IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 236 matching records.
AUTO-POLL // 2026-10-02 23:45 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P7 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 2

RANSOMWARE
P7
P7
COOL // 46 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
WED
Sep 30

RANSOMWARE
P10
P10
WARM // 59 ARTICLES
TUE
Sep 29

RANSOMWARE
P4
P4
COOL // 68 ARTICLES
MON
Sep 28

RANSOMWARE
P7
P7
COOL // 52 ARTICLES
SUN
Sep 27

RANSOMWARE
P25
P25
ELEVATED // 15 ARTICLES
SAT
Sep 26

RANSOMWARE
P13
P13
WARM // 20 ARTICLES
RESET
2026-09-04 11:00 UTC
Other

Chinese Hackers Use AI Agents in Multi-Country Cyber Campaign

Security Affairs · Pierluigi Paganini · indexed 2026-09-04 11:10 UTC

Hunt.io uncovered a Chinese-speaking campaign using AI agents to automate cyberattacks against Asian government, education and industrial targets. Threat intelligence firm Hunt.io just documented a second, separate China-linked campaign wiring commercial AI models directly into live cyberespionage operations, this time hitting Taiwan’s Kuomintang Party archives, Indonesia’s Ministry of Foreign Affairs, government and education systems in […]

AI SecurityAPT / Nation-StateThreat Intelligence
P0
2026-09-04 06:47 UTC
Security Journalism

GPT-6 Astra Scores 100% on ExploitBench as OpenAI Blocks PoC Exploit Requests

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-04 08:40 UTC

OpenAI on Thursday officially unveiled GPT‑6 Astra, which it described as the "world's most intelligent and aligned model." The development comes days after the artificial intelligence (AI) company said the model had reached the "Critical" cybersecurity capability threshold under its Preparedness Framework. "Astra is state-of-the-art on computer use, browsing, software engineering,

AI SecuritySecurity Research
P0
2026-09-03 16:00 UTC
Vendor Research

ASCII smuggling crosses over from AI prompt injection to phishing evasion

Microsoft Security Blog · Microsoft Security Research, Noam Kochavi and Sarah Wolstencroft · indexed 2026-09-03 16:45 UTC

Invisible Unicode characters popularized for hiding instructions from AI models are now being used to obfuscate words before email filters parse them. The post ASCII smuggling crosses over from AI prompt injection to phishing evasion appeared first on Microsoft Security Blog.

AI SecurityMicrosoftPhishing
P0
2026-09-03 14:38 UTC
Security Journalism

AI 'Machine Speed' Cuts 2-Week Attack Down to 10 Hours

Dark Reading · Elizabeth Montalbano · indexed 2026-09-03 15:00 UTC

The incident demonstrates how frontier AI agents can dramatically compress an attack timeline and coordinate a large-scale breach, according to researchers.

AI Security
P0
2026-09-02 18:36 UTC
Vendor Research

Agentic security: Detection and response at machine speed

AWS Security Blog · Gee Rittenhouse · indexed 2026-09-02 18:45 UTC

After talking with enterprise security leaders over the past year, one thing has become clear: the rise of autonomous AI agents is the most significant shift in security posture since the move to cloud. Organizations across every industry are adopting AI agents that authenticate on behalf of users, execute multistep workflows, and make decisions across […]

AI Security
P0
2026-09-02 14:06 UTC
Security Journalism

Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-02 14:15 UTC

Manifold Security has disclosed eight security flaws across seven command-line AI coding agents in which a repository's own Git configuration names a command that the agent runs on the developer's machine, four of them still unpatched at publication. The command executes as the user, outside the agent's sandbox and without an approval prompt, and exploitation requires the repository to arrive

AI SecurityCloud Security
P0
2026-09-02 10:00 UTC
Vendor Research

An AI-Assisted Cyber Attack: Inside a Unit 42 Investigation

Palo Alto Networks Unit 42 · Renzon Cruz, Nicolas Bareil, Eric Semaan and Omar Jbari · indexed 2026-09-02 10:25 UTC

Using autonomous AI agents, an attacker breached an enterprise network in a matter of hours. Understand how to address and defend against agentic attacks. The post An AI-Assisted Cyber Attack: Inside a Unit 42 Investigation appeared first on Unit 42.

AI SecurityDFIR
P0
2026-09-01 14:00 UTC
Vendor Research

Financially Motivated Threat Actor BREEZE COMET Targets Brazil

Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-09-01 03:50 UTC

Introduction Beginning in 2024 Mandiant investigated a string of compromises affecting Brazilian financial services, retail, and eCommerce organizations. Google Threat Intelligence Group (GTIG) tracks this activity as BREEZE COMET (formerly UNC5669), a financially motivated threat actor specializing in manipulating payment systems and banking software in Brazil to conduct fraudulent transfers. This activity overlaps with operations publicly reported as Plump Spider and SHADOW-AETHER-064. In thi…

AI SecurityCloud SecurityCybercrimeMalwareMicrosoftNetwork SecurityPhishingThreat ActorsThreat Intelligence
P0
2026-09-01 09:05 UTC
Security Journalism

Attackers Steal METR API Key and Consume AI Credits Worth About $600,000

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-01 10:35 UTC

METR (short for Model Evaluation and Threat Research and pronounced "Meter"), a research non-profit that evaluates frontier artificial intelligence (AI) models for their ability to carry out long-horizon, agentic tasks, disclosed that it suffered "two notable security incidents" where external actors attempted to gain unauthorized access to its systems. No sensitive information is believed to

AI Security
P0
2026-09-01 08:26 UTC
Security Journalism

Russia-Aligned UAC-0099 Plants Nuclear Weapon Prompt in Malware to Disrupt AI Analysis

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-01 08:55 UTC

Cybersecurity researchers have disclosed a new technique dubbed GuardBreaker that's been put to use by a Russia-aligned threat actor known as UAC-0099 against a target in Ukraine with an aim to interfere with artificial intelligence (AI)-assisted analysis. The idea, ESET said in a series of posts on X, is to deliberately trip a large language model's (LLM) safety mechanisms and prevent its

AI SecurityMalwareSecurity ResearchThreat Actors
P0
2026-08-31 20:00 UTC
Community

The Coding-Agent Trap: When a "Free" LLM Endpoint Is the Adversary, (Mon, Aug 31st)

SANS Internet Storm Center · indexed 2026-08-31 20:10 UTC

One of my internet-exposed inference honeypots was discovered, relabeled with sought-after model names, and incorporated into infrastructure apparently used to provide "free" LLM backends. It then received a real coding-agent session — history, filesystem output, working paths, and the agent's local tool manifest. The honeypot did not request or cause any tool execution; what the request exposed is what a malicious operator in that position could do.

AI Security
P0
2026-08-31 13:50 UTC
Security Journalism

⚡ Weekly Recap: Chinese Spy Proxy, AI Agents Go Off-Task, Router Backdoors and More

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-31 14:30 UTC

The boring parts caused most of the trouble. A router shipped ready to listen. A fake check turned the user into the installer. Trusted systems collected traffic and passwords, then cleaned the logs. Old bugs formed new attack chains. Even an AI agent decided its assigned task was optional. Elsewhere, fake apps, helpful support calls, cheap banking kits, exposed systems, and weak defaults kept

AI SecurityMalwareNetwork Security
P0
2026-08-31 11:47 UTC
Security Journalism

Aurora Ransomware Operators Use Cursor AI in Attacks Against 10 Targets

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-31 12:30 UTC

Threat actors associated with Aurora (aka Aur0ra) ransomware have been observed using SpaceX's artificial intelligence (AI)-powered coding assistant Cursor to break into target networks, according to findings from CloudSEK and Gambit Security. The two independent analyses are based on exposed infrastructure associated with the Russian-speaking cybercrime group, leading to the discovery of its

AI SecurityCybercrimeRansomwareThreat Actors
P15
2026-08-28 22:00 UTC
Vendor Research

Perturbation Probing: A New Diagnostic for the Fragility of LLM Safety

Palo Alto Networks Unit 42 · Tony Li, Hongliang Liu and Yuhao Wu · indexed 2026-08-28 22:10 UTC

New research reveals that AI safety refusal lives in a thin neural layer, highlighting the critical need for external, multi-layered security. The post Perturbation Probing: A New Diagnostic for the Fragility of LLM Safety appeared first on Unit 42.

AI Security
P0
2026-08-28 20:19 UTC
Security Journalism

Hundreds of OpenAI Agents Invaded Hugging Face Servers

Dark Reading · Nate Nelson · indexed 2026-08-28 20:45 UTC

The Hugging Face incident was bigger and worse than previously thought, with approximately 700 agents collaborating on a sophisticated, multistage attack.

AI Security
P0
2026-08-27 21:38 UTC
Security Journalism

Nearly 700 rogue AI agents coordinated in the Hugging Face attack

BleepingComputer · Bill Toulas · indexed 2026-08-27 21:45 UTC

New details about the July attack on Hugging Face reveal that hundreds of AI agents driven by OpenAI's internal IM1 model coordinated the compromise through an unauthorized message board. [...]

AI Security
P0
2026-08-27 18:36 UTC
Security Journalism

OpenAI Says Reward Hacking Drove AI Agents to Exploit Zero-Days and Breach Hugging Face

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-27 20:30 UTC

OpenAI on Wednesday revealed that reward hacking was a key driver behind the artificial intelligence (AI)-powered hack of Hugging Face last month, adding that it found evidence of misaligned behavior as early as late May. The incident, the company said, took place during cybersecurity evaluations of several OpenAI models, and that it was mainly fueled by what it described as a "highly capable

AI SecurityVulnerabilities
P25
2026-08-27 16:20 UTC
Vendor Research

Extend Amazon Bedrock Guardrails to Tool Interactions Using the Strands Agents SDK

AWS Security Blog · Stephan Traub · indexed 2026-08-27 16:35 UTC

If you’re running AI agents in production, Amazon Bedrock Guardrails protects the model boundary. But your agents also invoke tools, fetch external data, and communicate with other systems. That data flows outside the model boundary, where model-level guardrails can’t reach. You can extend guardrail coverage to those interactions using three validation checkpoints built with the […]

AI Security
P0
2026-08-27 14:30 UTC
Vendor Research

How to build an exposure management program the business trusts: Lessons from Tenable’s CSO

Tenable Blog · Robert Huber · indexed 2026-08-27 14:40 UTC

Discover how Tenable’s shift to an AI-driven exposure management program helped Tenable’s CSO, Robert Huber, overcome tool sprawl, unify data silos, mitigate the risk of rapid AI adoption, and shift from presenting granular, technical metrics to communicating business risk that the C-suite and the board can understand.Key takeawaysSecurity tool sprawl and data silos make it difficult for CISOs to holistically and accurately assess their organizations’ cyber risk.An exposure management program c…

AI SecurityAppleCloud SecurityMicrosoftVulnerabilities
P0
2026-08-27 13:39 UTC
Security Journalism

Amazon Kiro Prompt Injection Can Exfiltrate Sensitive Data Through Kiro Powers

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-27 15:05 UTC

Cybersecurity researchers have disclosed details of a vulnerability in Amazon Kiro, an artificial intelligence (AI)-powered, agentic integrated development environment (IDE), that could facilitate data exfiltration via prompt injection and Kiro Powers. The security flaw, which does not have a CVE identifier, works against Kiro IDE 0.7.45 on Windows, according to Mindgard. The latest version of

AI SecurityMicrosoftSecurity ResearchVulnerabilities
P0
2026-08-26 19:32 UTC
Vendor Research

ICYMI: July 2026 @AWS Security

AWS Security Blog · Rodolfo Brenes · indexed 2026-08-26 19:40 UTC

If you found time for a bit of vacation this summer, you might be in catch-up mode. Here’s a list to help: all the expert blog posts, new service capabilities, code samples, and workshops, in case you missed it, from July 2026. AWS Security Blog post This month’s AWS Security Blog posts covered AI agent […]

AI SecurityCloud Security
P0
2026-08-26 09:38 UTC
Security Journalism

OpenAI Bans Russian ChatGPT Accounts Used to Run Influence Operation

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-26 10:35 UTC

OpenAI on Tuesday said it banned a cluster of Russian ChatGPT accounts that used VPNs to bypass access restrictions and run an influence operation, which relied on its artificial intelligence (AI) tool to generate social media posts and comments that were shared on Substack, Telegram, X, Facebook and LinkedIn. The accounts "were being used to promote the International Burke Institute (IBI), a

AI SecurityNetwork Security
P0
2026-08-25 14:07 UTC
Security Journalism

A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-25 15:10 UTC

Oasis Security has disclosed a weakness in NVIDIA NemoClaw that could let an attacker-controlled webpage take unauthenticated control of the local Ollama instance serving an AI agent and plant hidden instructions inside the model itself. The findings were shared with The Hacker News ahead of publication, and the report says Oasis Security reported them to NVIDIA's Product Security Incident

AI Security
P0
2026-08-25 14:00 UTC
Security Journalism

Ukraine to give Britain access to battlefield data to train AI

The Record · indexed 2026-08-25 14:15 UTC

Ukraine will give Britain access to a vast trove of battlefield data collected during the war with Russia, allowing U.K. companies and researchers to use it to train and test artificial intelligence systems.

AI Security
P0
2026-08-21 18:53 UTC
Security Journalism

14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-21 20:30 UTC

Cybersecurity researchers have discovered a set of trojanized npm packages that masquerade as working calendar and streak utilities but are engineered to stealthily deliver an artificial intelligence (AI)-powered Linux implant dubbed RedC2 4.0. "When the module loads, it locates the bundled binary, marks it executable, and launches it as a detached background process," TrendAI, Trend Micro's

AI SecurityLinuxMalwareSecurity Research
P0
2026-08-21 13:30 UTC
Security Journalism

OpenAI Adds Controls That Should've Been There Already

Dark Reading · Alexander Culafi · indexed 2026-08-21 13:35 UTC

The new AI security controls follow the Hugging Face incident last month, though experts say many of these additions should have been in place prior to the frontier models escaping.

AI Security
P0
2026-08-21 11:21 UTC
Security Journalism

Wazuh and AI For Enhanced SOC Workflows

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-21 12:35 UTC

Artificial Intelligence (AI) has become one of this decade's defining technologies. From healthcare and finance to manufacturing and education, organizations increasingly rely on AI to automate repetitive tasks, uncover patterns hidden within large datasets, and support faster decision-making. Cybersecurity has experienced a similar transformation. While attackers employ AI to automate

AI Security
P0
3 4 5 6 7