IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 1,240 matching records.
AUTO-POLL // 2026-09-04 08:50 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
WARM
COOL WARM ELEVATED HOT CRITICAL
P16 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Sep 4

ACTIVE EXPLOITATION
P16
P16
WARM // 6 ARTICLES
THU
Sep 3

RANSOMWARE
P5
P5
COOL // 44 ARTICLES
WED
Sep 2

RANSOMWARE
P11
P11
WARM // 47 ARTICLES
TUE
Sep 1

RANSOMWARE
P6
P6
COOL // 43 ARTICLES
MON
Aug 31

RANSOMWARE
P1
P1
COOL // 37 ARTICLES
SUN
Aug 30

RANSOMWARE
P6
P6
COOL // 9 ARTICLES
SAT
Aug 29

RANSOMWARE
P9
P9
COOL // 8 ARTICLES
RESET
2026-09-04 08:24 UTC
Other

Google fixes the sixth actively exploited Chrome zero-day of 2026

Security Affairs · Pierluigi Paganini · indexed 2026-09-04 08:50 UTC

Google patched 12 Chrome flaws, including an actively exploited V8 zero-day that could enable remote code execution through a crafted webpage. Google released a Chrome security update fixing 12 vulnerabilities, including CVE-2026-85046 (CVSS score of 8.8), an actively exploited V8 type confusion flaw. The bug affects Chrome’s JavaScript and WebAssembly engine and could let a […]

Cloud SecurityVulnerabilitiesCVE-2026-85046
P45
2026-09-04 07:35 UTC
Security Journalism

Plex Urges Immediate Updates After Patching Multiple Undisclosed Security Flaws

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-04 08:40 UTC

Plex is urging users to update their instances to the latest version following the release of an update that patches multiple security flaws. The fixes are available in Plex Media Server 1.43.3 and Plex Desktop 1.115.0. The streaming media service did not elaborate on what those issues are, but said CVE identifiers have been requested for them. "We recommend all server owners and Desktop users

Cloud Security
P0
2026-09-04 07:18 UTC
Security Journalism

Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-04 08:40 UTC

Google on Thursday released security updates to patch 12 vulnerabilities, including one that has come under active exploitation in the wild. The high-severity vulnerability, tracked as CVE-2026-85046 (CVSS score: 8.8), has been described as a type confusion bug in V8, Chrome's JavaScript and WebAssembly engine. "Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote

VulnerabilitiesCVE-2026-85046
P50
2026-09-04 07:02 UTC
Other

Dark Web Service Nexus Sells 153M+ Driver’s Licenses

Security Affairs · Pierluigi Paganini · indexed 2026-09-04 07:55 UTC

FBI probes suspected breach at IDScan.net after dark web service Nexus offered 153M+ US and Canadian driver’s license scans. A dark web identity theft service called Nexus appeared on September 1, 2026, offering searchable access to more than 153 million scanned driver’s licenses belonging to people in the United States and Canada. The FBI’s New […]

CybercrimeLaw Enforcement
P0
2026-09-04 06:47 UTC
Security Journalism

GPT-6 Astra Scores 100% on ExploitBench as OpenAI Blocks PoC Exploit Requests

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-04 08:40 UTC

OpenAI on Thursday officially unveiled GPT‑6 Astra, which it described as the "world's most intelligent and aligned model." The development comes days after the artificial intelligence (AI) company said the model had reached the "Critical" cybersecurity capability threshold under its Preparedness Framework. "Astra is state-of-the-art on computer use, browsing, software engineering,

AI SecuritySecurity Research
P0
2026-09-03 22:01 UTC
Security Journalism

French hospital fined €500,000 after breach exposes data of 727,000

BleepingComputer · Bill Toulas · indexed 2026-09-03 22:10 UTC

France's data protection authority (CNIL) has fined Hôpital privé de la Loire €500,000 ($580,000) for failing to adequately protect patients' and their relatives' data. [...]

P0
2026-09-03 21:15 UTC
Vendor Research

Incident response guide for AWS CloudTrail investigations – Part 2

AWS Security Blog · Oscar Diaz · indexed 2026-09-03 21:35 UTC

In Part 1 of this guide, we examined two common incident scenarios: cross-account Amazon Simple Storage Service (Amazon S3) data deletion with ransomware implications, and cryptocurrency mining deployed through AWS CloudFormation using exposed AWS Management Console credentials. We also introduced key incident response terminology and investigative frameworks for analyzing AWS CloudTrail events. In this second […]

AppleCloud SecurityDFIRRansomware
P15
2026-09-03 21:15 UTC
Vendor Research

Incident response guide for AWS CloudTrail investigations – Part 1

AWS Security Blog · Oscar Diaz · indexed 2026-09-03 21:35 UTC

AWS CloudTrail logs contain the evidence you need when investigating suspicious activity in your AWS environment, but knowing which fields matter and how to interpret them can mean the difference between surface-level analysis and uncovering the full scope of an incident. This guide walks you through real-world scenarios, showing you how to analyze CloudTrail events […]

AppleCloud SecurityDFIR
P0
2026-09-03 21:03 UTC
Vendor Research

Introducing context-aware vulnerability discovery and remediation with Cloudflare Managed Defense and OpenAI Daybreak models

Cloudflare Security · Ken Sanderson · indexed 2026-09-03 21:05 UTC

Use production traffic and security signals to prioritize findings, prepare edge mitigations when safe, and propose code patches. By combining WAF data with OpenAI Daybreak models, Vulnerability Discovery and Remediation helps teams identify and patch the most critical threats first.

Vulnerabilities
P0
2026-09-03 20:17 UTC
Other

Pegasus and NoviSpy Used Against Serbian Protesters

Security Affairs · Pierluigi Paganini · indexed 2026-09-03 20:25 UTC

Serbian activists were targeted with zero-click Pegasus and NoviSpy spyware, exposing a major surveillance campaign ahead of elections. A member of Serbia’s student protest movement had their iPhone infected with NSO Group‘s Pegasus spyware without ever clicking a link or opening a file. The Citizen Lab confirmed the infection in collaboration with the SHARE Foundation, […]

Apple
P0
2026-09-03 20:04 UTC
Security Journalism

Coder's registry infrastructure compromised to push malicious modules

BleepingComputer · Bill Toulas · indexed 2026-09-03 20:15 UTC

Attackers compromised Coder's Cloudflare infrastructure and added unauthorized registry servers that delivered malicious Terraform modules containing credential-stealing code. [...]

P0
2026-09-03 19:47 UTC
Other

Cisco Fixed Critical RCE in Nexus 9000 Series Switches

Security Affairs · Pierluigi Paganini · indexed 2026-09-03 20:25 UTC

Cisco patched a critical Nexus 9000 vulnerability, CVE-2026-20212, allowing unauthenticated remote root code execution. Cisco has released patches for a critical flaw, tracked as tracked as CVE-2026-20212 (CVSS score of 9.8) in 10 Silicon One-based Nexus 9000 switches. The vulnerability could let an unauthenticated remote attacker execute code with root privileges. Cisco’s Technical Assistance Center […]

Network SecurityVulnerabilitiesCVE-2026-20212
P30
2026-09-03 19:42 UTC
Security Journalism

What We Missed: Did ShinyHunters 'Breach' ReliaQuest?

Dark Reading · Rob Wright · indexed 2026-09-03 20:15 UTC

In this video conversation, Dark Reading editors discuss some of the news they didn't get a chance to cover, from the latest antics of ShinyHunters to new research about the prevalence (or lack thereof) of AI-generated malware.

Malware
P0
2026-09-03 19:30 UTC
Security Journalism

Large group of Serbian opposition, activist figures targeted with spyware

The Record · indexed 2026-09-03 19:45 UTC

At least 14 Serbians have been targeted with advanced spyware since December, with victims including a member of Parliament, a local opposition politician and student protesters, according to digital forensic researchers.

P0
2026-09-03 18:53 UTC
Vendor Research

Cisco IOS XR Software Security Hardening Release: September 2026

Cisco Security Advisories · indexed 2026-09-02 16:10 UTC

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. These vulnerabilities were found during internal testing and are not known to be actively exploited. To assist customers in patching and streamline the disclosure process, Cisco has grouped these issues by …

AppleVulnerabilitiesCVE-2026-20274CVE-2026-20275CVE-2026-20276CVE-2026-20277CVE-2026-20278CVE-2026-20279CVE-2026-20280
P30
2026-09-03 18:20 UTC
Vendor Research

CVE-2026-85028: Creation of Temporary File in Directory with Insecure Permissions in AWS FPGA Development Kit

AWS Security Bulletins · aws@amazon.com · indexed 2026-09-03 18:25 UTC

Bulletin ID: 2026-096-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/03/2026 11:00 AM PDT Description: The AWS FPGA Developer Kit is a hardware-software development kit that enables developers to create accelerators for the high-performance accelerator cards on EC2 F2 instances. We identified CVE-2026-85028, where a creation of a temporary file in a directory with insecure permissions in the FPGA management tool installation component in AWS FPGA Development Ki…

Cloud SecurityVulnerabilitiesCVE-2026-85028
P5
2026-09-03 18:02 UTC
Security Journalism

ThreatsDay: CEO Phishing Kits, 5K Dropbox Account Hacks, OAuth Traps + 17 More Stories

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-03 19:15 UTC

The worst part is how normal these attacks look. A call from IT. A shared file. A trusted app. A simple request to click “Allow.” Why break in when someone might open the door? That idea runs through this edition. Attackers use real tools, fake login pages, old account links, and software guides that point to unsafe downloads. One wrong letter in a web address can be enough. There is also

Phishing
P0
2026-09-03 18:00 UTC
Vendor Research

The story behind the intelligence

Cisco Talos Intelligence Blog · Hazel Burton · indexed 2026-09-03 18:05 UTC

From engaging with cybercriminals to surviving a live Flamin’ Hot Cheetos taste test, Hazel reflects on the latest Beers with Talos with Azim, where they cover the full spectrum of what it takes to gather threat intel.

P0
2026-09-03 17:22 UTC
Vendor Research

CVE-2026-85012 - OS command injection in the Amazon CodeCatalyst blueprints SDK

AWS Security Bulletins · aws@amazon.com · indexed 2026-09-03 17:25 UTC

Bulletin ID: 2026-095-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/03/2026 10:00 AM PDT Description: Amazon CodeCatalyst blueprints are reusable project templates that generate a software project. The @amazon-codecatalyst/blueprints.blueprint npm package is the open source framework that blueprint authors build on, published from github.com/aws/codecatalyst-blueprints. We identified CVE-2026-85012 in the blueprint resynthesis framework. During resynthesis, th…

Cloud SecurityVulnerabilitiesCVE-2026-85012
P5
2026-09-03 16:00 UTC
Vendor Research

ASCII smuggling crosses over from AI prompt injection to phishing evasion

Microsoft Security Blog · Microsoft Security Research, Noam Kochavi and Sarah Wolstencroft · indexed 2026-09-03 16:45 UTC

Invisible Unicode characters popularized for hiding instructions from AI models are now being used to obfuscate words before email filters parse them. The post ASCII smuggling crosses over from AI prompt injection to phishing evasion appeared first on Microsoft Security Blog.

AI SecurityMicrosoftPhishing
P0
2026-09-03 15:52 UTC
Security Journalism

Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-03 16:45 UTC

Cisco has released patches to address a critical security flaw affecting 10 Silicon One-based Nexus 9000 switches that could allow an unauthenticated, remote attacker to execute code as root, alongside an IOS XR hardening release bundling 7 umbrella CVEs, 2 of which are rated 9.8, with no workaround for any IOS XR version. The Nexus vulnerability, tracked as CVE-2026-20212 (CVSS score: 9.8), is

AppleNetwork SecurityVulnerabilitiesCVE-2026-20212
P5
2026-09-03 15:26 UTC
Security Journalism

BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-03 16:45 UTC

Cybersecurity researchers have disclosed details of a sophisticated Python-based Windows malware framework called BraZetsu that fuels an underground marketplace commercializing access to compromised hosts. "Unlike the standard infostealer model, BraZetsu is a comprehensive master toolkit that empowers Initial Access Brokers (IABs) by turning compromised systems into highly valuable commercial

CybercrimeMalwareMicrosoftSecurity Research
P0
2026-09-03 15:02 UTC
Security Journalism

Anthropic confirms Claude is down, multiple models affected

BleepingComputer · Mayank Parmar · indexed 2026-09-03 15:10 UTC

Claude is experiencing an outage, with users encountering elevated errors when sending requests to multiple Anthropic AI models. [...]

P0
2026-09-03 14:39 UTC
Security Journalism

Thomson Reuters Court Software Breach May Have Exposed SSNs and Sealed Data

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-03 16:45 UTC

Thomson Reuters disclosed on Wednesday that an unauthorized party obtained files from C-Track, the court case management platform sold by its West Publishing Corporation unit, in March 2026, affecting courts in 11 U.S. states, the U.S. Virgin Islands, and Ontario, Canada. West Publishing said it discovered the activity on June 30, 2026. A subset of court records could contain individuals' names

P0
1 2 3