IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 1,241 matching records.
AUTO-POLL // 2026-09-04 10:40 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
WARM
COOL WARM ELEVATED HOT CRITICAL
P16 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Sep 4

ACTIVE EXPLOITATION
P16
P16
WARM // 7 ARTICLES
THU
Sep 3

RANSOMWARE
P5
P5
COOL // 44 ARTICLES
WED
Sep 2

RANSOMWARE
P11
P11
WARM // 47 ARTICLES
TUE
Sep 1

RANSOMWARE
P6
P6
COOL // 43 ARTICLES
MON
Aug 31

RANSOMWARE
P1
P1
COOL // 37 ARTICLES
SUN
Aug 30

RANSOMWARE
P6
P6
COOL // 9 ARTICLES
SAT
Aug 29

RANSOMWARE
P9
P9
COOL // 8 ARTICLES
RESET
2026-09-01 14:01 UTC
Security Journalism

Why Even the Best Edge Security Still Misses High-Risk Sessions

BleepingComputer · Sponsored by Spur Intelligence · indexed 2026-09-01 14:15 UTC

Attackers can hide behind residential proxies, VPNs, and other infrastructure that makes malicious sessions appear legitimate to existing edge security controls. Spur explains how session enrichment adds data points that help organizations identify risky sessions and make stronger enforcement decisions. [...]

Network Security
P0
2026-09-01 14:00 UTC
Vendor Research

Financially Motivated Threat Actor BREEZE COMET Targets Brazil

Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-09-01 03:50 UTC

Introduction Beginning in 2024 Mandiant investigated a string of compromises affecting Brazilian financial services, retail, and eCommerce organizations. Google Threat Intelligence Group (GTIG) tracks this activity as BREEZE COMET (formerly UNC5669), a financially motivated threat actor specializing in manipulating payment systems and banking software in Brazil to conduct fraudulent transfers. This activity overlaps with operations publicly reported as Plump Spider and SHADOW-AETHER-064. In thi…

AI SecurityCloud SecurityCybercrimeMalwareMicrosoftNetwork SecurityPhishingThreat ActorsThreat Intelligence
P0
2026-09-01 13:56 UTC
Security Journalism

ClickFix Campaign Compromises 31 Orgs, Abuses Polygon Blockchain

Dark Reading · Elizabeth Montalbano · indexed 2026-09-01 14:50 UTC

The campaign uses EtherHiding to dynamically update its command-and-control server, abusing the blockchain as an attacker-controlled address book.

P0
2026-09-01 13:50 UTC
Other

Five Venezuelan Nationals Plead Guilty in Kansas ATM Jackpotting Attempt

Security Affairs · Pierluigi Paganini · indexed 2026-09-01 14:40 UTC

Five Venezuelan nationals pleaded guilty after failed ATM jackpotting attempts in Kansas. The FBI recorded 700+ cases in 2025, causing $20M in losses. Five Venezuelan nationals have pleaded guilty after trying to steal cash from ATMs in Kansas using the popular ATM jackpotting technique. The U.S. Department of Justice announced the case on August 31, […]

Law Enforcement
P0
2026-09-01 13:08 UTC
Security Journalism

Iranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding Tests

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-01 13:20 UTC

The Iranian Nimbus Manticore hacking group has been attributed to two previously undocumented malware families that highlight the continued evolution of its toolset and likely expand its targeting footprint to infect Linux and Apple macOS systems using cross-platform remote access trojans (RATs) developed using Node.js and JavaScript. Russian cybersecurity company Kaspersky is tracking the

AppleLinuxMalware
P0
2026-09-01 11:30 UTC
Security Journalism

Threat Actors Don’t Want Better Attacks. They Want Repeatable Ones

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-01 11:50 UTC

The most common way into a company last year was to ask. A web page tells the visitor to prove they are not a robot. While they read the instructions, it quietly places a command on their clipboard. Then it talks them through opening a terminal and pasting it in. The technique is called ClickFix, and it was the most common initial access method Microsoft’s team observed last year, accounting

MicrosoftThreat Actors
P0
2026-09-01 11:08 UTC
Other

North Korea-linked IT Workers Are Getting Hired Inside Western Companies

Security Affairs · Pierluigi Paganini · indexed 2026-09-01 11:20 UTC

Huntress found five DPRK-linked workers hired in 2026 using fake identities, remote-access setups and proxy tools to infiltrate legitimate companies. Companies keep accidentally hiring North Korea-linked individuals as remote workers, and Huntress just published the receipts. The security firm’s investigation documents five confirmed cases in 2026 alone where DPRK-aligned workers, tracked under the name FAMOUS […]

DFIR
P0
2026-09-01 09:34 UTC
Other

Chaotic Eclipse Releases Kaspersky Zero-Day HardBreacher

Security Affairs · Pierluigi Paganini · indexed 2026-09-01 10:20 UTC

Chaotic Eclipse released HardBreacher, a PoC exploit for a Kaspersky Endpoint Security privilege escalation flaw, adding another zero-day to his list. Security researcher Chaotic Eclipse, also known as INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse, released a new zero-day exploit targeting Kaspersky Endpoint Security. The researcher named the exploit HardBreacher, it triggers a privilege escalation flaw. Nightmare Eclipse […]

Security ResearchVulnerabilities
P35
2026-09-01 09:05 UTC
Security Journalism

Attackers Steal METR API Key and Consume AI Credits Worth About $600,000

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-01 10:35 UTC

METR (short for Model Evaluation and Threat Research and pronounced "Meter"), a research non-profit that evaluates frontier artificial intelligence (AI) models for their ability to carry out long-horizon, agentic tasks, disclosed that it suffered "two notable security incidents" where external actors attempted to gain unauthorized access to its systems. No sensitive information is believed to

AI Security
P0
2026-09-01 08:26 UTC
Security Journalism

Russia-Aligned UAC-0099 Plants Nuclear Weapon Prompt in Malware to Disrupt AI Analysis

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-01 08:55 UTC

Cybersecurity researchers have disclosed a new technique dubbed GuardBreaker that's been put to use by a Russia-aligned threat actor known as UAC-0099 against a target in Ukraine with an aim to interfere with artificial intelligence (AI)-assisted analysis. The idea, ESET said in a series of posts on X, is to deliberately trip a large language model's (LLM) safety mechanisms and prevent its

AI SecurityMalwareSecurity ResearchThreat Actors
P0
2026-09-01 08:13 UTC
Other

U.S. CISA adds PaperCut NG/MF flaws to its Known Exploited Vulnerabilities catalog

Security Affairs · Pierluigi Paganini · indexed 2026-09-01 09:05 UTC

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds PaperCut NG/MF flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: PaperCut, the print management software running in schools, hospitals, and offices worldwide, recently confirmed that a pre-authentication remote code execution flaw, tracked as CVE-2026-81578, […]

Cloud SecurityVulnerabilitiesCVE-2026-81578
P50
2026-09-01 07:22 UTC
Security Journalism

Attackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 Activity

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-01 08:00 UTC

Threat actors are exploiting two critical flaws impacting Langflow and Ruby on Rails, according to new findings from VulnCheck. The vulnerabilities in question are listed below - CVE-2026-0768 (CVSS score: 9.8) - A lack of proper validation of a user-supplied input vulnerability that could be exploited to execute arbitrary Python code in the context of the root user. CVE-2026-66066 aka

Cloud SecurityThreat ActorsVulnerabilitiesCVE-2026-0768CVE-2026-66066
P15
2026-08-31 20:47 UTC
Security Journalism

Cronos blockchain restarts after $74 million Tectonic exploit

BleepingComputer · Bill Toulas · indexed 2026-08-31 21:00 UTC

The Cronos blockchain network has resumed trading activity after a price-manipulation attack on the Tectonic cryptocurrency lending platform allowed an attacker to borrow $74 million. [...]

P0
2026-08-31 20:00 UTC
Community

The Coding-Agent Trap: When a "Free" LLM Endpoint Is the Adversary, (Mon, Aug 31st)

SANS Internet Storm Center · indexed 2026-08-31 20:10 UTC

One of my internet-exposed inference honeypots was discovered, relabeled with sought-after model names, and incorporated into infrastructure apparently used to provide "free" LLM backends. It then received a real coding-agent session — history, filesystem output, working paths, and the agent's local tool manifest. The honeypot did not request or cause any tool execution; what the request exposed is what a malicious operator in that position could do.

AI Security
P0
2026-08-31 19:45 UTC
Other

ValleyRAT: When Legitimate Software Becomes a Malware Delivery Tool

Security Affairs · Pierluigi Paganini · indexed 2026-08-31 20:50 UTC

ValleyRAT hides behind legitimate adware, using DLL sideloading to evade detection, steal data and give Silver Fox control of infected systems. ValleyRAT doesn’t always need to disguise itself as a cracked game or a fake browser update. It can also hide behind something much more ordinary: an application that looks like adware and appears to […]

Malware
P0
2026-08-31 19:00 UTC
Vendor Research

We invited a direct competitor into Security Hub Extended. Here’s why.

AWS Security Blog · Michael Fuller · indexed 2026-08-31 19:05 UTC

When customers keep pointing you to a solution that overlaps with parts of your own offering, you have a choice to make. This post is about the choice we made with Upwind, and why we’d make it again. AWS Security Hub Extended exists because customers told us what was working for them in enterprise security […]

Cloud Security
P0
2026-08-31 18:51 UTC
Security Journalism

Microsoft warns of TerminalFix attacks deploying reverse tunnels

BleepingComputer · Bill Toulas · indexed 2026-08-31 19:05 UTC

A new ClickFix variant dubbed TerminalFix uses fake Cloudflare CAPTCHA prompts on compromised websites to trick victims into running malicious PowerShell commands in Windows Terminal. [...]

Microsoft
P0
2026-08-31 18:41 UTC
Vendor Research

CVE-2026-83497 - OpenSearch SQL Plugin - Unrestricted Java Deserialization in Cursor Pagination

AWS Security Bulletins · aws@amazon.com · indexed 2026-08-31 18:55 UTC

Bulletin ID: 2026-092-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/31/2026 11:30 AM PDT Description: OpenSearch is an open-source search and analytics engine. We identified CVE-2026-83497 where a remote authenticated user with basic read/search permissions can run arbitrary code on the server by providing a crafted cursor parameter to the plugins/sql endpoint. Affected Products & Versions: OpenSearch SQL Plugin (open-source, self-managed): - Affected: v2.8 to…

Cloud SecurityVulnerabilitiesCVE-2026-83497
P5
3 4 5 6 7