IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 237 matching records.
AUTO-POLL // 2026-10-02 22:50 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P6 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 2

RANSOMWARE
P6
P6
COOL // 45 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
WED
Sep 30

RANSOMWARE
P10
P10
WARM // 59 ARTICLES
TUE
Sep 29

RANSOMWARE
P4
P4
COOL // 68 ARTICLES
MON
Sep 28

RANSOMWARE
P7
P7
COOL // 52 ARTICLES
SUN
Sep 27

RANSOMWARE
P25
P25
ELEVATED // 15 ARTICLES
SAT
Sep 26

RANSOMWARE
P13
P13
WARM // 20 ARTICLES
RESET
2026-08-27 14:09 UTC
Other

Australian Police Charge Two Over TeamPCP Credential Theft

Security Affairs · Pierluigi Paganini · indexed 2026-08-27 14:25 UTC

Australian police charged two men linked to TeamPCP over malware hidden in open-source code that stole 500,000+ credentials from 1,000+ organizations. Australian police have charged two men from Western Australia over a global cybercrime operation that allegedly hid malicious code in open-source software and used it to steal data from thousands of organisations. “Two West […]

CybercrimeMalwarePhishing
P0
2026-08-27 13:51 UTC
Vendor Research

Identity-as-a-Service: Uncovering Dark Web Marketplaces Trading Executive SSNs

Rapid7 · Alexandra Blia · indexed 2026-08-27 14:25 UTC

IntroductionDespite modern verification controls, identity theft remains one of the most pervasive threats to both individuals and enterprise organizations. U.S. Federal Trade Commission statistics show over 1 million identity theft reports annually, with related fraud and imposter scams accounting for billions in financial losses each year. While stolen credit cards enable rapid, short-term monetization, Social Security numbers (SSNs) represent a far more permanent and dangerous tier within th…

APT / Nation-StateCybercrimeData BreachesMalwareMicrosoftPhishingThreat Actors
P0
2026-08-27 11:56 UTC
Security Journalism

Alleged TeamPCP Hackers Charged in Australia Over Major Supply Chain Attacks

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-27 12:55 UTC

The Australian Federal Police (AFP) has charged two Western Australian men with a combined total of 14 offences over their alleged role in TeamPCP, the cybercrime group behind the March 2026 compromise of the open-source security scanners Trivy and Checkmarx KICS and the AI gateway LiteLLM. Louis Michael Gaebler, 23, and Ruben Ian Thomson, 21, appeared in Perth Magistrates Court on August 27,

Cybercrime
P0
2026-08-27 11:17 UTC
Other

One Adversary, Two Outcomes: The 0.027% Proof

Group-IB · indexed 2026-09-07 17:30 UTC

One malware campaign, 11,000 compromised devices, two banks with very different outcomes. At the bank with fused defence, fraud succeeded on just 0.027% of compromised devices; nine times less than the market average. Regulators are taking notice too.

CybercrimeMalware
P0
2026-08-27 11:04 UTC
Independent Research

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia

Krebs on Security · BrianKrebs · indexed 2026-08-27 11:20 UTC

Authorities in Australia have arrested two men believed to be members of TeamPCP, a prolific cybercrime and data extortion group blamed for perpetrating the longest running spree of software supply chain attacks ever. In a statement released today, the Australian Federal Police (AFP) said two unnamed suspects from Western Australia, aged 21 and 23, were arrested in connection with a "sophisticated cybercrime syndicate that allegedly created malicious open-source software to rob thousands of glo…

CybercrimeLaw Enforcement
P0
2026-08-26 07:54 UTC
Security Journalism

INTERPOL Operation Jackal IV Arrests 58, Identifies 263 in Global Cyber Fraud Crackdown

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-26 08:50 UTC

An eight-month INTERPOL operation targeting West African organized crime groups has led to arrests of 58 people and the identification of 263 suspects. "The operation, which brought together 22 countries from six continents, is a response to the escalating global threat posed by West African criminal networks – such as the Black Axe and other similar groups," INTERPOL said. "These groups are

CybercrimeLaw Enforcement
P0
2026-08-26 07:17 UTC
Other

Operation Jackal: 58 Arrests Expose the Money Laundering Machine Behind Global Scams

Security Affairs · Pierluigi Paganini · indexed 2026-08-26 07:40 UTC

INTERPOL’s Operation Jackal IV made 58 arrests and exposed global networks laundering money from scams, fraud and sextortion. INTERPOL announced that Operation Jackal IV, running from November 2025 to June 2026, led to 58 arrests and identified 263 suspects tied to West African organized crime networks, groups like Black Axe that are responsible for a […]

CybercrimeLaw Enforcement
P0
2026-08-25 20:33 UTC
Security Journalism

58 arrested in international cybercrime crackdown

The Record · indexed 2026-08-25 20:50 UTC

Interpol officials said it uncovered a crime-as-a-service network in Argentina run by 196 people that provided website domains and money laundering support to West African organized crime groups like Black Axe.

CybercrimeLaw Enforcement
P0
2026-08-24 08:08 UTC
Security Journalism

UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-24 08:45 UTC

Cybersecurity researchers have disclosed details of a Chinese-speaking cybercrime group dubbed UAT-10147 that's targeting Windows and Linux web servers globally across the education, media, technology, and gaming sectors. The vast majority of the targets are located in Brazil, Bolivia, China, Canada, and Vietnam. Details of the threat activity came to light following the discovery of an open

CybercrimeLinuxMalwareMicrosoftSecurity Research
P0
2026-08-24 07:17 UTC
Other

iAuthFlow v2: The $10,000 Phishing Toolkit That Survives Your Password Reset

Security Affairs · Pierluigi Paganini · indexed 2026-08-24 07:35 UTC

iAuthFlow v2 phishing toolkit uses a phished Google session to enroll an attacker-controlled passkey that survives password resets. Abnormal Security researchers have published an analysis of iAuthFlow v2, a phishing toolkit sold on a Russian-language cybercrime forum for $10,000 base price. The author also offers for sale additional capability modules separately. The headline feature is […]

CybercrimePhishingSecurity Research
P0
2026-08-21 15:41 UTC
Security Journalism

Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-21 16:40 UTC

Cybersecurity researchers have flagged a new malware family that's specifically designed to infect Android-based vehicle head unit firmware developed by DoFun. Kaspersky, which discovered the threat in June 2026, said the end goal of the malware is to serve a multi-stage downloader to enable ad fraud and creation of a proxy botnet. "The malware spread through the built-in updaters of

CybercrimeMalwareMobile SecuritySecurity Research
P0
2026-08-20 18:03 UTC
Other

Manic: The Android Malware That Exfiltrates Data Even When the Phone Is Offline

Security Affairs · Pierluigi Paganini · indexed 2026-08-20 18:35 UTC

Manic Android malware combines banking fraud and spyware, using a Bluetooth relay to steal data even when devices are offline. ThreatFabric’s Mobile Threat Intelligence team has identified a new Android malware, dubbed Manic, which has been active in the wild since at least February 2026. The researchers state that the malware is still under development […]

CybercrimeMalwareMobile SecurityThreat Intelligence
P20
2026-08-20 17:32 UTC
Security Journalism

Money and Mindset: The Two Biggest Roadblocks to Cyber Policing

Dark Reading · Arielle Waldman · indexed 2026-08-20 18:35 UTC

Law enforcement training is falling behind the volume and rapid evolution of cybercrimes. Officers really only need to learn the basics, but lack of focus and budget hinder progress.

Cybercrime
P0
2026-08-20 11:26 UTC
Security Journalism

Manic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-20 13:15 UTC

A new Android threat codenamed Manic has been observed actively targeting Ukrainian banks, government and identity services, and messaging applications, as well as Russian and European financial institutions, global fintech and cryptocurrency services, and military-focused communications. "Manic sits at the intersection of Android banking malware and mobile spyware, combining financial-fraud

CybercrimeMalwareMobile Security
P0
2026-08-20 10:38 UTC
Security Journalism

ToxicPanda 2.0 and GoldDigger Expand Android Banking Attacks with On-Device Fraud

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-20 11:15 UTC

Cybersecurity researchers have shed light on an updated version of ToxicPanda (aka TgToxic) that comes with "significant enhancements," including a set of 167 remote commands and expands its targeting footprint globally. Zimperium zLabs, in a Wednesday report, said the Android malware also features a PIN harvesting workflow targeting more than 140 banking and cryptocurrency applications.

CybercrimeMalwareMobile SecuritySecurity Research
P0
2026-08-20 10:00 UTC
Vendor Research

UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations

Cisco Talos Intelligence Blog · Joey Chen · indexed 2026-08-20 10:15 UTC

Cisco Talos discovered a Chinese-speaking cybercrime group, tracked as UAT-10147, that targets a wide range of vulnerable web servers. This is an overview of the campaign, examining the countries affected, potential impact of BadIIS infections, the attack chain, and post-compromise tactics.

Cybercrime
P0
2026-08-20 07:20 UTC
Other

StopAndProtect Turns 2,000 Hacked WordPress Sites Into a Criminal Network

Security Affairs · Pierluigi Paganini · indexed 2026-08-20 07:30 UTC

StopAndProtect turned nearly 2,000 hacked WordPress sites into a criminal network for malware delivery, data theft, surveillance and ransomware. Check Point Research uncovered a cybercrime operation, dubbed StopAndProtect, that has turned thousands of hacked WordPress websites into a shared platform for malware delivery, data theft, surveillance and ransomware. The operation is a good reminder that […]

CybercrimeMalwareRansomware
P15
2026-08-20 07:05 UTC
Other

One Adversary: Fraud Is a Network, Not a Payment

Group-IB · indexed 2026-09-07 17:30 UTC

Payment was authorised. The transaction was, technically, legitimate. It was also part of a $187 million criminal network, and the payment was the worst place to fight it.

Cybercrime
P0
2026-08-19 20:32 UTC
Security Journalism

No-Filter 'Kriminal' AI Platform Raises Cybercrime Concerns

Dark Reading · Alexander Culafi · indexed 2026-08-19 21:00 UTC

The AI company officially forbids illicit use, while offering guardrail-free social engineering, offensive cybercrime, and OSINT scanning to anyone with a bit of cryptocurrency.

Cybercrime
P0
2026-08-19 11:25 UTC
Security Journalism

StopAndProtect Uses Nearly 2,000 Hacked WordPress Sites to Spread Malware and Steal Data

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-19 11:35 UTC

Cybersecurity researchers have flagged a global cybercrime operation that abuses thousands of hacked WordPress websites as infrastructure to disseminate malware, commandeer infected hosts, store stolen documents, screenshots, and activity logs created to track the status of the activity. "The operation doesn't rely on a single piece of malware, but on a whole toolkit of criminal software

CybercrimeMalwareSecurity Research
P0
2026-08-19 08:33 UTC
Other

50,000 Stripe Secrets Leaked in Public Code

Security Affairs · Pierluigi Paganini · indexed 2026-08-19 09:50 UTC

Over 50,000 exposed Stripe API keys show how leaked secrets can enable fraud, data access and account abuse within hours. Ransomnews researchers have documented a large-scale leak of Stripe merchant API keys found exposed in public code repositories, GitHub Actions logs, and misconfigured web servers, with over 50,000 unique keys identified in total. The research […]

Cybercrime
P0
2026-08-18 12:49 UTC
Vendor Research

New Report: AI threats are here. Why Q2 2026 signals the end of traditional patch cycles

Rapid7 · Rapid7 Labs · indexed 2026-08-18 15:35 UTC

You can’t patch everything. So what do you fix first? Findings in Q2 2026 have changed traditional answers.The latest Quarterly Threat Landscape Report from Rapid7 Labs shows vulnerability disclosures still surging while attackers use automation and AI-assisted tooling to compress the time between disclosure and exploitation. The gap that patch cycles were built to fill is closing. Speed and volume are overwhelming security teams that have relied on traditional patch cycles and reactive program…

APT / Nation-StateCloud SecurityCybercrimeDFIRICS / OTMicrosoftPhishingRansomwareVulnerabilities
P15
2026-08-17 15:15 UTC
Vendor Research

Detecting cloud ransomware in Azure with Tenable One’s cloud detection and response capabilities

Tenable Blog · Clément Notin · indexed 2026-08-17 15:35 UTC

Learn how Tenable One Cloud Exposure helps you unmask the sophisticated tactics of cybercrime group Storm-0501, which carries out Azure-based cloud ransomware campaigns. Tenable One Cloud Exposure uses AI-powered threat stories to expose Storm-0501 TTPs, backed by precision-engineered threat detection alerts.Key takeawaysStorm-0501 demonstrates that cloud-first ransomware groups have shifted from simple endpoint encryption to the total hijacking of cloud tenants.Storm-0501 systematically neutra…

AppleCloud SecurityCybercrimeDFIRMalwareMicrosoftRansomwareThreat ActorsThreat Intelligence
P15
2026-08-17 11:29 UTC
Vendor Research

Operation ASTERIX: Anatomy of a Crypto Fraud Pipeline

Rapid7 · Anna Širokova · indexed 2026-08-18 15:35 UTC

Operation ASTERIX overviewRapid7 researchers identified an exposed web directory on infrastructure used to support a cryptocurrency fraud operation. The server contained raw phone-number datasets, account-validation tools, enriched lead records, phishing panels, voice-dialing scripts, fake wallet applications, persistence mechanisms, and Telegram exfiltration code. Among the artifacts was evidence that the operator relied on AI coding assistants throughout the campaign's development; recovered …

AI SecurityAppleCybercrimeMalwareMicrosoftNetwork SecurityPhishing
P0
1 2 3 4 5