IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 1,241 matching records.
AUTO-POLL // 2026-09-04 09:50 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
WARM
COOL WARM ELEVATED HOT CRITICAL
P16 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Sep 4

ACTIVE EXPLOITATION
P16
P16
WARM // 7 ARTICLES
THU
Sep 3

RANSOMWARE
P5
P5
COOL // 44 ARTICLES
WED
Sep 2

RANSOMWARE
P11
P11
WARM // 47 ARTICLES
TUE
Sep 1

RANSOMWARE
P6
P6
COOL // 43 ARTICLES
MON
Aug 31

RANSOMWARE
P1
P1
COOL // 37 ARTICLES
SUN
Aug 30

RANSOMWARE
P6
P6
COOL // 9 ARTICLES
SAT
Aug 29

RANSOMWARE
P9
P9
COOL // 8 ARTICLES
RESET
2026-09-03 14:39 UTC
Security Journalism

Thomson Reuters Court Software Breach May Have Exposed SSNs and Sealed Data

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-03 16:45 UTC

Thomson Reuters disclosed on Wednesday that an unauthorized party obtained files from C-Track, the court case management platform sold by its West Publishing Corporation unit, in March 2026, affecting courts in 11 U.S. states, the U.S. Virgin Islands, and Ontario, Canada. West Publishing said it discovered the activity on June 30, 2026. A subset of court records could contain individuals' names

P0
2026-09-03 14:38 UTC
Security Journalism

AI 'Machine Speed' Cuts 2-Week Attack Down to 10 Hours

Dark Reading · Elizabeth Montalbano · indexed 2026-09-03 15:00 UTC

The incident demonstrates how frontier AI agents can dramatically compress an attack timeline and coordinate a large-scale breach, according to researchers.

AI Security
P0
2026-09-03 13:50 UTC
Security Journalism

Your Employee’s Password Appeared in an Infostealer Log. Now What?

BleepingComputer · Sponsored by Flare · indexed 2026-09-03 14:00 UTC

Infostealers can expose far more than passwords, including authenticated sessions that may let attackers bypass MFA. Flare explains how defenders can prioritize compromised identities, determine whether stolen access is still usable, and respond before it leads to account takeover. [...]

MalwareMicrosoft
P0
2026-09-03 13:17 UTC
Other

412,000 The Town 2025 Ticket Buyers’ Data Hits the Dark Web

Security Affairs · Pierluigi Paganini · indexed 2026-09-03 14:00 UTC

412,000 The Town 2025 festival buyer records are being sold for $10,000, with Brazil’s data openly marketed for bank fraud, loans and SIM registration. A seller on a Russian-language data-trading forum listed what they’re calling a Ticketmaster database on September 2, claiming over 412,000 Latin American purchase records with a heavy concentration of Brazilian data. […]

CybercrimeMicrosoft
P0
2026-09-03 12:00 UTC
Security Journalism

US and Canadian court data exposed in Thomson Reuters breach

The Record · indexed 2026-09-03 12:15 UTC

Sealed court information and sensitive personal data were exposed in a breach of a Thomson Reuters records platform affecting courts in at least 12 U.S. states, the U.S. Virgin Islands and Canada.

P0
2026-09-03 12:00 UTC
Government

Cyber Brief 26-09 - August 2026

CERT-EU Threat Intelligence · indexed 2026-09-03 10:25 UTC

Cyber Briefs are monthly executive reports that aim to present an overview of the most relevant developments in cyber security, based exclusively on open sources, with a view to inform political leadership and senior management in its constituency. Additional information on any item in this Brief can be provided upon request. Cyber Briefs are TLP:CLEAR.

P0
2026-09-03 11:58 UTC
Security Journalism

US Becomes Top Target in RMM Phishing Campaign Spanning 46 Countries

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-03 12:45 UTC

An RMM phishing campaign initially associated with Canadian targeting due to its use of Canada Revenue Agency (CRA) tax forms as lures has turned out to be part of a broader campaign spanning 46 countries. Around 45% of observed activity was associated with the United States, making it the campaign's top geographic target. ANY.RUN research connected 601 cases to the wider operation, which uses

Phishing
P0
2026-09-03 11:02 UTC
Security Journalism

Plex warns users to patch security vulnerabilities immediately

BleepingComputer · Sergiu Gatlan · indexed 2026-09-03 11:15 UTC

Plex urged users this week to update their desktop clients and media servers immediately to patch multiple security vulnerabilities. [...]

P0
2026-09-03 10:43 UTC
Security Journalism

Attackers Turn Trusted Node.js Runtime Into Malware Delivery Tool in Targeted Attacks

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-03 11:30 UTC

Threat actors are leveraging the trusted Node.js JavaScript runtime in multiple cyber attacks as a way to deploy malicious payloads. According to a new report published by the Symantec Threat Hunter Team today, the attack method has been put to use in attacks targeting government departments, technology companies, and hotels since February 2026. "The technique's appeal is that node.exe (the

MalwareThreat Actors
P0
2026-09-03 10:36 UTC
Security Journalism

Shai-Hulud's Reach Just Grew to 469 Credential Locations. Here's What That Means

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-03 11:30 UTC

In early August, GitGuardian researchers found that a recent Shai-Hulud infostealer worm variant had evolved to scan for credentials across 469 locations across developer environments, Continuous Integration/Continuous Deployment (CI/CD) tooling, cloud configurations, and even AI tool configs. Earlier variants of the infostealer worm only checked 189 paths. The jump says a lot. Attackers have

Malware
P0
2026-09-03 10:00 UTC
Vendor Research

Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America

Palo Alto Networks Unit 42 · Reese Lewis and Sara McBroom · indexed 2026-09-03 10:20 UTC

Explore how attackers targeting Latin American entities use AI for data exfiltration and how basic OpSec errors allow defenders to disrupt operations. The post Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America appeared first on Unit 42.

Microsoft
P0
2026-09-03 09:52 UTC
Other

Chaotic Eclipse Releases Crowdstrike Falcon ZeroDay FalconFlank

Security Affairs · Pierluigi Paganini · indexed 2026-09-03 10:40 UTC

Chaotic Eclipse released FalconFlank, a PoC exploit for a Crowdstrike Falcon ZeroDay Elevation of Privileges Vulnerability Security researcher Chaotic Eclipse, also known as INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse, released a new zero-day exploit targeting Crowdstrike Falcon cybersecurity platform. The researcher named the exploit FalconFlank, it triggers a privilege escalation flaw. According to the researcher, FalconFlank abuses […]

Security ResearchVulnerabilities
P35
2026-09-03 08:55 UTC
Security Journalism

Microsoft Teams, Outlook fail to launch on ARM-based Windows PCs

BleepingComputer · Sergiu Gatlan · indexed 2026-09-03 09:05 UTC

Microsoft is working to fix a known issue that causes crashes and launch failures for Microsoft Teams and New Outlook users after installing updates released since the August 2026 Patch Tuesday. [...]

Microsoft
P0
2026-09-03 08:43 UTC
Security Journalism

Pegasus Zero-Click Spyware Exploit Infects Serbian Student Movement Member's iPhone

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-03 10:00 UTC

The iPhone belonging to a member of Serbia's student protest movement was infected with NSO Group's Pegasus spyware, according to new findings from the Citizen Lab in collaboration with the SHARE Foundation. "Our analysis confirmed that an iMessage zero-click exploit was used to infect the device with NSO Group's Pegasus spyware," the Citizen Lab said. "We found high-confidence indicators of

Apple
P0
2026-09-03 08:12 UTC
Other

2,000 Leaked Documents Reveal How Russia Turns Engineering Students Into GRU Cyber Operators

Security Affairs · Pierluigi Paganini · indexed 2026-09-03 08:20 UTC

2,000 leaked files expose Bauman University’s hidden Department No. 4, which trained GRU-linked hackers and propagandists linked to APT28 and Sandworm. Leaked Documents Expose Bauman University’s Hidden Department That Trained Hackers, Propagandists, and Malware Developers for the GRU More than 2,000 internal documents from Bauman Moscow State Technical University have been reviewed by an international […]

APT / Nation-StateMalware
P0
2026-09-03 06:26 UTC
Security Journalism

Researcher Releases FalconFlank PoC Showing Privilege Escalation in CrowdStrike Falcon

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-03 06:45 UTC

The security researcher known as Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has dropped a new zero-day dubbed FalconFlank, a proof-of-concept (PoC) for a privilege escalation flaw impacting Crowdstrike Falcon. "FalconFlank is a 0-day privilege escalation that abuses the office malicious macros remediation in CrowdStrike Falcon Sensor," the researcher said in

Security ResearchVulnerabilities
P35
2026-09-03 05:19 UTC
Security Journalism

CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-03 06:45 UTC

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added seven security flaws to its Known Exploited Vulnerabilities (KEV) catalog after they landed in attackers' crosshairs. The vulnerabilities are as follows - CVE-2026-83548 (CVSS score: 10.0) - A server-side request forgery vulnerability in SonicWall SMA 1000 Appliances that could allow a remote unauthenticated

Cloud SecurityVulnerabilitiesCVE-2026-83548
P35
2026-09-02 22:51 UTC
Vendor Research

Impersonating IT support: how threat actors turn a remote session into enterprise-wide access

Microsoft Security Blog · Microsoft Security Research, Sagar Patil, Arlette Umuhire Sangwa, Jesse Birch and Ravikant Tiwari · indexed 2026-09-03 00:10 UTC

Microsoft Threat Intelligence observed a human-operated intrusion campaign that abuses Microsoft Teams external collaboration to impersonate IT support, gain remote access, and deploy a Node.js-based implant. Learn how attackers move from social engineering to lateral movement using legitimate tools, and how Microsoft Defender helps detect and disrupt the activity. The post Impersonating IT support: how threat actors turn a remote session into enterprise-wide access appeared first on Microsoft …

MicrosoftThreat ActorsThreat Intelligence
P0
2026-09-02 21:31 UTC
Other

OpenAI Astra Brings Autonomous Zero-Day Exploitation to AI

Security Affairs · Pierluigi Paganini · indexed 2026-09-02 21:35 UTC

OpenAI says Astra can autonomously find zero-days and build exploits, marking its first model to reach the “Critical” cyber risk level. Astra is now officially OpenAI’s highest-risk cybersecurity model. In August, OpenAI said it “couldn’t rule out” that its upcoming model had reached the highest cybersecurity risk level in its Preparedness Framework. In a new […]

Vulnerabilities
P25
2026-09-02 20:36 UTC
Vendor Research

Managing identity source transition for AWS IAM Identity Center

AWS Security Blog · Xiaoxue Xu · indexed 2026-09-02 20:55 UTC

September 2, 2026: This post was republished to include Active Directory migration strategies and automation for permission sets. AWS IAM Identity Center manages user access to Amazon Web Services (AWS) resources, including both AWS accounts and applications. You can use IAM Identity Center to create and manage user identities within the Identity Center identity store […]

Cloud Security
P0
2026-09-02 20:32 UTC
Vendor Research

CVE-2026-84851- Uncontrolled recursion in the Ion reader in Amazon Ion-C before 1.1.6

AWS Security Bulletins · aws@amazon.com · indexed 2026-09-02 20:50 UTC

Bulletin ID: 2026-094-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/02/2026 13:30 AM PDT Description: Amazon Ion-C (ion-c) is the C implementation of the Amazon Ion data serialization format. It is distributed as an open-source library (amazon-ion/ion-c) that applications embed to read and write Ion text and binary data. We identified CVE-2026-84851, an uncontrolled recursion issue in versions before 1.1.6 that might allow a remote unauthenticated actor to cra…

Cloud SecurityVulnerabilitiesCVE-2026-84851
P5
2026-09-02 19:46 UTC
Security Journalism

AI Gives Cybercriminals a Dangerous Time Advantage

Dark Reading · Kristina Beek · indexed 2026-09-02 20:30 UTC

Former cybercriminal Brett Johnson provides a look inside the mind of a threat actor and discusses where AI provides the most value for attackers.

Threat Actors
P0
1 2 3 4