IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 451 matching records.
AUTO-POLL // 2026-10-03 00:20 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
NO DATA
NO INTELLIGENCE AGGREGATED TODAY
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 3
NO DATA
--
NO INTEL
FRI
Oct 2

RANSOMWARE
P7
P7
COOL // 46 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
WED
Sep 30

RANSOMWARE
P10
P10
WARM // 59 ARTICLES
TUE
Sep 29

RANSOMWARE
P4
P4
COOL // 68 ARTICLES
MON
Sep 28

RANSOMWARE
P7
P7
COOL // 52 ARTICLES
SUN
Sep 27

RANSOMWARE
P25
P25
ELEVATED // 15 ARTICLES
RESET
2026-09-02 06:56 UTC
Security Journalism

Authorities Turn Sality's P2P Network Against Itself, Cutting Off New Malware Payloads

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-02 08:00 UTC

The U.S. Department of Justice (DoJ) on Tuesday announced the takedown of a long-standing peer-to-peer (P2P) botnet known as Sality as part of a coordinated law enforcement operation. The effort was undertaken on August 31, 2026, by authorities from the U.S., Bulgaria, Hungary, and Romania, in collaboration with private industry partners CrowdStrike and the Shadowserver Foundation. To that

Law EnforcementMalware
P0
2026-09-01 22:48 UTC
Vendor Research

Counterfeit installers to system compromise: Tracking a deceptive software download campaign

Microsoft Security Blog · Microsoft Security Research, Microsoft Defender Experts and Parth Jomadkar · indexed 2026-09-01 23:55 UTC

An active campaign is impersonating legitimate software vendors to deliver malware through look-alike download pages and regenerated installer archives. Microsoft Defender Experts shares observed attack techniques, Defender XDR detections, indicators of compromise, and practical mitigations to help organizations identify, block, and respond to this threat. The post Counterfeit installers to system compromise: Tracking a deceptive software download campaign appeared first on Microsoft Security B…

MalwareMicrosoft
P0
2026-09-01 14:00 UTC
Vendor Research

Financially Motivated Threat Actor BREEZE COMET Targets Brazil

Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-09-01 03:50 UTC

Introduction Beginning in 2024 Mandiant investigated a string of compromises affecting Brazilian financial services, retail, and eCommerce organizations. Google Threat Intelligence Group (GTIG) tracks this activity as BREEZE COMET (formerly UNC5669), a financially motivated threat actor specializing in manipulating payment systems and banking software in Brazil to conduct fraudulent transfers. This activity overlaps with operations publicly reported as Plump Spider and SHADOW-AETHER-064. In thi…

AI SecurityCloud SecurityCybercrimeMalwareMicrosoftNetwork SecurityPhishingThreat ActorsThreat Intelligence
P0
2026-09-01 13:08 UTC
Security Journalism

Iranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding Tests

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-01 13:20 UTC

The Iranian Nimbus Manticore hacking group has been attributed to two previously undocumented malware families that highlight the continued evolution of its toolset and likely expand its targeting footprint to infect Linux and Apple macOS systems using cross-platform remote access trojans (RATs) developed using Node.js and JavaScript. Russian cybersecurity company Kaspersky is tracking the

AppleLinuxMalware
P0
2026-09-01 08:26 UTC
Security Journalism

Russia-Aligned UAC-0099 Plants Nuclear Weapon Prompt in Malware to Disrupt AI Analysis

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-01 08:55 UTC

Cybersecurity researchers have disclosed a new technique dubbed GuardBreaker that's been put to use by a Russia-aligned threat actor known as UAC-0099 against a target in Ukraine with an aim to interfere with artificial intelligence (AI)-assisted analysis. The idea, ESET said in a series of posts on X, is to deliberately trip a large language model's (LLM) safety mechanisms and prevent its

AI SecurityMalwareSecurity ResearchThreat Actors
P0
2026-08-31 19:45 UTC
Other

ValleyRAT: When Legitimate Software Becomes a Malware Delivery Tool

Security Affairs · Pierluigi Paganini · indexed 2026-08-31 20:50 UTC

ValleyRAT hides behind legitimate adware, using DLL sideloading to evade detection, steal data and give Silver Fox control of infected systems. ValleyRAT doesn’t always need to disguise itself as a cracked game or a fake browser update. It can also hide behind something much more ordinary: an application that looks like adware and appears to […]

Malware
P0
2026-08-31 13:50 UTC
Security Journalism

⚡ Weekly Recap: Chinese Spy Proxy, AI Agents Go Off-Task, Router Backdoors and More

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-31 14:30 UTC

The boring parts caused most of the trouble. A router shipped ready to listen. A fake check turned the user into the installer. Trusted systems collected traffic and passwords, then cleaned the logs. Old bugs formed new attack chains. Even an AI agent decided its assigned task was optional. Elsewhere, fake apps, helpful support calls, cheap banking kits, exposed systems, and weak defaults kept

AI SecurityMalwareNetwork Security
P0
2026-08-31 13:38 UTC
Other

Breaking the Seal: Static Deobfuscation of JSCeal’s Compiled V8 Bytecode

Check Point Research · shlomoo@checkpoint.com · indexed 2026-09-07 17:30 UTC

Research by: hasherezade Key Points Introduction JSCeal is a stealer delivered as compiled V8 bytecode (.jsc) and executed by a bundled Node.js runtime, targeting cryptocurrency applications (other vendors also tag it with the names WEEVILPROXY or MeadowLocust). Its campaign activity dates back to March 2024 [1]; Check Point Research has been tracking the malware since early […] The post Breaking the Seal: Static Deobfuscation of JSCeal’s Compiled V8 Bytecode appeared first on Check Point Resea…

Malware
P0
2026-08-31 12:14 UTC
Security Journalism

ValleyRAT Backdoor Hides in Signed Adware That Users Add to Antivirus Exclusions

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-31 12:30 UTC

The threat actor known as Silver Fox has been observed distributing the ValleyRAT backdoor disguised as a signed Chinese adware application, running the malware under a trusted process to slip past users who add such software to their antivirus exclusions. Russian cybersecurity vendor Kaspersky said the attackers built the disguise around QN Wallpaper, a genuine Chinese desktop-wallpaper tool

MalwareThreat Actors
P0
2026-08-31 09:17 UTC
Other

Infostealers Are Hijacking Claude Sessions and Draining Subscriptions

Security Affairs · Pierluigi Paganini · indexed 2026-08-31 09:40 UTC

Infostealers can steal active Claude sessions, bypass 2FA and drain paid usage. Anthropic is revoking access and refunding unauthorized charges. Anthropic confirmed that several infostealer malware can hijack an active Claude login session and let attackers burn through your usage without ever touching your password. “Our investigation is ongoing. Our findings to date suggest that […]

DFIRMalware
P0
2026-08-30 14:17 UTC
Security Journalism

Chrome Web Store extensions caught stealing crypto, browser data

BleepingComputer · Bill Toulas · indexed 2026-08-30 14:25 UTC

Multiple extensions for Google Chrome and Microsoft Edge delivered a malware framework that deployed modules to steal cryptocurrency, sensitive data, and browser history, as well as inject ClickFix lures. [...]

MalwareMicrosoft
P0
2026-08-30 12:31 UTC
Other

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 112

Security Affairs · Pierluigi Paganini · indexed 2026-08-30 13:00 UTC

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Operation QUICSILVER: China-Nexus Actor Targets Myanmar Diplomats via VHD-Delivered Go Backdoor FTP Banners: The New Dead Drop Resolver Delivering Novel RATs The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic […]

Malware
P0
2026-08-30 07:36 UTC
Security Journalism

TerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-30 08:50 UTC

Microsoft has disclosed details of a new ClickFix variant, dubbed TerminalFix, that aims to trick users into running a malicious command in Windows Terminal or PowerShell. "While traditional ClickFix campaigns direct victims to the Windows Run dialog, TerminalFix campaigns apply the same technique but direct users to Windows Terminal or PowerShell instead, increasing the likelihood that complex

MalwareMicrosoft
P0
2026-08-28 08:20 UTC
Security Journalism

APT28-Linked HOOKEDGE Backdoor Targets European Government and Diplomatic Organizations

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-28 08:40 UTC

Cybersecurity researchers have flagged a fresh set of campaigns targeting government and diplomatic organizations in Romania, Spain, and Türkiye between late September 2025 and early April 2026. These campaigns, per Recorded Future Insikt Group, have led to the deployment of a previously undocumented backdoor dubbed HOOKEDGE, a lightweight Windows batch script that's distributed via

APT / Nation-StateMalwareMicrosoftSecurity Research
P0
2026-08-28 07:04 UTC
Community

Some Malicious PE Stats, (Thu, Aug 27th)

SANS Internet Storm Center · indexed 2026-08-28 07:10 UTC

During my last FOR610 session, a student asked me if I had some statistics in mind about the compilers used to generate malicious PE files? A couple of months ago, I shared some stats about the trend in 64bits VS. 32bits malware[1]. Can we go a bit further? I (vibe-)coded a Python script based on the pefile library[2] to extract some info from the PE headers. Indeed, the PE file format contains a lot of metadata! They can be accessed using a lot of tools, like Detect It Easy:

Malware
P0
2026-08-27 20:31 UTC
Other

Dark Caracal Deploys New Go Malware With Ethereum-Based C2 Fallback

Security Affairs · Pierluigi Paganini · indexed 2026-08-27 20:50 UTC

Dark Caracal targets Venezuela with GoCaracal, an upgraded Bandook toolkit and an Ethereum fallback for resilient C2 communications. Dark Caracal is back with new malware and the same hunting grounds. Arctic Wolf Labs researchers link a June 2026 intrusion against a communications organisation in Venezuela to the Lebanon‑linked espionage group, and says it deployed a […]

APT / Nation-StateMalware
P0
2026-08-27 15:12 UTC
Security Journalism

ThreatsDay: 296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New Stories

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-27 17:00 UTC

A fake login page. A fake security scan. A fake productivity app. Apparently, pretending to be useful is still one of the easier ways into a machine. The rest of the week gets stranger: botnets borrowing AI, command traffic hiding in public infrastructure, malicious tools waiting before showing their real behavior, exposed systems getting scanned, and exploit windows shrinking again. Different

MalwareMicrosoftVulnerabilities
P15
2026-08-27 14:09 UTC
Other

Australian Police Charge Two Over TeamPCP Credential Theft

Security Affairs · Pierluigi Paganini · indexed 2026-08-27 14:25 UTC

Australian police charged two men linked to TeamPCP over malware hidden in open-source code that stole 500,000+ credentials from 1,000+ organizations. Australian police have charged two men from Western Australia over a global cybercrime operation that allegedly hid malicious code in open-source software and used it to steal data from thousands of organisations. “Two West […]

CybercrimeMalwarePhishing
P0
2026-08-27 13:51 UTC
Vendor Research

Identity-as-a-Service: Uncovering Dark Web Marketplaces Trading Executive SSNs

Rapid7 · Alexandra Blia · indexed 2026-08-27 14:25 UTC

IntroductionDespite modern verification controls, identity theft remains one of the most pervasive threats to both individuals and enterprise organizations. U.S. Federal Trade Commission statistics show over 1 million identity theft reports annually, with related fraud and imposter scams accounting for billions in financial losses each year. While stolen credit cards enable rapid, short-term monetization, Social Security numbers (SSNs) represent a far more permanent and dangerous tier within th…

APT / Nation-StateCybercrimeData BreachesMalwareMicrosoftPhishingThreat Actors
P0
2026-08-27 11:17 UTC
Other

One Adversary, Two Outcomes: The 0.027% Proof

Group-IB · indexed 2026-09-07 17:30 UTC

One malware campaign, 11,000 compromised devices, two banks with very different outcomes. At the bank with fused defence, fraud succeeded on just 0.027% of compromised devices; nine times less than the market average. Regulators are taking notice too.

CybercrimeMalware
P0
5 6 7 8 9