IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 623 matching records.
AUTO-POLL // 2026-10-03 01:55 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
NO DATA
NO INTELLIGENCE AGGREGATED TODAY
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 3
NO DATA
--
NO INTEL
FRI
Oct 2

RANSOMWARE
P7
P7
COOL // 46 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
WED
Sep 30

RANSOMWARE
P10
P10
WARM // 59 ARTICLES
TUE
Sep 29

RANSOMWARE
P4
P4
COOL // 68 ARTICLES
MON
Sep 28

RANSOMWARE
P7
P7
COOL // 52 ARTICLES
SUN
Sep 27

RANSOMWARE
P25
P25
ELEVATED // 15 ARTICLES
RESET
2026-08-30 14:17 UTC
Security Journalism

Chrome Web Store extensions caught stealing crypto, browser data

BleepingComputer · Bill Toulas · indexed 2026-08-30 14:25 UTC

Multiple extensions for Google Chrome and Microsoft Edge delivered a malware framework that deployed modules to steal cryptocurrency, sensitive data, and browser history, as well as inject ClickFix lures. [...]

MalwareMicrosoft
P0
2026-08-30 07:36 UTC
Security Journalism

TerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-30 08:50 UTC

Microsoft has disclosed details of a new ClickFix variant, dubbed TerminalFix, that aims to trick users into running a malicious command in Windows Terminal or PowerShell. "While traditional ClickFix campaigns direct victims to the Windows Run dialog, TerminalFix campaigns apply the same technique but direct users to Windows Terminal or PowerShell instead, increasing the likelihood that complex

MalwareMicrosoft
P0
2026-08-29 03:43 UTC
Vendor Research

TerminalFix campaign deploys a reverse tunnel through multistage intrusion

Microsoft Security Blog · Microsoft Security Research, Sagar Patil, Suriyaraj Natarajan and Parasharan Raghavan · indexed 2026-08-29 05:20 UTC

Microsoft Threat Intelligence provides analysis of a ClickFix campaign that uses fake CAPTCHA prompts, DLL sideloading, and a reverse tunnel, with detections and hunting guidance. The post TerminalFix campaign deploys a reverse tunnel through multistage intrusion appeared first on Microsoft Security Blog.

MicrosoftThreat Intelligence
P0
2026-08-28 15:27 UTC
Security Journalism

19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-28 15:45 UTC

Cybersecurity researchers have discovered a cluster of 18 Google Chrome and one Microsoft Edge extensions that were published over the last six months and harbored wallet secret stealing and cryptocurrency draining capabilities. The extensions, per Socket security researcher Karlo Zanki, share similarities in code and tradecraft, with evidence indicating that the campaign may have been active

MicrosoftSecurity Research
P0
2026-08-28 14:01 UTC
Vendor Research

Why a cryptographic inventory is key for addressing the quantum computing threat

Tenable Blog · Christopher Day · indexed 2026-08-28 14:20 UTC

When quantum computers become generally available, they’ll be able to crack current public-key cryptographic algorithms, putting digitally stored and transmitted data at risk. But the threat already exists, as attackers use the "harvest now, decrypt later" tactic. Discover why building a comprehensive cryptographic inventory and executing a phased operational strategy are critical for protecting your data against quantum computing attacks.Key takeawaysQuantum computing risks are an operational …

APT / Nation-StateMicrosoftVulnerabilities
P0
2026-08-28 14:00 UTC
Security Journalism

AI Is Accelerating Vulnerability Discovery. Can Defenders Keep Up?

BleepingComputer · Sponsored by Action1 · indexed 2026-08-28 14:20 UTC

AI is accelerating vulnerability discovery, putting pressure on systems built to enrich, prioritize, and remediate flaws at a slower pace. Action1 explains why defenders increasingly need to correlate multiple intelligence sources and turn vulnerability data into faster remediation. [...]

Cloud SecurityMicrosoftVulnerabilities
P0
2026-08-28 11:26 UTC
Other

Russian APT BlueDelta Uses HOOKEDGE to Target Defense and Diplomatic Organizations

Security Affairs · Pierluigi Paganini · indexed 2026-08-28 11:30 UTC

BlueDelta (APT28) uses webhook.site and Microsoft Edge to hide HOOKEDGE espionage traffic targeting European governments. Recorded Future’s Insikt Group documented a campaign by BlueDelta, the Russian GRU-linked group that overlaps with the group APT28, running an entire espionage operation against European government targets using webhook.site, a service built for developers to test HTTP requests, as […]

APT / Nation-StateMicrosoft
P0
2026-08-28 09:10 UTC
Security Journalism

Windows 11 KB5120998 update released with 35 changes and fixes

BleepingComputer · Sergiu Gatlan · indexed 2026-08-28 09:25 UTC

Microsoft released the KB5120998 preview cumulative update for Windows 11 versions 25H2 and 24H2, which comes with 35 changes, including improvements to the Start menu, taskbar, and Windows search. [...]

Microsoft
P0
2026-08-28 09:07 UTC
Other

U.S. CISA adds Red Hat, Linux Kernel, Ajax.NET Professional, Microsoft SQL Server, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog

Security Affairs · Pierluigi Paganini · indexed 2026-08-28 09:30 UTC

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Red Hat, Linux Kernel, Ajax.NET Professional, Microsoft SQL Server, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2015-3246 is a race condition in Red Hat libuser that could let […]

Cloud SecurityLinuxMicrosoftVulnerabilitiesCVE-2015-3246
P35
2026-08-28 08:20 UTC
Security Journalism

APT28-Linked HOOKEDGE Backdoor Targets European Government and Diplomatic Organizations

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-28 08:40 UTC

Cybersecurity researchers have flagged a fresh set of campaigns targeting government and diplomatic organizations in Romania, Spain, and Türkiye between late September 2025 and early April 2026. These campaigns, per Recorded Future Insikt Group, have led to the deployment of a previously undocumented backdoor dubbed HOOKEDGE, a lightweight Windows batch script that's distributed via

APT / Nation-StateMalwareMicrosoftSecurity Research
P0
2026-08-27 16:00 UTC
Vendor Research

​​​​​​What’s new in Microsoft Security: August 2026

Microsoft Security Blog · Alym Rayani · indexed 2026-08-27 17:35 UTC

This month’s updates provide new capabilities to help organizations gain insights into agent activity, expand security coverage across supported environments, and enhance security management across their environments. The post ​​​​​​What’s new in Microsoft Security: August 2026 appeared first on Microsoft Security Blog.

Microsoft
P0
2026-08-27 15:13 UTC
Security Journalism

Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-27 17:00 UTC

Credit: Hacktron Vercel has released security patches for two critical-severity vulnerabilities in the Next.js web framework, both of which allow unauthenticated remote code execution, one exploitable via specially crafted AVIF image files and the other through a path traversal flaw affecting servers that use a Windows filesystem. The Windows path traversal, tracked as CVE-2026-75604&

Cloud SecurityMicrosoftVulnerabilitiesCVE-2026-75604
P20
2026-08-27 15:12 UTC
Security Journalism

ThreatsDay: 296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New Stories

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-27 17:00 UTC

A fake login page. A fake security scan. A fake productivity app. Apparently, pretending to be useful is still one of the easier ways into a machine. The rest of the week gets stranger: botnets borrowing AI, command traffic hiding in public infrastructure, malicious tools waiting before showing their real behavior, exposed systems getting scanned, and exploit windows shrinking again. Different

MalwareMicrosoftVulnerabilities
P15
2026-08-27 14:30 UTC
Vendor Research

How to build an exposure management program the business trusts: Lessons from Tenable’s CSO

Tenable Blog · Robert Huber · indexed 2026-08-27 14:40 UTC

Discover how Tenable’s shift to an AI-driven exposure management program helped Tenable’s CSO, Robert Huber, overcome tool sprawl, unify data silos, mitigate the risk of rapid AI adoption, and shift from presenting granular, technical metrics to communicating business risk that the C-suite and the board can understand.Key takeawaysSecurity tool sprawl and data silos make it difficult for CISOs to holistically and accurately assess their organizations’ cyber risk.An exposure management program c…

AI SecurityAppleCloud SecurityMicrosoftVulnerabilities
P0
2026-08-27 13:51 UTC
Vendor Research

Identity-as-a-Service: Uncovering Dark Web Marketplaces Trading Executive SSNs

Rapid7 · Alexandra Blia · indexed 2026-08-27 14:25 UTC

IntroductionDespite modern verification controls, identity theft remains one of the most pervasive threats to both individuals and enterprise organizations. U.S. Federal Trade Commission statistics show over 1 million identity theft reports annually, with related fraud and imposter scams accounting for billions in financial losses each year. While stolen credit cards enable rapid, short-term monetization, Social Security numbers (SSNs) represent a far more permanent and dangerous tier within th…

APT / Nation-StateCybercrimeData BreachesMalwareMicrosoftPhishingThreat Actors
P0
2026-08-27 13:39 UTC
Security Journalism

Amazon Kiro Prompt Injection Can Exfiltrate Sensitive Data Through Kiro Powers

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-27 15:05 UTC

Cybersecurity researchers have disclosed details of a vulnerability in Amazon Kiro, an artificial intelligence (AI)-powered, agentic integrated development environment (IDE), that could facilitate data exfiltration via prompt injection and Kiro Powers. The security flaw, which does not have a CVE identifier, works against Kiro IDE 0.7.45 on Windows, according to Mindgard. The latest version of

AI SecurityMicrosoftSecurity ResearchVulnerabilities
P0
2026-08-27 11:56 UTC
Security Journalism

Learn How to Build Security Operations Ready for AI-Powered Attacks

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-27 12:55 UTC

Security teams have spent years trying to detect threats faster. AI is changing the harder part: how much time defenders have left to act. Advanced AI models can now help attackers discover vulnerabilities, generate exploit code, and move through weaknesses faster than traditional security processes were built to handle. The challenge is no longer just finding another vulnerability or

MicrosoftVulnerabilities
P0
2026-08-26 16:43 UTC
Vendor Research

When AI infrastructure becomes the target: Securing gateways and control points

Microsoft Security Blog · Microsoft Security Research, Yash Gund and Sumith Maniath · indexed 2026-08-26 17:15 UTC

Microsoft Threat Intelligence examines attacks on exposed AI workloads, including LiteLLM gateway exploitation, credential harvesting, persistence, and cryptomining activity. The post When AI infrastructure becomes the target: Securing gateways and control points appeared first on Microsoft Security Blog.

MicrosoftPhishingThreat Intelligence
P0
2026-08-26 15:58 UTC
Community

Who Has Admin Rights in your Entra ID Directory?, (Wed, Aug 26th)

SANS Internet Storm Center · indexed 2026-08-26 16:15 UTC

A common thing that folks should "worry" about in Entra (or any platform really) is "who has rights to administer"?  Who can delete or change key things, or modify them in ways that might not be obvious (accidentally or on purpose).  Yes, we trust our people, but if they've moved on to other roles or to other organizations, they change from "our people" to "used to be our people".  
 Also,…

Microsoft
P0
2026-08-26 13:44 UTC
Security Journalism

NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-26 14:20 UTC

Cybersecurity researchers have disclosed details of a new adversary-in-the-middle (AitM) phishing toolkit called NovaCookies that's used as a proxy to redirect Microsoft 365 sign-ins, while capturing authenticated sessions in the process. In a report shared with The Hacker News ahead of publication, Island characterized the $320/month service as a subscription-based phishing platform that

MicrosoftPhishingSecurity Research
P0
2026-08-26 09:00 UTC
Vendor Research

Edge infrastructure under siege: what two independent datasets reveal about who's exploiting your perimeter

Tenable Cyber Exposure Alerts · Research Special Operations · indexed 2026-08-26 13:15 UTC

A joint Tenable-SentinelOne analysis of 93 CVE-actor attribution pairs reveals that both state-sponsored actors and cybercriminals independently converge on the same edge infrastructure. Special thanks to SentinelOne® Incident Readiness & Response for their contributions to this publication.It is the shared attack surface where state-sponsored threat actors and financially motivated criminal groups independently converge — not the province of a single adversary category, and not exclusively a n…

APT / Nation-StateData BreachesDFIRMicrosoftNetwork SecurityPhishingRansomwareThreat ActorsThreat IntelligenceVulnerabilities
P45
2026-08-26 07:12 UTC
Security Journalism

New SLEEPWALKER Backdoor Waits for One Crafted Packet, Then Runs Its Own Bytecode

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-26 08:50 UTC

An independent malware researcher has documented a previously unreported Windows backdoor, dubbed SLEEPWALKER, that stays inert in memory until a specifically crafted network packet reaches the machine and then runs commands written in a 23-instruction language of its own design. The sample is an unsigned 64-bit Windows dynamic-link library (DLL) of 59,904 bytes, built to be side-loaded into&

MalwareMicrosoft
P0
8 9 10 11 12