IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 1,262 matching records.
AUTO-POLL // 2026-09-04 18:30 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P9 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Sep 4

ACTIVE EXPLOITATION
P9
P9
COOL // 28 ARTICLES
THU
Sep 3

RANSOMWARE
P5
P5
COOL // 44 ARTICLES
WED
Sep 2

RANSOMWARE
P11
P11
WARM // 47 ARTICLES
TUE
Sep 1

RANSOMWARE
P6
P6
COOL // 43 ARTICLES
MON
Aug 31

RANSOMWARE
P1
P1
COOL // 37 ARTICLES
SUN
Aug 30

RANSOMWARE
P6
P6
COOL // 9 ARTICLES
SAT
Aug 29

RANSOMWARE
P9
P9
COOL // 8 ARTICLES
RESET
2026-08-20 19:59 UTC
Security Journalism

Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-20 20:30 UTC

Three distinct suspected Russian cyber espionage threat clusters have been observed leveraging legitimate authentication flows to single out individuals working in academia, aerospace and defense, governments, and think tanks across Europe, as well as academia and think tanks within the U.S. These clusters include UNC6293, UNC7005, and UNC5976. "These clusters engage in persistent, adaptive

APT / Nation-State
P0
2026-08-20 19:11 UTC
Security Journalism

What We Missed: Delta Flight Disrupted With Wi-Fi Hack

Dark Reading · Rob Wright, Alexander Culafi · indexed 2026-08-20 19:45 UTC

In this video, Dark Reading editors discuss some of the news they didn't get a chance to cover, including some scary airplane security risks and the US government's newest "hack back" strategy.

P0
2026-08-20 18:40 UTC
Vendor Research

AWS Network Firewall now supports rule hit count

AWS Security Blog · Preetkumar Shah · indexed 2026-08-20 18:45 UTC

As firewall rule sets grow in complexity, security teams face a common challenge: manual log analysis is used to determine which rules are actively matching traffic and which are consuming capacity without being triggered. This lack of visibility creates operational and compliance gaps. Organizations with governance policies that require removal of dormant rules after a […]

Cloud SecurityNetwork Security
P0
2026-08-20 18:03 UTC
Other

Manic: The Android Malware That Exfiltrates Data Even When the Phone Is Offline

Security Affairs · Pierluigi Paganini · indexed 2026-08-20 18:35 UTC

Manic Android malware combines banking fraud and spyware, using a Bluetooth relay to steal data even when devices are offline. ThreatFabric’s Mobile Threat Intelligence team has identified a new Android malware, dubbed Manic, which has been active in the wild since at least February 2026. The researchers state that the malware is still under development […]

CybercrimeMalwareMobile SecurityThreat Intelligence
P20
2026-08-20 18:00 UTC
Vendor Research

Is Cyber missing the Marque?

Cisco Talos Intelligence Blog · Mick Baccio · indexed 2026-08-20 18:10 UTC

In this week's newsletter, new author Mick Baccio introduces himself and explores the operational and security implications of the new White House memorandum regarding private sector participation in government-authorized offensive cyber operations.

P0
2026-08-20 17:53 UTC
Security Journalism

Hackers poison arrayref Rust crate to push infostealer malware

BleepingComputer · Bill Toulas · indexed 2026-08-20 18:00 UTC

Hackers compromised the maintainer account behind the widely used Rust crate arrayref to introduce malware that executed on developers' systems during compilation. [...]

Malware
P0
2026-08-20 17:39 UTC
Security Journalism

N-able Bug Exposes Password Vault Master Keys

Dark Reading · Nate Nelson · indexed 2026-08-20 17:50 UTC

The popular "Passportal" password manager, favored by MSPs and SMBs, remains risky even after its patch, thanks to its cloud-based design. Should these products stay away from the cloud entirely?

P0
2026-08-20 17:36 UTC
Other

NSA, CISA, FBI, DOE, and EPA Warn of Active AI-Assisted Attacks on Siemens S7 PLCs

Security Affairs · Pierluigi Paganini · indexed 2026-08-20 18:35 UTC

NSA, CISA, FBI, DOE, and EPA warn of active AI-assisted attacks against Siemens S7 PLCs across US critical infrastructure sectors. Five U.S. federal agencies issued a joint advisory this week warning of an active hacking campaign against Siemens S7 Series programmable logic controllers. The advisory, CISA AA26-231A, is co-signed by NSA, FBI, DOE, and EPA […]

Law Enforcement
P0
2026-08-20 17:33 UTC
Security Journalism

Senators press TikTok over withholding of safety features for some users

The Record · indexed 2026-08-20 17:50 UTC

In a letter on Wednesday, Sens. Marsha Blackburn (R-TN) and Richard Blumenthal (D-CT) criticized the company for having “knowingly withheld a critical safety measure for millions of American users."

P0
2026-08-20 17:32 UTC
Security Journalism

Money and Mindset: The Two Biggest Roadblocks to Cyber Policing

Dark Reading · Arielle Waldman · indexed 2026-08-20 18:35 UTC

Law enforcement training is falling behind the volume and rapid evolution of cybercrimes. Officers really only need to learn the basics, but lack of focus and budget hinder progress.

Cybercrime
P0
2026-08-20 17:23 UTC
Security Journalism

ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit, and More

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-20 18:50 UTC

A lot of this week’s trouble starts with something trusted doing exactly what it was allowed to do. Signed drivers get turned against defenses. Legitimate apps help malware blend in. A weak header check opens a path to code execution. Elsewhere, exposed systems, old bugs, odd hiding tricks, and AI-assisted exploit research keep lowering the effort needed to cause damage. Nothing here needs

Malware
P0
2026-08-20 16:59 UTC
Security Journalism

AI-Generated Exploit Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructure

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-20 17:25 UTC

The U.S. government on Wednesday warned of an "active threat" targeting critical infrastructure organizations in the country using artificial intelligence (AI)-generated exploit scripts. The activity is targeting Siemens S7 SeriesProgrammable Logic Controllers (PLCs) to conduct reconnaissance and capability development using AI-generated scripts disguised as legitimate monitoring tools. That

AI Security
P0
2026-08-20 14:36 UTC
Security Journalism

New Cryptographic Context Injection Attack Could Let Web Pages Steal Grok Chat Data

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-20 16:10 UTC

Adversa AI has disclosed an attack technique that it says can cause xAI's Grok chatbot to send a user's name, approximate location, subscription tier, and the prompts from the ongoing conversation to an attacker-controlled server after the user asks it to summarize an ordinary web page. The AI security company, which has codenamed the technique "Cryptographic Context Injection," said the

AI Security
P0
2026-08-20 14:01 UTC
Vendor Research

Frequently asked questions about the active threat to Siemens S7 Series PLCs

Tenable Cyber Exposure Alerts · Research Special Operations · indexed 2026-08-20 14:10 UTC

A joint cybersecurity advisory released by multiple U.S. government agencies warns that threat actors are using AI-generated exploitation scripts to target exposed Siemens S7 Series PLCs across critical infrastructure sectors.Key TakeawaysUnattributed threat actors are exploiting known weaknesses and unnecessary internet exposure to conduct reconnaissance and possible pre-positioning for future disruptive attacks against Siemens S7 Series PLCs.The attackers are leveraging AI to build and refine…

DFIRICS / OTLaw EnforcementMicrosoftThreat ActorsVulnerabilities
P25
2026-08-20 14:01 UTC
Security Journalism

How MSPs can catch phishing attacks email filters miss

BleepingComputer · Sponsored by Kaseya · indexed 2026-08-20 14:20 UTC

AI is making phishing attacks more personalized, convincing, and difficult for traditional email filters to detect. Kaseya explains how MSPs can monitor identity, email, and endpoint activity to detect and contain attacks that make it past the inbox. [...]

Phishing
P0
2026-08-20 14:00 UTC
Vendor Research

Going with the Flow(s): Distinct Clusters Target Individuals of Interest to Russia

Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-08-20 14:40 UTC

Written by: Gabby Roncone, Wesley Shields Overview Google Threat Intelligence Group (GTIG) is tracking three distinct suspected Russian cyber espionage threat clusters abusing legitimate authentication flows to target individuals working in academia, aerospace and defense, governments and think tanks across Europe, as well as academia and think tanks within the United States. Examples of these techniques can be found in our previous blog on UNC6293’s phishing operations. We now track an additio…

APT / Nation-StateMalwareMicrosoftPhishingThreat Intelligence
P0
2026-08-20 13:48 UTC
Security Journalism

Isolated-vm Flaw Lets Sandboxed JavaScript Escape to Host for Potential RCE

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-20 14:30 UTC

Cybersecurity researchers have disclosed a critical security flaw in isolated-vm, a popular open-source sandbox with more than 2,900 stars and 190 forks on GitHub, that could allow attackers to escape the confines of the isolated environment. The vulnerability ("GHSA-864f-rcv7-6rh4"), which has yet to be assigned a CVE identifier, impacts all versions of the library before and including 7.0.0.

Security ResearchVulnerabilities
P15
2026-08-20 13:35 UTC
Security Journalism

Critical NetScaler Flaw Can Bypass Authentication on Certain Gateway and AAA Servers

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-20 14:30 UTC

Citrix has released updates to address two security flaws impacting NetScaler ADC and NetScaler Gateway deployments, including a critical-severity authentication bypass vulnerability. According to the cloud computing and virtualization technology company, the issues affect customer-managed NetScaler ADC and NetScaler Gateway, including certain FIPS and NDcPP builds, as well as SecurAccess

Cloud SecurityVulnerabilities
P10
2026-08-20 13:24 UTC
Security Journalism

Attackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-20 14:30 UTC

A now-patched security flaw impacting Zimbra Collaboration (ZCS) has come under active exploitation in the wild, according to the Polish Computer Emergency Response Team (CERT Polska). The vulnerability in question is CVE-2026-73570 (CVSS score: 8.9), which refers to a case of command injection that can lead to remote code execution. "A remote code execution vulnerability exists in Zimbra

VulnerabilitiesCVE-2026-73570
P40
2026-08-20 12:45 UTC
Community

Using Microsoft Graph and Powershell to Mine for Information - Stale Accounts and Licenses, (Thu, Aug 20th)

SANS Internet Storm Center · indexed 2026-08-20 12:00 UTC

Microsoft Graph is a newer API that is meant to replace several others.  OK, it's at version 2.3.9, so it's not all that new, but it's new enough that lots of folks (and commercial tools) aren't using it yet.   It allows you to Get and Set info from/to M365, Entra Users and Entra managed machines for starters.  Let's dig in!

Microsoft
P0
2026-08-20 12:01 UTC
Security Journalism

Zombie Card Attack Can Revive Expired Visa Cards for Contactless Payments

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-20 13:15 UTC

Researchers at the University of Massachusetts Amherst have demonstrated an attack that revives expired Visa contactless credit cards for real in-store purchases by rewriting the expiration date a point-of-sale (POS) terminal reads over near-field communication (NFC), without breaking any of the card's cryptography. The attack, which the researchers named "Zombie Card," requires physical

P0
2026-08-20 11:45 UTC
Security Journalism

Why "Shady AI" is Security's Next Big Governance Problem

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-20 13:15 UTC

In March 2026, an internal AI agent at Meta triggered a “Sev 1” incident after sensitive company and user data was exposed to employees who weren’t authorized to access it. The incident began when a Meta employee posted a technical question on an internal forum. An engineer used an approved AI agent to analyze it, but the agent posted its response publicly without approval. The employee

AI Security
P0
2026-08-20 11:39 UTC
Security Journalism

CDN Tsunami Attack Abuses HTTP/3 Translation for Up to 350x DoS Amplification

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-20 13:15 UTC

Cybersecurity researchers have disclosed two denial-of-service (DoS) attacks that exploit how major content delivery networks (CDNs) convert client-facing HTTP/3 traffic into HTTP/1.1 requests to the websites they front, amplifying a low-bandwidth request stream by up to 350x against the origin server. The attacks, collectively named "CDN Tsunami," were evaluated against Alibaba, Baidu,

Security Research
P0
2026-08-20 11:26 UTC
Security Journalism

Manic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-20 13:15 UTC

A new Android threat codenamed Manic has been observed actively targeting Ukrainian banks, government and identity services, and messaging applications, as well as Russian and European financial institutions, global fintech and cryptocurrency services, and military-focused communications. "Manic sits at the intersection of Android banking malware and mobile spyware, combining financial-fraud

CybercrimeMalwareMobile Security
P0
18 19 20 21 22