IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 1,057 matching records.
AUTO-POLL // 2026-08-30 11:30 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P5 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Aug 30

RANSOMWARE
P5
P5
COOL // 3 ARTICLES
SAT
Aug 29

RANSOMWARE
P9
P9
COOL // 8 ARTICLES
FRI
Aug 28

RANSOMWARE
P8
P8
COOL // 47 ARTICLES
THU
Aug 27

RANSOMWARE
P4
P4
COOL // 48 ARTICLES
WED
Aug 26

RANSOMWARE
P4
P4
COOL // 46 ARTICLES
TUE
Aug 25

ACTIVE EXPLOITATION
P4
P4
COOL // 40 ARTICLES
MON
Aug 24

RANSOMWARE
P4
P4
COOL // 34 ARTICLES
RESET
2026-08-25 11:52 UTC
Security Journalism

24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-25 12:45 UTC

Cybersecurity researchers have disclosed details of a new campaign that uses a cluster of 24 npm packages as free phishing infrastructure for redirecting to ClickFix-style fake CAPTCHA pages. "While the malware is simply a single HTML page inside the npm package, and while downloading it wouldn't do harm, the threat actor’s use of npm isn't to infect developers who install it, but to use the

MalwarePhishingSecurity ResearchThreat Actors
P0
2026-08-25 11:45 UTC
Security Journalism

Large DDoS attack knocks Norwegian public services offline

The Record · indexed 2026-08-25 11:55 UTC

The Norwegian Digitalisation Agency said it was working with its IT partner to stabilize systems affected by a distributed denial-of-service attack, with some services gradually coming back online.

P0
2026-08-25 11:33 UTC
Security Journalism

E4del and PINHOLE RATs Turn FTP Banners Into Dead Drops for Malware Commands

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-25 12:45 UTC

Cybersecurity researchers are calling attention to a new campaign that employs FTP banners as dead drop resolvers (DDRs) to deliver two previously unreported remote access trojans (RATs) tracked as E4del and PINHOLE. While threat actors are known to abuse legitimate services to point to additional command-and-control (C2) infrastructure and blend in with regular network traffic, the development

MalwareSecurity ResearchThreat Actors
P0
2026-08-25 11:14 UTC
Security Journalism

Frontier AI: Vulnerability Management's Systemic Revolution

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-25 12:45 UTC

Vulnerability management has been a staple of security programs since the dawn of the cybersecurity discipline. The symbiotic relationship between vulnerability and patch management teams has also existed for that time and has gone through waves of contention and thankfulness. While this relationship required thoughtful care and feeding from both sides, both sides were aiming to work toward a

Vulnerabilities
P0
2026-08-25 10:00 UTC
Vendor Research

The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution

Palo Alto Networks Unit 42 · Sara McBroom · indexed 2026-08-25 10:20 UTC

Explore Unit 42 research on AI-enabled malware. Learn how existing behavioral detection and endpoint analytics stop AI-authored code before execution. The post The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution appeared first on Unit 42.

Malware
P0
2026-08-25 10:00 UTC
Vendor Research

The safety penalty: Reclaiming operational sovereignty in the age of AI

Cisco Talos Intelligence Blog · David J. Bianco · indexed 2026-08-25 10:15 UTC

As frontier AI models become increasingly restrictive, security teams are facing a "safety penalty" that hampers real-time incident response. Discover how organizations can move toward operational sovereignty to ensure their defensive AI keeps pace with unconstrained adversaries.

DFIR
P0
2026-08-25 08:48 UTC
Other

U.S. CISA adds maximum-severity Oracle flaw to its Known Exploited Vulnerabilities catalog

Security Affairs · Pierluigi Paganini · indexed 2026-08-25 09:40 UTC

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Oracle flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added an Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in flaw, tracked as CVE-2026-21962 (CVSS score of 10,0), to its Known Exploited Vulnerabilities (KEV) catalog. CVE-2026-21962 is a critical, unauthenticated vulnerability […]

VulnerabilitiesCVE-2026-21962
P35
2026-08-25 08:34 UTC
Security Journalism

Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-25 09:40 UTC

Bad actors are attempting to exploit two severe unauthenticated authentication bypasses in the Xecurify miniOrange SAML 2.0 Single Sign On plugin that make it possible for an attacker to sign in as any WordPress user, including administrators. The vulnerabilities, as disclosed by Patchstack, are listed below - CVE-2026-61979 (CVSS score: 8.1) - An unauthenticated privilege escalation

Cloud SecurityVulnerabilitiesCVE-2026-61979
P15
2026-08-25 07:15 UTC
Other

Fake Minecraft Sites Are Still Spreading WeedHack After C2 Takedown

Security Affairs · Pierluigi Paganini · indexed 2026-08-25 07:25 UTC

WeedHack Minecraft Malware Survives C2 Takedown: Fake Client Sites Still Active, SEO Poisoning Puts Malicious Downloads at the Top of Google McAfee Labs published a follow-up report on the WeedHack Malware-as-a-Service campaign this week, documenting ten active malicious sites and multiple file-hosting accounts that are still spreading the infostealer despite a disruption to its command-and-control […]

Malware
P0
2026-08-25 06:12 UTC
Security Journalism

Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-25 06:55 UTC

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a maximum-severity security flaw impacting Oracle HTTP Server and Oracle WebLogic Server to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability, tracked as CVE-2026-21962 (CVSS score: 10.0), allows an unauthenticated attacker with network access via HTTP to

VulnerabilitiesCVE-2026-21962
P60
2026-08-24 23:00 UTC
Security Journalism

US sanctions Iranian cyber actors as UK discloses power plant attack

The Record · indexed 2026-08-24 23:00 UTC

The U.S. sanctioned several Iranian nationals for cyberattacks on critical infrastructure just days after reports emerged of a cyber intrusion on a small power plant in the United Kingdom.

P0
2026-08-24 20:36 UTC
Security Journalism

New Zealand to pursue social media ban for children under 16

The Record · indexed 2026-08-24 20:45 UTC

The legislation would mandate that high-risk social media platforms such as Instagram, TikTok, Snapchat and Facebook take “reasonable steps” to ensure users are over age 16 by using tools like facial age estimation, digital ID services, formal IDs and existing account information for verification.

P0
2026-08-24 19:26 UTC
Security Journalism

Hackers target WordPress sites in miniOrange auth bypass attacks

BleepingComputer · Bill Toulas · indexed 2026-08-24 19:35 UTC

Hackers are attempting to exploit two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress that can be used to forge SAML responses and log in as administrators. [...]

P10
2026-08-24 17:56 UTC
Security Journalism

TikTok reaches $400M settlement with US over COPPA violations

BleepingComputer · Bill Toulas · indexed 2026-08-24 18:10 UTC

The U.S. Department of Justice announced a $400 million settlement with TikTok, ByteDance, and affiliated companies over allegations that they violated the Children's Online Privacy Protection Act (COPPA). [...]

Law Enforcement
P0
2026-08-24 17:41 UTC
Security Journalism

Shipping More AI Code Than You Can Secure? Watch How to Control Remediation Debt

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-24 12:10 UTC

If your developers are using AI coding tools, you are probably already seeing the upside: faster development, more code, and less time spent on routine work. The harder part is what comes after. AI can also introduce open-source packages at a pace your security team was never built to handle. More dependencies mean more vulnerabilities to review, more remediation work, and a backlog that can

P0
2026-08-24 17:41 UTC
Security Journalism

Weedhack Malware Spreads via Fake Minecraft Clients and SEO Poisoning

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-24 23:15 UTC

Cybersecurity researchers have found that several websites are still actively distributing a malware family known as Weedhack to gamers by masquerading as Minecraft clients. McAfee Labs said it detected and blocked more than 6,300 attempts to access malicious sites, adding that it found lookalike gaming websites designed to mimic legitimate projects, including branding, feature lists, FAQs,

MalwareSecurity Research
P0
2026-08-24 17:27 UTC
Other

Cybercriminals Turn GTA VI Leaks Into Malware Bait

Security Affairs · Pierluigi Paganini · indexed 2026-08-24 18:10 UTC

A fake 113GB GTA VI build is packed with malware, using massive empty files to hide a tiny malicious payload. GTA VI hype has reached the point where people are volunteering to infect their own computers just to check if a leak is real. Someone on X asked their followers to “take one for the […]

Malware
P0
2026-08-24 15:17 UTC
Security Journalism

ReliaQuest confirms failed data-theft attack after ShinyHunters breach

BleepingComputer · Bill Toulas · indexed 2026-08-24 15:30 UTC

Cybersecurity company ReliaQuest has confirmed that one of its employees was targeted in a social engineering attack after hackers impersonated a member of the security team. [...]

P0
2026-08-24 15:02 UTC
Security Journalism

Tricky 'SynkLoader' Multitool May Herald Ransomware

Dark Reading · Nate Nelson · indexed 2026-08-24 15:50 UTC

An advanced, multilingual malware family brings back a trick from yesteryear — screen hijacking — for effective password theft, along with a slew of novel features.

MalwareRansomware
P15
2026-08-24 14:32 UTC
Security Journalism

⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-24 16:05 UTC

A package gets installed. A login prompt opens. A box sits exposed to the internet. Nothing looks unusual yet. That’s roughly the mood this week. Trusted tools turn hostile, old weak spots get fresh attention, AI makes exploit work cheaper, and researchers keep finding attacks that sound harder than they actually are. Plenty to clean up. Here’s the short version. ⚡ Threat of the Week U.S.

ICS / OT
P0
2026-08-24 14:00 UTC
Security Journalism

South Korean startup platform breach exposes key management failures

BleepingComputer · Sponsored by Penta Security · indexed 2026-08-24 14:05 UTC

A breach at South Korea's government-backed startup platform exposed encrypted personal data after an encryption key was included in an API. Penta Security explains why encryption keys must be securely managed and kept separate from the data they protect. [...]

P0
5 6 7 8 9