IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 1,270 matching records.
AUTO-POLL // 2026-09-04 20:35 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P8 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Sep 4

ACTIVE EXPLOITATION
P8
P8
COOL // 36 ARTICLES
THU
Sep 3

RANSOMWARE
P5
P5
COOL // 44 ARTICLES
WED
Sep 2

RANSOMWARE
P11
P11
WARM // 47 ARTICLES
TUE
Sep 1

RANSOMWARE
P6
P6
COOL // 43 ARTICLES
MON
Aug 31

RANSOMWARE
P1
P1
COOL // 37 ARTICLES
SUN
Aug 30

RANSOMWARE
P6
P6
COOL // 9 ARTICLES
SAT
Aug 29

RANSOMWARE
P9
P9
COOL // 8 ARTICLES
RESET
2026-08-18 17:05 UTC
Other

Project noRecognition: Teaching AI to Fool Surveillance Cameras

Security Affairs · Pierluigi Paganini · indexed 2026-08-18 18:10 UTC

Researchers tested 31 million patterns to disrupt surveillance AI, with promising results but significant gaps between simulation and real-world use. The Kansas City-based cybersecurity researcher Bill Swearingen spent the past year doing something that sounds almost too simple to work: printing patterns, watching cameras fail to detect them, and repeating. TechCrunch reports that after roughly […]

Security Research
P0
2026-08-18 17:04 UTC
Vendor Research

Security Hub Extended adds Supply Chain Security as its tenth category

AWS Security Blog · Michael Fuller · indexed 2026-08-18 17:30 UTC

Since February, we’ve grown AWS Security Hub Extended from 14 curated partners across 9 categories to 23 partners across 10. At Black Hat this month, 14 of those partners were at the Amazon Web Services (AWS) booth demoing live. Four of those partners delivered theater talks and ten were featured on SecurityLive streaming. We hosted […]

Cloud Security
P0
2026-08-18 16:58 UTC
Security Journalism

Ransom Busters Claims It Hacked Ransomware Servers, Asks Victims for Up to $60,000

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-18 18:35 UTC

A ransomware affiliate calling itself Ransom Busters has been spotted proactively sending emails to victim organizations and claims to delete stolen data from ransomware groups' servers in exchange for a fee ranging from $20,000 to $60,000. "In these messages, the third-party offers to help the victim recover from ransomware attack. This immediately stands out as anomalous," GuidePoint Research

Data BreachesMicrosoftRansomware
P15
2026-08-18 16:40 UTC
Security Journalism

Berlin cuts two state ministries off government network after security breach

The Record · indexed 2026-08-18 17:00 UTC

The affected ministries — one responsible for urban development, construction and housing, and the other for mobility, transport, climate protection and the environment — have been isolated from government networks since Friday as a precaution.

P0
2026-08-18 14:01 UTC
Security Journalism

Your Controls Block Known Attacks. What About the Behavior?

BleepingComputer · Sponsored by Picus Security · indexed 2026-08-18 14:15 UTC

Security controls can block a familiar attack method while missing quieter ways to achieve the same objective. Picus Security's Blue Report 2026 shows how prevention rates can vary dramatically by technique and why behavioral testing is needed to uncover those gaps. [...]

P0
2026-08-18 14:00 UTC
Vendor Research

Staying Ahead of Adversarial AI Through Agentic Source Code Review

Google Threat Intelligence / Mandiant · Mandiant · indexed 2026-08-18 15:55 UTC

Written by: Alex Tselevich, Michael Maturi Introduction Adversarial misuse of AI has increased the risk of data theft and extortion events, because when proprietary source code is exposed, defenders must scramble to identify and patch vulnerabilities while attackers deploy machine-speed AI tools against them. By structuring the analysis process, enforcing skeptical validation steps, and injecting domain-specific human expertise directly into the pipeline, we’ve achieved a leap in efficacy. Comb…

AI SecurityCloud SecurityDFIRMicrosoftThreat IntelligenceVulnerabilitiesCVE-2026-13242CVE-2026-55803
P20
2026-08-18 12:49 UTC
Vendor Research

New Report: AI threats are here. Why Q2 2026 signals the end of traditional patch cycles

Rapid7 · Rapid7 Labs · indexed 2026-08-18 15:35 UTC

You can’t patch everything. So what do you fix first? Findings in Q2 2026 have changed traditional answers.The latest Quarterly Threat Landscape Report from Rapid7 Labs shows vulnerability disclosures still surging while attackers use automation and AI-assisted tooling to compress the time between disclosure and exploitation. The gap that patch cycles were built to fill is closing. Speed and volume are overwhelming security teams that have relied on traditional patch cycles and reactive program…

APT / Nation-StateCloud SecurityCybercrimeDFIRICS / OTMicrosoftPhishingRansomwareVulnerabilities
P15
2026-08-18 12:38 UTC
Security Journalism

AI "Mind Viruses" Can Spread Between Agents Through Persistent Prompt Files

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-18 13:05 UTC

Security researchers at Anthropic and Switzerland's EPFL have demonstrated that self-propagating payloads can spread from one artificial intelligence (AI) agent to the next through the editable system prompt files that autonomous agent harnesses use to carry state between sessions. The work, released as a preprint on August 10, 2026, tests the technique in a simulated six-agent coding

AI SecuritySecurity Research
P0
2026-08-18 12:38 UTC
Security Journalism

TWINLOOT Abuses SharePoint and Teams to Steal Credentials and Move Across Networks

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-18 13:05 UTC

Cybersecurity researchers have disclosed details of a previously undocumented Python implant framework dubbed TWINLOOT. "TWINLOOT is a modular, PyArmor-hardened Python implant designed to operate its entire command-and-control infrastructure inside trusted Microsoft services," Ontinue said in a technical report shared with The Hacker News. "Tasking flows through SharePoint Online file

MicrosoftSecurity Research
P0
2026-08-18 11:30 UTC
Security Journalism

One Attacker Has Scraped Both Salesforce and ServiceNow Portals Since 2025

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-18 11:55 UTC

A single piece of infrastructure has been pulling records out of Salesforce and ServiceNow customer portals across multiple industries for more than a year, according to research published this week by agent security platform Reco. The activity, which Reco has named the City Forum campaign after a domain tied to the attacker's IP address, traces back to one server: 158.220.87.79, hosted on a

P0
2026-08-18 11:20 UTC
Security Journalism

16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-18 11:55 UTC

Cybersecurity researchers have flagged a new typosquatting campaign targeting RubyGems users with a Windows-based information stealer. OpenSourceMalware, which discovered the activity on August 15, 2026, is tracking the threat under the moniker StubMaker. The complete list of packages published as part of the campaign is below - ubnuler ubnlder ri18nr reaker rakier orakw joxn

MalwareMicrosoftSecurity Research
P0
2026-08-18 11:14 UTC
Security Journalism

Microsoft tests faster Windows File Explorer, new context menu

BleepingComputer · Sergiu Gatlan · indexed 2026-08-18 11:25 UTC

Microsoft has started testing a faster File Explorer and a less cluttered and more customizable context menu in Windows 11 preview builds rolling out to Insiders this week. [...]

Microsoft
P0
2026-08-18 09:10 UTC
Security Journalism

SafePal Hardware Wallet Maker Says Flaw Exposed Data of Nearly 40,000 Customers

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-18 09:15 UTC

SafePal has disclosed that an authorization flaw in an order-tracking plug-in exposed the names, email addresses, shipping addresses, phone numbers, and purchase details of approximately 39,798 customers. The hardware wallet maker said all affected customers were notified individually by email on August 16 from security@safepal.com, with the subject line "[Important] Your SafePal Order

P0
2026-08-18 08:44 UTC
Other

GitLab Patches Critical Unauthenticated GraphQL Vulnerability

Security Affairs · Pierluigi Paganini · indexed 2026-08-18 09:00 UTC

GitLab patched a critical GraphQL flaw that let unauthenticated attackers remotely modify or delete public projects on self-managed servers. GitLab pushed out an emergency patch this week to address a critical flaw, tracked as CVE-2026-19478 (CVSS score of 9.4), that could let an attacker with zero credentials remotely modify or delete public projects and user […]

VulnerabilitiesCVE-2026-19478
P15
2026-08-18 08:12 UTC
Security Journalism

Microsoft starts removing WMIC tool used by cybercriminals

BleepingComputer · Sergiu Gatlan · indexed 2026-08-18 08:15 UTC

Microsoft announced that it removed the Windows Management Instrumentation Command-line (WMIC) tool from Windows 11 24H2 and 25H2, as well as from Windows 11 beta builds released this week. [...]

Microsoft
P0
2026-08-18 08:02 UTC
Other

U.S. CISA adds a Ray-Project Ray flaw to its Known Exploited Vulnerabilities catalog

Security Affairs · Pierluigi Paganini · indexed 2026-08-18 09:00 UTC

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a Ray-Project Ray vulnerability to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Progress LoadMaster vulnerability, tracked as CVE-2025-62593 (CVSS score of 9.4), to its Known Exploited Vulnerabilities (KEV) catalog. CVE-2025-62593 is a critical remote code execution (RCE) vulnerability in Ray, […]

VulnerabilitiesCVE-2025-62593
P50
2026-08-18 07:18 UTC
Other

New Mirai-Based Evooo1Bot Botnet Targets Linux Devices

Security Affairs · Pierluigi Paganini · indexed 2026-08-18 07:50 UTC

Evooo1Bot is a Mirai-based Linux botnet that hijacks routers and IoT devices for DDoS attacks, credential theft and criminal proxy services. Fortinet’s FortiGuard Labs disclosed Evooo1Bot in mid-August, a previously undocumented Linux botnet that’s been active since July 2026. The bot borrows Mirai‘s DDoS engine but adds encrypted command-and-control communications, an SSH brute-force scanner, a […]

LinuxMalwareNetwork SecurityPhishing
P0
2026-08-18 06:34 UTC
Security Journalism

CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-18 07:15 UTC

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a critical flaw impacting Ray to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. Ray is an open-source, Python-native distributed computing framework designed to scale artificial intelligence and machine learning workloads. As of writing, the GitHub project has more than

AI SecurityVulnerabilities
P80
2026-08-17 21:03 UTC
Security Journalism

Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-17 21:20 UTC

GitLab has released security updates to address a critical vulnerability impacting its Community Edition (CE) and Enterprise Edition (EE) software that, under certain conditions, could allow an unauthenticated attacker to remotely modify or delete public projects and user data. The flaw, tracked as CVE-2026-19478, has been rated Critical by GitLab and assigned a CVSS score of 9.4. Released on

VulnerabilitiesCVE-2026-19478
P15
2026-08-17 20:26 UTC
Community

Apple Patches iOS and macOS, (Mon, Aug 17th)

SANS Internet Storm Center · indexed 2026-08-17 20:35 UTC

Apple today released updates for iOS/iPadOS (26 and 18) and macOS 26. This update fixes 108 vulnerabilities and comes about two weeks after the much smaller macOS update that addressed the single screen-sharing vulnerability. This vulnerability did not affect iOS/iPadOS.

AppleVulnerabilities
P0
22 23 24 25 26