IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 1,263 matching records.
AUTO-POLL // 2026-09-04 18:35 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P9 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Sep 4

ACTIVE EXPLOITATION
P9
P9
COOL // 29 ARTICLES
THU
Sep 3

RANSOMWARE
P5
P5
COOL // 44 ARTICLES
WED
Sep 2

RANSOMWARE
P11
P11
WARM // 47 ARTICLES
TUE
Sep 1

RANSOMWARE
P6
P6
COOL // 43 ARTICLES
MON
Aug 31

RANSOMWARE
P1
P1
COOL // 37 ARTICLES
SUN
Aug 30

RANSOMWARE
P6
P6
COOL // 9 ARTICLES
SAT
Aug 29

RANSOMWARE
P9
P9
COOL // 8 ARTICLES
RESET
2026-08-20 11:26 UTC
Security Journalism

Manic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-20 13:15 UTC

A new Android threat codenamed Manic has been observed actively targeting Ukrainian banks, government and identity services, and messaging applications, as well as Russian and European financial institutions, global fintech and cryptocurrency services, and military-focused communications. "Manic sits at the intersection of Android banking malware and mobile spyware, combining financial-fraud

CybercrimeMalwareMobile Security
P0
2026-08-20 11:05 UTC
Security Journalism

NASA AIT-GUI Flaws Could Let Unauthenticated Attackers Issue Spacecraft Commands

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-20 11:15 UTC

Security researchers at Cycode have disclosed a chain of flaws in AIT-GUI, the browser-based operator console for NASA/JPL's open-source AMMOS Instrument Toolkit, that allow an unauthenticated attacker to issue arbitrary commands to the software's spacecraft and instrument command bus. The chain, tracked as GHSA-p9r8-2q67-fp86 and rated 9.4 on the CVSS v3.1 scoring system, impacts AIT-GUI

Cloud SecuritySecurity ResearchVulnerabilities
P0
2026-08-20 10:38 UTC
Security Journalism

ToxicPanda 2.0 and GoldDigger Expand Android Banking Attacks with On-Device Fraud

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-20 11:15 UTC

Cybersecurity researchers have shed light on an updated version of ToxicPanda (aka TgToxic) that comes with "significant enhancements," including a set of 167 remote commands and expands its targeting footprint globally. Zimperium zLabs, in a Wednesday report, said the Android malware also features a PIN harvesting workflow targeting more than 140 banking and cryptocurrency applications.

CybercrimeMalwareMobile SecuritySecurity Research
P0
2026-08-20 10:00 UTC
Vendor Research

UAT-10147 deploys SPECTRE: A cross-platform implant with Linux rootkit and BYOVD capabilities

Cisco Talos Intelligence Blog · Joey Chen · indexed 2026-08-20 10:15 UTC

The newly identified SPECTRE implant represents an evolution in commodity intrusion tooling, integrating cross-platform C2 operations, process injection, credential theft, anti-analysis protections, and kernel-level endpoint detection and response (EDR) bypass functionality.

LinuxMalwarePhishing
P0
2026-08-20 10:00 UTC
Vendor Research

UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations

Cisco Talos Intelligence Blog · Joey Chen · indexed 2026-08-20 10:15 UTC

Cisco Talos discovered a Chinese-speaking cybercrime group, tracked as UAT-10147, that targets a wide range of vulnerable web servers. This is an overview of the campaign, examining the countries affected, potential impact of BadIIS infections, the attack chain, and post-compromise tactics.

Cybercrime
P0
2026-08-20 10:00 UTC
Vendor Research

Identity Abuse Through Trusted Communication Channels

Palo Alto Networks Unit 42 · Bill Batchelor · indexed 2026-08-20 10:05 UTC

Unit 42 details how attackers exploit enterprise collaboration tools for identity phishing and credential theft. Discover key defense strategies. The post Identity Abuse Through Trusted Communication Channels appeared first on Unit 42.

Phishing
P0
2026-08-20 08:55 UTC
Other

U.S. CISA adds an MLflow flaw to its Known Exploited Vulnerabilities catalog

Security Affairs · Pierluigi Paganini · indexed 2026-08-20 09:45 UTC

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds an MLflow vulnerability to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Progress LoadMaster vulnerability, tracked as CVE-2026-64849 (CVSS score of 9.3), to its Known Exploited Vulnerabilities (KEV) catalog. CVE-2026-64849 is a critical server-side request forgery (SSRF) vulnerability in MLflow, a […]

VulnerabilitiesCVE-2026-64849
P35
2026-08-20 08:42 UTC
Security Journalism

40 Malicious Firefox Extensions Pose as Web3 Products to Steal Wallet Secrets

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-20 11:15 UTC

A set of 40 Mozilla Firefox extensions has been found to engage in cryptocurrency wallet theft by masquerading as OKX, Rabby Wallet, TronLink, and other Web3 products. According to the Socket Threat Research team, the extensions are part of a broader set of 77 browser add-ons that share source code and infrastructure overlaps. The campaign, dubbed Offside Wallet Theft Factory, is believed to

P0
2026-08-20 08:36 UTC
Other

US Indicts 17 Iranians Over Years-Long Cyber Espionage Campaign

Security Affairs · Pierluigi Paganini · indexed 2026-08-20 09:45 UTC

The US charged 17 Iranians over a years-long hacking campaign that stole 31TB from universities, companies and government agencies worldwide. Eight years after the original indictment first went public, US prosecutors just added eight more names to the list. The Justice Department unsealed a superseding indictment this week charging 17 members of the Mabna Institute, […]

APT / Nation-State
P0
2026-08-20 07:20 UTC
Other

StopAndProtect Turns 2,000 Hacked WordPress Sites Into a Criminal Network

Security Affairs · Pierluigi Paganini · indexed 2026-08-20 07:30 UTC

StopAndProtect turned nearly 2,000 hacked WordPress sites into a criminal network for malware delivery, data theft, surveillance and ransomware. Check Point Research uncovered a cybercrime operation, dubbed StopAndProtect, that has turned thousands of hacked WordPress websites into a shared platform for malware delivery, data theft, surveillance and ransomware. The operation is a good reminder that […]

CybercrimeMalwareRansomware
P15
2026-08-20 06:51 UTC
Security Journalism

Microsoft says August Windows updates may cause gaming issues

BleepingComputer · Sergiu Gatlan · indexed 2026-08-20 06:55 UTC

Microsoft is investigating a potential issue with the August 2026 updates that may prevent some games from launching or cause them to crash on affected Windows 11 systems. [...]

Microsoft
P0
2026-08-20 06:04 UTC
Security Journalism

Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-20 06:15 UTC

Cybersecurity researchers have disclosed details of a critical flaw in the Elementor Pro WordPress plugin that, if successfully exploited, could lead to remote code execution. The vulnerability, tracked as CVE-2026-32475, carries a CVSS score of 9.0 out of 10.0. It has been described as a case of unrestricted upload of a file with a dangerous type. "The flaw lives in the Forms module's File

Security ResearchVulnerabilitiesCVE-2026-32475
P30
2026-08-20 00:20 UTC
Security Journalism

OpenAI confirms ChatGPT is down as logins and signups fail

BleepingComputer · Mayank Parmar · indexed 2026-08-20 00:25 UTC

ChatGPT is experiencing a major outage, and users are unable to sign in, create accounts, or load chats, including previous conversations. [...]

P0
2026-08-19 20:59 UTC
Security Journalism

Rogue ransomware affiliate poses as recovery firm to steal payments

BleepingComputer · Lawrence Abrams · indexed 2026-08-19 22:15 UTC

A suspected ransomware affiliate is posing as a ransomware recovery service called "Ransom Busters," contacting the victims before the attacks become public and claiming to be able to provide decryption keys and delete stolen data for a fee. [...]

Data BreachesRansomware
P15
2026-08-19 20:53 UTC
Security Journalism

Sakura Internet hack exposes data of up to 1.36 million accounts

BleepingComputer · Bill Toulas · indexed 2026-08-19 20:55 UTC

Japanese cloud and data center service provider Sakura Internet disclosed that hackers accessed its sales management system, where customer contract and membership information is stored. [...]

P0
2026-08-19 20:32 UTC
Security Journalism

No-Filter 'Kriminal' AI Platform Raises Cybercrime Concerns

Dark Reading · Alexander Culafi · indexed 2026-08-19 21:00 UTC

The AI company officially forbids illicit use, while offering guardrail-free social engineering, offensive cybercrime, and OSINT scanning to anyone with a bit of cryptocurrency.

Cybercrime
P0
2026-08-19 19:54 UTC
Security Journalism

Agentic AI Presents New Insider Threat Model for Orgs

Dark Reading · indexed 2026-08-20 11:10 UTC

Katie Moussouris of Luta Security talks with the Dark Reading News Desk about how enterprises will now need to monitor risks posed by their own agents in the wake of the recent Hugging Face attack.

P0
2026-08-19 19:02 UTC
Security Journalism

Cloudflare Workers Spectre Attack Leaks JWT From Co-Located Worker at 12 Bits/Second

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-19 19:55 UTC

Cybersecurity researchers have disclosed details of a remote Spectre attack against Cloudflare Workers that leaked a JSON Web Token (JWT) from a co-located Worker in the production environment at up to 12 bits per second, 360 times the rate of an earlier attack demonstrated in 2021. The end-to-end experiment used an attacker Worker and a victim Worker controlled by the researchers,

Security Research
P0
2026-08-19 18:10 UTC
Security Journalism

Electronic health record company CareCloud says 3.7 million people affected by breach

The Record · indexed 2026-08-19 18:15 UTC

Healthcare software firm CareCloud filed documents with the Department of Health and Human Services confirming that 3,756,469 people had information leaked after a hacker spent eight hours in one of the company’s electronic health record environments.

P0
2026-08-19 18:09 UTC
Security Journalism

Hackers compromise 14,500 Dahua web cameras in 35-day campaign

BleepingComputer · Bill Toulas · indexed 2026-08-19 18:20 UTC

In a large-scale campaign that researchers dubbed CameraSwarm, hackers compromised more than 14,500 Dahua IP cameras mostly in Ukraine and Russia. [...]

P0
2026-08-19 18:06 UTC
Security Journalism

OpenAI Pauses Frontier RL Training as It Tightens Defenses Against Unsafe AI Behavior

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-19 19:55 UTC

OpenAI on Tuesday revealed that it paused reinforcement learning (RL) training for its latest artificial intelligence (AI) models for two weeks while it shored up additional defenses and increased the scope of its monitoring to avert another Hugging Face-like incident. "As models become more capable, the risks associated with developing and testing them internally also grow," the AI company

AI Security
P0
19 20 21 22 23