IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 451 matching records.
AUTO-POLL // 2026-10-02 21:55 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P6 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 2

RANSOMWARE
P6
P6
COOL // 45 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
WED
Sep 30

RANSOMWARE
P10
P10
WARM // 59 ARTICLES
TUE
Sep 29

RANSOMWARE
P4
P4
COOL // 68 ARTICLES
MON
Sep 28

RANSOMWARE
P7
P7
COOL // 52 ARTICLES
SUN
Sep 27

RANSOMWARE
P25
P25
ELEVATED // 15 ARTICLES
SAT
Sep 26

RANSOMWARE
P13
P13
WARM // 20 ARTICLES
RESET
2026-10-02 17:33 UTC
Security Journalism

Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-02 17:45 UTC

Government and policy organizations across Asia have become the target of a new campaign orchestrated by a China-nexus threat actor. The activity, which has targeted government and policy organizations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, and Myanmar, involves the deployment of a previously undocumented backdoor codenamed Antino. Cisco Talos is tracking the cluster

APT / Nation-StateMalwareThreat Actors
P0
2026-10-02 13:15 UTC
Security Journalism

macOS Users Targeted by Fake Zoom Installer Carrying CloudSyncD Backdoor

Security Week · Kevin Townsend · indexed 2026-10-02 13:30 UTC

The dropper “carries a complete universal Mach-O inside itself, roughly 756 KB in the development build, and extracts it at runtime. The post macOS Users Targeted by Fake Zoom Installer Carrying CloudSyncD Backdoor appeared first on SecurityWeek.

AppleMalware
P0
2026-10-02 13:00 UTC
Vendor Research

SMTP is the key: BPFDoor and AVERAT hitting the network edge

Rapid7 · Rapid7 Intelligence · indexed 2026-10-02 13:30 UTC

OverviewRapid7 tracked a set of Linux samples that blend into the software and device conventions of the telecom environments they target. The set spans a newly observed BPFDoor variant, a BPF Rekoobe build seen against South Korean targets, a dropper, and six builds of a Linux implant we track as AVERAT, deployed against Taiwanese appliances. Additionally, we provide source code details of the Rapid7 BPFDoor controller introduced in our April 2026 blog, Stealthy BPFDoor Variants are a Needle T…

LinuxMalwareNetwork Security
P0
2026-10-02 08:01 UTC
Security Journalism

Android 17 Advanced Protection Locks Accessibility Services to Verified Accessibility Tools

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-02 08:20 UTC

Google has announced a new security measure that limits access to Android's accessibility services to verified applications classified as Accessibility Tools when Advanced Protection is enabled. With malicious Android applications abusing the API serving as the main conduit for malware and financial fraud, the tech giant said the move would block a major attack pathway. Advanced Protection is a

CybercrimeMalwareMobile Security
P0
2026-10-01 14:37 UTC
Security Journalism

WordPress Backdoor Rebuilds Itself After Cleanup Using Files, Database, and Shared Memory

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-01 14:50 UTC

Cybersecurity researchers have shed light on a WordPress compromise in which threat actors deployed multiple persistence mechanisms to ensure that the final payload kept returning without having to infect the site again. The backdoor has been codenamed SC after the "SC_" markers present in the injected content. Sucuri has described the malware as a "self-healing mesh" that's

MalwareSecurity ResearchThreat Actors
P0
2026-10-01 10:51 UTC
Security Journalism

Treasury Blacklists Most-Wanted ATM Malware Developer and His Network

Security Week · Eduard Kovacs · indexed 2026-10-01 11:00 UTC

The US government continues its crackdown on Tren de Aragua over its ATM jackpotting scheme. The post Treasury Blacklists Most-Wanted ATM Malware Developer and His Network appeared first on SecurityWeek.

Malware
P0
2026-09-30 22:35 UTC
Security Journalism

US sanctions 10 over ATM malware scheme tied to Tren de Aragua

The Record · indexed 2026-09-30 22:55 UTC

Treasury’s Office of Foreign Assets Control (OFAC) targeted multiple Venezuelan nationals and several companies they control that are part of the effort to launder the money stolen from dozens of ATMs.

Malware
P0
2026-09-30 15:00 UTC
Security Journalism

Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix Lures

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-30 15:30 UTC

Threat actors are abusing ChatGPT Custom GPTs to disguise them as legitimate product offerings and direct unsuspecting victims to malicious sites that employ ClickFix lures to deliver malware. Huntress, which observed the activity in late September 2026, said it marks the abuse of yet another feature in trusted artificial intelligence (AI) platforms. Prior campaigns have weaponized shared

AI SecurityMalwareThreat Actors
P0
2026-09-30 14:16 UTC
Vendor Research

Higher education is under siege, and fragmented security is making it harder to respond

Rapid7 · Rapid7 · indexed 2026-09-30 15:05 UTC

Higher education faces a difficult security equation. Universities hold large volumes of sensitive student, financial, health, and research data while supporting open networks, distributed users, legacy infrastructure, and increasingly complex cloud environments. Attackers have taken notice, and the pressure on security teams continues to grow.In Q2 2025, universities faced an average of 4,388 cyberattacks per organization per week, up 24% from the same period in 2024. Nine in ten universities …

Data BreachesDFIRMalwareMicrosoftRansomwareThreat IntelligenceVulnerabilities
P40
2026-09-30 10:00 UTC
Vendor Research

China-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoor

Cisco Talos Intelligence Blog · Ashley Shen · indexed 2026-09-30 10:10 UTC

Cisco Talos uncovered a cluster of activity we track as UAT-11587 targeting government and policy organizations across Asia, including in Taiwan, India, the Philippines, and Cambodia, to deliver a previously undocumented backdoor referred to as “Antino” in developer artifacts.

Malware
P0
2026-09-29 20:59 UTC
Security Journalism

Custom ChatGPTs push ClickFix attacks to deploy RAT malware

BleepingComputer · Bill Toulas · indexed 2026-09-29 21:05 UTC

Custom variants of OpenAI's ChatGPT promoted in sponsored Google results are directing unsuspecting users to malicious sites that use ClickFix attacks to deliver malware. [...]

Malware
P0
2026-09-29 17:20 UTC
Security Journalism

Russia's Star Blizzard Targets 100+ Organizations With Fake Event Invites to Deliver Backdoor

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-29 18:35 UTC

Russian state hackers known as Star Blizzard have been using fake event invitations to trick people into installing a backdoor on their Windows computers, according to Microsoft. The campaigns, aimed at people and organizations tied to Ukraine, have affected more than 100 organizations since January, mostly in the U.S. and U.K. At least one computer was infected, but the number of breached

MalwareMicrosoft
P0
2026-09-29 15:00 UTC
Vendor Research

Star Blizzard refines phishing and malware delivery with the RedFlick technique

Microsoft Security Blog · Microsoft Threat Intelligence · indexed 2026-09-29 15:35 UTC

Since January 2026, Microsoft has observed Russian state threat actor Star Blizzard evolve their detection evasion capabilities through large-scale phishing campaigns, the use of accounts on compromised websites, and a novel malware delivery technique, tracked by Microsoft as “RedFlick”. The post Star Blizzard refines phishing and malware delivery with the RedFlick technique appeared first on Microsoft Security Blog.

MalwareMicrosoftPhishingThreat Actors
P0
2026-09-29 14:00 UTC
Vendor Research

Defending Against Active Exploitation of Citrix NetScaler ADC and Gateway Appliances

Google Threat Intelligence / Mandiant · Mandiant · indexed 2026-09-29 14:00 UTC

Introduction In late September 2026, Mandiant Consulting and Google Threat Intelligence Group (GTIG) identified active, in-the-wild exploitation of a zero-day vulnerability (CVE-2026-88772) affecting Citrix NetScaler ADC and NetScaler Gateway appliances. We have observed evidence that organizations in North America and Europe in the government, financial services, technology, education, and legal and professional services sectors were likely impacted by this exploitation campaign, which has bee…

LinuxMalwareMicrosoftNetwork SecurityPhishingThreat ActorsThreat IntelligenceVulnerabilitiesCVE-2026-88771CVE-2026-88772
P30
2026-09-29 09:46 UTC
Security Journalism

Daemon Tools Hackers’ NeedyMantis Malware Dissected by Microsoft

Security Week · Ionut Arghire · indexed 2026-09-29 10:00 UTC

The malware framework uses a modular architecture and a custom executable file format for long-term persistence. The post Daemon Tools Hackers’ NeedyMantis Malware Dissected by Microsoft appeared first on SecurityWeek.

MalwareMicrosoft
P0
2026-09-28 20:14 UTC
Other

AI Accounts Are Becoming the New Target for Infostealers

Security Affairs · Pierluigi Paganini · indexed 2026-09-28 21:25 UTC

Infostealers are exposing corporate AI accounts, sessions and API keys, giving attackers access to sensitive data, compute and connected systems. SOCRadar analyzed stealer log data from the last 90 days and found 482 companies with exposed AI accounts and credentials. Of those, 295 appeared in active logs during that period, suggesting the exposure is recent […]

Malware
P0
1 2 3