.0 Gets a Major Upgrade, Expanding Attacks Across 16 Countries

Security Affairs · Pierluigi Paganini · indexed 2026-08-22 17:35 UTC

ToxicPanda 2.0 targets 349 financial apps and abuses Android Wireless Debugging to gain deeper device access and steal banking credentials. ToxicPanda used to be a Europe-focused nuisance targeting a manageable list of banks. That version is gone. Zimperium’s zLabs team just documented ToxicPanda 2.0, and the numbers alone tell the story: 349 targeted financial institutions […]

Mobile Security
P0
2026-08-22 14:32 UTC
Security Journalism

TikTok Agrees to $400 Million Settlement in U.S. Child Privacy Lawsuit

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-22 15:15 UTC

The U.S. Department of Justice (DoJ) announced on Friday that ByteDance-owned TikTok will pay $400 million to settle a 2024 lawsuit accusing the company of violating child privacy laws in the country. As part of the settlement, the social media platform will pay $300 million immediately, and an additional $100 million "upon entry of an order vacating a prior consent decree entered against

Cloud SecurityLaw Enforcement
P0
2026-08-22 13:00 UTC
Security Journalism

Named Pipes Under Attack: Securing Windows Interprocess Communication

BleepingComputer · Sponsored by ThreatLocker · indexed 2026-08-22 13:15 UTC

Windows named pipes provide fast interprocess communication, but weak access controls can expose privileged services to untrusted processes. ThreatLocker explains how endpoint verification, command authorization, strict input validation, and narrowly scoped privileges can help secure named-pipe communication. [...]

Microsoft
P0
2026-08-22 08:55 UTC
Other

Malware Hijacks Android Car Head Units

Security Affairs · Pierluigi Paganini · indexed 2026-08-22 09:15 UTC

Malware is abusing car infotainment updates to install proxy software, turning Android head units into nodes for the BADBOX network. Kaspersky researchers found something in June 2026 that made them stop and look twice: an Android app with no interface at all, installed like any ordinary app but making zero effort to disguise itself as […]

MalwareMobile Security
P0
2026-08-22 08:04 UTC
Other

Critical Flaw in NASA/JPL Open-Source Spacecraft Command Software Allowed Unauthenticated Command Execution

Security Affairs · Pierluigi Paganini · indexed 2026-08-22 08:20 UTC

A critical flaw (CVSS 9.4) in NASA/JPL’s AIT-GUI let anyone send unauthenticated commands to spacecraft instruments. Cycode researchers found that AIT-GUI, the browser-based operator console in NASA/JPL open-source AMMOS Instrument Toolkit, shipped with no authentication, no session checks, and no CSRF protection on any of its state-changing endpoints. “AIT-GUI, the web front end of NASA/JPL’s […]

Vulnerabilities
P10
2026-08-22 07:17 UTC
Other

U.S. CISA adds Zimbra Collaboration Suite (ZCS) flaw to its Known Exploited Vulnerabilities catalog

Security Affairs · Pierluigi Paganini · indexed 2026-08-22 08:20 UTC

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Zimbra Collaboration Suite (ZCS) flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the Zimbra Collaboration Suite (ZCS) flaw CVE-2026-73570 to its Known Exploited Vulnerabilities (KEV) catalog. CERT Polska, Poland’s national computer emergency response team, confirmed this week that threat actors […]

Threat ActorsVulnerabilitiesCVE-2026-73570
P35
2026-08-21 23:00 UTC
Vendor Research

Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain

Palo Alto Networks Unit 42 · Yaron Avital · indexed 2026-08-21 23:05 UTC

Attackers are targeting CI/CD pipelines and developer tools instead of application code, requiring total SDLC visibility and strict security controls The post Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain appeared first on Unit 42.

P0
2026-08-21 20:12 UTC
Vendor Research

CVE-2026-77811 - Stored Cross-Site Scripting via Integration Template Asset in OpenSearch Dashboards

AWS Security Bulletins · aws@amazon.com · indexed 2026-08-21 20:20 UTC

Bulletin ID: 2026-088-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/21/2026 13:00 PM PDT Description: Amazon OpenSearch Service is a managed service that makes it easy to deploy, operate, and scale OpenSearch clusters. We identified CVE-2026-77811, a stored cross-site scripting issue in the dashboards-observability plugin in OpenSearch Dashboards. Improper input validation in the integrations static file endpoint allows a remote authenticated actor with write …

Cloud SecurityVulnerabilitiesCVE-2026-77811
P5
2026-08-21 19:42 UTC
Vendor Research

CVE-2026-77810 - Issue with Athena Federated Query Neptune Connector

AWS Security Bulletins · aws@amazon.com · indexed 2026-08-21 20:00 UTC

Bulletin ID: 2026-087-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/21/2026 12:30 PM PDT Description: Amazon Athena is a serverless, interactive query service that lets you analyze data directly in Amazon S3 using standard SQL. Athena Query Federation is a feature that allows you to connect to data sources outside of Amazon S3 like DynamoDB, Azure Synapse, and custom connectors using standard SQL syntax. These connectors are open source and deployed to the Ath…

Cloud SecurityVulnerabilitiesCVE-2026-77810
P5
2026-08-21 18:53 UTC
Security Journalism

14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-21 20:30 UTC

Cybersecurity researchers have discovered a set of trojanized npm packages that masquerade as working calendar and streak utilities but are engineered to stealthily deliver an artificial intelligence (AI)-powered Linux implant dubbed RedC2 4.0. "When the module loads, it locates the bundled binary, marks it executable, and launches it as a detached background process," TrendAI, Trend Micro's

AI SecurityLinuxMalwareSecurity Research
P0
2026-08-21 18:03 UTC
Other

Your Shredded Visa Card May Still Work at the Checkout

Security Affairs · Pierluigi Paganini · indexed 2026-08-21 18:45 UTC

UMass Amherst researchers showed expired Visa contactless cards can make real purchases by exploiting an unsigned expiry field in Visa’s EMV kernel. Researchers at the University of Massachusetts Amherst demonstrated at USENIX Security 2026 in Baltimore that expired Visa contactless credit cards can complete real purchases, including transactions at live retail and grocery merchants, by […]

Linux
P0
2026-08-21 17:59 UTC
Vendor Research

Issue with FreeRTOS-Kernel - CVE-2026-77234, CVE-2026-77235, CVE-2026-77236, CVE-2026-77237

AWS Security Bulletins · aws@amazon.com · indexed 2026-08-21 18:10 UTC

Bulletin ID: 2026-086-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/21/2026 10:30 AM PDT Description: FreeRTOS-Kernel is a real-time operating system kernel for microcontrollers and small microprocessors. AWS identified four issues with FreeRTOS-Kernel, affecting multiple versions. - CVE-2026-77234: This issue affects configurations that use the FreeRTOS MPU together with software timers; applications that do not use the FreeRTOS MPU are not affected. - CVE-20…

Cloud SecurityLinuxVulnerabilitiesCVE-2026-77234CVE-2026-77235CVE-2026-77236CVE-2026-77237
P5
2026-08-21 17:36 UTC
Security Journalism

OWASP Flags Top AI Skill Risks in New Security Blueprint

Dark Reading · Robert Lemos · indexed 2026-08-21 17:45 UTC

The Open Worldwide Application Security Project has a brand-new top 10 security list tailored for the modern era, and it debuts a Universal Skill Format to add consistency and security to the AI add-ons.

P0
2026-08-21 16:54 UTC
Vendor Research

Cisco Crosswork Security Hardening Release: August 2026

Cisco Security Advisories · indexed 2026-08-19 16:10 UTC

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. These vulnerabilities were found during internal testing and are not known to be actively exploited. To assist customers in patching and to streamline the disclosure process, Cisco has grouped these issues by …

VulnerabilitiesCVE-2026-20030CVE-2026-20357CVE-2026-20358CVE-2026-20359
P30
2026-08-21 15:52 UTC
Security Journalism

Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-21 16:40 UTC

Check Point Research has disclosed a technique that uses Microsoft Defender's own legitimately signed boot-time remediation driver to perform arbitrary kernel-level file and registry operations on Windows systems ranging from Windows 7 through Windows 11 25H2, with no software flaw exploited and no driver imported from outside the machine. The driver, BTR.sys (Boot Time Removal Tool), is a

LinuxMicrosoft
P0
2026-08-21 15:41 UTC
Security Journalism

Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-21 16:40 UTC

Cybersecurity researchers have flagged a new malware family that's specifically designed to infect Android-based vehicle head unit firmware developed by DoFun. Kaspersky, which discovered the threat in June 2026, said the end goal of the malware is to serve a multi-stage downloader to enable ad fraud and creation of a proxy botnet. "The malware spread through the built-in updaters of

CybercrimeMalwareMobile SecuritySecurity Research
P0
13 14 15 16 17