IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 110 matching records.
AUTO-POLL // 2026-10-02 22:55 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P6 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 2

RANSOMWARE
P6
P6
COOL // 45 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
WED
Sep 30

RANSOMWARE
P10
P10
WARM // 59 ARTICLES
TUE
Sep 29

RANSOMWARE
P4
P4
COOL // 68 ARTICLES
MON
Sep 28

RANSOMWARE
P7
P7
COOL // 52 ARTICLES
SUN
Sep 27

RANSOMWARE
P25
P25
ELEVATED // 15 ARTICLES
SAT
Sep 26

RANSOMWARE
P13
P13
WARM // 20 ARTICLES
RESET
2026-09-08 14:00 UTC
Vendor Research

GTIG AI Threat Tracker: From Prompting to Autonomy – The Evolution of Adversarial AI

Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-09-08 13:45 UTC

Executive Summary Since the release of our May 2026 report detailing adversarial misuse of artificial intelligence (AI), Google Threat Intelligence Group (GTIG) has observed forward leaning adversaries transition from basic prompting to agentic AI workflows and AI-enabled automation. In these operations, human-in-the-loop latency is dramatically reduced, compressing the traditional window for defenders to respond. In Q2 2026, GTIG observed threat actors compromise a cloud resource, then plan, b…

AI SecurityAPT / Nation-StateCloud SecurityData BreachesDFIRMalwareMicrosoftPhishingRansomwareThreat ActorsThreat IntelligenceVulnerabilities
P35
2026-09-07 12:12 UTC
Security Journalism

North Korean Hackers Deploy New Linux Espionage Toolkit

Security Week · Ionut Arghire · indexed 2026-09-07 17:25 UTC

The stealthy toolkit embeds a backdoor in HAProxy and targets automotive and media organizations in South Korea for long-term surveillance. The post North Korean Hackers Deploy New Linux Espionage Toolkit appeared first on SecurityWeek.

APT / Nation-StateLinuxMalware
P0
2026-09-04 12:00 UTC
Vendor Research

DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors

Rapid7 · Rapid7 Intelligence · indexed 2026-09-04 12:25 UTC

OverviewA new Linux toolkit, identified by Rapid7 Labs, has been targeting organizations across South Korea’s automotive and media industries with minimal detection. The campaign made use of a HAProxy instance named “ted backdoor”, alongside trojanized versions of crond, agetty, atd, sshd, and polkitd. This previously undocumented framework enabled threat actors to execute remote commands on compromised servers, inject malicious scripts into web traffic, perform credential harvesting, and engag…

APT / Nation-StateLinuxMalwarePhishingThreat ActorsVulnerabilities
P15
2026-09-04 11:00 UTC
Other

Chinese Hackers Use AI Agents in Multi-Country Cyber Campaign

Security Affairs · Pierluigi Paganini · indexed 2026-09-04 11:10 UTC

Hunt.io uncovered a Chinese-speaking campaign using AI agents to automate cyberattacks against Asian government, education and industrial targets. Threat intelligence firm Hunt.io just documented a second, separate China-linked campaign wiring commercial AI models directly into live cyberespionage operations, this time hitting Taiwan’s Kuomintang Party archives, Indonesia’s Ministry of Foreign Affairs, government and education systems in […]

AI SecurityAPT / Nation-StateThreat Intelligence
P0
2026-09-03 08:12 UTC
Other

2,000 Leaked Documents Reveal How Russia Turns Engineering Students Into GRU Cyber Operators

Security Affairs · Pierluigi Paganini · indexed 2026-09-03 08:20 UTC

2,000 leaked files expose Bauman University’s hidden Department No. 4, which trained GRU-linked hackers and propagandists linked to APT28 and Sandworm. Leaked Documents Expose Bauman University’s Hidden Department That Trained Hackers, Propagandists, and Malware Developers for the GRU More than 2,000 internal documents from Bauman Moscow State Technical University have been reviewed by an international […]

APT / Nation-StateMalware
P0
2026-09-02 10:25 UTC
Other

Iran-linked APT Mirage Kitten Uses Fake Job Tests to Spread Malware

Security Affairs · Pierluigi Paganini · indexed 2026-09-02 10:45 UTC

Mirage Kitten used fake LinkedIn coding tests to spread NodeRabbit and PollCat, even banning AI tools that could have spotted the malware. Iran-linked Mirage Kitten hackers just found a genuinely clever way to make their own malware harder to detect: telling job candidates not to use AI tools while reviewing the trojanized code they were […]

APT / Nation-StateMalware
P0
2026-08-31 11:10 UTC
Other

China-linked Fire Ant Hides Inside Trusted Infrastructure

Security Affairs · Pierluigi Paganini · indexed 2026-08-31 11:40 UTC

Fire Ant hijacked Cisco routers, stole credentials and altered logs to hide its tracks, using trusted infrastructure to reach high-value networks. Chinese-linked cyber espionage group Fire Ant has spent the past year quietly graduating from hacking individual computers to hacking the infrastructure that connects them. Sygnia’s new report traces how the group expanded from compromising […]

APT / Nation-StateNetwork Security
P0
2026-08-31 09:04 UTC
Security Journalism

China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-31 10:35 UTC

A China-nexus cyber espionage actor tracked as Fire Ant has expanded a long-running campaign beyond VMware hypervisors to compromise Cisco IOS XR routers, Terminal Access Controller Access-Control System (TACACS) servers, and Linux management hosts used to route, authenticate, and manage high-value networks. Sygnia, the incident response firm that investigated the intrusion, said the actor

AppleAPT / Nation-StateDFIRLinuxNetwork Security
P0
2026-08-28 14:01 UTC
Vendor Research

Why a cryptographic inventory is key for addressing the quantum computing threat

Tenable Blog · Christopher Day · indexed 2026-08-28 14:20 UTC

When quantum computers become generally available, they’ll be able to crack current public-key cryptographic algorithms, putting digitally stored and transmitted data at risk. But the threat already exists, as attackers use the "harvest now, decrypt later" tactic. Discover why building a comprehensive cryptographic inventory and executing a phased operational strategy are critical for protecting your data against quantum computing attacks.Key takeawaysQuantum computing risks are an operational …

APT / Nation-StateMicrosoftVulnerabilities
P0
2026-08-28 11:26 UTC
Other

Russian APT BlueDelta Uses HOOKEDGE to Target Defense and Diplomatic Organizations

Security Affairs · Pierluigi Paganini · indexed 2026-08-28 11:30 UTC

BlueDelta (APT28) uses webhook.site and Microsoft Edge to hide HOOKEDGE espionage traffic targeting European governments. Recorded Future’s Insikt Group documented a campaign by BlueDelta, the Russian GRU-linked group that overlaps with the group APT28, running an entire espionage operation against European government targets using webhook.site, a service built for developers to test HTTP requests, as […]

APT / Nation-StateMicrosoft
P0
2026-08-28 08:20 UTC
Security Journalism

APT28-Linked HOOKEDGE Backdoor Targets European Government and Diplomatic Organizations

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-28 08:40 UTC

Cybersecurity researchers have flagged a fresh set of campaigns targeting government and diplomatic organizations in Romania, Spain, and Türkiye between late September 2025 and early April 2026. These campaigns, per Recorded Future Insikt Group, have led to the deployment of a previously undocumented backdoor dubbed HOOKEDGE, a lightweight Windows batch script that's distributed via

APT / Nation-StateMalwareMicrosoftSecurity Research
P0
2026-08-27 20:31 UTC
Other

Dark Caracal Deploys New Go Malware With Ethereum-Based C2 Fallback

Security Affairs · Pierluigi Paganini · indexed 2026-08-27 20:50 UTC

Dark Caracal targets Venezuela with GoCaracal, an upgraded Bandook toolkit and an Ethereum fallback for resilient C2 communications. Dark Caracal is back with new malware and the same hunting grounds. Arctic Wolf Labs researchers link a June 2026 intrusion against a communications organisation in Venezuela to the Lebanon‑linked espionage group, and says it deployed a […]

APT / Nation-StateMalware
P0
2026-08-27 13:51 UTC
Vendor Research

Identity-as-a-Service: Uncovering Dark Web Marketplaces Trading Executive SSNs

Rapid7 · Alexandra Blia · indexed 2026-08-27 14:25 UTC

IntroductionDespite modern verification controls, identity theft remains one of the most pervasive threats to both individuals and enterprise organizations. U.S. Federal Trade Commission statistics show over 1 million identity theft reports annually, with related fraud and imposter scams accounting for billions in financial losses each year. While stolen credit cards enable rapid, short-term monetization, Social Security numbers (SSNs) represent a far more permanent and dangerous tier within th…

APT / Nation-StateCybercrimeData BreachesMalwareMicrosoftPhishingThreat Actors
P0
2026-08-26 16:42 UTC
Security Journalism

FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-26 17:50 UTC

The U.S. Department of Justice (DoJ) on Wednesday announced the disruption of two hacking platforms named QScan and QTRouter operated by Chinese threat actors to target critical infrastructure and other sensitive networks in the country. The activity has been attributed to a Chinese state-sponsored group known as QTFY, employed by Nanjing Xinjiuwei Network Technology Company (南京鑫玖维网络科技有限公司).&

APT / Nation-StateLaw EnforcementNetwork SecurityThreat Actors
P0
2026-08-26 15:35 UTC
Security Journalism

Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunneler

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-26 17:50 UTC

Cybersecurity researchers have discovered additional infrastructure and previously undocumented malware associated with Nimbus Manticore, an Iranian state-sponsored hacking group affiliated with the Islamic Revolutionary Guard Corps (IRGC). Group-IB, in a new analysis published today, described the cyber espionage actor as among the most active Iranian APT groups in 2026. Nimbus Manticore (aka

APT / Nation-StateMalwareSecurity Research
P0
2026-08-26 09:00 UTC
Vendor Research

Edge infrastructure under siege: what two independent datasets reveal about who's exploiting your perimeter

Tenable Cyber Exposure Alerts · Research Special Operations · indexed 2026-08-26 13:15 UTC

A joint Tenable-SentinelOne analysis of 93 CVE-actor attribution pairs reveals that both state-sponsored actors and cybercriminals independently converge on the same edge infrastructure. Special thanks to SentinelOne® Incident Readiness & Response for their contributions to this publication.It is the shared attack surface where state-sponsored threat actors and financially motivated criminal groups independently converge — not the province of a single adversary category, and not exclusively a n…

APT / Nation-StateData BreachesDFIRMicrosoftNetwork SecurityPhishingRansomwareThreat ActorsThreat IntelligenceVulnerabilities
P45
2026-08-24 11:51 UTC
Security Journalism

Operation QUICSILVER Targets Myanmar Government and IT with QUICAgent Backdoor

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-24 12:10 UTC

Cybersecurity researchers have flagged a cyber espionage campaign targeting Myanmar that uses graduation ceremony invitation lures to deliver a Go backdoor called QUICAgent. The campaign, codenamed Operation QUICSILVER, has been found to target government and information technology sectors, per Seqrite Labs. The activity is assessed to be the work of a China-nexus threat actor with moderate

APT / Nation-StateMalwareSecurity ResearchThreat Actors
P0
2026-08-21 11:11 UTC
Other

Fake Conferences, OAuth and WhatsApp: Inside Russia’s New Espionage Tactics

Security Affairs · Pierluigi Paganini · indexed 2026-08-21 11:40 UTC

Google tracks three Russia-linked espionage clusters using phishing and legitimate authentication tools to target researchers, diplomats and defense staff. Google’s Threat Intelligence Group tracked three separate suspected Russia-linked cyber espionage clusters. All three focus on the same thing: abusing authentication features that are supposed to protect accounts to access them instead. Threat actors target researchers, […]

APT / Nation-StatePhishingThreat ActorsThreat Intelligence
P0
2026-08-20 19:59 UTC
Security Journalism

Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-20 20:30 UTC

Three distinct suspected Russian cyber espionage threat clusters have been observed leveraging legitimate authentication flows to single out individuals working in academia, aerospace and defense, governments, and think tanks across Europe, as well as academia and think tanks within the U.S. These clusters include UNC6293, UNC7005, and UNC5976. "These clusters engage in persistent, adaptive

APT / Nation-State
P0
2026-08-20 14:00 UTC
Vendor Research

Going with the Flow(s): Distinct Clusters Target Individuals of Interest to Russia

Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-08-20 14:40 UTC

Written by: Gabby Roncone, Wesley Shields Overview Google Threat Intelligence Group (GTIG) is tracking three distinct suspected Russian cyber espionage threat clusters abusing legitimate authentication flows to target individuals working in academia, aerospace and defense, governments and think tanks across Europe, as well as academia and think tanks within the United States. Examples of these techniques can be found in our previous blog on UNC6293’s phishing operations. We now track an additio…

APT / Nation-StateMalwareMicrosoftPhishingThreat Intelligence
P0
2026-08-20 08:36 UTC
Other

US Indicts 17 Iranians Over Years-Long Cyber Espionage Campaign

Security Affairs · Pierluigi Paganini · indexed 2026-08-20 09:45 UTC

The US charged 17 Iranians over a years-long hacking campaign that stole 31TB from universities, companies and government agencies worldwide. Eight years after the original indictment first went public, US prosecutors just added eight more names to the list. The Justice Department unsealed a superseding indictment this week charging 17 members of the Mabna Institute, […]

APT / Nation-State
P0
2026-08-19 13:12 UTC
Security Journalism

SilkParasite Espionage Campaign Targets Central Asian Governments with Five New RATs

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-19 13:35 UTC

A previously unreported cyber espionage operation dubbed SilkParasite has been observed targeting government bodies in Central Asia. The intrusion set makes use of seven remote access tool (RAT) families, five of which have never been previously documented: DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT. SilkParasite, first discovered in late 2025, is assessed to be a

APT / Nation-StateMicrosoft
P0
1 2 3 4