IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 451 matching records.
AUTO-POLL // 2026-10-02 23:35 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P7 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 2

RANSOMWARE
P7
P7
COOL // 46 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
WED
Sep 30

RANSOMWARE
P10
P10
WARM // 59 ARTICLES
TUE
Sep 29

RANSOMWARE
P4
P4
COOL // 68 ARTICLES
MON
Sep 28

RANSOMWARE
P7
P7
COOL // 52 ARTICLES
SUN
Sep 27

RANSOMWARE
P25
P25
ELEVATED // 15 ARTICLES
SAT
Sep 26

RANSOMWARE
P13
P13
WARM // 20 ARTICLES
RESET
2026-09-14 14:40 UTC
Security Journalism

⚡ Weekly Recap: Rogue AI Agents, WeChat Worm, PaperCut Attacks, AI Espionage, and Rootkits

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-14 15:35 UTC

AI keeps showing up in the wrong places. Attackers are using it to speed up exploits, test defenses, and automate more of the job. Some models are also crossing lines on their own. That is not a great combination. The rest of the week is more familiar: old bugs still working, fresh exploit chains, exposed systems, weak defaults, and simple paths that should have been harder to abuse. A few of

AI SecurityAPT / Nation-StateMalware
P0
2026-09-13 17:27 UTC
Other

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 114

Security Affairs · Pierluigi Paganini · indexed 2026-09-13 17:50 UTC

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter REVSTEALER ramps up Breaking the Seal: Static Deobfuscation of JSCeal’s Compiled V8 Bytecode GuardBreaker: Derailing AI-assisted malware analysis with a code comment DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive […]

APT / Nation-StateMalware
P0
2026-09-13 09:19 UTC
Other

Conti Hacker Who Built Malware and Attacked Victims Gets Four-Year Sentence

Security Affairs · Pierluigi Paganini · indexed 2026-09-13 10:15 UTC

Ukrainian lawyer and Conti malware developer Oleksii Lytvynenko was sentenced to four years in U.S. prison for ransomware attacks. Oleksii Oleksiyovych Lytvynenko had, by most accounts, a fairly ordinary legal career in Ukraine before he switched to writing malware. A US federal court sentenced the 44-year-old to four years in prison this week for conspiracy […]

MalwareNetwork SecurityRansomware
P15
2026-09-11 14:10 UTC
Security Journalism

Russian State-Sponsored Hackers Use Claude to Rebuild Malware After Detection

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-11 15:30 UTC

Anthropic on Thursday revealed it disrupted a campaign mounted by a Russian state-sponsored threat actor that abused Claude for developing an AI-assisted workflow to get ahead of the detection curve. The operation has been attributed to a cyber espionage group it calls GTG-20006 (where "GTG" stands for Generative Threat Group), which aligns with broader reporting linking the cluster to Midnight

APT / Nation-StateMalwareThreat Actors
P0
2026-09-11 14:01 UTC
Security Journalism

How Threat Actors Are Turning Trusted AI Platforms Into an Attack Surface

BleepingComputer · Sponsored by Huntress Labs · indexed 2026-09-11 14:10 UTC

Threat actors are abusing trusted AI platforms to host malicious content, poison search results, and trick users into installing malware. Huntress examines campaigns targeting AI users through weaponized Claude Artifacts, shared AI conversations, sponsored search results, and ClickFix-style lures. [...]

MalwareThreat Actors
P0
2026-09-11 13:33 UTC
Vendor Research

The Fraud Ecosystem: A Transition From Known Marketplaces to a Fragmented Environment

Rapid7 · Gal Givon · indexed 2026-09-11 15:05 UTC

IntroductionThe surge in emerging threat actors directly correlates with the rapid escalation of victim counts and stolen financial resources. Simultaneously, this growth has spurred the proliferation of specialized supply storefronts across social media platforms, dark web channels, and various smaller niche marketplaces. Security teams today face evolving challenges, requiring them to continuously refine monitoring channels, adjust operational strategies, and foster cross-functional internal …

CybercrimeMalwarePhishingThreat ActorsThreat Intelligence
P0
2026-09-11 08:47 UTC
Security Journalism

Anthropic Says Russian Hackers Used Claude AI to Automate Malware Evasion

Security Week · Eduard Kovacs · indexed 2026-09-11 09:05 UTC

Anthropic reveals how criminal groups are increasingly targeting AI vendors' own infrastructure, including to steal a pre-release Claude model. The post Anthropic Says Russian Hackers Used Claude AI to Automate Malware Evasion appeared first on SecurityWeek.

Malware
P0
2026-09-11 07:31 UTC
Security Journalism

Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-11 07:40 UTC

Attackers have chained two flaws in JFrog Artifactory, the repository that software build pipelines pull from, to take administrator control of self-hosted servers and plant backdoors, cloud security company Wiz said in a report. Wiz saw the attacks between August 15 and September 8. JFrog had fixed both flaws before then, so only servers that had not been updated were open to them.

Cloud SecurityMalware
P0
2026-09-11 07:14 UTC
Security Journalism

China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-11 07:40 UTC

A China-linked hacking group exploited a flaw in Sogou Input Method, one of the most widely used tools for typing Chinese characters on Windows, to install a backdoor on victims' computers, security company Gen Digital said in research published Thursday. The attack started with a crafted link and ended with the attacker able to do anything the logged-in user could do. Tencent, which owns

MalwareMicrosoft
P0
2026-09-10 16:00 UTC
Vendor Research

Detect and disrupt AI-themed attacks with Microsoft Defender

Microsoft Security Blog · Rob Lefferts · indexed 2026-09-10 18:15 UTC

See how Microsoft Defender detects and disrupts AI-themed phishing, malware, and multi-stage attacks across the attack chain. The post Detect and disrupt AI-themed attacks with Microsoft Defender appeared first on Microsoft Security Blog.

MalwareMicrosoftPhishing
P0
2026-09-10 11:33 UTC
Security Journalism

Gigabud Creates Android Work Profiles to Hide From Banking App Malware Checks

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-10 13:15 UTC

The Gigabud banking trojan now installs a second Android app that creates a work profile on an infected phone and drops a tampered banking app inside it, security firm Group-IB said in a report published on September 9. A work profile is a separate space that Android typically reserves for employer apps, and what's inside it is kept separate from everything in the personal space. That

MalwareMobile Security
P0
2026-09-09 14:23 UTC
Security Journalism

Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-09 14:40 UTC

Cybercriminals are hijacking artificial intelligence (AI) user accounts via information stealer logs to create "stolen keys" that grant illicit access to tools from model providers like Google, Anthropic, and others. Information stealers like Lumma Stealer or Vidar are equipped to harvest a wide range of data from compromised systems. This can include credential, session tokens, and API

AI SecurityMalware
P0
2026-09-09 10:00 UTC
Vendor Research

Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure

Palo Alto Networks Unit 42 · Rem Dudas · indexed 2026-09-09 10:10 UTC

An investigation into how cybercriminals used YouTube gaming lures and SEO poisoning to deliver multi-payload malware to enterprise networks. The post Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure appeared first on Unit 42.

DFIRMalware
P0
2026-09-09 08:50 UTC
Other

PoisonedRefresh: A Fileless Linux Rootkit That Injects PHP Web Shells Into F5 BIG-IP APM Server Memory

Security Affairs · Pierluigi Paganini · indexed 2026-09-09 09:30 UTC

PoisonedRefresh rootkit injects PHP web shells into F5 BIG-IP APM Apache memory, leaving no disk artifacts. SophosLabs published a detailed technical analysis on September 8, 2026, of a Linux implant, dubbed PoisonedRefresh by ESET, they found in compromised F5 BIG-IP Access Policy Manager environments. Sophos tracks it as Linux/Agnt-IC. F5 has confirmed exploitation of the […]

LinuxMalware
P0
2026-09-09 07:36 UTC
Security Journalism

F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-09 09:30 UTC

Malware linked to break-ins at F5 BIG-IP Access Policy Manager appliances hides a PHP web shell in memory instead of in a file on disk, Sophos said in an analysis published on September 7. When Apache loads any of the three appliances' own PHP scripts, the malware adds the web shell to the copy held in memory, so a check of the file on disk can come back clean. Those three scripts are

Malware
P0
2026-09-08 20:08 UTC
Security Journalism

Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit

BleepingComputer · Bill Toulas · indexed 2026-09-08 20:10 UTC

A Linux rootkit targeting devices in F5 BIG-IP APM environments can intercept PHP file loading and inject a fileless web shell directly into memory, avoiding the need to write malicious code to disk. [...]

LinuxMalware
P0
2026-09-08 14:00 UTC
Vendor Research

StyleSmuggler (CVE-2026-75650): Frequently asked questions about Adobe Commerce and Magento zero-day

Tenable Cyber Exposure Alerts · Satnam Narang · indexed 2026-09-08 14:20 UTC

A critical unauthenticated remote code execution (RCE) zero-day in Adobe Commerce and Magento Open Source, dubbed StyleSmuggler, has been actively exploited since September 4 with attacks observed three days before a vendor patch became available.Key takeawaysCVE-2026-75650 is a critical remote code execution vulnerability in Adobe Commerce, Adobe Commerce B2B and Magento Open Source that can be triggered without authentication.Active exploitation of CVE-2026-75650 began on September 4, 2026, t…

DFIRLinuxMalwareThreat ActorsThreat IntelligenceVulnerabilitiesCVE-2026-75650
P95
2026-09-08 14:00 UTC
Vendor Research

GTIG AI Threat Tracker: From Prompting to Autonomy – The Evolution of Adversarial AI

Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-09-08 13:45 UTC

Executive Summary Since the release of our May 2026 report detailing adversarial misuse of artificial intelligence (AI), Google Threat Intelligence Group (GTIG) has observed forward leaning adversaries transition from basic prompting to agentic AI workflows and AI-enabled automation. In these operations, human-in-the-loop latency is dramatically reduced, compressing the traditional window for defenders to respond. In Q2 2026, GTIG observed threat actors compromise a cloud resource, then plan, b…

AI SecurityAPT / Nation-StateCloud SecurityData BreachesDFIRMalwareMicrosoftPhishingRansomwareThreat ActorsThreat IntelligenceVulnerabilities
P35
2026-09-08 09:13 UTC
Security Journalism

Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-08 10:00 UTC

Adobe on Monday released security patches to address a maximum-severity flaw impacting Adobe Commerce and Magento Open Source that has come under active exploitation in the wild. The vulnerability, now tracked as CVE-2026-75650 (CVSS score: 10.0), has been codenamed StyleSmuggler by Sansec, which discovered zero-day exploitation starting September 4, 2026. "This update resolves a critical

MalwareVulnerabilitiesCVE-2026-75650
P50
2026-09-08 09:11 UTC
Other

North Korea-linked Hackers Hide a Backdoor Inside HAProxy

Security Affairs · Pierluigi Paganini · indexed 2026-09-08 10:10 UTC

North Korea-linked hackers hid a backdoor inside HAProxy, masking C2 traffic and stealing data while keeping the load balancer working normally. North Korean-linked hackers found a genuinely clever hiding spot for their malware: inside the actual source code of HAProxy, the load balancing software running at the edge of two South Korean companies’ networks. Rapid7’s […]

Malware
P0
3 4 5 6 7