IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 451 matching records.
AUTO-POLL // 2026-10-03 00:20 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
NO DATA
NO INTELLIGENCE AGGREGATED TODAY
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 3
NO DATA
--
NO INTEL
FRI
Oct 2

RANSOMWARE
P7
P7
COOL // 46 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
WED
Sep 30

RANSOMWARE
P10
P10
WARM // 59 ARTICLES
TUE
Sep 29

RANSOMWARE
P4
P4
COOL // 68 ARTICLES
MON
Sep 28

RANSOMWARE
P7
P7
COOL // 52 ARTICLES
SUN
Sep 27

RANSOMWARE
P25
P25
ELEVATED // 15 ARTICLES
RESET
2026-09-08 08:43 UTC
Security Journalism

BengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support Scams

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-08 10:00 UTC

Cybersecurity researchers have disclosed details of a sprawling search engine optimization (SEO) poisoning campaign that paves the way for malware deployment and tech support scams. The campaign, discovered by the DFIR Report in March 2026, has been codenamed BengalSEO. It has operated out of the Indian state of Rajasthan since at least 2015, driven by two IT service providers named WeConnect

DFIRMalwareSecurity Research
P0
2026-09-08 07:41 UTC
Other

IT Help Desk Impersonation Lets Hackers Bypass MFA

Security Affairs · Pierluigi Paganini · indexed 2026-09-08 08:15 UTC

Attackers bypass endpoint security by posing as IT staff, stealing Microsoft 365 sessions, draining SaaS data and demanding extortion. Forget installing malware because today’s extortionists just pick up the phone instead of writing code. A widespread threat cluster tracked as PREY-0058 bypasses endpoint security entirely by targeting Microsoft 365 and SaaS environments through pure social […]

MalwareMicrosoft
P0
2026-09-07 18:12 UTC
Security Journalism

PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-07 18:40 UTC

Cybersecurity researchers have disclosed details of a complex Chromium-based post-exploitation toolkit called PEEP that masquerades as a bookmarks extension for the web browser. "Requiring prior administrative or code execution access, its installer injects the extension directly into Chrome/Edge profiles, bypassing Web Store checks and user prompts by forging Chromium's own Secure Preferences

MalwareSecurity Research
P0
2026-09-07 17:49 UTC
Other

StyleSmuggler: The Magento Zero-Day Behind New Store Attacks

Security Affairs · Pierluigi Paganini · indexed 2026-09-07 18:00 UTC

StyleSmuggler Magento zero-day is under active attack, letting unauthenticated attackers execute code and install backdoors on stores that may already be patched. A new zero-day flaw, dubbed StyleSmuggler, in Magento and Adobe Commerce is under active attack, giving unauthenticated attackers a path to run code on vulnerable online stores. Sansec researchers say it affects current […]

MalwareVulnerabilities
P25
2026-09-07 12:12 UTC
Security Journalism

North Korean Hackers Deploy New Linux Espionage Toolkit

Security Week · Ionut Arghire · indexed 2026-09-07 17:25 UTC

The stealthy toolkit embeds a backdoor in HAProxy and targets automotive and media organizations in South Korea for long-term surveillance. The post North Korean Hackers Deploy New Linux Espionage Toolkit appeared first on SecurityWeek.

APT / Nation-StateLinuxMalware
P0
2026-09-07 11:58 UTC
Security Journalism

Adobe Commerce Zero-Day Exploited to Backdoor Online Stores

Security Week · Ionut Arghire · indexed 2026-09-07 17:25 UTC

The StyleSmuggler zero-day allows attackers to execute code and deploy a stealthy backdoor on Adobe Commerce and Magento stores. The post Adobe Commerce Zero-Day Exploited to Backdoor Online Stores appeared first on SecurityWeek.

MalwareVulnerabilities
P25
2026-09-07 11:45 UTC
Security Journalism

Modified ScreenConnect Clients Used in Worm-Like Campaign

Security Week · Ionut Arghire · indexed 2026-09-07 17:25 UTC

The attacks rely on backdoored ScreenConnect instances to transfer and execute payloads to newly connected clients. The post Modified ScreenConnect Clients Used in Worm-Like Campaign appeared first on SecurityWeek.

Malware
P0
2026-09-07 10:19 UTC
Other

JSCeal Hides Crypto Malware in V8 Bytecode

Security Affairs · Pierluigi Paganini · indexed 2026-09-07 10:50 UTC

JSCeal hides crypto-stealing malware in V8 bytecode, but researchers built a tool to decompile it and expose its advanced theft capabilities. JSCeal is a cryptocurrency stealer that Check Point Research has tracked since early 2025. Unlike most malware, it hides its code in a format that makes analysis much harder. Check Point presented its latest […]

Malware
P0
2026-09-07 07:53 UTC
Security Journalism

JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-07 08:35 UTC

Cybersecurity researchers have unpacked JSCeal, a sophisticated compiled V8 JavaScript (JSC) malware with credential harvesting, surveillance, and traffic-interception capabilities. "The payloads are protected with javascript-obfuscator, using multiple techniques including RC4-protected strings, control-flow flattening, proxy functions, and operation wrappers," Check Point Research said in a

MalwarePhishingSecurity Research
P0
2026-09-06 08:34 UTC
Security Journalism

Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-06 10:00 UTC

Elastic Security Labs has documented four previously unreported programs associated with REVSTEALER, an emerging Windows information stealer, that remain on an infected machine after the stealer deletes itself. One of them switches off Windows Update and Microsoft Defender before running a cryptocurrency miner. The company named the four programs ProManager, WinUpdate, SoftManager, and

MalwareMicrosoftNetwork Security
P0
2026-09-06 08:27 UTC
Other

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 113

Security Affairs · Pierluigi Paganini · indexed 2026-09-06 08:55 UTC

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Hackers Steal Claude Login Sessions With Infostealer Malware to Hijack Accounts Fire Ant Evolves: From Hypervisors to Trusted Infrastructure Gryxa: The AI-Built Toolkit That Watches How You Remove It ValleyRAT masquerading as adware […]

Malware
P0
2026-09-05 20:14 UTC
Security Journalism

Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-05 20:50 UTC

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is

MalwareVulnerabilities
P25
2026-09-04 14:51 UTC
Security Journalism

New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-04 15:10 UTC

A previously undocumented Linux toolkit has been found compiled directly into the trojanized HAProxy load balancers of two South Korean organizations, where it intercepted web traffic and served altered pages to selected visitors. The attackers named the implant ted in debug strings left in the binary. It is not a HAProxy vulnerability, and installing it requires code execution on the host and

LinuxMalwareVulnerabilities
P0
2026-09-04 12:00 UTC
Vendor Research

DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors

Rapid7 · Rapid7 Intelligence · indexed 2026-09-04 12:25 UTC

OverviewA new Linux toolkit, identified by Rapid7 Labs, has been targeting organizations across South Korea’s automotive and media industries with minimal detection. The campaign made use of a HAProxy instance named “ted backdoor”, alongside trojanized versions of crond, agetty, atd, sshd, and polkitd. This previously undocumented framework enabled threat actors to execute remote commands on compromised servers, inject malicious scripts into web traffic, perform credential harvesting, and engag…

APT / Nation-StateLinuxMalwarePhishingThreat ActorsVulnerabilities
P15
2026-09-03 19:42 UTC
Security Journalism

What We Missed: Did ShinyHunters 'Breach' ReliaQuest?

Dark Reading · Rob Wright, Alexander Culafi · indexed 2026-09-03 20:15 UTC

In this video conversation, Dark Reading editors discuss some of the news they didn't get a chance to cover, from the latest antics of ShinyHunters to new research about the prevalence (or lack thereof) of AI-generated malware.

Malware
P0
2026-09-03 15:26 UTC
Security Journalism

BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-03 16:45 UTC

Cybersecurity researchers have disclosed details of a sophisticated Python-based Windows malware framework called BraZetsu that fuels an underground marketplace commercializing access to compromised hosts. "Unlike the standard infostealer model, BraZetsu is a comprehensive master toolkit that empowers Initial Access Brokers (IABs) by turning compromised systems into highly valuable commercial

CybercrimeMalwareMicrosoftSecurity Research
P0
2026-09-03 13:50 UTC
Security Journalism

Your Employee’s Password Appeared in an Infostealer Log. Now What?

BleepingComputer · Sponsored by Flare · indexed 2026-09-03 14:00 UTC

Infostealers can expose far more than passwords, including authenticated sessions that may let attackers bypass MFA. Flare explains how defenders can prioritize compromised identities, determine whether stolen access is still usable, and respond before it leads to account takeover. [...]

MalwareMicrosoft
P0
2026-09-03 10:43 UTC
Security Journalism

Attackers Turn Trusted Node.js Runtime Into Malware Delivery Tool in Targeted Attacks

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-03 11:30 UTC

Threat actors are leveraging the trusted Node.js JavaScript runtime in multiple cyber attacks as a way to deploy malicious payloads. According to a new report published by the Symantec Threat Hunter Team today, the attack method has been put to use in attacks targeting government departments, technology companies, and hotels since February 2026. "The technique's appeal is that node.exe (the

MalwareThreat Actors
P0
2026-09-03 10:36 UTC
Security Journalism

Shai-Hulud's Reach Just Grew to 469 Credential Locations. Here's What That Means

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-03 11:30 UTC

In early August, GitGuardian researchers found that a recent Shai-Hulud infostealer worm variant had evolved to scan for credentials across 469 locations across developer environments, Continuous Integration/Continuous Deployment (CI/CD) tooling, cloud configurations, and even AI tool configs. Earlier variants of the infostealer worm only checked 189 paths. The jump says a lot. Attackers have

Malware
P0
2026-09-03 08:12 UTC
Other

2,000 Leaked Documents Reveal How Russia Turns Engineering Students Into GRU Cyber Operators

Security Affairs · Pierluigi Paganini · indexed 2026-09-03 08:20 UTC

2,000 leaked files expose Bauman University’s hidden Department No. 4, which trained GRU-linked hackers and propagandists linked to APT28 and Sandworm. Leaked Documents Expose Bauman University’s Hidden Department That Trained Hackers, Propagandists, and Malware Developers for the GRU More than 2,000 internal documents from Bauman Moscow State Technical University have been reviewed by an international […]

APT / Nation-StateMalware
P0
2026-09-02 16:41 UTC
Security Journalism

Fake Software Installers Disable Windows Update and Weaken Microsoft Defender

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-02 17:50 UTC

An active malware campaign is using bogus software-download websites to impersonate trusted vendors and distribute malicious installers. "The campaign has targeted users looking to download popular software and has resulted in compromises across multiple organizations and industries, primarily affecting China-based operations of multinational organizations and Chinese-speaking users," Microsoft

MalwareMicrosoft
P0
2026-09-02 12:22 UTC
Security Journalism

Meta Ads Push StreamRat Android Trojan That Can Gain Near-Complete Device Control

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-02 13:45 UTC

Cybersecurity researchers have disclosed details of a new Android banking trojan called StreamRat that was promoted to Spanish-speaking users through a fake television-streaming campaign on Meta and can give operators near-complete control of infected devices. ThreatFabric said the campaign's advertisement focused on Spain and reached an estimated 570,950 Meta accounts in the European Union

MalwareMobile SecuritySecurity Research
P0
2026-09-02 10:25 UTC
Other

Iran-linked APT Mirage Kitten Uses Fake Job Tests to Spread Malware

Security Affairs · Pierluigi Paganini · indexed 2026-09-02 10:45 UTC

Mirage Kitten used fake LinkedIn coding tests to spread NodeRabbit and PollCat, even banning AI tools that could have spotted the malware. Iran-linked Mirage Kitten hackers just found a genuinely clever way to make their own malware harder to detect: telling job candidates not to use AI tools while reviewing the trojanized code they were […]

APT / Nation-StateMalware
P0
2026-09-02 10:16 UTC
Other

Gaming the system: how a Chinese-speaking actor turned Brazilian government sites into an SEO weapon

Check Point Research · stcpresearch · indexed 2026-09-07 17:30 UTC

Research by: Amit Yardeni Key Points Introduction Since mid-2025, Check Point Research has tracked a sustained campaign against Brazilian organizations. The tradecraft points to a Chinese-speaking cybercrime group connected to Earth Berberoka, an actor first documented targeting gambling sites across Asia. Once inside a victim, the group deploys a broad Linux toolkit: a custom downloader, several backdoors, […] The post Gaming the system: how a Chinese-speaking actor turned Brazilian government…

CybercrimeLinuxMalware
P0
2026-09-02 09:10 UTC
Security Journalism

Extradited Russian Hacker Faces Charges Over Excel Malware Campaign That Infected Thousands

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-02 09:40 UTC

The U.S. Department of Justice (DoJ) has charged a Russian national, extradited from Cyprus on August 28, with using roughly 255 fake accounts on a freelance platform to send malware-laced Excel attachments to about 80,000 of its users in 2016 and 2017. Searzhudin Tamirlanovich Aktulaev, 40, was arrested in Cyprus in May 2025, the U.S. Attorney's Office for the Northern District of California

Law EnforcementMalware
P0
4 5 6 7 8