IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 451 matching records.
AUTO-POLL // 2026-10-02 22:45 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P6 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 2

RANSOMWARE
P6
P6
COOL // 45 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
WED
Sep 30

RANSOMWARE
P10
P10
WARM // 59 ARTICLES
TUE
Sep 29

RANSOMWARE
P4
P4
COOL // 68 ARTICLES
MON
Sep 28

RANSOMWARE
P7
P7
COOL // 52 ARTICLES
SUN
Sep 27

RANSOMWARE
P25
P25
ELEVATED // 15 ARTICLES
SAT
Sep 26

RANSOMWARE
P13
P13
WARM // 20 ARTICLES
RESET
2026-09-28 18:35 UTC
Security Journalism

Hackers Use NeedyMantis to Maintain Long-Term Access in Breached Networks

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-28 20:10 UTC

Hackers have used a malware family called NeedyMantis to maintain long-term access to networks they had already breached, Microsoft said in a technical analysis. The malware has been seen in a small number of targeted intrusions at telecommunications organizations, universities, medical nonprofits, intergovernmental organizations, and government contractors. Its use goes back to at least

MalwareMicrosoft
P0
2026-09-28 17:38 UTC
Security Journalism

RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-28 18:40 UTC

RatHat's operators build and publish the Android banking trojan and control infected phones from a web console, according to security company Cleafy. Cleafy has traced nearly 100 deployments of that console since April 2026. It said this fits a malware-as-a-service model, in which each customer runs a separate copy. The console stores what the malware collects from each phone,

MalwareMobile Security
P0
2026-09-28 15:00 UTC
Vendor Research

NeedyMantis: Unpacking a post-compromise malware family used in targeted operations

Microsoft Security Blog · Microsoft Threat Intelligence · indexed 2026-09-28 16:30 UTC

Microsoft Threat Intelligence identified NeedyMantis, a modular post-compromise malware framework used in targeted intrusions that combines custom loaders, encrypted archives, and extensible components to maintain long-term access and support follow-on operations. The post NeedyMantis: Unpacking a post-compromise malware family used in targeted operations appeared first on Microsoft Security Blog.

MalwareMicrosoftThreat Intelligence
P0
2026-09-28 14:00 UTC
Security Journalism

80,000+ Organizations Had AI Logins Stolen: From Shadow AI to LLMjacking

BleepingComputer · Sponsored by SOCRadar · indexed 2026-09-28 14:10 UTC

Infostealer logs exposed AI account credentials and sessions tied to more than 80,000 corporate domains, creating risks ranging from stolen conversations to LLMjacking. SOCRadar examines the growing market for stolen AI logins and how organizations can identify their exposure. [...]

AI SecurityMalware
P0
2026-09-28 11:46 UTC
Security Journalism

Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-28 12:40 UTC

Cybersecurity researchers have disclosed details of a new botnet malware called Carbonato that's targeting exposed Docker daemons to deploy an open-source artificial intelligence (AI) agent framework called Hermes Agent. "The implant installs the framework unchanged, then overwrites its SOUL.md persona file," ThreatDown said. "The 39-line prompt directs it to execute tasks received through

AI SecurityMalwareSecurity Research
P0
2026-09-27 15:05 UTC
Other

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 116

Security Affairs · Pierluigi Paganini · indexed 2026-09-27 15:35 UTC

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Threat Intel | One Kit, Forty Companies: How a Malware-as-a-Service Platform Used GitHub as a Distribution Network for its Campaign Group Policy hijacked: PAYLOAD ransomware weaponizes Active Directory GPO ChainScript: Tracing a Node.js RAT […]

MalwareRansomware
P15
2026-09-26 18:22 UTC
Security Journalism

Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-26 19:05 UTC

The Psychedelic Stealer malware distributed via compromised Ukrainian websites using ClickFix-style Cloudflare verification checks is part of a wider malware-as-a-service (MaaS) platform called Lunex. The new findings come from Ontinue, which described the activity as a four-stage attack chain aimed at targeting Ukrainian-speaking users. "The attack chain begins with a fake CAPTCHA page and

Malware
P0
2026-09-26 12:00 UTC
Security Journalism

New x47.c Windows Botnet Weaponizes xAI Grok, AI API Draining

Security Week · Ionut Arghire · indexed 2026-09-26 12:10 UTC

The Windows botnet relies on AI to maintain persistence, using xAI Grok to choose from predefined actions. The post New x47.c Windows Botnet Weaponizes xAI Grok, AI API Draining appeared first on SecurityWeek.

MalwareMicrosoft
P0
2026-09-25 15:07 UTC
Security Journalism

In Other News: Clop Leak Site Takeover, Docker Botnet Hunts AI Keys, Water Utility Exposure

Security Week · SecurityWeek News · indexed 2026-09-25 15:10 UTC

Noteworthy stories that might have slipped under the radar: BragJack attack against browser AI assistants, TDengine flaw threatens industrial telemetry uptime, Ubuntu update overhaul. The post In Other News: Clop Leak Site Takeover, Docker Botnet Hunts AI Keys, Water Utility Exposure appeared first on SecurityWeek.

LinuxMalware
P0
2026-09-25 14:44 UTC
Security Journalism

Compromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-25 16:10 UTC

Two actions-cool GitHub Actions have been disabled for a second time after the repositories became accessible last week, months after they were compromised during the May 2026 Mini Shai-Hulud campaign. The affected GitHub Actions are listed below - actions-cool/issues-helper actions-cool/maintain-one-comment Visiting either of the repositories now shows the message: "Access to this

Malware
P0
2026-09-25 13:49 UTC
Other

ClickFix Campaign Abuses Trusted Websites to Deploy Psychedelic Stealer

Security Affairs · Pierluigi Paganini · indexed 2026-09-25 14:10 UTC

Attackers hijacked Ukrainian websites to deliver a fake Cloudflare CAPTCHA that installs Psychedelic Stealer and steals browser and crypto credentials. Psychedelic Stealer is being distributed through compromised Ukrainian business websites. Attackers injected hidden iframes into legitimate pages and used them to display a fake Cloudflare verification screen to visitors. The affected sites included a hair-treatment […]

Malware
P0
2026-09-25 13:18 UTC
Security Journalism

PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-25 16:10 UTC

Cybersecurity researchers have flagged a new version of PamStealer that ensures that the main payload can only be recovered using a server-side decryption chain. The latest artifacts, per Jamf Threat Labs, continue to rely on the same JavaScript for Automation (JXA) dropper mechanism, but modify the lure and the delivery method. "Where earlier variants embedded their payload key material

AppleMalwareSecurity Research
P0
2026-09-25 09:55 UTC
Other

AI-Powered CARBONATO Botnet Steals Credentials to Fund Its Own LLM Gateway

Security Affairs · Pierluigi Paganini · indexed 2026-09-25 10:40 UTC

CARBONATO exploits exposed Docker daemons, installs an AI agent, steals API keys and spreads across networks with autonomous command execution. CARBONATO is a Docker-based botnet that has been active since at least October 2024. ThreatDown discovered the operation after finding an unauthenticated container registry exposed to the internet. The registry contained the attackers’ entire toolchain […]

AI SecurityMalware
P0
2026-09-24 20:32 UTC
Security Journalism

SectopRAT Returns, Hiding Inside a Legitimate Application

Dark Reading · Jai Vijayan · indexed 2026-09-24 21:00 UTC

The latest activity from the remote access Trojan (RAT) shows why organizations should monitor the behavior of applications rather than blindly trusting them, experts say.

Malware
P0
2026-09-24 14:29 UTC
Security Journalism

Hacked Ukrainian Sites Serve Fake Cloudflare ClickFix Lures for Psychedelic Stealer

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-24 15:10 UTC

An active ClickFix campaign has been observed compromising legitimate Ukrainian business websites to inject bogus Cloudflare verification pages and trick victims into downloading a previously undocumented information stealer called Psychedelic. "When a visitor interacts with the page, the lure copies a Windows Installer command to the clipboard and instructs the visitor to paste it into the

MalwareMicrosoft
P0
2026-09-24 09:14 UTC
Security Journalism

17,000 URLs Reveal How ClickFix Turns Trusted Websites Into Malware Traps: Report by CTM360

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-24 11:05 UTC

ClickFix has become the most common way attackers get into enterprise networks, and it does it without an exploit, an attachment, or a file on disk. Our new global threat report traces the technique from a novelty in late 2023 to a subscription product with on-chain infrastructure and a state-sponsored user base, and explains why blocking malicious domains is no longer a useful defense. Read

APT / Nation-StateMalware
P0
2026-09-24 05:44 UTC
Other

CLOSEDQUORUM, the malware that asks four AI models what to do next

Security Affairs · Pierluigi Paganini · indexed 2026-09-24 05:50 UTC

Cisco Talos finds CLOSEDQUORUM, malware that lets four commercial AI models vote on its next move, with no human operator required. Cisco Talos found malware, dubbed CLOSEDQUORUM, that holds a vote before deciding what to steal from you. Four AI models vote on its next move, without any human interaction. CLOSEDQUORUM is the first Windows […]

MalwareMicrosoft
P0
2026-09-23 18:06 UTC
Security Journalism

Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-23 20:00 UTC

Cybersecurity researchers have disclosed Go-based malware distributed via two Go Modules and two Terraform providers, marking the first time threat actors are using the centralized repository hosted by HashiCorp as a distribution vector for malicious payloads. According to Aikido, the list of Terraform providers and Go modules is below - gocommunity-io/dockerd (222 downloads) kreuzwenker/

MalwareMicrosoftSecurity ResearchThreat Actors
P0
2026-09-23 14:17 UTC
Security Journalism

This Windows Malware is Built to Let Up to Four AI Models Vote on Its Next Move

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-23 15:25 UTC

A Windows malware called CLOSEDQUORUM is built to take orders from a vote of up to four AI models instead of an attacker's server, Cisco Talos said on September 22. The models can choose to steal Windows credentials, saved browser passwords, and crypto wallet data. Talos has not seen this setup work from start to finish, and the public version of the malware does not work as it is.

MalwareMicrosoft
P0
2026-09-23 13:52 UTC
Security Journalism

Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-23 14:10 UTC

Unknown threat actors have managed to compromise two legitimate MemTensor packages across the npm and Python Package Index (PyPI) repositories to push a platform-specific Go-based implant dubbed sckit designed for Windows, Linux, and macOS. According to reports from Aikido, SafeDep, Socket, and StepSecurity, the libraries in question below - @memtensor/memos-cloud-openclaw-plugin versions

AppleLinuxMalwareMicrosoftThreat Actors
P0
2026-09-23 08:29 UTC
Security Journalism

Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-23 08:45 UTC

A Chinese threat actor codenamed UTA0565 has been observed exploiting the recently disclosed Google Chrome-Microsoft Windows exploit chain as zero-days through fake websites. The attacks, detected on September 3 and 4, 2026, involved the chaining of two vulnerabilities in Chrome (CVE-2026-85046, CVE-2026-87491) and one impacting Windows Advanced Local Procedure Call (CVE-2026-85880) to break

MalwareMicrosoftThreat ActorsVulnerabilitiesCVE-2026-85046CVE-2026-85880CVE-2026-87491
P30
2026-09-23 08:25 UTC
Other

Fake LastPass on GitHub Led to an Infostealer That Killed 145 Security Tools

Security Affairs · Pierluigi Paganini · indexed 2026-09-23 08:50 UTC

Attackers spoofed LastPass on GitHub, used a Microsoft-signed driver to disable 145 security products, then deployed an infostealer. Someone impersonated LastPass on GitHub, got users to download a fake authenticator, and ended up killing 145 different antivirus and EDR products using a driver that Microsoft itself had signed. That last part is the one worth […]

MalwareMicrosoft
P0
2026-09-22 13:10 UTC
Community

LausivLoader analysis, or how to pass data between malware stages, (Thu, Sep 17th)

SANS Internet Storm Center · indexed 2026-09-17 15:05 UTC

At the end of August, a malspam message was caught in the quarantine of a mail gateway operated by one of my customers. The message was not especially remarkable – it asked the recipient to review some attached requirements and provide a price quotation for a fiber optic system and appeared to impersonate an employee of a legitimate company.

Malware
P0
1 2 3 4