IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 623 matching records.
AUTO-POLL // 2026-10-03 03:40 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
NO DATA
NO INTELLIGENCE AGGREGATED TODAY
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 3
NO DATA
--
NO INTEL
FRI
Oct 2

RANSOMWARE
P7
P7
COOL // 46 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
WED
Sep 30

RANSOMWARE
P10
P10
WARM // 59 ARTICLES
TUE
Sep 29

RANSOMWARE
P4
P4
COOL // 68 ARTICLES
MON
Sep 28

RANSOMWARE
P7
P7
COOL // 52 ARTICLES
SUN
Sep 27

RANSOMWARE
P25
P25
ELEVATED // 15 ARTICLES
RESET
2026-08-11 05:00 UTC
Other

ZDI-26-542: Microsoft Windows UMPDDrvBitBlt Improper Object Management Local Privilege Escalation Vulnerability

Zero Day Initiative · indexed 2026-09-07 17:35 UTC

This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-62712.

MicrosoftVulnerabilitiesCVE-2026-62712
P15
2026-08-11 05:00 UTC
Other

ZDI-26-541: (Pwn2Own) Microsoft Windows win32kfull Use-After-Free Local Privilege Escalation Vulnerability

Zero Day Initiative · indexed 2026-09-07 17:35 UTC

This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-65775.

MicrosoftVulnerabilitiesCVE-2026-65775
P15
2026-08-11 05:00 UTC
Other

ZDI-26-540: (Pwn2Own) Microsoft Windows win32kfull Use-After-Free Information Disclosure Vulnerability

Zero Day Initiative · indexed 2026-09-07 17:35 UTC

This vulnerability allows local attackers to disclose sensitive information on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.5. The following CVEs are assigned: CVE-2026-65776.

MicrosoftVulnerabilitiesCVE-2026-65776
P5
2026-08-11 05:00 UTC
Other

ZDI-26-539: (Pwn2Own) Microsoft Windows ipt.sys Incorrect Permission Assignment Local Privilege Escalation Vulnerability

Zero Day Initiative · indexed 2026-09-07 17:35 UTC

This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-65773.

MicrosoftVulnerabilitiesCVE-2026-65773
P15
2026-08-11 05:00 UTC
Other

ZDI-26-538: (Pwn2Own) Microsoft Exchange Improper Authorization Privilege Escalation Vulnerability

Zero Day Initiative · indexed 2026-09-07 17:35 UTC

This vulnerability allows remote attackers to escalate privileges on affected installations of Microsoft Exchange. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-62911.

MicrosoftVulnerabilitiesCVE-2026-62911
P15
2026-08-11 05:00 UTC
Other

ZDI-26-537: (Pwn2Own) Microsoft Windows storport Integer Overflow Local Privilege Escalation Vulnerability

Zero Day Initiative · indexed 2026-09-07 17:35 UTC

This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-65814.

MicrosoftVulnerabilitiesCVE-2026-65814
P15
2026-08-11 05:00 UTC
Other

ZDI-26-536: (Pwn2Own) Microsoft Windows http.sys Integer Overflow Local Privilege Escalation Vulnerability

Zero Day Initiative · indexed 2026-09-07 17:35 UTC

This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-62735.

MicrosoftVulnerabilitiesCVE-2026-62735
P15
2026-08-11 05:00 UTC
Other

ZDI-26-535: (Pwn2Own) Microsoft Exchange External Control of File Path Remote Code Execution Vulnerability

Zero Day Initiative · indexed 2026-09-07 17:35 UTC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Exchange. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-62911.

MicrosoftVulnerabilitiesCVE-2026-62911
P20
2026-08-10 22:00 UTC
Vendor Research

The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications

Palo Alto Networks Unit 42 · Chris Navarrete, Sai Sathvik Ruppa and Haozhe Zhang · indexed 2026-08-15 18:55 UTC

Analysis of the Aeternum botnet loader, a threat leveraging Polygon blockchain smart contracts for decentralized C2 infrastructure and payload execution. The post The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications appeared first on Unit 42.

MalwareMicrosoft
P0
2026-08-10 16:38 UTC
Security Journalism

China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-15 14:33 UTC

Microsoft has disclosed that Storm-1175, a financially motivated threat actor linked to China, has deployed a previously undocumented ransomware strain called StormEncryptor. The use of StormEncryptor marks a shift from the adversary's previous use of Medusa ransomware, the Microsoft Threat Intelligence Team said. "StormEncryptor is written in C++ and appends the file name extension .encrypted

MicrosoftRansomwareThreat ActorsThreat Intelligence
P15
2026-08-10 16:00 UTC
Vendor Research

Microsoft named a Leader in the 2026 IDC MarketScape for MDR/MXDR for the Enterprise

Microsoft Security Blog · Srikanth Shoroff · indexed 2026-08-15 18:55 UTC

Microsoft is named a Leader in the 2026 IDC MarketScape for MDR services. Discover how Microsoft Defender Experts MDR combines AI, threat intelligence, and human expertise. The post Microsoft named a Leader in the 2026 IDC MarketScape for MDR/MXDR for the Enterprise appeared first on Microsoft Security Blog.

MicrosoftThreat Intelligence
P0
2026-08-10 15:00 UTC
Vendor Research

DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure

Microsoft Security Blog · Microsoft Threat Intelligence · indexed 2026-08-15 18:55 UTC

Microsoft Threat Intelligence examines DeadLock ransomware, an emerging financially motivated operation distinguished by its use of decentralized infrastructure to support victim communications, negotiations, and data leak operations alongside double extortion tactics used to pressure victims. The post DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure appeared first on Microsoft Security Blog.

Data BreachesMicrosoftRansomwareThreat Intelligence
P15
2026-08-10 12:25 UTC
Security Journalism

New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-15 14:33 UTC

Three separate research efforts last week demonstrated ways to defeat passkey protections without breaking the cryptography they rest on. Passkeys are designed to replace reusable passwords and resist phishing. The attacks instead reused signed authentication material that Windows had exposed, abused a cloud-synced passkey system from malware already on the victim's machine, and used a

MalwareMicrosoftPhishing
P0
2026-08-10 07:38 UTC
Security Journalism

Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-15 14:33 UTC

Cybersecurity researchers have flagged a malicious Microsoft Visual Studio Code (VS Code) extension named Solidity Pro ("solidity-pro") that has been observed delivering a browser wallet and credential stealer. The names of the extensions are below - helper-beeps.solidity-pro web3devtoolsx.solidity-pro Although neither of the extensions is now available on Open VSX, the GitHub repository

MalwareMicrosoftSecurity Research
P0
2026-08-08 06:57 UTC
Security Journalism

N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-15 14:33 UTC

N-able has released a fresh round of hotfixes for N‑central as part of its investigation into ongoing exploitation of a recently disclosed security flaw in the Remote Monitoring and Management (RMM) product. "We are proactively expanding protections in response to ongoing monitoring of threat actors as they evolve their attack techniques," the company said. "This is not a duplicate of our

DFIRMicrosoftThreat Actors
P0
2026-08-07 19:37 UTC
Vendor Research

A decade of enterprise identity in the cloud with AWS Managed Microsoft AD

AWS Security Blog · Vladimir Provorov · indexed 2026-08-15 18:55 UTC

Ten years ago, we launched AWS Directory Service for Microsoft Active Directory, a fully managed Microsoft Active Directory in the AWS Cloud. In that original announcement, Jeff Barr described a straightforward promise: “You will spend less time administering and more time working on your applications and your business.” A decade later, AWS Managed Microsoft AD […]

Cloud SecurityMicrosoft
P0
2026-08-07 18:48 UTC
Security Journalism

Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-15 14:33 UTC

A cluster of nearly 800 malicious packages has been published to the npm registry as part of a new campaign designed to deliver cross-platform malware targeting Windows, Mac, and Linux systems. "These packages appear to use AI slop squatted, or randomly generated typo-squatting package names, but all of them deliver a powerful RAT and infostealer payload," OpenSourceMalware researcher Paul

LinuxMalwareMicrosoft
P0
2026-08-07 14:32 UTC
Vendor Research

Rapid7 Analysis: Unauthenticated Remote Code Execution in JetBrains TeamCity (CVE-2026-63077)

Rapid7 · Stephen Fewer · indexed 2026-08-15 18:55 UTC

OverviewOn July 27, 2026, JetBrains published a security advisory for CVE-2026-63077, a critical unsafe deserialization vulnerability affecting JetBrains TeamCity. An attacker who can reach a TeamCity server over HTTP or HTTPS can exploit the agent polling protocol without credentials and execute operating system commands with the privileges of the TeamCity server process.JetBrains reported no known active exploitation when it disclosed the vulnerability. However, on August 5, 2026, CISA added …

MicrosoftVulnerabilitiesCVE-2026-63077
P70
2026-08-07 12:00 UTC
Vendor Research

Agentic AI for cyber defenders: What security teams built at Black Hat USA 2026

Tenable Blog · Nick Hayes · indexed 2026-08-15 18:55 UTC

Agentic AI armed attackers first, but it also put real building power in defenders’ hands. Here’s what security practitioners built in two days at Black Hat USA 2026, and how the CyberAgents Exchange keeps that work compounding long after the event.Key takeawaysBuilding defensive cybersecurity tooling no longer requires a developer. Agentic tooling drove the cost of finding and exploiting a vulnerability down to 1990s levels; it also removed the engineering barrier that kept defenders from buil…

AI SecurityCloud SecurityMicrosoftThreat ActorsVulnerabilities
P0
2026-08-07 10:58 UTC
Security Journalism

New NatJack Attacks Hijack TCP Sessions and Spoof DNS by Manipulating NAT Tables

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-15 14:33 UTC

Security researcher Malcolm Stagg has disclosed a new attack class called NatJack that manipulates network address translation (NAT) connection state to hijack active TCP sessions, spoof DNS responses, expose mapped ports, and exhaust NAT tables. Presented at Black Hat USA 2026, the research found affected behavior across independently developed implementations, including Windows and

MicrosoftSecurity Research
P0
2026-08-07 10:38 UTC
Security Journalism

Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-15 14:33 UTC

Cybersecurity researchers have called attention to an active "widespread email-driven phishing campaign" that employs adversary-in-the-middle (AitM) techniques to take control of Microsoft 365 accounts with an aim to identify key personnel involved in financial workflows and gather related email. "The campaign uses residential proxies to disguise malicious sign-ins as ordinary consumer traffic,

MicrosoftPhishingSecurity Research
P0
2026-08-07 08:52 UTC
Security Journalism

Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-15 14:33 UTC

Entra ID researcher Dirk-jan Mollema demonstrated that malware already running in a signed-in Windows session can silently use the victim's Windows Hello for Business key to authenticate to Microsoft Entra ID. The attacker can then establish longer-term cloud access, register a device it controls, obtain a Primary Refresh Token (PRT), and add further authentication methods where tenant policies

MalwareMicrosoft
P0
2026-08-06 14:00 UTC
Vendor Research

UNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments

Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-08-15 18:55 UTC

Written by: Tyler McLellan, Austin Larsen Introduction Google Threat Intelligence Group (GTIG) continues to track UNC6671 actively conducting compromises leading to data theft extortion, despite the alleged announced retirement of the BlackFile extortion brand in May 2026. Telemetry and infrastructure analysis reveal that rather than disbanding, UNC6671 has diversified its operations across multiple extortion fronts including Redact, Pink, Helix, and Falcon. UNC6671 continues to rely on voice p…

AppleData BreachesMicrosoftPhishingThreat ActorsThreat Intelligence
P0
2026-08-06 12:00 UTC
Vendor Research

AI code security with Claude Mythos Preview: Inside Tenable’s 500+ hours of testing for Project Glasswing

Tenable Blog · Robert Huber, Tenable Research · indexed 2026-08-15 18:55 UTC

We spent 500+ hours and 40 billion tokens testing Anthropic’s Claude Mythos Preview for Project Glasswing. The takeaway: frontier AI won't run your code security program, but used well, it can make one even stronger.Key takeawaysFrontier AI dramatically scales security testing. In one month, Tenable dedicated 11 security experts and more than 40 billion tokens testing Claude Mythos Preview across source code analysis, exploit creation, binary reverse engineering, threat modeling, and dynamic te…

Cloud SecurityMicrosoft
P0
2026-08-05 21:00 UTC
Vendor Research

AWS partners with Anthropic and OpenAI to bring AWS Continuum into developer workflows

AWS Security Blog · Chet Kapoor · indexed 2026-08-15 18:55 UTC

Customers have access to models that are continuously getting better with each new generation bringing larger context windows, stronger reasoning, and lower token costs. Getting the strongest AI-powered security will come from tools that combine the most relevant models with deep knowledge of a customer’s specific environment. AWS Continuum for code vulnerabilities (Preview) is built […]

Cloud SecurityMicrosoft
P0
2026-08-05 16:30 UTC
Vendor Research

​​Microsoft named a Leader in the KuppingerCole Leadership Compass for Cloud Native Application Protection Platforms (CNAPP)

Microsoft Security Blog · Ran Rosin · indexed 2026-08-15 18:55 UTC

Learn why KuppingerCole named Microsoft a Leader in its Leadership Compass: Cloud Native Application Protection Platforms report. The post ​​Microsoft named a Leader in the KuppingerCole Leadership Compass for Cloud Native Application Protection Platforms (CNAPP) appeared first on Microsoft Security Blog.

Microsoft
P0
2026-08-05 16:01 UTC
Vendor Research

Cisco Advance Notification for Publication of August 5, 2026, Security Advisories

Cisco Security Advisories · indexed 2026-08-15 14:33 UTC

On August 5, 2026, the Cisco Product Security Incident Response Team (PSIRT) published the following advisories: Cisco Security Advisory CVE ID Security Impact Rating CVSS Base Score Cisco Catalyst SD-WAN Software Security Hardening Release: August 2026 CVE-2026-20303CVE-2026-20304CVE-2026-20310CVE-2026-20312CVE-2026-20313 Critical 9.9 Cisco IOS XE Software Security Hardening Release: August 2026 CVE-2026-20267CVE-2026-20268CVE-2026-20269CVE-2026-20270CVE-2026-20271CVE-2026-20272CVE-2026-20273 …

AppleDFIRMicrosoftNetwork SecurityVulnerabilitiesCVE-2026-20028CVE-2026-20124CVE-2026-20198CVE-2026-20263CVE-2026-20289CVE-2026-20294CVE-2026-20301CVE-2026-20311
P5
12 13 14 15 16