IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 236 matching records.
AUTO-POLL // 2026-10-03 01:10 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
NO DATA
NO INTELLIGENCE AGGREGATED TODAY
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 3
NO DATA
--
NO INTEL
FRI
Oct 2

RANSOMWARE
P7
P7
COOL // 46 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
WED
Sep 30

RANSOMWARE
P10
P10
WARM // 59 ARTICLES
TUE
Sep 29

RANSOMWARE
P4
P4
COOL // 68 ARTICLES
MON
Sep 28

RANSOMWARE
P7
P7
COOL // 52 ARTICLES
SUN
Sep 27

RANSOMWARE
P25
P25
ELEVATED // 15 ARTICLES
RESET
2026-04-02 16:00 UTC
Vendor Research

Google Workspace’s continuous approach to mitigating indirect prompt injections

Google Online Security Blog · Kimberly Samra · indexed 2026-08-15 14:33 UTC

Posted by Adam Gavish, Google GenAI Security TeamIndirect prompt injection (IPI) is an evolving threat vector targeting users of complex AI applications with multiple data sources, such as Workspace with Gemini. This technique enables the attacker to influence the behavior of an LLM by injecting malicious instructions into the data or tools used by the LLM as it completes the user’s query. This may even be possible without any input directly from the user.IPI is not the kind of technical proble…

AI SecurityMicrosoftSecurity ResearchVulnerabilities
P0
2026-04-01 14:00 UTC
Security Journalism

OpenClaw, Rogue Agents, and Application Hygiene

Huntress · indexed 2026-09-07 17:30 UTC

OpenClaw AI agents pose identity and data risks if deployed with broad cloud permissions. Learn how to find and secure these apps before an attacker does.

AI Security
P0
2026-03-23 12:00 UTC
Government

Reflections from the Second NIST Cyber AI Profile Workshop

NIST Cybersecurity Insights · Katerina Megas, Barbara Cuthill, Julie Nethery Snyder , Christina Sames, Ishika Khemani · indexed 2026-08-15 20:45 UTC

Thank you to everyone who participated in the Cybersecurity Framework Profile for Artificial Intelligence (Cyber AI Profile) Workshop in January! The input we received on the Preliminary Draft during this workshop has been invaluable and is informing the development of the next draft of the NIST Cyber AI Profile. We are working toward publishing a full workshop summary soon that captures themes and highlights from the event. In the interim, we would like to share a preview of what we heard… Bac…

AI Security
P0
2026-03-18 07:04 UTC
Other

AI Exposure and CTEM: The Next Frontier of External Risk

Red Hunt Labs · Sudhanshu Chauhan · indexed 2026-09-07 17:30 UTC

Prepared by: Sudhanshu Chauhan 🔗 (Director, RedHunt Labs) and Devang Solanki 🔗 (Security Researcher, RedHunt Labs) There is a loop in cybersecurity. A new technology enters the enterprise. Adoption moves faster than governance. Security teams hear about it during incident response instead of during planning. And the exposure window, that gap between deployment and visibility, gets exploited before anyone realizes it even existed. We saw it with open cloud storage buckets. We saw it with expos…

AI SecurityCloud SecurityDFIRSecurity ResearchVulnerabilities
P15
2026-03-11 13:00 UTC
Vendor Research

AI Security for Apps is now generally available

Cloudflare Security · Liam Reese · indexed 2026-08-15 18:58 UTC

Cloudflare AI Security for Apps is now generally available, providing a security layer to discover and protect AI-powered applications, regardless of the model or hosting provider. We are also making AI discovery free for all plans, to help teams find and secure shadow AI deployments.

AI Security
P0
2026-03-11 13:00 UTC
Vendor Research

AI Security for Apps is now generally available

Cloudflare Security · Liam Reese · indexed 2026-08-15 18:58 UTC

Cloudflare AI Security for Apps is now generally available, providing a security layer to discover and protect AI-powered applications, regardless of the model or hosting provider. We are also making AI discovery free for all plans, to help teams find and secure shadow AI deployments.

AI Security
P0
2025-12-08 18:03 UTC
Vendor Research

Architecting Security for Agentic Capabilities in Chrome

Google Online Security Blog · Google · indexed 2026-08-15 14:33 UTC

Posted by Nathan Parker, Chrome security team Chrome has been advancing the web’s security for well over 15 years, and we’re committed to meeting new challenges and opportunities with AI. Billions of people trust Chrome to keep them safe by default, and this is a responsibility we take seriously. Following the recent launch of Gemini in Chrome and the preview of agentic capabilities, we want to share our approach and some new innovations to improve the safety of agentic browsing. The primary ne…

AI SecurityData Breaches
P0
2025-10-30 16:59 UTC
Vendor Research

How Android provides the most effective protection to keep you safe from mobile scams

Google Online Security Blog · Edward Fernandez · indexed 2026-08-15 14:33 UTC

Posted by Lyubov Farafonova, Product Manager, Phone by Google; Alberto Pastor Nieto, Sr. Product Manager Google Messages and RCS Spam and Abuse; Vijay Pareek, Manager, Android Messaging Trust and Safety As Cybersecurity Awareness Month wraps up, we’re focusing on one of today's most pervasive digital threats: mobile scams. In the last 12 months, fraudsters have used advanced AI tools to create more convincing schemes, resulting in over $400 billion in stolen funds globally.¹ For years, Android …

AI SecurityAppleCybercrimeMobile SecuritySecurity Research
P0
2025-09-24 18:42 UTC
Vendor Research

Accelerating adoption of AI for cybersecurity at DEF CON 33

Google Online Security Blog · Kimberly Samra · indexed 2026-08-15 14:33 UTC

Posted by Elie Bursztein and Marianna Tishchenko, Google Privacy, Safety and Security TeamEmpowering cyber defenders with AI is critical to tilting the cybersecurity balance back in their favor as they battle cybercriminals and keep users safe. To help accelerate adoption of AI for cybersecurity workflows, we partnered with Airbus at DEF CON 33 to host the GenSec Capture the Flag (CTF), dedicated to human-AI collaboration in cybersecurity. Our goal was to create a fun, interactive environment, …

AI SecurityMicrosoft
P0
2025-06-13 16:03 UTC
Vendor Research

Mitigating prompt injection attacks with a layered defense strategy

Google Online Security Blog · Kimberly Samra · indexed 2026-08-15 14:33 UTC

Posted by Adam Gavish, Google GenAI Security TeamWith the rapid adoption of generative AI, a new wave of threats is emerging across the industry with the aim of manipulating the AI systems themselves. One such emerging attack vector is indirect prompt injections. Unlike direct prompt injections, where an attacker directly inputs malicious commands into a prompt, indirect prompt injections involve hidden malicious instructions within external data sources. These may include emails, documents, or…

AI SecurityMalwarePhishingSecurity ResearchThreat ActorsThreat IntelligenceVulnerabilities
P0
2025-06-12 12:00 UTC
Government

The Impact of Artificial Intelligence on the Cybersecurity Workforce

NIST Cybersecurity Insights · Karen Wetzel · indexed 2026-08-15 20:45 UTC

The NICE Workforce Framework for Cybersecurity ( NICE Framework) was revised in November 2020 as NIST Special Publication 800-181 rev.1 to enable more effective and rapid updates to the NICE Framework Components, including how the advent of emerging technologies would impact cybersecurity work. NICE has been actively engaging in conversations with: federal departments and agencies; industry; education, training, and certification providers; and international representatives to understand how Ar…

AI Security
P0
2025-05-22 00:00 UTC
Other

Remote Prompt Injection in GitLab Duo Leaks Source Code

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A remote prompt injection vulnerability in GitLab Duo allowed attackers to steal source code from private projects, manipulate code suggestions, and exfiltrate confidential information. The attack chain involved hidden prompts, HTML injection, and exploitation of Duo's access to private data. GitLab has since patched both the HTML and prompt injection vectors.

AI SecurityVulnerabilities
P0
2024-11-12 00:00 UTC
Other

ModeLeak: LLM Model Exfiltration Vulnerability in Vertex AI

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability in GCP's Vertex AI service allows privilege escalation and unauthorized access to sensitive LLM models. Attackers can exfiltrate these models by exploiting misconfigurations in access controls and service bindings. By exploiting custom job permissions, researchers were able to escalate their privileges and gain unauthorized access to all data services in the project. In addition, deploying a poisoned model in Vertex AI led to the exfiltration of all other fine-tuned models, posi…

AI SecurityVulnerabilities
P10
2024-09-19 12:00 UTC
Government

Managing Cybersecurity and Privacy Risks in the Age of Artificial Intelligence: Launching a New Program at NIST

NIST Cybersecurity Insights · Katerina Megas · indexed 2026-08-15 20:45 UTC

The rapid proliferation of Artificial Intelligence (AI) promises significant value for industry, consumers, and broader society, but as with many technologies, new risks from these advancements in AI must be managed to realize it’s full potential. The NIST AI Risk Management Framework (AI RMF) was developed to manage the benefits and risks to individuals, organizations, and society associated with AI and covers a wide range of risk ranging from safety to lack of transparency and accountability.…

AI Security
P0
2024-06-14 00:00 UTC
Other

GitHub Copilot Chat Vulnerable to Data Exfiltration

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

GitHub Copilot Chat VS Code Extension was vulnerable to data exfiltration via prompt injection when analyzing untrusted source code. The vulnerability allowed attackers to access previous conversation turns and append information from the chat history to an image URL, which was then automatically retrieved by Copilot, sending the data to the attacker.

AI SecurityVulnerabilities
P0
2024-01-18 00:00 UTC
Other

Amazon Q for Business Data Exfiltration

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

An Indirect Prompt Injection attack can cause the LLM to return markdown tags. This allows an adversary who’s data makes it into the chat context (e.g via an uploaded file) to achieve data exfiltration of the victim’s data by rendering hyperlinks.

AI Security
P0
2023-11-03 00:00 UTC
Other

Hacking Google Bard via Prompt Injection

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A vulnerability in Google Bard allowed for prompt injection and data exfiltration through its Extensions feature. By injecting malicious instructions into shared Google Docs, an attacker could force Bard to render images with exfiltrated chat history data in the URL. The exploit bypassed Content Security Policy using Google Apps Script.

AI SecurityVulnerabilities
P0
2023-10-19 00:00 UTC
Other

Azure AI Playground data exfiltration

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

In Azure AI Playground, a Prompt Injection attack could cause an LLM to return markdown tags. This would have allowed an adversary whose data makes it into the chat context (e.g., via an uploaded file) to achieve exfiltration of the victim’s data by rendering hyperlinks. However, the severity of this issue is low, as there were no integrations that could pull remote content. This means Indirect Prompt Injection was not possible, and it would require the victim to copy the malicious prompt from …

AI SecurityCloud Security
P0
2023-10-19 00:00 UTC
Other

Vertex AI Studio data exfiltration

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

In Vertex AI Studio, a Prompt Injection attack could cause the LLM to return markdown tags. This could have allowed an adversary whose data makes it into the chat context (e.g., via an uploaded file) to achieve exfiltration of the victim’s data by rendering hyperlinks. However, the severity of this issue is low, as there were no integrations that could pull remote content. This means Indirect Prompt Injection was not possible, and it would require the victim to copy the malicious prompt from el…

AI SecurityCloud Security
P0
6 7 8