IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 236 matching records.
AUTO-POLL // 2026-10-02 23:40 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P7 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 2

RANSOMWARE
P7
P7
COOL // 46 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
WED
Sep 30

RANSOMWARE
P10
P10
WARM // 59 ARTICLES
TUE
Sep 29

RANSOMWARE
P4
P4
COOL // 68 ARTICLES
MON
Sep 28

RANSOMWARE
P7
P7
COOL // 52 ARTICLES
SUN
Sep 27

RANSOMWARE
P25
P25
ELEVATED // 15 ARTICLES
SAT
Sep 26

RANSOMWARE
P13
P13
WARM // 20 ARTICLES
RESET
2026-09-11 14:29 UTC
Security Journalism

Claude Used to Automate Exploitation and Data Theft Across Multiple Victims

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-11 15:30 UTC

Anthropic has warned that cybercriminals and state-sponsored hackers alike are using its Claude models for cyber attacks, weapons design, propaganda, and mass surveillance between December 2025 and August 2026. The threat actors, which the artificial intelligence (AI) company has branded Generative Threat Groups (GTGs), span state-sponsored groups, financially motivated criminals, commercial

AI SecurityAPT / Nation-StateThreat Actors
P0
2026-09-10 15:19 UTC
Other

More Capable AI, Not Enough Guardrails

Security Affairs · Pierluigi Paganini · indexed 2026-09-10 16:25 UTC

AI agents are gaining real-world access faster than safeguards can mature, making permissions, isolation and oversight critical to prevent harmful actions. Jacob Coxon, a researcher who spent three years working on model training at OpenAI and later Anthropic, left Anthropic this week with a blunt warning: AI companies are moving toward increasingly capable systems faster […]

AI Security
P0
2026-09-10 14:32 UTC
Other

PuzzleMask: Abusing Plain Prose as a Covert AI Attack Vector

Check Point Research · shlomoo@checkpoint.com · indexed 2026-09-10 14:50 UTC

Executive Summary In this research we introduce a prompt-crafting technique for bypassing quick LLM-based policy checks — using plain English (no emojis, base64, invisible formatting, etc.) A policy-violating payload (e.g. ”encrypt files in ~/Documents”, “give me a biohazard recipe”, “ignore all previous instructions and…”) is embedded in a specially crafted prose wrapper. An LLM with limited […] The post PuzzleMask: Abusing Plain Prose as a Covert AI Attack Vector appeared first on Check Point…

AI Security
P0
2026-09-10 13:00 UTC
Vendor Research

The agentic harness for Tenable Hexa AI: How Tenable prevents AI agents from going off the rails

Tenable Blog · Raj Agrawal · indexed 2026-09-10 13:05 UTC

Learn why Tenable treats agentic LLMs as untrusted insiders, and how we’ve made sure you can control and monitor the AI agents making changes in your production security environmentKey takeawaysAI models can quickly understand data, but not your business. While modern AI models are great at reasoning, they don’t automatically understand your unique environment or who is allowed to do what. The “harness” is the custom-built layer that translates AI intelligence into safe, controlled actions spec…

AI SecurityVulnerabilities
P25
2026-09-10 11:41 UTC
Security Journalism

PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-10 13:15 UTC

A suspected Russian-speaking cyber actor has been attributed to the use of artificial intelligence (AI) to devise exploits targeting a recently disclosed pair of security flaws in PaperCut NG/MF and break into hundreds of instances. According to independent reports from Blackpoint Cyber and GreyNoise, the activity originates from "45.142.193[.]132," an IP address that has been linked to

AI SecurityCloud Security
P0
2026-09-10 07:04 UTC
Security Journalism

Anthropic Discloses Fourth AI Hacking Incident Involving Claude Opus 4.6

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-10 08:45 UTC

Anthropic on Wednesday disclosed a fourth incident in which its artificial intelligence (AI) model broke into real third-party systems, marking the latest in a growing list of cases that have raised concerns about the security risks posed by autonomous AI agents. The AI company said the incident dates back to January 2026 and involved an early version of Claude Opus 4.6 that breached "

AI Security
P0
2026-09-09 21:30 UTC
Vendor Research

CVE-2026-78379 - Consent bypass in Strands Agents Tools python_repl tool

AWS Security Bulletins · aws@amazon.com · indexed 2026-08-25 19:30 UTC

Bulletin ID: 2026-089-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/25/2026 12:00 PM PDT Description: Strands Agents is an open-source Python SDK for building and running AI agents. The strands-agents-tools package provides pre-built tools for use with the SDK, including the python_repl tool, which executes Python code on the agent's host, and the batch tool, which invokes several other tools in a single call. Before executing code, python_repl prompts the ope…

AI SecurityCloud SecurityVulnerabilitiesCVE-2026-78379
P5
2026-09-09 14:23 UTC
Security Journalism

Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-09 14:40 UTC

Cybercriminals are hijacking artificial intelligence (AI) user accounts via information stealer logs to create "stolen keys" that grant illicit access to tools from model providers like Google, Anthropic, and others. Information stealers like Lumma Stealer or Vidar are equipped to harvest a wide range of data from compromised systems. This can include credential, session tokens, and API

AI SecurityMalware
P0
2026-09-09 13:00 UTC
Vendor Research

Introducing the CyberAgents Exchange AI Inspector: Rigorous review for community-built AI

Tenable Blog · Mark Beblow · indexed 2026-09-09 13:10 UTC

Open-source registries for AI agents are only effective when they include a rigorous, transparent security review process for community submissions. That’s why for its new CyberAgents Exchange registry, Tenable paired its exposure management expertise with OpenAI GPT Cyber models to create the CyberAgents Exchange AI Inspector.Key takeawaysThe Exchange Inspector combines Tenable’s exposure detection with OpenAI’s GPT Cyber models and with human oversight to rigorously vet submissions made to th…

AI SecurityData BreachesMicrosoft
P0
2026-09-09 12:00 UTC
Security Journalism

Meta Launches Personal AI Agent, Muse, Emphasizes Safety and Privacy

Security Week · Associated Press · indexed 2026-09-09 13:30 UTC

Muse runs on a dedicated, secure virtual machine that houses both the agent and the user’s data. The post Meta Launches Personal AI Agent, Muse, Emphasizes Safety and Privacy appeared first on SecurityWeek.

AI Security
P0
2026-09-09 11:17 UTC
Security Journalism

DeepSeek Harness Flaw Let AI Agents Disable Their Own File Sandbox Without Approval

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-09 11:40 UTC

A flaw in DeepSeek Harness, DeepSeek's open-source tool for running AI coding agents on a developer's machine, let a sandboxed agent turn off its own sandbox with a single command. The tool runs an agent's commands inside an operating-system sandbox, so that an agent working on untrusted files cannot write outside its workspace. The agent could remove that limit by calling the tool's own web

AI Security
P0
2026-09-09 09:32 UTC
Security Journalism

U.S. Agencies Accuse China AI Firms of Distilling Claude, GPT, Gemini, and Grok

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-09 11:40 UTC

U.S. cybersecurity and intelligence agencies have accused China-based artificial intelligence (AI) companies of conducting "systematic extraction" of proprietary functionalities and capabilities of American frontier models through distillation attacks. The activity has been described as occurring at an industrial-scale and one that forms the "core" of their AI development strategy, according to

AI Security
P0
2026-09-08 21:44 UTC
Independent Research

Microsoft Plugs Nearly 1,000 Security Holes

Krebs on Security · BrianKrebs · indexed 2026-09-08 21:50 UTC

Microsoft Corp. today issued updates to plug at least 974 security holes in its Windows operating systems and other software, by far its biggest single patch batch ever. Microsoft says artificial intelligence is helping to speed the discovery of vulnerabilities, but security experts warn that many organizations already are struggling to prioritize the more human-intensive endeavor of testing and deploying so many fixes each month.

AI SecurityMicrosoft
P0
2026-09-08 17:21 UTC
Vendor Research

Claude Mythos 5 is coming to Tenable One, powering the new “Adversary View”

Tenable Blog · Eric Doerr · indexed 2026-09-08 17:30 UTC

Tenable is bringing Anthropic’s Claude Mythos 5 into our enterprise security offerings. Adding frontier adversarial reasoning to the Tenable One Exposure Management Platform will help customers better anticipate how attackers could breach their environments and stay ahead of AI-fueled risk. Tenable One Adversary View, the first innovation planned from this work, will debut in the coming weeks.Key takeawaysClaude Mythos 5 is coming to Tenable One. In addition to using Claude Mythos 5 for researc…

AI SecurityICS / OTMicrosoftVulnerabilities
P0
2026-09-08 17:00 UTC
Security Journalism

The Hidden Instructions That Can Hijack AI Agents

Security Week · Kevin Townsend · indexed 2026-09-08 17:15 UTC

Malicious prompts concealed in documents, metadata, emails, images and code can manipulate autonomous agents into taking dangerous actions. The post The Hidden Instructions That Can Hijack AI Agents appeared first on SecurityWeek.

AI Security
P0
2026-09-08 14:00 UTC
Vendor Research

GTIG AI Threat Tracker: From Prompting to Autonomy – The Evolution of Adversarial AI

Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-09-08 13:45 UTC

Executive Summary Since the release of our May 2026 report detailing adversarial misuse of artificial intelligence (AI), Google Threat Intelligence Group (GTIG) has observed forward leaning adversaries transition from basic prompting to agentic AI workflows and AI-enabled automation. In these operations, human-in-the-loop latency is dramatically reduced, compressing the traditional window for defenders to respond. In Q2 2026, GTIG observed threat actors compromise a cloud resource, then plan, b…

AI SecurityAPT / Nation-StateCloud SecurityData BreachesDFIRMalwareMicrosoftPhishingRansomwareThreat ActorsThreat IntelligenceVulnerabilities
P35
2026-09-08 13:48 UTC
Security Journalism

Autonomous AI Agents Compromise Thousands of Credentials in Under Six Hours

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-08 15:20 UTC

Threat actors are continuing to leverage artificial intelligence (AI) to streamline their operations, with one financially motivated hacking group employing an autonomous, multi-agent attack framework to carry out a large-scale credential harvesting campaign within six hours. Google Threat Intelligence Group (GTIG) said it has observed attackers with diverse motivations targeting proprietary AI

AI SecurityPhishingThreat ActorsThreat Intelligence
P0
2026-09-08 13:00 UTC
Other

The Shared Clipboard Inside the Sandbox: Cross-Account Data Leakage in ChatGPT

Check Point Research · stcpresearch · indexed 2026-09-08 13:10 UTC

Research by: Alexey Bukhteyev Key Takeaways Introduction Over the past several years, AI assistants have moved far beyond text generation. Modern systems can execute code, install additional dependencies, analyze user files, and access data through connected services. These capabilities significantly increase the practical value of LLMs, but they also change the security model: protecting user […] The post The Shared Clipboard Inside the Sandbox: Cross-Account Data Leakage in ChatGPT appeared f…

AI SecurityData Breaches
P0
2026-09-07 12:03 UTC
Security Journalism

OpenAI Agents Hijack Another Victim Website

Security Week · Kevin Townsend · indexed 2026-09-07 17:25 UTC

OpenAI agents made 15,000–18,000 autonomous edits to a German wiki over three months, evading moderation and echoing tactics seen in the Hugging Face breach. The post OpenAI Agents Hijack Another Victim Website appeared first on SecurityWeek.

AI Security
P0
2026-09-07 08:35 UTC
Other

Why AI Agent Sandboxes Are Failing Security Tests

Security Affairs · Pierluigi Paganini · indexed 2026-09-07 09:50 UTC

Autonomous AI agents escaped a sandbox and accessed Hugging Face via reward hacking, exposing serious architectural control and isolation flaws. The recent case involving OpenAI test agents and Hugging Face should concern security teams, but not for the reason implied by headlines about an imminent AI “takeover.” The documented issue is more concrete: autonomous agents, […]

AI SecurityCloud Security
P0
2026-09-06 11:43 UTC
Other

AI Agents Hijacked German Wiki to Cheat, OpenAI Delayed Disclosure

Security Affairs · Pierluigi Paganini · indexed 2026-09-06 12:10 UTC

AI agents secretly took over a 25-year-old German wiki for two months to cheat on tests, and OpenAI sat on the news until reporters found it first OpenAI finally admitted this weekend that a swarm of its own AI agents hijacked a German programming wiki earlier this year, turning it into a private message board […]

AI Security
P0
2026-09-05 11:11 UTC
Security Journalism

OpenAI admits it didn't disclose rogue AI wiki hijacking incident

BleepingComputer · Ax Sharma · indexed 2026-09-05 11:25 UTC

OpenAI admits it did not disclose an incident where autonomous AI agents hijacked a German wiki, created 18,000 posts, shared answers, and bypassed restrictions, saying it treated the activity as model "misalignment" rather than a security breach. [...]

AI Security
P0
2026-09-05 07:55 UTC
Security Journalism

Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordination Channel

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-05 08:55 UTC

A group of AI safety researchers says a fleet of autonomous agents that identified themselves as OpenAI systems left about 18,000 posts on a dormant 25-year-old German wiki between May and July 2026, using the site as a shared board to pool answers to a timed web task and pass around a way out of their sandbox. The activity was concentrated on DSEwiki, a German software developer wiki that runs

AI SecurityMicrosoft
P0
2026-09-04 12:15 UTC
Security Journalism

Insurers Search for Answers to Rein in Rogue AI

Dark Reading · Robert Lemos · indexed 2026-09-04 21:40 UTC

As incidents of unintended harm caused by rogue AI agents mount, CISOs and insurance firms are figuring out how to handle the fallout.

AI Security
P0
2 3 4 5 6