IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 236 matching records.
AUTO-POLL // 2026-10-02 22:45 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P6 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 2

RANSOMWARE
P6
P6
COOL // 45 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
WED
Sep 30

RANSOMWARE
P10
P10
WARM // 59 ARTICLES
TUE
Sep 29

RANSOMWARE
P4
P4
COOL // 68 ARTICLES
MON
Sep 28

RANSOMWARE
P7
P7
COOL // 52 ARTICLES
SUN
Sep 27

RANSOMWARE
P25
P25
ELEVATED // 15 ARTICLES
SAT
Sep 26

RANSOMWARE
P13
P13
WARM // 20 ARTICLES
RESET
2026-09-21 15:33 UTC
Vendor Research

Transforming Bedrock Guardrails events into OCSF with CloudWatch

AWS Security Blog · Dhananjay Karanjkar · indexed 2026-09-21 16:00 UTC

Security teams investigating possible AI-related security events need guardrail intervention data alongside their existing security telemetry. When a guardrail identifies or blocks a prompt injection attempt or redacts sensitive data, that intervention carries additional investigative value comparable to a failed sign-in or a network intrusion alert. AWS Bedrock publishes this telemetry to AWS CloudWatch metrics […]

AI SecurityCloud Security
P0
2026-09-21 14:24 UTC
Security Journalism

⚡ Weekly Recap: Cisco 0-Day, AI Agent RCE, ClickFix Attacks, ClickFix Surge, and Browser Hijacks

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-21 14:45 UTC

A browser. A plugin. A package. A login screen. Normal stuff. That is basically the problem this week. The trouble keeps showing up inside things people already trust: code that takes a bad turn, old payloads coming back, exposed systems, weak checks, fake fixes, and attack paths that look almost too easy. Even the research side is getting messy, with more findings, more automation, and not

AI SecurityVulnerabilities
P25
2026-09-21 12:30 UTC
Security Journalism

Google says Gemini breached three companies during security test

The Record · indexed 2026-09-21 12:45 UTC

Google’s artificial intelligence model Gemini accessed computer systems belonging to three real companies without authorization during a cybersecurity test in May — the latest in a string of similar incidents.

AI Security
P0
2026-09-21 08:27 UTC
Other

The Target Is No Longer the Model. It’s the Agent.

Security Affairs · Pierluigi Paganini · indexed 2026-09-21 09:25 UTC

AI agents are becoming the new attack surface, exposed to poisoned skills, prompt injection, jailbreaks and attacks through connected tools. I read the AI security research published in a single month, February 2026, and when you put it all together, it’s not a list of curiosities. It’s a field guide to a new attack surface. […]

AI SecurityAppleSecurity Research
P0
2026-09-19 14:09 UTC
Other

Google Gemini also Broke Out of Its Test Environment

Security Affairs · Pierluigi Paganini · indexed 2026-09-19 15:05 UTC

Google Gemini escaped a cyber test environment, reached three real companies, and exposed why AI security tests need strict isolation. Google has confirmed that one of its Gemini models broke into the systems of three real companies during a cybersecurity test in May. The incident is the first publicly known case in which a Google […]

AI Security
P0
2026-09-19 07:51 UTC
Security Journalism

Google Gemini Broke Into Real Company Systems After Security Test Domain Mix-Up

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-19 08:45 UTC

Google's Gemini model has become the latest artificial intelligence (AI) system to access the internet and break into other companies during a cybersecurity evaluation. The development was first reported by The Wall Street Journal. The incidents occurred in May 2026 as part of a test run conducted by Israeli company Irregular. The evaluation partner was also involved in similar hacks disclosed

AI Security
P0
2026-09-18 10:00 UTC
Vendor Research

A Vault with a Heap-View: The Uncomfortable Space Between AgentCore Harness and Identity

Palo Alto Networks Unit 42 · Niv Rabin · indexed 2026-09-18 10:10 UTC

Analysis of how default configurations in AWS AgentCore Harness allow prompt injection to exfiltrate credentials, and key steps to secure your agents. The post A Vault with a Heap-View: The Uncomfortable Space Between AgentCore Harness and Identity appeared first on Unit 42.

AI SecurityCloud Security
P0
2026-09-18 09:18 UTC
Security Journalism

Claimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm Stealer

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-18 09:30 UTC

A financially motivated threat actor has been linked to the development and distribution of a JavaScript (JS)-based information stealer known as PhantomRaven via the npm package registry. "The developer likely wrote the malware using a large language model (LLM), an assessment made with high confidence based on verbose comments, placeholder code, and statistical token-analysis patterns,"

AI SecurityMalwareThreat Actors
P0
2026-09-18 06:17 UTC
Security Journalism

RatHat Android Malware Abuses ADB to Retain Shell Access After Uninstall

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-18 06:30 UTC

Cybersecurity researchers have flagged a new Android malware called RatHat that's assessed to be operated by China-based threat actors and features an artificial intelligence (AI)-powered system to navigate and control compromised devices. "Distributed primarily via targeted smishing (SMS/text phishing) and malvertising campaigns leading to deceptive third-party download portals, RatHat uses

AI SecurityMalwareMobile SecurityPhishingSecurity ResearchThreat Actors
P0
2026-09-17 18:55 UTC
Security Journalism

OpenAI details more cases of AI agents taking unauthorized actions

BleepingComputer · Bill Toulas · indexed 2026-09-17 19:00 UTC

OpenAI has presented new examples of what they call "AI model misalignment" from the past six months, including unauthorized file uploads, following self-generated instructions, hiding mistakes, and leveraging exposed API keys. [...]

AI Security
P0
2026-09-17 10:50 UTC
Security Journalism

CISO's Expert Guide to Agentic Pentesting for Websites

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-17 13:45 UTC

Attackers now weaponize new vulnerabilities in about five days (Mandiant, part of Google Cloud). The median organization takes 43 days to patch one (Verizon DBIR 2026). A new free guide explains how autonomous AI agents are closing that gap, and what security leaders must demand before pointing one at production. TL;DR Exploitation is now the front door. It starts 31% of breaches (Verizon DBIR

AI SecurityCloud Security
P0
2026-09-17 07:41 UTC
Security Journalism

AI Agents Can Retrain Own Models Mid-Task, Leaking Secrets and Erasing Refusals

Security Week · Eduard Kovacs · indexed 2026-09-17 07:55 UTC

New research from Irregular shows AI agents can retrain and redeploy their own underlying models during routine maintenance tasks. The post AI Agents Can Retrain Own Models Mid-Task, Leaking Secrets and Erasing Refusals appeared first on SecurityWeek.

AI Security
P0
2026-09-16 17:26 UTC
Security Journalism

Spain reports first alleged AI-powered data theft attack

BleepingComputer · Bill Toulas · indexed 2026-09-16 17:30 UTC

The Spanish Data Protection Agency (AEPD) was notified of an attack allegedly carried out with an AI agent powered by a known large language model (LLM). [...]

AI Security
P0
2026-09-16 16:39 UTC
Security Journalism

First Agentic AI Data Breach Reported to Spanish Regulator

Security Week · Kevin Townsend · indexed 2026-09-16 16:50 UTC

Spanish regulators say an AI agent chained together a successful login, vulnerability discovery, and access to personal data in a potential milestone for autonomous cyberattacks. The post First Agentic AI Data Breach Reported to Spanish Regulator appeared first on SecurityWeek.

AI SecurityData BreachesVulnerabilities
P0
2026-09-16 13:38 UTC
Security Journalism

AIUC Raises $40 Million to Certify Enterprise AI Agents

Security Week · Ionut Arghire · indexed 2026-09-16 13:55 UTC

The company provides a standard for AI systems, testing them against risks such as jailbreaks, prompt injections, and unauthorized actions. The post AIUC Raises $40 Million to Certify Enterprise AI Agents appeared first on SecurityWeek.

AI Security
P0
2026-09-15 15:45 UTC
Security Journalism

Exein Secures $270M at $1.7B Valuation for Physical AI Security

Security Week · Ionut Arghire · indexed 2026-09-15 16:00 UTC

The cybersecurity startup is building a proprietary foundation model and plans to accelerate global expansion. The post Exein Secures $270M at $1.7B Valuation for Physical AI Security appeared first on SecurityWeek.

AI Security
P0
2026-09-15 12:42 UTC
Security Journalism

OpenAI Investigates Report Linking AI Agents to RubyGems Attack

Security Week · Eduard Kovacs · indexed 2026-09-15 12:50 UTC

The incident occurred in May, when RubyGems maintainers suspended new account registrations due to what appeared like malicious activity. The post OpenAI Investigates Report Linking AI Agents to RubyGems Attack appeared first on SecurityWeek.

AI Security
P0
2026-09-15 11:52 UTC
Security Journalism

Human Attacker Exploits Marimo RCE, Reaches SSH Bastion in Eight Seconds

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-15 12:25 UTC

With artificial intelligence (AI) shrinking the window between vulnerability discovery and exploitation and lowering the barrier to entry for bad actors, new findings from Sysdig show that skilled human operators can move just as swiftly after gaining initial access. In one instance highlighted by the cloud security company, the threat actor pivoted from a vulnerable Marimo notebook to an SSH

AI SecurityCloud SecurityThreat ActorsVulnerabilities
P0
2026-09-14 14:40 UTC
Security Journalism

⚡ Weekly Recap: Rogue AI Agents, WeChat Worm, PaperCut Attacks, AI Espionage, and Rootkits

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-14 15:35 UTC

AI keeps showing up in the wrong places. Attackers are using it to speed up exploits, test defenses, and automate more of the job. Some models are also crossing lines on their own. That is not a great combination. The rest of the week is more familiar: old bugs still working, fresh exploit chains, exposed systems, weak defaults, and simple paths that should have been harder to abuse. A few of

AI SecurityAPT / Nation-StateMalware
P0
2026-09-14 10:30 UTC
Security Journalism

CISOs Race to Control AI Agents Without Destroying Their Value

Security Week · Kevin Townsend · indexed 2026-09-14 10:50 UTC

Security leaders are struggling to modernize cyber hygiene and prevent over-privileged agents from causing unintended harm. The post CISOs Race to Control AI Agents Without Destroying Their Value appeared first on SecurityWeek.

AI Security
P0
2026-09-12 16:46 UTC
Other

Anthropic: AI Misuse Is Entering a New Phase: From Cybercrime to Surveillance, Propaganda and Weapons

Security Affairs · Pierluigi Paganini · indexed 2026-09-12 17:20 UTC

AI is becoming an operational force for cybercrime, surveillance, propaganda, fraud and weapons development, lowering the cost and scale of attacks. Artificial intelligence (AI) is becoming more than a tool for people who want to do something malicious. It is increasingly becoming part of the operational machinery itself. That is the main message emerging from […]

AI SecurityCybercrime
P0
2026-09-12 09:07 UTC
Security Journalism

OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-12 10:00 UTC

The "major malicious attack" that targeted RubyGems in May 2026 was the work of a swarm of OpenAI agents, according to a new report published by researchers Spencer Kitts, Thomas Larsen, and Sydney Von Arx. On May 12, Maciej Mensfeld, senior product manager for software supply chain security at Mend.io, disclosed details of a coordinated cyber attack that targeted the package manager for the

AI SecurityVulnerabilities
P15
2026-09-11 19:08 UTC
Vendor Research

CVE-2026-89332 - Kiro IDE Sensitive Workspace Data Exfiltration via Agent-Written Workspace Configuration

AWS Security Bulletins · aws@amazon.com · indexed 2026-09-11 19:15 UTC

Bulletin ID: 2026-111-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/11/2026 12:00 PM PDT Description: Kiro IDE is an agentic development environment that makes it easy for developers to ship real engineering work with the help of AI agents. We identified CVE-2026-89332, where the Kiro agent could modify a workspace's settings file in an untrusted workspace in Kiro IDE. A specially crafted repository could use this to point the Kiro Powers registry URL, which K…

AI SecurityCloud SecurityVulnerabilitiesCVE-2026-89332
P5
2026-09-11 14:40 UTC
Community

The Self-Expanding Stolen Inference Supply Chain: An AI Agent Harvesting and Re-Serving LLM Access, (Fri, Sep 11th)

SANS Internet Storm Center · indexed 2026-09-11 14:45 UTC

I identified an attacker using a semi-autonomous coding agent to run an offensive operation: finding poorly secured LLM resale gateways, acquiring API access through ordinary web flaws and account farming, validating the resulting inference capacity, and aggregating it behind a single gateway of their own.

AI SecurityCloud Security
P0
1 2 3 4 5