IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 1,063 matching records.
AUTO-POLL // 2026-08-30 20:55 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P6 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Aug 30

RANSOMWARE
P6
P6
COOL // 9 ARTICLES
SAT
Aug 29

RANSOMWARE
P9
P9
COOL // 8 ARTICLES
FRI
Aug 28

RANSOMWARE
P8
P8
COOL // 47 ARTICLES
THU
Aug 27

RANSOMWARE
P4
P4
COOL // 48 ARTICLES
WED
Aug 26

RANSOMWARE
P4
P4
COOL // 46 ARTICLES
TUE
Aug 25

ACTIVE EXPLOITATION
P4
P4
COOL // 40 ARTICLES
MON
Aug 24

RANSOMWARE
P4
P4
COOL // 34 ARTICLES
RESET
2026-08-11 16:39 UTC
Vendor Research

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access SSL VPN Denial of Service Vulnerability

Cisco Security Advisories · indexed 2026-08-15 14:33 UTC

A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to insufficient error checking when processing HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to the Remot…

Network SecurityVulnerabilitiesCVE-2026-20349
P5
2026-08-11 16:35 UTC
Security Journalism

DeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to Disrupt

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-15 14:33 UTC

The ransomware group known as DeadLock has been observed using decentralized infrastructure to facilitate victim communications and data leak operations in a bid to improve operational resilience. "Its recovery ecosystem combines the Session messaging network with blockchain-backed services that store and deliver resources used throughout the extortion process," the Microsoft Threat

Data BreachesMicrosoftRansomware
P15
2026-08-11 16:12 UTC
Vendor Research

AWS successfully completed its 2025-26 NHS DSPT assessment

AWS Security Blog · Tariro Dongo · indexed 2026-08-15 18:55 UTC

Amazon Web Services (AWS) is pleased to announce its successful completion of the 2025-26 NHS Data Security and Protection Toolkit (NHS DSPT) assessment audit and achieving a status of Standards Exceeded. The NHS DSPT is an assessment that allows organizations to measure their performance against the National Data Guardian’s 10 data security standards. All organizations […]

Cloud Security
P0
2026-08-11 14:04 UTC
Vendor Research

Microsoft's August 2026 Patch Tuesday addresses 398 CVEs (CVE-2026-68820)

Tenable Blog · Research Special Operations · indexed 2026-08-15 18:55 UTC

42Critical355Important1Moderate0LowMicrosoft addresses 398 CVEs in the eighth Patch Tuesday of 2026, with three zero-days, including one that was exploited in the wild.Microsoft patched 398 CVEs in its August 2026 Patch Tuesday release, with 42 rated critical, 355 rated as important and one rated as moderate. Our counts omitted two CVEs assigned by MITRE; CVE-2026-6726 and CVE-2026-6727.This month’s update includes patches for:.NET.NET Core.NET FrameworkAMD ZenActive Directory Certificate Servi…

Cloud SecurityLinuxMicrosoftMobile SecurityNetwork SecurityVulnerabilitiesCVE-2022-21919CVE-2022-26904CVE-2024-38193CVE-2025-21418CVE-2025-32709CVE-2026-61348CVE-2026-62714CVE-2026-62715CVE-2026-62716CVE-2026-62718CVE-2026-62720CVE-2026-62742CVE-2026-62745CVE-2026-62761CVE-2026-62776CVE-2026-62803CVE-2026-62807CVE-2026-62812CVE-2026-62814CVE-2026-6726CVE-2026-6727CVE-2026-68820CVE-2026-70307
P65
2026-08-11 13:11 UTC
Security Journalism

OpenAI Launches GPT-5.6-Cyber with Reduced Safeguards for Exploit Development

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-15 14:33 UTC

OpenAI on Monday unveiled a new cybersecurity-focused model called GPT‑5.6‑Cyber that it said is focused on vulnerability research, penetration testing, and incident response. "Built on GPT‑5.6 Sol, it is trained to improve capabilities on several specialized cybersecurity tasks (e.g., finding zero-day vulnerabilities and developing exploit chains) and to reduce refusals for certain higher-risk

DFIRVulnerabilities
P25
2026-08-11 13:00 UTC
Vendor Research

CVE-2026-63520: Microsoft SharePoint Remote Code Execution (FIXED)

Rapid7 · Stephen Fewer · indexed 2026-08-15 18:55 UTC

OverviewRapid7 Labs conducted a zero-day research project against Microsoft SharePoint, resulting in the discovery of two new vulnerabilities that, when chained together, achieve unauthenticated remote code execution (RCE) against a vulnerable SharePoint server. Today, both Rapid7 and Microsoft are disclosing the second vulnerability in this chain, the RCE vulnerability CVE-2026-63520. The first vulnerability in the chain, CVE-2026-55040, was disclosed by Rapid7 and Microsoft last month.Our ful…

AI SecurityMicrosoftSecurity ResearchVulnerabilitiesCVE-2026-55040CVE-2026-63520
P85
2026-08-11 13:00 UTC
Vendor Research

Rapid7 Analysis: Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040)

Rapid7 · Stephen Fewer · indexed 2026-08-15 18:55 UTC

OverviewOn July 14, 2026, Rapid7 and Microsoft disclosed CVE-2026-55040, an authentication bypass vulnerability affecting Microsoft SharePoint. Today we are publishing a technical analysis of the vulnerability along with an accompanying proof-of-concept (PoC) script.Figure 1: The Rapid7 Labs PoC for CVE-2026-55040.⠀A remote unauthenticated attacker can leverage CVE-2026-55040 to bypass authentication on a vulnerable SharePoint server, and perform operations as a SharePoint site user or administ…

MicrosoftVulnerabilitiesCVE-2026-55040
P15
2026-08-11 12:05 UTC
Security Journalism

A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-15 14:33 UTC

A malicious SIM card can order the device it sits in to run commands of the attacker's choosing. On the cellular modules built into electric-vehicle chargers, industrial routers, and car telematics units, that is enough to take the whole device over. Researchers at the University of Birmingham and the security firm Fuzzware tested 26 phones and cellular modules for the capability, found it

Network Security
P0
2026-08-11 12:04 UTC
Security Journalism

Mozilla Revokes Firefox and Thunderbird Linux Signing Key After Key Lands in Private Repo

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-15 14:33 UTC

Mozilla has scrapped the cryptographic key behind Firefox and Thunderbird downloads for Linux after an unencrypted copy of it was committed by mistake to one of the company's own private code repositories. That key is how a user, or a Linux distribution packaging the browser, confirms a downloaded Firefox tarball came from Mozilla and was not tampered with. That decision carries a cost for

Linux
P0
2026-08-11 11:35 UTC
Security Journalism

Researchers Built a Fake Crypto Startup and Hired Three Suspected North Korean IT Workers

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-15 14:33 UTC

Security researchers invented a cryptocurrency startup, advertised developer jobs, and hired three people they believe were North Korean operatives. Every virtual machine the company issued was recording. The onboarding paperwork is the part hiring teams can use. The first hire claimed to live in Pasadena, Texas, then sent a California driver's license and a New York bank account. The

Security Research
P0
2026-08-11 10:48 UTC
Security Journalism

Researchers Turn USB Auto-Install Into a Full SYSTEM Takeover on Windows 11

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-15 14:33 UTC

Windows Plug and Play can be abused to fetch signed vendor software for an emulated USB device and execute privileged installation components that researchers chained to SYSTEM access on a fully updated Windows 11 machine. The same PnP path can be triggered over Remote Desktop without physical hardware when supported Plug and Play or low-level USB redirection is enabled; Microsoft says that

Microsoft
P0
2026-08-11 10:24 UTC
Security Journalism

Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-15 14:33 UTC

A malicious tool server connected to an AI coding assistant can quietly walk off with SSH keys, environment secrets, source code, and customer data without ever sending one obviously harmful instruction. The trick can work even after a blunt version of the same theft is refused: split the request into fragments that each look routine, place them in channels the assistant already uses, and let

P0
2026-08-11 10:00 UTC
Vendor Research

Kimwolf v7: An Evolution of the Kimwolf Botnet

Palo Alto Networks Unit 42 · Asher Davila, Chris Navarrete and Doel Santos · indexed 2026-08-15 18:55 UTC

Discover how Kimwolf v7 targets Android IoT devices with HTTP/2 DDoS fingerprinting, Ethereum ENS C2 resolution and Tor backup routing. The post Kimwolf v7: An Evolution of the Kimwolf Botnet appeared first on Unit 42.

MalwareMobile Security
P0
2026-08-11 09:16 UTC
Security Journalism

Gunra Ransomware Exploits Fortinet FortiOS, FortiProxy Flaws to Breach Networks

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-15 14:33 UTC

Cybersecurity and intelligence agencies from South Korea and the U.S. warned of Gunra ransomware attacks targeting critical infrastructure sectors and organizations across the world. Targets of these attacks include healthcare and public health, financial services, government services and facilities, and professional and nonprofit services. "Gunra is another variant in the ongoing trend of

AppleCloud SecurityNetwork SecurityRansomware
P15
2026-08-11 06:55 UTC
Security Journalism

Hackers Breach Polish Power Plant Controls via Private Cellular Network and Shut Turbine

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-15 14:33 UTC

Attackers shut down a steam turbine and the process-water treatment system at a Polish combined heat and power plant by coming in over the private cellular network the local grid operator uses to reach remote equipment. The plant supplies heat to roughly 50,000 residents. Recovery began at about 7:30 a.m. while the intruders were still active inside the network, and customers lost neither heat

P0
2026-08-11 05:48 UTC
Security Journalism

BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-15 14:33 UTC

Cybersecurity researchers have warned of a supply chain compromise impacting WordPress plugin vendor BdThemes, prompting the content management systems (CMS) platform's plugins team to temporarily disable their downloads. "Unlike traditional software supply chain attacks, zero source code files were modified within the official WordPress.org repository," Wordfence researcher Paolo Tresso said.

Security Research
P0
2026-08-10 22:00 UTC
Vendor Research

The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications

Palo Alto Networks Unit 42 · Chris Navarrete, Sai Sathvik Ruppa and Haozhe Zhang · indexed 2026-08-15 18:55 UTC

Analysis of the Aeternum botnet loader, a threat leveraging Polygon blockchain smart contracts for decentralized C2 infrastructure and payload execution. The post The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications appeared first on Unit 42.

MalwareMicrosoft
P0
2026-08-10 21:34 UTC
Security Journalism

Multistate Water System Attacks Widen, Iran Suspected

Dark Reading · Alexander Culafi · indexed 2026-08-15 18:55 UTC

Attacks targeting water systems just keep flowing across a dozen states, against ill-secured, Internet-exposed PLCs.

P0
2026-08-10 20:21 UTC
Vendor Research

AWS completes the 2026 Police-Assured Secure Facilities (PASF) audit in Europe (London)

AWS Security Blog · Tariro Dongo · indexed 2026-08-15 18:55 UTC

We’re excited to announce that our Europe (London) AWS Region has renewed its accreditation for United Kingdom (UK) Police-Assured Secure Facilities (PASF) for Official-Sensitive data. Since 2017, the Amazon Web Services (AWS) Europe (London) Region has been accredited under the PASF program. This demonstrates our continuous commitment to adhere to the heightened expectations of customers […]

Cloud Security
P0
2026-08-10 17:29 UTC
Security Journalism

Shipping 10–50× More Code? Watch This Webinar on Securing AI-Speed Development

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-15 14:33 UTC

AI is helping development teams produce far more code, far faster. But security teams still have to review vulnerabilities, manage dependencies, prioritize fixes, and control risk at human speed. When software output jumps 10 to 50 times, the problem is no longer just finding vulnerabilities. It is keeping security from becoming the bottleneck, or worse, losing control of what gets shipped.

P0
2026-08-10 17:09 UTC
Vendor Research

2026 AWS CyberVadis report now available for due diligence on third-party suppliers

AWS Security Blog · Tariro Dongo · indexed 2026-08-15 18:55 UTC

We’re excited to announce that Amazon Web Services (AWS) has completed theCyberVadis assessment of its security posture with the highest score (Mature) in all assessed areas. This demonstrates our continued commitment to meet the heightened expectations for cloud service providers. Customers can now use the 2026 AWS CyberVadis report and scorecard to reduce their supplier […]

Cloud Security
P0
2026-08-10 16:38 UTC
Security Journalism

China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-15 14:33 UTC

Microsoft has disclosed that Storm-1175, a financially motivated threat actor linked to China, has deployed a previously undocumented ransomware strain called StormEncryptor. The use of StormEncryptor marks a shift from the adversary's previous use of Medusa ransomware, the Microsoft Threat Intelligence Team said. "StormEncryptor is written in C++ and appends the file name extension .encrypted

MicrosoftRansomwareThreat ActorsThreat Intelligence
P15
2026-08-10 16:35 UTC
Vendor Research

Google Cloud Platform (GCP) Apigee Cross-Tenant Data Exfiltration via Confused Deputy

Tenable Research Advisories · Ben Smith · indexed 2026-08-15 18:55 UTC

Google Cloud Platform (GCP) Apigee Cross-Tenant Data Exfiltration via Confused Deputy Tenable Research has identified and responsibly disclosed a critical cross-tenant data exfiltration vulnerability in Google Cloud Apigee. This flaw allowed an attacker to abuse a "confused deputy" in Apigee's internal analytics infrastructure to read arbitrary Google Cloud Storage (GCS) objects across different tenants, as well as shared production infrastructure buckets. The vulnerability stems from how Apige…

Cloud SecuritySecurity ResearchVulnerabilities
P0
2026-08-10 16:24 UTC
Community

Scans for Solana (Surfpool?) Endpoints, (Mon, Aug 10th)

SANS Internet Storm Center · indexed 2026-08-15 14:33 UTC

Solana is a crypto platform known for speed. Developers like it to develop distributed applications or to implement crypto payments. To interact with the blockchain, APIs are provided for developers. These APIs will either "speak" JSON or gRPC. One implementation often used for development is "surfpool," which is used to test programs before deploying them to a Solana network.

P0
21 22 23 24 25