IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 110 matching records.
AUTO-POLL // 2026-10-02 22:55 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P6 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 2

RANSOMWARE
P6
P6
COOL // 45 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
WED
Sep 30

RANSOMWARE
P10
P10
WARM // 59 ARTICLES
TUE
Sep 29

RANSOMWARE
P4
P4
COOL // 68 ARTICLES
MON
Sep 28

RANSOMWARE
P7
P7
COOL // 52 ARTICLES
SUN
Sep 27

RANSOMWARE
P25
P25
ELEVATED // 15 ARTICLES
SAT
Sep 26

RANSOMWARE
P13
P13
WARM // 20 ARTICLES
RESET
2026-10-02 17:33 UTC
Security Journalism

Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-02 17:45 UTC

Government and policy organizations across Asia have become the target of a new campaign orchestrated by a China-nexus threat actor. The activity, which has targeted government and policy organizations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, and Myanmar, involves the deployment of a previously undocumented backdoor codenamed Antino. Cisco Talos is tracking the cluster

APT / Nation-StateMalwareThreat Actors
P0
2026-09-27 05:35 UTC
Vendor Research

Frequently asked questions about reported Citrix NetScaler zero-day vulnerabilities

Tenable Blog · Satnam Narang · indexed 2026-09-27 10:00 UTC

CVE-2026-88771 and CVE-2026-88772, two zero-day vulnerabilities in Citrix NetScaler, have been confirmed as exploited in the wild. Citrix released patches on September 27, 2026.Change logUpdate September 27: Citrix published security bulletin CTX697096, confirming CVE-2026-88771 and CVE-2026-88772 as the two zero-day RCE vulnerabilities and releasing patches. Post updated with CVE IDs, CVSS scores, patch versions, and IoC guidance.Click here to review the change log historyUpdate September 27: …

APT / Nation-StateCloud SecurityNetwork SecurityRansomwareThreat ActorsThreat IntelligenceVulnerabilitiesCVE-2023-6549CVE-2025-6543CVE-2026-19489CVE-2026-19490CVE-2026-88771CVE-2026-88772
P95
2026-09-24 09:14 UTC
Security Journalism

17,000 URLs Reveal How ClickFix Turns Trusted Websites Into Malware Traps: Report by CTM360

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-24 11:05 UTC

ClickFix has become the most common way attackers get into enterprise networks, and it does it without an exploit, an attachment, or a file on disk. Our new global threat report traces the technique from a novelty in late 2023 to a subscription product with on-chain infrastructure and a state-sponsored user base, and explains why blocking malicious domains is no longer a useful defense. Read

APT / Nation-StateMalware
P0
2026-09-18 15:24 UTC
Security Journalism

Transparent Tribe Deploys New Rust Backdoor Using Private GitHub Repositories for C2

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-18 15:55 UTC

The Pakistan-aligned threat group tracked as Transparent Tribe (aka APT36 and Earth Karkaddan) has been attributed to a fresh set of cyber attacks targeting government and defense entities in India and Afghanistan. The attacks, per Zscaler ThreatLabz, involve the use of previously undocumented tools called RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH. The activity has been codenamed Operation

APT / Nation-StateMalware
P0
2026-09-17 10:05 UTC
Security Journalism

China-Aligned FamousSparrow Deploys SparroWocky Backdoor Across Latin America

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-17 13:45 UTC

The China-aligned state-sponsored threat actor known as FamousSparrow has been observed deploying a previously unreported backdoor called SparroWocky in attacks targeting multiple countries in Latin America since at least August 2025. "SparroWocky is a modular, C++ backdoor," ESET security researchers Alexandre Côté Cyr and Romain Dumont said in a technical report shared with The Hacker News

APT / Nation-StateMalwareSecurity ResearchThreat Actors
P0
2026-09-16 15:27 UTC
Security Journalism

Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-16 16:25 UTC

Enterprises in Russia have emerged as the target of three threat activity clusters tracked as NightEagle, Hacking Cat, and Toy Ghouls, according to multiple reports from Kaspersky. The cybersecurity vendor said it has identified attacks mounted by NightEagle (aka APT-Q-95), a threat actor known to be active since at least 2023, that involve new techniques for persistence and lateral movement.

APT / Nation-StateMalwareRansomwareThreat Actors
P15
2026-09-15 10:17 UTC
Other

One Exploit Chain, Two Espionage Campaigns: Chrome and Windows Under Fire

Security Affairs · Pierluigi Paganini · indexed 2026-09-15 11:30 UTC

Two China-linked groups ran identical Chrome/Windows zero-day exploits against NGOs, before Chrome’s patch shipped, deploying different backdoors each. Two China-linked threat actors used the same Chrome/Windows zero-day against NGOs starting September 1, 2026, Volexity’s new report lays out the whole chain in detail. On September 1, Volexity detected a spear-phishing campaign by UTA0560 targeting several […]

APT / Nation-StateMalwareMicrosoftPhishingThreat ActorsVulnerabilities
P25
2026-09-14 14:40 UTC
Security Journalism

⚡ Weekly Recap: Rogue AI Agents, WeChat Worm, PaperCut Attacks, AI Espionage, and Rootkits

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-14 15:35 UTC

AI keeps showing up in the wrong places. Attackers are using it to speed up exploits, test defenses, and automate more of the job. Some models are also crossing lines on their own. That is not a great combination. The rest of the week is more familiar: old bugs still working, fresh exploit chains, exposed systems, weak defaults, and simple paths that should have been harder to abuse. A few of

AI SecurityAPT / Nation-StateMalware
P0
2026-09-13 17:27 UTC
Other

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 114

Security Affairs · Pierluigi Paganini · indexed 2026-09-13 17:50 UTC

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter REVSTEALER ramps up Breaking the Seal: Static Deobfuscation of JSCeal’s Compiled V8 Bytecode GuardBreaker: Derailing AI-assisted malware analysis with a code comment DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive […]

APT / Nation-StateMalware
P0
2026-09-11 14:29 UTC
Security Journalism

Claude Used to Automate Exploitation and Data Theft Across Multiple Victims

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-11 15:30 UTC

Anthropic has warned that cybercriminals and state-sponsored hackers alike are using its Claude models for cyber attacks, weapons design, propaganda, and mass surveillance between December 2025 and August 2026. The threat actors, which the artificial intelligence (AI) company has branded Generative Threat Groups (GTGs), span state-sponsored groups, financially motivated criminals, commercial

AI SecurityAPT / Nation-StateThreat Actors
P0
2026-09-11 14:10 UTC
Security Journalism

Russian State-Sponsored Hackers Use Claude to Rebuild Malware After Detection

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-11 15:30 UTC

Anthropic on Thursday revealed it disrupted a campaign mounted by a Russian state-sponsored threat actor that abused Claude for developing an AI-assisted workflow to get ahead of the detection curve. The operation has been attributed to a cyber espionage group it calls GTG-20006 (where "GTG" stands for Generative Threat Group), which aligns with broader reporting linking the cluster to Midnight

APT / Nation-StateMalwareThreat Actors
P0
2026-09-11 06:19 UTC
Security Journalism

Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-11 07:40 UTC

Cisco has revealed that three distinct threat clusters linked to ransomware and state-sponsored attacks have been exploiting two recently patched Secure Firewall Management Center (FMC) vulnerabilities. The attacks leverage CVE-2026-20079 (CVSS score: 10.0), an authentication bypass vulnerability in the web interface of FMC software that could allow an unauthenticated, remote attacker to bypass

APT / Nation-StateCloud SecurityNetwork SecurityRansomwareVulnerabilitiesCVE-2026-20079
P30
2026-09-10 05:35 UTC
Other

Four Nation-State Actors Used the Same Chrome Zero-Day Exploit Kit Within 12 Days

Security Affairs · Pierluigi Paganini · indexed 2026-09-10 06:35 UTC

Four espionage groups used the BlueMoon Chrome+Windows exploit kit within 12 days. Researchers suspect AI development. Proofpoint published a detailed analysis of a Chrome-and-Windows exploit kit it tracks as BlueMoon that four nation-state actors adopted within roughly two weeks of the first observed use. Google’s Threat Intelligence Group, Microsoft’s MSTIC, and Volexity all contributed to […]

APT / Nation-StateMicrosoftThreat IntelligenceVulnerabilities
P25
2026-09-09 16:34 UTC
Security Journalism

Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-09 19:50 UTC

Multiple espionage-motivated threat activity clusters have been found deploying a previously undocumented exploit kit called BlueMoon that chains together multiple vulnerabilities in Microsoft Windows and Google Chrome. The first in-the-wild use of BlueMoon has been attributed to the China-aligned state-sponsored group tracked as APT31 (aka Bronze Vinewood, Judgement Panda, JungleBamboo,

APT / Nation-StateMicrosoft
P0
1 2 3