IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 1,063 matching records.
AUTO-POLL // 2026-08-30 19:35 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P6 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Aug 30

RANSOMWARE
P6
P6
COOL // 9 ARTICLES
SAT
Aug 29

RANSOMWARE
P9
P9
COOL // 8 ARTICLES
FRI
Aug 28

RANSOMWARE
P8
P8
COOL // 47 ARTICLES
THU
Aug 27

RANSOMWARE
P4
P4
COOL // 48 ARTICLES
WED
Aug 26

RANSOMWARE
P4
P4
COOL // 46 ARTICLES
TUE
Aug 25

ACTIVE EXPLOITATION
P4
P4
COOL // 40 ARTICLES
MON
Aug 24

RANSOMWARE
P4
P4
COOL // 34 ARTICLES
RESET
2026-08-14 21:27 UTC
Vendor Research

Metasploit Wrap Up: Lot of summer shells and fit http profiles

Rapid7 · Rapid7 Labs · indexed 2026-08-15 18:55 UTC

This wrap-up brings a full-on shell parade. Thirteen shiny new modules landed, starting with a buffet of RCEs. WordPress WP2Shell, Ghost CMS, Joomla JCE, Langflow, OpenCATS, Pterodactyl Panel, SonicWall SMA1000, Ray Dashboard, a Pix-for-WooCommerce, and for those who like their exploits closer to the bare-metal, the Fragnesia Linux kernel LPE (CVE-2026-46300). Metasploit also got the glow-up of the summer with the new http malleable profiles, MCP functionality and linux multi fetch payloads (mo…

LinuxMicrosoftVulnerabilitiesCVE-2025-49132CVE-2026-15409CVE-2026-27760CVE-2026-29053CVE-2026-3891CVE-2026-46300CVE-2026-48907CVE-2026-60137CVE-2026-63030
P20
2026-08-14 19:24 UTC
Security Journalism

Mission-Driven Security: Inside a Global Bank's Defense

Dark Reading · Kristina Beek · indexed 2026-08-15 18:55 UTC

In this video interview, Standard Chartered's group CISO shares insights on transitioning from technical roles to strategic leadership, the importance of business-savvy security executives, and how AI is reshaping both defensive capabilities and adversarial tactics in banking.

P0
2026-08-14 18:48 UTC
Security Journalism

Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-17 10:50 UTC

Threat actors are acquiring expired domains to inherit website traffic and reputation to redirect victims to scams and malware on a large scale. DNS threat intelligence firm Infoblox has given the name dropcatch domains to those that get a second chance, where an expired domain becomes available for registration and is then snapped up by another party. During the first half of 2026, 50,400

MalwareThreat ActorsThreat Intelligence
P0
2026-08-14 17:32 UTC
Security Journalism

Amid AI-Driven Bug-Hunt Tsunami, NIST Looks to … AI

Dark Reading · Robert Lemos · indexed 2026-08-15 18:55 UTC

Driven by AI-augmented research and scanning, vulnerability volumes continue to surge, driving the National Institute of Standards and Technology to ask whether AI could be the answer.

Vulnerabilities
P0
2026-08-14 17:19 UTC
Security Journalism

IAM Compliance Requirements and Best Practices

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-17 10:50 UTC

IAM compliance is the practice of demonstrating that identity and access controls are not only documented but actually enforced across users, applications, infrastructure, and non-human identities. This guide explains what IAM compliance requires, which regulations matter, and how organizations move from periodic access reviews toward continuous, evidence-backed verification that auditors can

P0
2026-08-14 17:09 UTC
Other

Apple warned hundreds of users of mercenary spyware attacks

Security Affairs · Pierluigi Paganini · indexed 2026-08-16 18:35 UTC

Apple warns users of credible, targeted attacks and urges immediate verification, stronger protections, and expert assistance. Apple has sent a new round of threat notifications to users it believes may have been singled out by mercenary spyware. The company told TechCrunch the latest alerts reached people in 110 countries, adding to notifications it has already […]

Apple
P0
2026-08-14 14:00 UTC
Security Journalism

The Modern Attack Chain: Rethinking Google Workspace Security in the Age of AI

BleepingComputer · Sponsored by Material Security · indexed 2026-08-15 14:33 UTC

Google Workspace attacks do not always begin with phishing. Stolen OAuth tokens can provide another path into Gmail, Drive, and connected systems. Material Security explains why organizations need defenses that cover the entire Workspace attack chain. [...]

Phishing
P0
2026-08-14 14:00 UTC
Security Journalism

What Boards Need to Know About Tech Risk

Dark Reading · Chris Drumgoole · indexed 2026-08-15 18:55 UTC

Why do so many boards underestimate technology risk until it becomes a crisis?

P0
2026-08-14 13:08 UTC
Security Journalism

Mustang Panda Adds Signed Windows Rootkit to CoolClient Backdoor for Stealth

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-17 10:50 UTC

The threat actor known as HoneyMyte (aka Mustang Panda) has been observed deploying an updated version of the CoolClient backdoor with a signed Windows kernel-mode rootkit that can hide and protect malicious processes, files, registry objects, and command-and-control (C2) network information. Russian cybersecurity vendor Kaspersky said it identified victims in Myanmar, Mongolia, Pakistan,

LinuxMalwareMicrosoftThreat Actors
P0
2026-08-14 12:17 UTC
Security Journalism

Cyera's Oasis Security Buy Is All About AI Agent Control

Dark Reading · Jeffrey Schwartz · indexed 2026-08-15 18:55 UTC

The $1 billion deal aims to converge data security and identity into a single control plane for agents, with privileged access redefined around business context rather than static roles.

AI Security
P0
2026-08-14 11:24 UTC
Independent Research

Who’s Tracking You? Use This New Service to Find Out

Krebs on Security · BrianKrebs · indexed 2026-08-15 14:33 UTC

It can be daunting to determine who's responsible for showing ads on the websites we visit, or who's harvesting data from the mobile apps we use every day. That information is already semi-public, but it is not easily parsed and traditionally much of it has remained walled away in the hands of large advertising platforms. Not anymore: A powerful and free new service called DecryptAds scrapes and correlates this adtech data and makes it simple to quickly learn a great deal about the entities tha…

P0
2026-08-14 11:07 UTC
Security Journalism

Chrome DevTools Technique Enables Authenticated Session Hijacking in Live Windows Browsers

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-17 10:50 UTC

Cybersecurity researchers have detailed a post-exploitation technique that enables the Chrome DevTools Protocol (CDP) inside a running Google Chrome or Microsoft Edge process on Windows, allowing an operator to access cookies, saved data, and authenticated browser sessions. The technique assumes that an operator already has code execution on the Windows host and does not involve

MicrosoftSecurity Research
P0
2026-08-14 10:57 UTC
Security Journalism

CTM360 Uncovers Over 3,000 Recruitment Phishing URLs Using Browser-in-the-Browser (BitB) Credential Traps

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-17 10:50 UTC

Cybersecurity researchers have uncovered a large-scale, global recruitment-themed phishing campaign that uses fake interview scheduling pages and Browser-in-the-Browser (BitB) windows to steal Google and Facebook credentials and, in more advanced cases, relay multi-factor authentication (MFA) prompts in real time. CTM360, which detailed the activity in a new report titled RecruitTrap, said it

MicrosoftPhishingSecurity Research
P0
2026-08-14 10:44 UTC
Security Journalism

Apple Warns Users in 110 Countries They May Be Targets of Mercenary Spyware

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-17 10:50 UTC

Apple on Thursday sent a fresh batch of notifications to customers whom it suspects may have been targeted by mercenary spyware attacks. In a statement shared with TechCrunch, the iPhone maker said it alerted an unspecified number of users targeted in 110 countries and that it has notified customers in over 150 countries to date. Apple began sending threat notifications to users in late 2021.

Apple
P0
2026-08-14 09:38 UTC
Security Journalism

Trump Memo Paves Way for U.S. Firms to Hack and Disrupt Foreign Crime Groups

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-17 10:50 UTC

A new White House memo signed by U.S. President Donald Trump has instructed the National Coordination Center (NCC) to establish a program that would allow private sector companies to take advantage of their "innovative capabilities" to break into foreign Transnational Criminal Organizations (TCOs) and disrupt them. "By partnering with vetted United States companies subject to the direction and

P0
2026-08-14 08:27 UTC
Security Journalism

Data analyst sent to prison for stealing data, extorting employer

BleepingComputer · Sergiu Gatlan · indexed 2026-08-15 14:33 UTC

A former data analyst contractor for Brightly Software has been sentenced to two years in prison for targeting his employer in a $2.5 million extortion scheme. [...]

P0
2026-08-14 07:54 UTC
Security Journalism

China-Linked Jewelbug Uses XG-Web for Government Espionage and Crypto Fraud

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-17 10:50 UTC

The China-linked threat actor known as Jewelbug has been observed carrying out cyber espionage operations targeting governments and militaries, while simultaneously engaging in cryptocurrency fraud. "Both missions are administered from a single control panel, XG-Web, a browser-centric remote-access and information-stealing framework that turns a victim's browser into a full remote-control

APT / Nation-StateCybercrimeThreat Actors
P0
2026-08-13 21:23 UTC
Vendor Research

AWS Certificate Manager will discontinue email validation to prove domain validation for certificates

AWS Security Blog · Adam Aboudi · indexed 2026-08-15 18:55 UTC

Today, we’re announcing that AWS Certificate Manager (ACM) will discontinue support for email-validated public certificates by September 30, 2027. If you use email validation for your ACM public certificates, you need to migrate to DNS validation before that date. This change aligns with the Certification Authority/Browser (CA/B) Forum’s industry-wide deprecation of email-based domain validation and […]

Cloud Security
P0
18 19 20 21 22