IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 451 matching records.
AUTO-POLL // 2026-10-03 02:50 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
NO DATA
NO INTELLIGENCE AGGREGATED TODAY
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 3
NO DATA
--
NO INTEL
FRI
Oct 2

RANSOMWARE
P7
P7
COOL // 46 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
WED
Sep 30

RANSOMWARE
P10
P10
WARM // 59 ARTICLES
TUE
Sep 29

RANSOMWARE
P4
P4
COOL // 68 ARTICLES
MON
Sep 28

RANSOMWARE
P7
P7
COOL // 52 ARTICLES
SUN
Sep 27

RANSOMWARE
P25
P25
ELEVATED // 15 ARTICLES
RESET
2025-10-28 17:01 UTC
Vendor Research

HTTPS by default

Google Online Security Blog · Google · indexed 2026-08-15 14:33 UTC

One year from now, with the release of Chrome 154 in October 2026, we will change the default settings of Chrome to enable “Always Use Secure Connections”. This means Chrome will ask for the user's permission before the first access to any public site without HTTPS. The “Always Use Secure Connections” setting warns users before accessing a site without HTTPS Chrome Security's mission is to make it safe to click on links. Part of being safe means ensuring that when a user types a URL or clicks o…

LinuxMalwareMicrosoftMobile Security
P0
2025-10-22 07:01 UTC
Other

Unmasking MuddyWater’s New Malware Toolkit Driving International Espionage

Group-IB · indexed 2026-09-07 17:30 UTC

Group-IB Threat Intelligence has uncovered a sophisticated phishing campaign, attributed with high confidence to the Advanced Persistent Threat (APT) MuddyWater. The attack used a compromised mailbox to distribute Phoenix backdoor malware to international organizations and across the whole Middle East and North Africa region, targeting more than 100 government entities.

APT / Nation-StateMalwarePhishingThreat Intelligence
P0
2025-10-15 04:00 UTC
Security Journalism

The Crown Prince, Nezha | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

Beginning in mid-2025, Huntress discovered a new tool being used to facilitate webserver intrusions known as Nezha, which up until now hasn’t been publicly reported on. This was used in tandem with other families of malware and web shell management tools such as Ghost RAT and AntSword.

Malware
P0
2025-08-29 05:00 UTC
Security Journalism

From a Fake AnyDesk Installer to MetaStealer

Huntress · indexed 2026-09-07 17:30 UTC

Learn how a fake AnyDesk installer led to a unique MetaStealer attack, highlighting how threat actors evolve ClickFix techniques beyond the classic playbook to steal credentials and files.

MalwareThreat Actors
P0
2025-08-25 09:04 UTC
Other

Trust issues: How email threats hide behind your partners

Group-IB · indexed 2026-09-07 17:30 UTC

The most widely used email security tools still focus on yesterday’s threats. Meanwhile, attackers have moved on. By hijacking legitimate business relationships and embedding infostealers in familiar-sounding, well-written emails, cybercriminals bypass conventional defenses. The only way to keep up is by using a behavioral approach.

Malware
P0
2025-07-21 21:34 UTC
Vendor Research

Introducing OSS Rebuild: Open Source, Rebuilt to Last

Google Online Security Blog · Kimberly Samra · indexed 2026-08-15 14:33 UTC

Posted by Matthew Suozzo, Google Open Source Security Team (GOSST)Today we're excited to announce OSS Rebuild, a new project to strengthen trust in open source package ecosystems by reproducing upstream artifacts. As supply chain attacks continue to target widely-used dependencies, OSS Rebuild gives security teams powerful data to avoid compromise without burden on upstream maintainers.The project comprises:Automation to derive declarative build definitions for existing PyPI (Python), npm (JS/T…

MalwareSecurity ResearchVulnerabilities
P0
2025-07-08 17:36 UTC
Vendor Research

Advancing Protection in Chrome on Android

Google Online Security Blog · Google · indexed 2026-08-15 14:33 UTC

Posted by David Adrian, Javier Castro & Peter Kotwicz, Chrome Security Team Android recently announced Advanced Protection, which extends Google’s Advanced Protection Program to a device-level security setting for Android users that need heightened security—such as journalists, elected officials, and public figures. Advanced Protection gives you the ability to activate Google’s strongest security for mobile devices, providing greater peace of mind that you’re better protected against the most s…

Data BreachesMalwareMobile SecurityVulnerabilities
P0
2025-07-02 08:08 UTC
Other

June’s Dark Gift: The Rise of Qwizzserial

Group-IB · indexed 2026-09-07 17:30 UTC

Discovered by Group-IB in mid-2024, the Qwizzserial, which was initially not very active, began to spread strongly in Uzbekistan, masquerading as legitimate applications. The malware steals banking information and intercepts 2FA sms, transmitting it to fraudsters via Telegram bots.

CybercrimeMalware
P0
2025-06-13 16:03 UTC
Vendor Research

Mitigating prompt injection attacks with a layered defense strategy

Google Online Security Blog · Kimberly Samra · indexed 2026-08-15 14:33 UTC

Posted by Adam Gavish, Google GenAI Security TeamWith the rapid adoption of generative AI, a new wave of threats is emerging across the industry with the aim of manipulating the AI systems themselves. One such emerging attack vector is indirect prompt injections. Unlike direct prompt injections, where an attacker directly inputs malicious commands into a prompt, indirect prompt injections involve hidden malicious instructions within external data sources. These may include emails, documents, or…

AI SecurityMalwarePhishingSecurity ResearchThreat ActorsThreat IntelligenceVulnerabilities
P0
2025-06-03 05:00 UTC
Security Journalism

Infostealers Crash Course: A Tradecraft Tuesday Recap

Huntress · indexed 2026-09-07 17:30 UTC

Cybercriminals are sitting on a pile of stolen credentials, financial information, and sensitive data, thanks to the success of infostealers. Read more to learn how infostealers have grown to become a scourge to defenders, and how businesses can protect themselves.

CybercrimeMalwareMicrosoft
P0
2025-04-24 05:00 UTC
Security Journalism

How to Stop Malware Attacks with a Security-First Culture

Huntress · indexed 2026-09-07 17:30 UTC

Protect your business from malware attacks by fostering a security-first culture. Learn how to defend against cyber threats, establish strategies, and train employees to spot malware before it strikes.

Malware
P0
2025-04-22 05:00 UTC
Security Journalism

Say Hello to Mac Malware

Huntress · indexed 2026-09-07 17:30 UTC

In this month’s Tradecraft Tuesday, we talked about how threat actors are finetuning their macOS malware in order to maintain persistent access and avoid detection by Apple’s security features.

AppleMalwareThreat Actors
P0
2025-03-28 05:00 UTC
Security Journalism

Securing Endpoints from Common Vulnerabilities

Huntress · indexed 2026-09-07 17:30 UTC

Learn how to lock down common endpoint vulnerabilities like weak passwords and unpatched software to secure your systems against threats like phishing and malware.

MalwarePhishing
P0
2024-12-16 00:00 UTC
Other

Dirty DAG - Azure Apache Airflow Integration Vulnerabilities

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

Unit 42 researchers identified vulnerabilities in the Azure Data Factory's integration with Apache Airflow. These vulnerabilities include misconfigured Kubernetes Role-Based Access Control (RBAC), improper secret handling in Azure’s internal Geneva service, and weak authentication mechanisms. Exploiting these flaws, attackers could gain shadow admin control over Azure infrastructure by crafting malicious DAG files or compromising service principals, leading to unauthorized access, data exfiltra…

Cloud SecurityMalware
P0
2024-11-21 09:33 UTC
Other

Tracing the Path of VietCredCare and DuckTail: Vietnamese dark market of infostealers’ data

Group-IB · indexed 2026-09-07 17:30 UTC

Following the arrest in May 2024 of more than 20 individuals behind Facebook infostealers campaigns in Vietnam, we have compared the tactics of operators behind VietCredCare and DuckTail stealers. These 2 malware families have been active before the arrest in Vietnam and are believed to be controlled by Vietnamese threat actors. Based on the research, we decided that the groups operate in a different way and the arrest probably affected the VietCredCare operators.

MalwareThreat Actors
P0
2024-09-25 07:00 UTC
Other

Inside the Dragon: DragonForce Ransomware Group

Group-IB · indexed 2026-09-07 17:30 UTC

In this blog, we look at the DragonForce ransomware group, which poses a severe threat with two variants—a LockBit fork and a customized Conti fork with advanced features and SystemBC malware.

MalwareRansomware
P15
2024-09-20 00:00 UTC
Security Journalism

Akira Ransomware Indicators | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

Tracking various indicators associated with different attacks, Huntress analysts have been able to identify specific indicators (threat actor workstation names, passwords associated with new user account creation or current account modification, CloudFlare tunnel tokens) that are associated with Akira ransomware infections. By detecting these indicators much earlier in the attack chain, organizations can inhibit or even obviate file encryption malware deployment.

MalwareRansomwareThreat Actors
P15
11 12 13 14 15