IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 1,063 matching records.
AUTO-POLL // 2026-08-30 21:55 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P6 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Aug 30

RANSOMWARE
P6
P6
COOL // 9 ARTICLES
SAT
Aug 29

RANSOMWARE
P9
P9
COOL // 8 ARTICLES
FRI
Aug 28

RANSOMWARE
P8
P8
COOL // 47 ARTICLES
THU
Aug 27

RANSOMWARE
P4
P4
COOL // 48 ARTICLES
WED
Aug 26

RANSOMWARE
P4
P4
COOL // 46 ARTICLES
TUE
Aug 25

ACTIVE EXPLOITATION
P4
P4
COOL // 40 ARTICLES
MON
Aug 24

RANSOMWARE
P4
P4
COOL // 34 ARTICLES
RESET
2026-08-07 10:09 UTC
Security Journalism

AI-Assisted HTTP Terminator Finds Novel HTTP Desync Techniques and Apache Zero-Day

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-15 14:33 UTC

PortSwigger says HTTP Terminator, an artificial intelligence (AI)-assisted research system built by James Kettle, generated and proved new HTTP desynchronization techniques after exploring 30,000 candidate desync vectors. PortSwigger said a separate human-guided discovery cascade also exposed a zero-day in Apache Traffic Server. Kettle said HTTP Terminator tested 30,000 websites where

AI SecurityVulnerabilities
P25
2026-08-07 08:52 UTC
Security Journalism

Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-15 14:33 UTC

Entra ID researcher Dirk-jan Mollema demonstrated that malware already running in a signed-in Windows session can silently use the victim's Windows Hello for Business key to authenticate to Microsoft Entra ID. The attacker can then establish longer-term cloud access, register a device it controls, obtain a Primary Refresh Token (PRT), and add further authentication methods where tenant policies

MalwareMicrosoft
P0
2026-08-07 08:18 UTC
Security Journalism

Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-15 14:33 UTC

A GitHub issue opened by an account with no repository privileges was enough to execute code on the CI runners behind Anthropic's and Google's own coding-agent repositories. On OpenAI's, it was enough to hijack the next agent run. Novee Security ran the attack against each vendor's agent in the configuration that the vendor ships by default, and presented the work at Black Hat USA on August 5.

Cloud Security
P0
2026-08-07 07:22 UTC
Community

Linux Shell Forensic: Let?s Dive Into Atuin!, (Fri, Aug 7th)

SANS Internet Storm Center · indexed 2026-08-15 14:33 UTC

UNIX systems (including Linux) are well-known to record a lot of activities in many different locations. But there is one domain where they definitely lack of "modern" logging: shells. Most shells provide an historization of the typed commands through a flat file in the $HOME directory (ex: $HOME/.bash_history). They suffer of multiple problems:

Linux
P0
2026-08-06 22:26 UTC
Vendor Research

ChainDrop: Inside a Self-Propagating npm Worm

Palo Alto Networks Unit 42 · Unit 42 · indexed 2026-08-15 18:55 UTC

Analysis of ChainDrop, an npm supply chain worm extracting GitHub Actions runner secrets and using Ethereum smart contracts for C2 routing. The post ChainDrop: Inside a Self-Propagating npm Worm appeared first on Unit 42.

P0
2026-08-06 22:03 UTC
Vendor Research

Automate certificates with ACME support in AWS Certificate Manager

AWS Security Blog · Anthony Harvey · indexed 2026-08-15 18:55 UTC

Customers tell us that managing TLS certificates at scale is one of their biggest operational concerns. The Certification Authority Browser Forum (CA/Browser Forum) has mandated a phased reduction in maximum certificate validity for public certificates. By March 2027, the maximum validity drops to 100 days. By March 2029, it lasts for 47 days. For an […]

Cloud Security
P0
2026-08-06 20:38 UTC
Security Journalism

Researcher Claims Control of ChatGPT Secure Sandbox

Dark Reading · Alexander Culafi · indexed 2026-08-15 18:55 UTC

A researcher demonstrated a proof-of-concept attack chain that provided C2-style influence over ChatGPT's isolated sandbox during a session at Black Hat USA 2026.

P0
2026-08-06 18:00 UTC
Vendor Research

Why metaphor may dictate your security strategy

Cisco Talos Intelligence Blog · Martin Lee · indexed 2026-08-15 14:33 UTC

In this week's newsletter, Martin looks at how the metaphors we use to describe AI "escaping" its sandbox can completely change how we react to the threat.

P0
2026-08-06 17:00 UTC
Independent Research

Canadian Man Pleads Guilty in Snowflake Extortions

Krebs on Security · BrianKrebs · indexed 2026-08-15 14:33 UTC

A 26-year-old Canadian man once described as one of the most consequential cybercrime threat actors of 2024 has pleaded guilty to computer fraud and conspiracy to hack and extort more than 165 organizations that used the cloud data storage provider Snowflake. Connor Riley Moucka, of Kitchener, Ontario, also admitted to stealing call and text history records of more than 100 million AT&T customers.

CybercrimeThreat Actors
P0
2026-08-06 16:16 UTC
Vendor Research

Caching KMS data keys in multi-thread environments: Per-tenant encryption for event-driven systems at scale

AWS Security Blog · Maria Gutovsky · indexed 2026-08-15 18:55 UTC

This post assumes familiarity with envelope encryption and the AWS Encryption SDK. When your encryption system generates millions of duplicate API calls per hour, costs spiral and performance degrades. That’s exactly the challenge NICE Actimize faced while operating their global-scale, event-driven financial crime detection platform on Amazon Web Services (AWS). NICE Actimize, a leading provider […]

Cloud Security
P0
2026-08-06 14:00 UTC
Vendor Research

UNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments

Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-08-15 18:55 UTC

Written by: Tyler McLellan, Austin Larsen Introduction Google Threat Intelligence Group (GTIG) continues to track UNC6671 actively conducting compromises leading to data theft extortion, despite the alleged announced retirement of the BlackFile extortion brand in May 2026. Telemetry and infrastructure analysis reveal that rather than disbanding, UNC6671 has diversified its operations across multiple extortion fronts including Redact, Pink, Helix, and Falcon. UNC6671 continues to rely on voice p…

AppleData BreachesMicrosoftPhishingThreat ActorsThreat Intelligence
P0
2026-08-06 12:00 UTC
Vendor Research

AI code security with Claude Mythos Preview: Inside Tenable’s 500+ hours of testing for Project Glasswing

Tenable Blog · Robert Huber, Tenable Research · indexed 2026-08-15 18:55 UTC

We spent 500+ hours and 40 billion tokens testing Anthropic’s Claude Mythos Preview for Project Glasswing. The takeaway: frontier AI won't run your code security program, but used well, it can make one even stronger.Key takeawaysFrontier AI dramatically scales security testing. In one month, Tenable dedicated 11 security experts and more than 40 billion tokens testing Claude Mythos Preview across source code analysis, exploit creation, binary reverse engineering, threat modeling, and dynamic te…

Cloud SecurityMicrosoft
P0
2026-08-06 10:00 UTC
Vendor Research

Token Jacking: Cybercriminals Could Be Stealing Your AI Resources

Palo Alto Networks Unit 42 · Unit 42 · indexed 2026-08-15 18:55 UTC

Discover how attackers hijack AI tokens to fuel gray market transfer stations by stealing developer API keys. The post Token Jacking: Cybercriminals Could Be Stealing Your AI Resources appeared first on Unit 42.

P0
2026-08-05 23:35 UTC
Security Journalism

AI Sends Global Crime Syndicates Into Fraud Nirvana

Dark Reading · Tara Seals · indexed 2026-08-15 18:55 UTC

Organized crime is convincingly scamming at scale, making billions thanks to AI-enabled voice cloning, deepfake real-time video overlays, LLM-driven persona management, and automated translation.

AI SecurityCybercrime
P0
2026-08-05 23:30 UTC
Security Journalism

AI Browsers Vulnerable to 'PleaseFix' Zero-Click Agent Hijacking

Dark Reading · Jai Vijayan · indexed 2026-08-15 18:55 UTC

Attackers can take control of agents through malicious instructions hidden in content supplied to AI browsers, and there's no simple fix for the threat.

P0
2026-08-05 21:00 UTC
Vendor Research

AWS partners with Anthropic and OpenAI to bring AWS Continuum into developer workflows

AWS Security Blog · Chet Kapoor · indexed 2026-08-15 18:55 UTC

Customers have access to models that are continuously getting better with each new generation bringing larger context windows, stronger reasoning, and lower token costs. Getting the strongest AI-powered security will come from tools that combine the most relevant models with deep knowledge of a customer’s specific environment. AWS Continuum for code vulnerabilities (Preview) is built […]

Cloud SecurityMicrosoft
P0
2026-08-05 19:47 UTC
Security Journalism

CSS: The Hidden Threat Lurking in Your Inbox

Dark Reading · Kristina Beek · indexed 2026-08-15 18:55 UTC

CSS was once just about design. Now researchers warn it's powerful enough to exfiltrate data from webmail — and some vendors aren't prepared.

P0
2026-08-05 19:08 UTC
Security Journalism

15 TP-Link Bugs Expose Risks in Zero-Trust Provisioning

Dark Reading · Nate Nelson · indexed 2026-08-15 18:55 UTC

Researchers are calling attention to the risks inherent in automated network device provisioning, using a world-leading device manufacturer as a case study.

P0
2026-08-05 17:17 UTC
Vendor Research

From 2 weeks to 2 minutes: Amazon Cognito launches Provisioned limits for self-service rate limit management

AWS Security Blog · Kiran Dongara · indexed 2026-08-15 18:55 UTC

Imagine preparing for your biggest sales event of the year, and you want to ensure your customer identity management service can handle the elevated traffic for carrying out application activities. For security teams, business leaders, and technologists managing identity infrastructure at scale, this scenario has been all too familiar. Whether you’re a CISO evaluating security […]

P0
2026-08-05 16:30 UTC
Vendor Research

​​Microsoft named a Leader in the KuppingerCole Leadership Compass for Cloud Native Application Protection Platforms (CNAPP)

Microsoft Security Blog · Ran Rosin · indexed 2026-08-15 18:55 UTC

Learn why KuppingerCole named Microsoft a Leader in its Leadership Compass: Cloud Native Application Protection Platforms report. The post ​​Microsoft named a Leader in the KuppingerCole Leadership Compass for Cloud Native Application Protection Platforms (CNAPP) appeared first on Microsoft Security Blog.

Microsoft
P0
2026-08-05 16:01 UTC
Vendor Research

Cisco Advance Notification for Publication of August 5, 2026, Security Advisories

Cisco Security Advisories · indexed 2026-08-15 14:33 UTC

On August 5, 2026, the Cisco Product Security Incident Response Team (PSIRT) published the following advisories: Cisco Security Advisory CVE ID Security Impact Rating CVSS Base Score Cisco Catalyst SD-WAN Software Security Hardening Release: August 2026 CVE-2026-20303CVE-2026-20304CVE-2026-20310CVE-2026-20312CVE-2026-20313 Critical 9.9 Cisco IOS XE Software Security Hardening Release: August 2026 CVE-2026-20267CVE-2026-20268CVE-2026-20269CVE-2026-20270CVE-2026-20271CVE-2026-20272CVE-2026-20273 …

AppleDFIRMicrosoftNetwork SecurityVulnerabilitiesCVE-2026-20028CVE-2026-20124CVE-2026-20198CVE-2026-20263CVE-2026-20289CVE-2026-20294CVE-2026-20301CVE-2026-20311
P5
2026-08-05 16:00 UTC
Vendor Research

Cisco IOS XE Software Security Hardening Release: August 2026

Cisco Security Advisories · indexed 2026-08-24 19:40 UTC

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. These vulnerabilities were found during internal testing and are not known to be actively exploited. To assist customers in patching and to streamline the disclosure process, Cisco has grouped these issues …

AppleVulnerabilitiesCVE-2026-20267CVE-2026-20268CVE-2026-20269CVE-2026-20270CVE-2026-20271CVE-2026-20272CVE-2026-20273
P30
2026-08-05 16:00 UTC
Vendor Research

Cisco IOS XE Software Web-Based Management Interface Denial of Service Vulnerability

Cisco Security Advisories · indexed 2026-08-15 14:33 UTC

A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, remote attacker with low privileges to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient error handling in the web-based management interface. An attacker could exploit this vulnerability by authenticating with a malformed certificate. A successful exploit could allow the attacker to cause the affected device to reload, resulting i…

AppleVulnerabilitiesCVE-2026-20311
P5
2026-08-05 16:00 UTC
Vendor Research

Cisco Integrated Management Controller Cross-Site Scripting Vulnerability

Cisco Security Advisories · indexed 2026-08-15 14:33 UTC

A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of an affected interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the b…

VulnerabilitiesCVE-2026-20198
P5
2026-08-05 16:00 UTC
Vendor Research

Cisco RoomOS Logging Subsystem Information Disclosure Vulnerability

Cisco Security Advisories · indexed 2026-08-15 14:33 UTC

A vulnerability in the logging subsystem of Cisco RoomOS could allow an authenticated, local attacker with low privileges to access sensitive information. This vulnerability is due to the logging of sensitive information. An attacker could exploit this vulnerability by enabling a specific logging level and then collecting the system logs. A successful exploit could allow the attacker to view sensitive information like user login credentials. Cisco has released software updates that address this…

VulnerabilitiesCVE-2026-20289
P5
23 24 25 26 27