IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 568 matching records.
AUTO-POLL // 2026-10-02 22:45 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P6 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 2

RANSOMWARE
P6
P6
COOL // 45 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
WED
Sep 30

RANSOMWARE
P10
P10
WARM // 59 ARTICLES
TUE
Sep 29

RANSOMWARE
P4
P4
COOL // 68 ARTICLES
MON
Sep 28

RANSOMWARE
P7
P7
COOL // 52 ARTICLES
SUN
Sep 27

RANSOMWARE
P25
P25
ELEVATED // 15 ARTICLES
SAT
Sep 26

RANSOMWARE
P13
P13
WARM // 20 ARTICLES
RESET
2026-09-28 06:24 UTC
Security Journalism

CISA orders feds to patch exploited Citrix flaws by Wednesday

BleepingComputer · Sergiu Gatlan · indexed 2026-09-28 06:35 UTC

The Cybersecurity and Infrastructure Security Agency (CISA) has ordered U.S. government agencies over the weekend to secure their systems against attacks exploiting two critical Citrix NetScaler vulnerabilities. [...]

Cloud Security
P0
2026-09-27 17:29 UTC
Other

Citrix Confirmed Two New NetScaler Flaws Exploited as Zero-Day

Security Affairs · Pierluigi Paganini · indexed 2026-09-27 18:10 UTC

Citrix confirmed two critical NetScaler zero-days were exploited before patches were available, with attackers able to remotely execute code. Citrix confirmed that two critical zero-day vulnerabilities in NetScaler ADC and NetScaler Gateway were exploited before the company released patches. The flaws allow remote code execution, meaning attackers can potentially take control of affected appliances. The […]

Cloud SecurityVulnerabilities
P40
2026-09-27 07:47 UTC
Security Journalism

Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-27 08:15 UTC

Two critical vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway that allow remote code execution have been exploited in the wild, Citrix confirmed on September 27. It released fixes for both, along with six other flaws. One of the two affects every deployment on an affected version, including those in the default configuration. The bulletin came a day after security firm watchTowr

Cloud SecurityVulnerabilities
P60
2026-09-27 05:35 UTC
Vendor Research

Frequently asked questions about reported Citrix NetScaler zero-day vulnerabilities

Tenable Blog · Satnam Narang · indexed 2026-09-27 10:00 UTC

CVE-2026-88771 and CVE-2026-88772, two zero-day vulnerabilities in Citrix NetScaler, have been confirmed as exploited in the wild. Citrix released patches on September 27, 2026.Change logUpdate September 27: Citrix published security bulletin CTX697096, confirming CVE-2026-88771 and CVE-2026-88772 as the two zero-day RCE vulnerabilities and releasing patches. Post updated with CVE IDs, CVSS scores, patch versions, and IoC guidance.Click here to review the change log historyUpdate September 27: …

APT / Nation-StateCloud SecurityNetwork SecurityRansomwareThreat ActorsThreat IntelligenceVulnerabilitiesCVE-2023-6549CVE-2025-6543CVE-2026-19489CVE-2026-19490CVE-2026-88771CVE-2026-88772
P95
2026-09-26 08:49 UTC
Security Journalism

SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-26 10:05 UTC

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added two security flaws impacting Microsoft SharePoint and Mikrotik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerabilities in question are as follows - CVE-2026-65660 (CVSS score: 8.8) - A code injection vulnerability in Microsoft Office SharePoint

Cloud SecurityMicrosoftNetwork SecurityVulnerabilitiesCVE-2026-65660
P95
2026-09-25 21:03 UTC
Other

U.S. CISA adds Microsoft SharePoint and Mikrotik RouterOS flaws to its Known Exploited Vulnerabilities catalog

Security Affairs · Pierluigi Paganini · indexed 2026-09-25 22:00 UTC

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Microsoft SharePoint and Mikrotik RouterOS flaws flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2026-65660 is a code-injection vulnerability in Microsoft SharePoint Server that allows an authenticated, low-privileged attacker to execute arbitrary […]

Cloud SecurityMicrosoftNetwork SecurityVulnerabilitiesCVE-2026-65660
P35
2026-09-25 15:35 UTC
Vendor Research

Storm-3168: Agentic-driven cloud attacks using compromised service principals

Microsoft Security Blog · Microsoft Security Research, Yossi Weizman and Tushar Mudi · indexed 2026-09-25 17:40 UTC

Microsoft details JADEPUFFER-linked Azure reconnaissance, resource deletion, and credential access using compromised service principals, identifying the activity as associated with Storm-3168 and providing guidance for defenders. The post Storm-3168: Agentic-driven cloud attacks using compromised service principals appeared first on Microsoft Security Blog.

Cloud SecurityMicrosoft
P0
2026-09-25 08:22 UTC
Other

U.S. CISA adds Adobe and WSO2 flaws to its Known Exploited Vulnerabilities catalog

Security Affairs · Pierluigi Paganini · indexed 2026-09-25 08:25 UTC

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Adobe and WSO2 flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: The first flaw added to the catalog, tracked as CVE-2026-5430 (CVSS score 10.0), is an authentication bypass in multiple WSO2 products […]

Cloud SecurityVulnerabilitiesCVE-2026-5430
P45
2026-09-25 04:46 UTC
Security Journalism

WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-25 06:35 UTC

The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added two critical security flaws impacting WSO2 and Adobe Commerce and Magento to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation. The vulnerabilities are listed below - CVE-2026-5430 (CVS score: 9.8) - A path traversal vulnerability in WSO2 API Control Plane,

Cloud SecurityVulnerabilitiesCVE-2026-5430
P55
2026-09-24 20:35 UTC
Security Journalism

Autonomous AI Hacks Raise Thorny Questions of Legal Accountability

Security Week · Associated Press · indexed 2026-09-24 20:40 UTC

The prospect of legal accountability is unclear. Lawsuits are a possibility, but some legal experts believe any criminal investigations would face an extremely high burden. The post Autonomous AI Hacks Raise Thorny Questions of Legal Accountability appeared first on SecurityWeek.

Cloud SecurityDFIR
P0
2026-09-24 19:17 UTC
Vendor Research

CVE-2026-96883 - Type confusion in AWS pgcollection allows remote code execution

AWS Security Bulletins · aws@amazon.com · indexed 2026-09-24 19:35 UTC

Bulletin ID: 2026-118-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/24/2026 12:00 PM PDT Description: pgcollection is an open source extension to PostgreSQL. We identified CVE-2026-96883, an issue in pgcollection's type coercion logic. When requesting a stored icollection value as a type incompatible with how it was actually stored causes the extension to misinterprets the datum's representation, allowing an authenticated database user to crash the PostgreSQL …

Cloud SecurityVulnerabilitiesCVE-2026-96883
P20
2026-09-24 18:16 UTC
Other

AI Helps Uncover MikroTrick Attack Chain in MikroTik RouterOS

Security Affairs · Pierluigi Paganini · indexed 2026-09-24 19:20 UTC

MikroTrick chains two RouterOS flaws to bypass authentication and gain admin access. AI helped researchers uncover the attack chain within days. MikroTik pushed out patches on September 3, 2026 for several RouterOS issues at once, calling it an important security update without saying what it actually fixed. That silence was deliberate, and it didn’t last […]

Cloud SecurityNetwork Security
P5
2026-09-24 18:10 UTC
Security Journalism

Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-24 19:00 UTC

A OnePlus 15 running the latest OxygenOS can be rooted by a malicious app the owner installs, one that asks for no special permissions. A researcher, Rasmus Moorats, chained two flaws in OnePlus's own software to gain root access, the highest level of control over an Android phone. OnePlus told him the same flaws affect many more of its own devices and those of OPPO, though it has not

Cloud SecurityMobile Security
P0
2026-09-24 17:21 UTC
Vendor Research

CVE-2026-95985 - Kiro IDE Allows Agentic Writes to Global Configurations While Working in Untrusted Workspaces

AWS Security Bulletins · aws@amazon.com · indexed 2026-09-24 18:00 UTC

Bulletin ID: 2026-117-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/24/2026 10:00 AM PDT Description: Kiro is an agentic IDE that users install on their desktop. We identified CVE-2026-95985. The file write tool in Kiro IDE before version 1.0.242 might allow remote unauthenticated actors to execute arbitrary commands and to inject crafted instructions into the agent's context. When a user runs the agent in a crafted repository as an untrusted workspace, sendin…

Cloud SecurityVulnerabilitiesCVE-2026-95985
P5
2026-09-24 06:32 UTC
Security Journalism

TeamFiltration Campaign Compromises Seven Microsoft 365 Accounts Using Default Passwords

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-24 08:35 UTC

Cybersecurity researchers have disclosed details of an active TeamFiltration campaign codenamed UNK_CondorFiltration that has targeted over 5,700 accounts across 28 Microsoft 365 tenants. According to Proofpoint, the activity has primarily focused on Chilean retail and financial institutions. It originated from 1,487 unique AWS EC2 source IP addresses. "The campaign compromised 7 accounts –

Cloud SecurityMicrosoftSecurity Research
P0
2026-09-23 23:07 UTC
Vendor Research

ICYMI: August 2026 @AWS Security

AWS Security Blog · Rodolfo Brenes · indexed 2026-09-23 23:25 UTC

Read all about the latest AWS security features, compliance updates, and hands-on resources in our monthly digest posts. You’ll find expert blog posts, new service capabilities, code samples, and workshops. AWS Security Blog posts August brought 20 AWS Security Blog posts organized across seven categories. Identity and access management led the month with five posts […]

Cloud Security
P0
2026-09-23 20:37 UTC
Other

U.S. CISA adds Check Point, Arista VeloCloud Orchestrator, and F5 BIG-IP APM flaws to its Known Exploited Vulnerabilities catalog

Security Affairs · Pierluigi Paganini · indexed 2026-09-23 21:00 UTC

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Check Point, Arista VeloCloud Orchestrator, and F5 BIG-IP APM flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2026-85102 resides in the VPN negotiation process and lets an unauthenticated attacker bypass security checks […]

Cloud SecurityNetwork SecurityVulnerabilitiesCVE-2026-85102
P35
2026-09-23 14:45 UTC
Vendor Research

Supporting ASD’s multi-factor authentication campaign: Why MFA matters more than ever

AWS Security Blog · Grace Zhang · indexed 2026-09-23 15:00 UTC

The Australian Signals Directorate (ASD) has this month issued a clear call to action through its Multi-factor authentication: Switch it on campaign, urging businesses, organisations, and individuals to enable multi-factor authentication (MFA) across their online accounts. At AWS, we strongly support this message. As threat actors continue to target credentials through phishing, credential stuffing, and […]

Cloud SecurityNetwork SecurityPhishingThreat Actors
P0
2026-09-23 14:01 UTC
Security Journalism

How One Kubernetes YAML Can Hand Over a GCP Organization

BleepingComputer · Sponsored by Varonis · indexed 2026-09-23 14:15 UTC

A Kubernetes user with limited permissions can potentially gain control of an entire Google Cloud organization by exploiting the authority granted to Google Kubernetes Config Connector. Varonis explains how this confused deputy problem can turn a single Kubernetes YAML file into a path to organization-wide privilege escalation. [...]

Cloud SecurityVulnerabilities
P10
2026-09-23 10:36 UTC
Security Journalism

Chrome 154 Patches 108 Vulnerabilities

Security Week · Ionut Arghire · indexed 2026-09-23 10:50 UTC

The browser update resolves several critical-severity memory safety and memory corruption flaws. The post Chrome 154 Patches 108 Vulnerabilities appeared first on SecurityWeek.

Cloud Security
P0
2026-09-22 20:08 UTC
Vendor Research

CVE-2026-94450 - Potential denial of service when configured to send Retry packets in s2n-quic

AWS Security Bulletins · aws@amazon.com · indexed 2026-09-22 20:10 UTC

Bulletin ID: 2026-116-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/22/2026 13:00 PM PDT Description: s2n-quic is a Rust implementation of the QUIC protocol. We identified CVE-2026-94450, an issue with improper validation of the Destination Connection ID length when a server is configured to send Retry packets. s2n-quic 1.88.0 and earlier allow an unauthenticated user to shut down a server endpoint via a single crafted UDP datagram. No AWS services are affecte…

Cloud SecurityVulnerabilitiesCVE-2026-94450
P5
1 2 3 4