IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 167 matching records.
AUTO-POLL // 2026-10-02 21:55 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P6 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 2

RANSOMWARE
P6
P6
COOL // 45 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
WED
Sep 30

RANSOMWARE
P10
P10
WARM // 59 ARTICLES
TUE
Sep 29

RANSOMWARE
P4
P4
COOL // 68 ARTICLES
MON
Sep 28

RANSOMWARE
P7
P7
COOL // 52 ARTICLES
SUN
Sep 27

RANSOMWARE
P25
P25
ELEVATED // 15 ARTICLES
SAT
Sep 26

RANSOMWARE
P13
P13
WARM // 20 ARTICLES
RESET
2026-10-02 13:00 UTC
Vendor Research

SMTP is the key: BPFDoor and AVERAT hitting the network edge

Rapid7 · Rapid7 Intelligence · indexed 2026-10-02 13:30 UTC

OverviewRapid7 tracked a set of Linux samples that blend into the software and device conventions of the telecom environments they target. The set spans a newly observed BPFDoor variant, a BPF Rekoobe build seen against South Korean targets, a dropper, and six builds of a Linux implant we track as AVERAT, deployed against Taiwanese appliances. Additionally, we provide source code details of the Rapid7 BPFDoor controller introduced in our April 2026 blog, Stealthy BPFDoor Variants are a Needle T…

LinuxMalwareNetwork Security
P0
2026-09-30 14:00 UTC
Vendor Research

Vulnerability Discovery and Exploitation Trends in the AI Era

Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-09-30 14:45 UTC

Written by: Robin Grunewald, Supriya Mazumdar, Kelli Vanderlee Introduction Google Threat Intelligence Group (GTIG) examines vulnerability disclosure and exploitation statistics to evaluate the impact of artificial intelligence (AI) on the vulnerability threat landscape. We found that AI is measurably changing not just the pace of vulnerability discovery and exploitation, but also the types and typical risk profiles of vulnerabilities that are being discovered. Key findings: Vulnerability discl…

AI SecurityCloud SecurityLinuxMicrosoftNetwork SecurityThreat ActorsThreat IntelligenceVulnerabilities
P60
2026-09-29 17:20 UTC
Security Journalism

New Spectre-v2 BTR Attack Leaks Linux Memory Despite Existing Defenses

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-29 17:20 UTC

A group of academics from VUSec and Scuola Superiore Sant'Anna have disclosed details of a new Spectre CPU vulnerability variant that affects Just-In-Time (JIT) engines present in web browsers, language runtimes, and the operating system kernel, across multiple CPU vendors. The new Spectre v2 variant has been codenamed Branch Target Reuse (BTR). "The key insight is that, while modern CPUs

LinuxVulnerabilities
P0
2026-09-29 17:00 UTC
Security Journalism

New Spectre v2 Variant Exposes Intel, AMD, Arm CPUs to Data Leaks

Security Week · Eduard Kovacs · indexed 2026-09-29 17:15 UTC

Branch Target Reuse (BTR) is a new Spectre v2 attack targeting JIT compilers in web browsers, language runtimes, and the operating system kernel The post New Spectre v2 Variant Exposes Intel, AMD, Arm CPUs to Data Leaks appeared first on SecurityWeek.

Data BreachesLinux
P0
2026-09-29 14:00 UTC
Vendor Research

Defending Against Active Exploitation of Citrix NetScaler ADC and Gateway Appliances

Google Threat Intelligence / Mandiant · Mandiant · indexed 2026-09-29 14:00 UTC

Introduction In late September 2026, Mandiant Consulting and Google Threat Intelligence Group (GTIG) identified active, in-the-wild exploitation of a zero-day vulnerability (CVE-2026-88772) affecting Citrix NetScaler ADC and NetScaler Gateway appliances. We have observed evidence that organizations in North America and Europe in the government, financial services, technology, education, and legal and professional services sectors were likely impacted by this exploitation campaign, which has bee…

LinuxMalwareMicrosoftNetwork SecurityPhishingThreat ActorsThreat IntelligenceVulnerabilitiesCVE-2026-88771CVE-2026-88772
P30
2026-09-25 15:07 UTC
Security Journalism

In Other News: Clop Leak Site Takeover, Docker Botnet Hunts AI Keys, Water Utility Exposure

Security Week · SecurityWeek News · indexed 2026-09-25 15:10 UTC

Noteworthy stories that might have slipped under the radar: BragJack attack against browser AI assistants, TDengine flaw threatens industrial telemetry uptime, Ubuntu update overhaul. The post In Other News: Clop Leak Site Takeover, Docker Botnet Hunts AI Keys, Water Utility Exposure appeared first on SecurityWeek.

LinuxMalware
P0
2026-09-25 14:00 UTC
Vendor Research

ShinyHunters Renewed Mass Exploitation Campaign Targeting Oracle PeopleSoft

Google Threat Intelligence / Mandiant · Mandiant · indexed 2026-09-26 06:55 UTC

Introduction As an update to the June 2026 post, ShinyHunters Targets Education Sector with Oracle PeopleSoft Exploit, Mandiant and Google Threat Intelligence Group (GTIG) have identified renewed mass exploitation of CVE-2026-35273 by UNC6240 (ShinyHunters), along with expanded global targeting across multiple sectors. In June, the threat actor exploited this vulnerability as a zero-day predominantly against academic institutions. This new wave of activity stems from UNC6240 modifying its explo…

LinuxMicrosoftNetwork SecurityThreat ActorsThreat IntelligenceVulnerabilitiesCVE-2026-35273
P50
2026-09-23 13:52 UTC
Security Journalism

Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-23 14:10 UTC

Unknown threat actors have managed to compromise two legitimate MemTensor packages across the npm and Python Package Index (PyPI) repositories to push a platform-specific Go-based implant dubbed sckit designed for Windows, Linux, and macOS. According to reports from Aikido, SafeDep, Socket, and StepSecurity, the libraries in question below - @memtensor/memos-cloud-openclaw-plugin versions

AppleLinuxMalwareMicrosoftThreat Actors
P0
2026-09-23 11:12 UTC
Security Journalism

Exploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container Escape

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-23 12:40 UTC

A use-after-free in the Linux kernel's AF_UNIX socket subsystem can be used to escape a container and gain root on the host, security firm DepthFirst said in research published September 22. The flaw, tracked as CVE-2026-80521 (CVSS score: 7.8), was fixed upstream on August 6, but Ubuntu has not shipped the patch for its 26.04, 24.04, or 22.04 LTS releases. DepthFirst

LinuxVulnerabilitiesCVE-2026-80521
P5
2026-09-22 11:38 UTC
Security Journalism

New Linux Kernel Flaw Gives ARM64 KVM Guests Read-Write Access to Host Memory

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-22 12:10 UTC

A new flaw in the Linux kernel's KVM virtualization code for ARM64 processors can leave a freed piece of host memory exposed to a guest virtual machine on hosts with nested virtualization enabled. The bug, tracked as CVE-2026-89775, allows a guest to read and write host kernel memory, and the researcher who found it says it can be used to escape the guest and run code on the host machine.

LinuxVulnerabilitiesCVE-2026-89775
P5
2026-09-21 17:31 UTC
Security Journalism

Fake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus and EDR

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-21 18:15 UTC

A fake LastPass Authenticator installer offered on GitHub installs a Windows kernel driver that shuts off antivirus and other security software before a password stealer runs if a victim downloads and runs it, researchers at LastPass and Delphos Labs said on September 17. Microsoft's own hardware-compatibility program signs the driver, scored zero detections on VirusTotal when researchers

LinuxMalwareMicrosoft
P0
2026-09-20 16:12 UTC
Other

U.S. CISA adds Linux Kernel flaws to its Known Exploited Vulnerabilities catalog

Security Affairs · Pierluigi Paganini · indexed 2026-09-20 17:10 UTC

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Linux Kernel flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added [1, 2] the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: Below are detailed descriptions of the flaws: At the time of this writing, there are currently no details on how the […]

Cloud SecurityLinux
P30
2026-09-20 12:22 UTC
Other

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 115

Security Affairs · Pierluigi Paganini · indexed 2026-09-20 12:30 UTC

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Gray Rabbits and the Tale of a One-Click Backdoor Red Heron exploits Gitea n-day flaw in multinational campaign, exposing new Linux rootkit Malicious Twitch Browser Extension Exposes 30,000 Users’ OAuth Tokens to Russian Bot […]

LinuxMalware
P0
2026-09-19 06:24 UTC
Security Journalism

CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-19 07:15 UTC

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added three security flaws impacting the Linux kernel to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerabilities are listed below - CVE-2025-39682 (CVSS score: 9.8) - An improper check for unusual or exceptional conditions vulnerability in the TLS receive path

Cloud SecurityLinuxVulnerabilitiesCVE-2025-39682
P55
2026-09-18 18:02 UTC
Security Journalism

Public Exploits Released for Four Linux Kernel Flaws That Enable Local Root

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-18 20:25 UTC

A security researcher has released working exploit code for four Linux kernel flaws that each let a local user gain root, the highest level of access on a machine. Kernel maintainers have fixed all four over the past few weeks, so a system running an up-to-date kernel is not affected. But the exploit code is now public, and any machine still running an older kernel should be updated. The flaws

Cloud SecurityLinuxSecurity Research
P0
2026-09-18 05:00 UTC
Other

ZDI-26-715: Linux Mint Xreader PDF File Parsing Type Confusion Remote Code Execution Vulnerability

Zero Day Initiative · indexed 2026-09-18 14:35 UTC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Linux Mint Xreader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-19772.

LinuxVulnerabilitiesCVE-2026-19772
P20
2026-09-16 20:20 UTC
Other

BambooToken: The Malware That Speaks MQTT to Stay Under the Radar

Security Affairs · Pierluigi Paganini · indexed 2026-09-16 21:00 UTC

Lumen exposes BambooToken, a stealthy malware family using MQTT and sideloading to quietly infect targets across Asia and beyond. BambooToken is a new malware family that uses MQTT, a lightweight messaging protocol commonly found in smart devices and industrial systems, to quietly control infected Windows and Linux machines. Most malware connects directly to a command-and-control […]

LinuxMalwareMicrosoft
P0
2026-09-16 11:08 UTC
Security Journalism

Acronis cPanel Backup Plugin Vulnerability Exploited in Targeted Attacks

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-16 11:45 UTC

Acronis has warned that a high-severity security flaw in its Backup plugin for cPanel and Web Host Manager (WHM) deployments has been exploited in the wild. The vulnerability, tracked as CVE-2026-87886 (CVSS score: 7.8), is described as a case of local privilege escalation due to insecure file permissions. It affects the following versions - Acronis Backup plugin for cPanel & WHM (Linux

LinuxVulnerabilitiesCVE-2026-87886
P35
1 2 3