IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 451 matching records.
AUTO-POLL // 2026-10-02 22:45 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P6 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 2

RANSOMWARE
P6
P6
COOL // 45 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
WED
Sep 30

RANSOMWARE
P10
P10
WARM // 59 ARTICLES
TUE
Sep 29

RANSOMWARE
P4
P4
COOL // 68 ARTICLES
MON
Sep 28

RANSOMWARE
P7
P7
COOL // 52 ARTICLES
SUN
Sep 27

RANSOMWARE
P25
P25
ELEVATED // 15 ARTICLES
SAT
Sep 26

RANSOMWARE
P13
P13
WARM // 20 ARTICLES
RESET
2026-09-22 11:33 UTC
Security Journalism

Malicious B-tree NPM Package Accumulates Millions of Downloads

Security Week · Ionut Arghire · indexed 2026-09-22 11:50 UTC

Posing as the legitimate sorted-btree package, indexed-btree hides a malware trigger in its prototype method. The post Malicious B-tree NPM Package Accumulates Millions of Downloads appeared first on SecurityWeek.

Malware
P0
2026-09-22 10:00 UTC
Vendor Research

The Closed Quorum: Inside the first reported autonomous AI C2 implant

Cisco Talos Intelligence Blog · Ryan Fetterman · indexed 2026-09-22 10:05 UTC

CLOSEDQUORUM, a malware binary discovered through Cisco Talos’ CAIRN project, exhibits fully autonomous command and control (C2). It represents a shift in effort displacement for attackers, in which expanding portions of the attack chain can be executed without operator involvement.

Malware
P0
2026-09-22 06:33 UTC
Security Journalism

One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-22 06:55 UTC

Malware already running on a Mac can quietly take over Meta's Muse assistant and use the broad access its owner granted the app, security researcher Patrick Wardle has shown in a proof-of-concept released on September 21. It works by changing a hidden setting so that when the user taps the microphone and dictates a prompt, the words go to the attacker instead of Meta. The flaw is in

MalwareSecurity Research
P0
2026-09-21 17:31 UTC
Security Journalism

Fake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus and EDR

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-21 18:15 UTC

A fake LastPass Authenticator installer offered on GitHub installs a Windows kernel driver that shuts off antivirus and other security software before a password stealer runs if a victim downloads and runs it, researchers at LastPass and Delphos Labs said on September 17. Microsoft's own hardware-compatibility program signs the driver, scored zero detections on VirusTotal when researchers

LinuxMalwareMicrosoft
P0
2026-09-21 14:15 UTC
Security Journalism

TASK#STOMP PowerShell Backdoor Steals Documents, Wi-Fi Passwords, and Clipboard Data

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-21 14:45 UTC

Cybersecurity researchers have disclosed details of a new campaign dubbed TASK#STOMP that delivers a PowerShell backdoor designed to harvest sensitive data from compromised hosts. The backdoor "automatically harvests and exfiltrates business documents, watches the filesystem for new files in real time, steals Wi-Fi passwords and clipboard contents, takes screenshots, and accepts arbitrary

MalwareSecurity Research
P0
2026-09-21 13:32 UTC
Other

ChainScript: the RAT that hides its command server inside a blockchain contract

Security Affairs · Pierluigi Paganini · indexed 2026-09-21 13:50 UTC

Blackpoint uncovers ChainScript, a Node.js RAT that queries a Polygon smart contract to find and rotate its command server. Blackpoint’s Adversary Pursuit Group was chasing a ClickFix campaign spreading an unknown RAT namend ChainScript. The malicious code is a previously undocumented Node.js remote access trojan that hides its command server on a public blockchain. The […]

Malware
P0
2026-09-21 12:51 UTC
Security Journalism

RatHat Android Trojan Uses AI for Automation

Security Week · Ionut Arghire · indexed 2026-09-21 12:55 UTC

The malware relies on AI for real-time device navigation and control, increasing adaptability and evasion. The post RatHat Android Trojan Uses AI for Automation appeared first on SecurityWeek.

MalwareMobile Security
P0
2026-09-21 10:33 UTC
Community

TerminalFix: PNG Steganography, (Mon, Sep 21st)

SANS Internet Storm Center · indexed 2026-09-21 10:30 UTC

Microsoft Security Research published an interesting blog post "TerminalFix campaign deploys a reverse tunnel through multistage intrusion" about a malware campaign. The aspect that I want to take a closer look at, is the fact that the threat actors used PNG files with steganography. I reached out to the researchers and they kindly shared the IOCs for the PNG files with me.

MalwareMicrosoftSecurity ResearchThreat ActorsThreat Intelligence
P0
2026-09-21 08:39 UTC
Security Journalism

ClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 Infrastructure

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-21 08:45 UTC

Threat actors are leveraging ClickFix-like lures to deliver a previously undocumented remote access trojan (RAT) called ChainScript. "ChainScript has appeared under multiple build names, including ComponentTask33, UpdateDigital, HostShared, and OrchidViolet66, while presenting itself as Spotify, Zoom Workplace, and Microsoft Teams software," Blackpoint Adversary Pursuit Group (APG)

MalwareMicrosoftThreat Actors
P0
2026-09-21 06:06 UTC
Security Journalism

Jade Sleet Linked to Indian IT Provider Breach With FLATROOF and ROOFDECK Backdoors

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-21 06:15 UTC

The North Korean threat actor known as Jade Sleet has been attributed to the compromise of an India-based "much smaller organization" in the information technology (IT) services industry, once again highlighting how the adversary continues to target developers to breach target networks. Cybersecurity company SentinelOne, which disclosed details of the activity, said it involved the use of Apple

AppleMalwareThreat Actors
P0
2026-09-20 14:11 UTC
Security Journalism

Malicious npm packages evade install-script defenses at runtime

BleepingComputer · Bill Toulas · indexed 2026-09-20 14:20 UTC

An ongoing npm malware campaign involving the 'indexed-btree' package shows how threat actors bypass supply chain defenses by hiding malicious code in a package's normal runtime behavior rather than in installation scripts. [...]

MalwareThreat Actors
P0
2026-09-20 12:22 UTC
Other

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 115

Security Affairs · Pierluigi Paganini · indexed 2026-09-20 12:30 UTC

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Gray Rabbits and the Tale of a One-Click Backdoor Red Heron exploits Gitea n-day flaw in multinational campaign, exposing new Linux rootkit Malicious Twitch Browser Extension Exposes 30,000 Users’ OAuth Tokens to Russian Bot […]

LinuxMalware
P0
2026-09-18 21:38 UTC
Other

Brevo Supply-Chain Attack Infected Over 100,000 Websites

Security Affairs · Pierluigi Paganini · indexed 2026-09-18 21:55 UTC

A Brevo supply-chain attack used compromised Cloudflare access to inject malware into websites, potentially affecting over 100,000 sites. Brevo, formerly known as Sendinblue, is a French cloud-based marketing and customer communication platform whose clients include eBay, Louis Vuitton and Michelin. The company was first compromised on September 10, when attackers exploited a vulnerability in its […]

MalwareVulnerabilities
P0
2026-09-18 15:24 UTC
Security Journalism

Transparent Tribe Deploys New Rust Backdoor Using Private GitHub Repositories for C2

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-18 15:55 UTC

The Pakistan-aligned threat group tracked as Transparent Tribe (aka APT36 and Earth Karkaddan) has been attributed to a fresh set of cyber attacks targeting government and defense entities in India and Afghanistan. The attacks, per Zscaler ThreatLabz, involve the use of previously undocumented tools called RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH. The activity has been codenamed Operation

APT / Nation-StateMalware
P0
2026-09-18 14:25 UTC
Security Journalism

In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw

Security Week · SecurityWeek News · indexed 2026-09-18 14:30 UTC

Noteworthy stories that might have slipped under the radar: Mandiant's 2026 AI risk report, PhantomRaven malware used by bug bounty hunter, WordPress plugin bug exploited. The post In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw appeared first on SecurityWeek.

MalwareRansomware
P15
2026-09-18 10:40 UTC
Security Journalism

WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storage

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-18 11:00 UTC

Cybersecurity researchers have discovered a cluster of 13 npm packages that have been found to deliver a previously undocumented JavaScript stealer codenamed WeaselBiscuit. The new malware family, per OpenSourceMalware, exhibits functional overlaps with two malware strains associated with the Democratic People's Republic of Korea's (DPRK) Contagious Interview campaign: BeaverTail and

MalwareSecurity Research
P0
2026-09-18 10:04 UTC
Other

RatHat Turns Android Accessibility Into an Attack Weapon

Security Affairs · Pierluigi Paganini · indexed 2026-09-18 10:50 UTC

RatHat combines AI-driven screen control, Android debugging abuse and advanced credential theft to give attackers deep control of infected phones. RatHat is the new Android trojan you should know about. Zimperium researchers just published a breakdown of a strain they’ve traced to China-based operators, and what makes it different isn’t the credential theft, which is […]

MalwareMobile SecurityPhishing
P0
2026-09-18 09:46 UTC
Security Journalism

Brevo Supply Chain Attack Injects Malware Into 100,000 Websites

Security Week · Ionut Arghire · indexed 2026-09-18 09:50 UTC

Hackers used a compromised API key to deploy a Cloudflare worker that injected malicious scripts. The post Brevo Supply Chain Attack Injects Malware Into 100,000 Websites appeared first on SecurityWeek.

Malware
P0
2026-09-18 09:18 UTC
Security Journalism

Claimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm Stealer

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-18 09:30 UTC

A financially motivated threat actor has been linked to the development and distribution of a JavaScript (JS)-based information stealer known as PhantomRaven via the npm package registry. "The developer likely wrote the malware using a large language model (LLM), an assessment made with high confidence based on verbose comments, placeholder code, and statistical token-analysis patterns,"

AI SecurityMalwareThreat Actors
P0
2026-09-18 06:17 UTC
Security Journalism

RatHat Android Malware Abuses ADB to Retain Shell Access After Uninstall

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-18 06:30 UTC

Cybersecurity researchers have flagged a new Android malware called RatHat that's assessed to be operated by China-based threat actors and features an artificial intelligence (AI)-powered system to navigate and control compromised devices. "Distributed primarily via targeted smishing (SMS/text phishing) and malvertising campaigns leading to deceptive third-party download portals, RatHat uses

AI SecurityMalwareMobile SecurityPhishingSecurity ResearchThreat Actors
P0
2026-09-17 17:11 UTC
Security Journalism

Brevo supply-chain attack injected ClickFix scripts on customer sites

BleepingComputer · Bill Toulas · indexed 2026-09-17 17:20 UTC

Brevo confirmed that attackers stole a Cloudflare API key and used it to inject malicious ClickFix scripts into its websites and JavaScript files embedded on customer sites to distribute malware. [...]

Malware
P0
2026-09-17 14:16 UTC
Other

SilkParasite Infrastructure Links SpiceRAT to Central Asian Targets

Security Affairs · Pierluigi Paganini · indexed 2026-09-17 14:30 UTC

Hunt.io links SpiceRAT, NodeEdgeRAT and NomadRAT to a four-year SilkParasite campaign targeting governments and critical sectors in Central Asia. Hunt.io and researcher Guy Yasur have traced a tight cluster of SpiceRAT command‑and‑control servers that predate and extend Bitdefender’s August 2026 SilkParasite report. The work doesn’t dissect malware samples; it maps the network side of the […]

MalwareMicrosoft
P0
2026-09-17 14:03 UTC
Security Journalism

Iran-Linked Handala Hack Tied to HEAVYGRAM Telegram Backdoor That Can Steal Passwords

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-18 03:55 UTC

The Iran-linked "hacktivist" persona known as Handala Hack has been attributed to a Telegram-based surveillance backdoor called HEAVYGRAM and a Delphi-based utility known as CRUDEEXCLUDE. "HEAVYGRAM offers builtin commands supporting remote command execution, system, network and process information discovery, data and Telegram session files exfiltration, screenshot capture, DLL sideloading,

Malware
P0
1 2 3 4 5