IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 1,241 matching records.
AUTO-POLL // 2026-09-04 10:40 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
WARM
COOL WARM ELEVATED HOT CRITICAL
P16 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Sep 4

ACTIVE EXPLOITATION
P16
P16
WARM // 7 ARTICLES
THU
Sep 3

RANSOMWARE
P5
P5
COOL // 44 ARTICLES
WED
Sep 2

RANSOMWARE
P11
P11
WARM // 47 ARTICLES
TUE
Sep 1

RANSOMWARE
P6
P6
COOL // 43 ARTICLES
MON
Aug 31

RANSOMWARE
P1
P1
COOL // 37 ARTICLES
SUN
Aug 30

RANSOMWARE
P6
P6
COOL // 9 ARTICLES
SAT
Aug 29

RANSOMWARE
P9
P9
COOL // 8 ARTICLES
RESET
2026-09-02 07:58 UTC
Other

Hackers Target Langflow in CVE-2026-0768 Attacks

Security Affairs · Pierluigi Paganini · indexed 2026-09-02 08:30 UTC

Hackers are exploiting a critical Langflow flaw that lets unauthenticated attackers remotely execute Python code on vulnerable systems. Hackers have started exploiting a critical vulnerability, tracked as CVE-2026-0768 (CVSS score of 9.8), in the AI-focused low-code platform Langflow. The flaw affects the code validator in Langflow’s custom component editor, it impacts all Langflow versions up […]

VulnerabilitiesCVE-2026-0768
P15
2026-09-02 07:47 UTC
Security Journalism

Researchers Use Claude to Port Pre-Auth RCE Exploit From One PLC Model to Another

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-02 08:00 UTC

Forescout Research - Vedere Labs said it used Anthropic's Claude to port a working pre-authentication remote code execution (RCE) exploit from one WAGO programmable logic controller (PLC) to another, executing attacker-supplied ARM shellcode on live hardware. The exploit targets CVE-2021-31886, a stack-based buffer overflow in the Nucleus FTP server's handling of the USER command

ICS / OTVulnerabilitiesCVE-2021-31886
P20
2026-09-02 07:08 UTC
Security Journalism

Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-02 08:00 UTC

Threat actors are exploiting a severe security vulnerability in Sangoma Switchvox, an enterprise VoIP platform, that could allow unauthenticated remote code execution. The vulnerability in question is CVE-2026-9586 (CVSS score: 9.3), a critical unauthenticated SQL injection vulnerability in Sangoma Switchvox SMB Edition 8.3 (104997) that can allow attackers to remotely execute arbitrary code as

Network SecurityThreat ActorsVulnerabilitiesCVE-2026-9586
P20
2026-09-02 06:56 UTC
Security Journalism

Authorities Turn Sality's P2P Network Against Itself, Cutting Off New Malware Payloads

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-02 08:00 UTC

The U.S. Department of Justice (DoJ) on Tuesday announced the takedown of a long-standing peer-to-peer (P2P) botnet known as Sality as part of a coordinated law enforcement operation. The effort was undertaken on August 31, 2026, by authorities from the U.S., Bulgaria, Hungary, and Romania, in collaboration with private industry partners CrowdStrike and the Shadowserver Foundation. To that

Law EnforcementMalware
P0
2026-09-01 22:48 UTC
Vendor Research

Counterfeit installers to system compromise: Tracking a deceptive software download campaign

Microsoft Security Blog · Microsoft Security Research, Microsoft Defender Experts and Parth Jomadkar · indexed 2026-09-01 23:55 UTC

An active campaign is impersonating legitimate software vendors to deliver malware through look-alike download pages and regenerated installer archives. Microsoft Defender Experts shares observed attack techniques, Defender XDR detections, indicators of compromise, and practical mitigations to help organizations identify, block, and respond to this threat. The post Counterfeit installers to system compromise: Tracking a deceptive software download campaign appeared first on Microsoft Security B…

MalwareMicrosoft
P0
2026-09-01 22:40 UTC
Independent Research

FBI Probes Service Selling 153M+ Drivers Licenses

Krebs on Security · BrianKrebs · indexed 2026-09-01 23:05 UTC

A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada. Based on interviews with individuals whose licenses are available for purchase on this service, it appears to be siphoning images collected by a widely-used identity verification company based in Louisiana. KrebsOnSecurity also has learned that the New Orleans field office of the Federal Bureau of Investigation (FBI) toda…

CybercrimeDFIRLaw Enforcement
P0
2026-09-01 20:53 UTC
Security Journalism

Hackers abuse Faronics Deploy admin tool to install ScreenConnect

BleepingComputer · Bill Toulas · indexed 2026-09-01 20:55 UTC

Phishing actors are abusing the legitimate Faronics Deploy endpoint-management platform to gain remote administrative control over victim computers and install the ScreenConnect remote support software. [...]

Phishing
P0
2026-09-01 18:55 UTC
Vendor Research

Cybersecurity IR Workshop: The workshop you shouldn’t miss

Microsoft Security Blog · Microsoft Defender Experts Cybersecurity Incident Response · indexed 2026-09-01 20:15 UTC

Cyber resilience starts before a crisis. Gain practical insights from DART to strengthen readiness and response. The post Cybersecurity IR Workshop: The workshop you shouldn’t miss appeared first on Microsoft Security Blog.

Microsoft
P0
2026-09-01 18:21 UTC
Vendor Research

CVE-2026-83551 - Cleartext storage of HMAC signing key in Amazon SageMaker Python SDK

AWS Security Bulletins · aws@amazon.com · indexed 2026-09-01 18:40 UTC

Bulletin ID: 2026-093-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/01/2026 11:00 AM PDT Description: SageMaker Python SDK's @step and @remote decorator pipeline component uses an HMAC key to protect the integrity of serialized function payloads stored in S3. We identified an issue where the HMAC secret key is stored in cleartext within pipeline definitions and accessible via the DescribePipeline API. This allows an actor with a role in that account that has p…

Cloud SecurityVulnerabilitiesCVE-2026-83551
P5
2026-09-01 17:53 UTC
Security Journalism

Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-01 18:15 UTC

Threat actors are exploiting a newly patched critical security flaw impacting JFrog Artifactory merely days after public disclosure, according to watchTowr. The vulnerability in question is CVE-2026-82329 (CVSS score: 9.8), a case of authentication bypass that could lead to administrative access in Artifactory. "JFrog Artifactory contains an authentication weakness that, under default

Threat ActorsVulnerabilitiesCVE-2026-82329
P15
2026-09-01 17:19 UTC
Security Journalism

Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-01 18:15 UTC

Brazilian financial services, retail, and e-commerce organizations have become the target of a financially motivated threat actor dubbed Breeze Comet (formerly UNC5669) since 2024. Google Threat Intelligence Group (GTIG) and Mandiant teams described the threat actor as "specializing in manipulating payment systems and banking software in Brazil to conduct fraudulent transfers." The adversary

CybercrimeThreat ActorsThreat Intelligence
P0
2026-09-01 15:12 UTC
Other

Attackers Access Aesto Health AWS Infrastructure, Exposing 9.5 Million Records

Security Affairs · Pierluigi Paganini · indexed 2026-09-01 15:40 UTC

Aesto Health suffered a breach exposing personal and health data of more than 9.5 million people after attackers accessed its AWS infrastructure. Aesto Health, a U.S. healthcare technology company, disclosed a data breach that exposed personal and health information belonging to more than 9.5 million people. The company discovered the incident on December 18, 2025, […]

Cloud SecurityData Breaches
P0
2026-09-01 14:45 UTC
Security Journalism

Hackers push malicious Virtualizor update in BGP hijacking attack

BleepingComputer · Bill Toulas · indexed 2026-09-01 15:00 UTC

Hackers delivered malicious updates to the Virtualizor VPS management software after hijacking BGP routing for its update infrastructure and redirecting update requests to malicious servers. [...]

P0
2026-09-01 14:33 UTC
Other

Chaotic Eclipse Releases GenDigital Avast Antivirus ZeroDay PrettyPrague

Security Affairs · Pierluigi Paganini · indexed 2026-09-01 14:40 UTC

Chaotic Eclipse released PrettyPrague, a PoC exploit for a GenDigital Avast Antivirus ZeroDay Elevation of Privileges Vulnerability Security researcher Chaotic Eclipse, also known as INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse, released a new zero-day exploit targeting GenDigital Avast Antivirus. The researcher named the exploit PrettyPrague, it triggers a privilege escalation flaw. The researcher claims to have found […]

Security ResearchVulnerabilities
P35
2026-09-01 14:07 UTC
Security Journalism

13 Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Wallet Seeds

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-01 14:45 UTC

Cybersecurity researchers have identified a set of 13 malicious Composer theme packages on Packagist that are designed to inject JavaScript into Vietnamese movie and comic streaming sites that install those libraries and initiate the deployment of spyware aimed at unpatched iOS devices. "The injected code runs two operations against a site's visitors: a mobile ad-fraud and gambling-redirect

AppleCybercrimeSecurity Research
P0
2 3 4 5 6