IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 1,057 matching records.
AUTO-POLL // 2026-08-30 10:15 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P5 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Aug 30

RANSOMWARE
P5
P5
COOL // 3 ARTICLES
SAT
Aug 29

RANSOMWARE
P9
P9
COOL // 8 ARTICLES
FRI
Aug 28

RANSOMWARE
P8
P8
COOL // 47 ARTICLES
THU
Aug 27

RANSOMWARE
P4
P4
COOL // 48 ARTICLES
WED
Aug 26

RANSOMWARE
P4
P4
COOL // 46 ARTICLES
TUE
Aug 25

ACTIVE EXPLOITATION
P4
P4
COOL // 40 ARTICLES
MON
Aug 24

RANSOMWARE
P4
P4
COOL // 34 ARTICLES
RESET
2026-08-27 11:10 UTC
Security Journalism

Carhartt data breach exposes information of 12.9 million accounts

BleepingComputer · Sergiu Gatlan · indexed 2026-08-27 11:15 UTC

The ShinyHunters extortion group has published sensitive data from nearly 13 million accounts stolen from clothing retailer giant Carhartt earlier this month, according to data breach notification service Have I Been Pwned. [...]

Data Breaches
P0
2026-08-27 11:04 UTC
Independent Research

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia

Krebs on Security · BrianKrebs · indexed 2026-08-27 11:20 UTC

Authorities in Australia have arrested two men believed to be members of TeamPCP, a prolific cybercrime and data extortion group blamed for perpetrating the longest running spree of software supply chain attacks ever. In a statement released today, the Australian Federal Police (AFP) said two unnamed suspects from Western Australia, aged 21 and 23, were arrested in connection with a "sophisticated cybercrime syndicate that allegedly created malicious open-source software to rob thousands of glo…

CybercrimeLaw Enforcement
P0
2026-08-27 11:00 UTC
Security Journalism

Spark RAT Targets Cambodia, Abuses Vulnerable OPSWAT Driver to Disable Security Tools

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-27 11:25 UTC

Individuals and organizations in Cambodia have emerged as the target of a new campaign that delivers an open-source remote access trojan (RAT) called Spark RAT. "The samples employ diverse lure themes, suggesting an effort to appeal to a broad range of potential victims. These include government notices, public health materials, real estate-related content, and other topics," Acronis Threat

Malware
P0
2026-08-27 09:33 UTC
Security Journalism

GoCaracal Malware Uses Ethereum Smart Contract to Fetch Replacement C2 Address

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-27 10:15 UTC

Threat actors linked by Arctic Wolf to Dark Caracal with medium confidence deployed a previously undocumented Go-based malware framework, GoCaracal, during a June 2026 intrusion at an unnamed communications organization in Venezuela. GoCaracal provides operators with remote shell access and payload execution, while the extended profile adds browser data theft, keylogging, remote desktop control

MalwareThreat Actors
P0
2026-08-27 08:15 UTC
Other

Meta to Pay Up to $18B Over Teen Social Media Use

Security Affairs · Pierluigi Paganini · indexed 2026-08-27 09:05 UTC

Meta will pay up to $18B and cap teen Facebook and Instagram use at two hours daily after nearly all US states sued over child safety. Meta will pay up to $18 billion over the next decade and impose real usage limits on teenagers using Facebook and Instagram, settling claims that the company deliberately designed […]

P0
2026-08-27 08:13 UTC
Security Journalism

New GPUThor Rowhammer Defeats ECC on NVIDIA RTX A6000 to Gain Host Root Access

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-27 08:50 UTC

Academic researchers have disclosed a Rowhammer attack impacting NVIDIA workstation GPUs with GDDR6 memory that defeats error correction codes (ECC), the mitigation NVIDIA recommends against GPU Rowhammer, and enables denial-of-service (DoS) and privilege escalation to a root shell. Dubbed GPUThor, the attack was developed by researchers at the University of Toronto, who hammered four DRAM

Vulnerabilities
P10
2026-08-27 07:36 UTC
Other

CISA Warns Water Utilities: Find Your Exposed PLCs Before Attackers Do

Security Affairs · Pierluigi Paganini · indexed 2026-08-27 08:10 UTC

CISA urges water utilities to find and secure internet-exposed PLCs after July attacks showed how easily exposed industrial systems can be compromised. Over 100 internet-exposed systems in the US water and wastewater sector got hit by cyberattacks in July 2026, and CISA’s response wasn’t just an incident report, it was a how-to guide for making […]

P0
2026-08-27 07:05 UTC
Security Journalism

CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-27 07:15 UTC

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added six flaws to its Known Exploited Vulnerabilities (KEV) catalog, including a high-severity security vulnerability impacting Citrix NetScaler ADC and NetScaler Gateway, citing evidence of active exploitation. The vulnerabilities are listed below - CVE-2019-1068 - A remote code execution vulnerability in

Cloud SecurityLinuxVulnerabilitiesCVE-2019-1068
P50
2026-08-27 04:39 UTC
Other

OpenAI banned Russian ChatGPT accounts backing covert influence operation

Security Affairs · Pierluigi Paganini · indexed 2026-08-27 05:50 UTC

OpenAI banned Russian ChatGPT accounts backing a fake think tank, IBI, that used AI posts and a fake “sovereignty” index to push pro‑Russia narratives. OpenAI says it has banned a cluster of ChatGPT accounts that likely originated in Russia and were used to support a covert influence operation. The campaign promoted an organisation called the […]

P0
2026-08-26 23:20 UTC
Other

CISA Red Team Fully Compromised Two Critical Infrastructure Orgs

Security Affairs · Pierluigi Paganini · indexed 2026-08-27 00:30 UTC

CISA red teams fully compromised two critical infrastructure orgs. One SOC isolated hosts in minutes; the other never detected the breach. CISA published an advisory (AA26-237A) documenting two simultaneous red team assessments at critical infrastructure organizations. Both organizations lost full domain control and had their cloud environments compromised. One of them didn’t know until CISA […]

P0
2026-08-26 20:53 UTC
Security Journalism

Exclusive: NSA to host a hacker reunion in bid to rebuild secretive unit

The Record · indexed 2026-08-26 21:05 UTC

The National Security Agency will welcome back to campus potentially hundreds of former members of the elite group known as Tailored Access Operations (TAO) to celebrate the division’s recent rebranding.

P0
2026-08-26 19:54 UTC
Security Journalism

'HTTP Terminator' Hunts for Novel Desync Attacks

Dark Reading · indexed 2026-08-27 12:40 UTC

James Kettle of PortSwigger talks with the Dark Reading News Desk about his AI-powered open source tool, which found new HTTP request-smuggling techniques.

P0
2026-08-26 19:32 UTC
Vendor Research

ICYMI: July 2026 @AWS Security

AWS Security Blog · Rodolfo Brenes · indexed 2026-08-26 19:40 UTC

If you found time for a bit of vacation this summer, you might be in catch-up mode. Here’s a list to help: all the expert blog posts, new service capabilities, code samples, and workshops, in case you missed it, from July 2026. AWS Security Blog post This month’s AWS Security Blog posts covered AI agent […]

AI SecurityCloud Security
P0
2026-08-26 19:21 UTC
Security Journalism

Red Flags That Expose Fake North Korean IT Workers

Dark Reading · Alexander Culafi · indexed 2026-08-26 21:05 UTC

North Korean operatives posing as IT workers are improving their tactics, but researchers say there are still ways to spot them before they do damage.

P0
2026-08-26 17:39 UTC
Vendor Research

Detecting multi-stage attacks on AWS: A guide to cross-service signal correlation

AWS Security Blog · Nisha Kashyap · indexed 2026-08-26 18:00 UTC

A single alert from one security service tells you something happened. Read that signal alongside activity from other services and your own business context, and you will know whether what happened is part of a multi-stage attack. Consider a short sequence. An identity calls GetCallerIdentity from a source address it hasn’t previously used. Within minutes, […]

Cloud Security
P0
2026-08-26 17:33 UTC
Other

FBI Seizes China-Linked Hacking Platforms QScan and QTRouter Used Against Critical Infrastructure

Security Affairs · Pierluigi Paganini · indexed 2026-08-26 17:50 UTC

FBI seizes QScan and QTRouter, China-linked platforms used to hide intrusions and target U.S. critical infrastructure. The U.S. Department of Justice and the FBI have seized two platforms, QScan and QTRouter, used by a China-linked group to hide cyberattacks and target critical infrastructure. The operation matters because it shows how state-backed actors no longer need […]

Law EnforcementNetwork Security
P0
2026-08-26 16:43 UTC
Vendor Research

When AI infrastructure becomes the target: Securing gateways and control points

Microsoft Security Blog · Microsoft Security Research, Yash Gund and Sumith Maniath · indexed 2026-08-26 17:15 UTC

Microsoft Threat Intelligence examines attacks on exposed AI workloads, including LiteLLM gateway exploitation, credential harvesting, persistence, and cryptomining activity. The post When AI infrastructure becomes the target: Securing gateways and control points appeared first on Microsoft Security Blog.

MicrosoftPhishingThreat Intelligence
P0
2026-08-26 16:42 UTC
Security Journalism

FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-26 17:50 UTC

The U.S. Department of Justice (DoJ) on Wednesday announced the disruption of two hacking platforms named QScan and QTRouter operated by Chinese threat actors to target critical infrastructure and other sensitive networks in the country. The activity has been attributed to a Chinese state-sponsored group known as QTFY, employed by Nanjing Xinjiuwei Network Technology Company (南京鑫玖维网络科技有限公司).&

APT / Nation-StateLaw EnforcementNetwork SecurityThreat Actors
P0
2026-08-26 16:41 UTC
Security Journalism

Meta agrees to $18 billion settlement over teen social media harms

BleepingComputer · Lawrence Abrams · indexed 2026-08-26 16:50 UTC

Meta has reached a proposed settlement worth up to approximately $18 billion with a bipartisan coalition of 52 attorneys generals over allegations that Facebook and Instagram were deliberately designed to encourage compulsive use by children and teenagers. [...]

P0
2 3 4 5 6