IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 623 matching records.
AUTO-POLL // 2026-10-03 04:55 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
NO DATA
NO INTELLIGENCE AGGREGATED TODAY
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 3
NO DATA
--
NO INTEL
FRI
Oct 2

RANSOMWARE
P7
P7
COOL // 46 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
WED
Sep 30

RANSOMWARE
P10
P10
WARM // 59 ARTICLES
TUE
Sep 29

RANSOMWARE
P4
P4
COOL // 68 ARTICLES
MON
Sep 28

RANSOMWARE
P7
P7
COOL // 52 ARTICLES
SUN
Sep 27

RANSOMWARE
P25
P25
ELEVATED // 15 ARTICLES
RESET
2026-01-29 15:00 UTC
Security Journalism

The (!FALSE) Pattern | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

SOAPHound's LDAP query (!soaphound=*) never appears in Event 1644 logs, but it transforms into (! (FALSE)) through LDAP optimization. Understanding this transformation reveals a unique detection signature that most defenders have never seen.

Microsoft
P0
2026-01-15 06:07 UTC
Other

DeadLock Ransomware: Smart Contracts for Malicious Purposes

Group-IB · indexed 2026-09-07 17:30 UTC

This blog uncovers DeadLock’s stealthy usage of Polygon smart contracts for proxy address storage, a poorly-documented and under-reported technique that Group-IB analysts have observed increased usage in the wild. Variants of this technique are very wide and offer great alternatives to threat actors for bypassing traditional defenses by abusing decentralized blockchains available worldwide.

MicrosoftRansomwareThreat Actors
P35
2026-01-13 06:00 UTC
Security Journalism

Cross-Platform Unity in EDR

Huntress · indexed 2026-09-07 17:30 UTC

Huntress researchers weigh in on the challenge of getting feature parity across Windows, macOS, and Linux. And learn how unique security models and platform maturity shape the way products are built.

AppleLinuxMicrosoft
P0
2025-11-26 14:00 UTC
Security Journalism

#ShadyHacks with Kyle Hanslovan

Huntress · indexed 2026-09-07 17:30 UTC

Huntress CEO Kyle Hanslovan's live hack demo: modern hacker playbook, with stolen credentials, MFA bypass, and M365 token hijacking. Get defense tips, stay protected.

CybercrimeMicrosoft
P0
2025-11-26 08:22 UTC
Other

Bloody Wolf: A Blunt Crowbar Threat To Justice

Group-IB · indexed 2026-09-07 17:30 UTC

Since late June 2025, Group-IB analysts observed a surge in spear-phishing emails across Central Asia. The attackers impersonate government agencies to gain the trust of their victims. This blog describes the techniques, tools and ongoing activity of the threat group known as Bloody Wolf.

MicrosoftPhishing
P0
2025-11-17 14:00 UTC
Security Journalism

Huntress Lands on the Microsoft Marketplace

Huntress · indexed 2026-09-07 17:30 UTC

Huntress is now on the Microsoft Marketplace. Combine our protection with Microsoft 365 and Defender, get 24/7 monitoring, and enjoy enterprise-grade security without the hefty price tag.

Microsoft
P0
2025-10-28 17:01 UTC
Vendor Research

HTTPS by default

Google Online Security Blog · Google · indexed 2026-08-15 14:33 UTC

One year from now, with the release of Chrome 154 in October 2026, we will change the default settings of Chrome to enable “Always Use Secure Connections”. This means Chrome will ask for the user's permission before the first access to any public site without HTTPS. The “Always Use Secure Connections” setting warns users before accessing a site without HTTPS Chrome Security's mission is to make it safe to click on links. Part of being safe means ensuring that when a user types a URL or clicks o…

LinuxMalwareMicrosoftMobile Security
P0
2025-10-06 08:11 UTC
Other

From Cost Center to ROI Engine: Making ASM a Security Investment That Pays for Itself

Red Hunt Labs · Lohit · indexed 2026-09-07 17:30 UTC

In today’s sprawling digital landscape, the question for security leaders isn’t whether Attack Surface Management (ASM) matters; it’s whether your ASM platform is doing enough to earn its place in the budget. If your board or finance team is asking you to justify the spend, you’re not alone. Saying it “improves visibility” or “reduces risk” isn’t enough anymore. You need to show real outcomes, saved hours, reduced incidents, lower cloud costs, and stronger operational resilience. That’s where C…

MicrosoftVulnerabilities
P0
2025-09-24 18:42 UTC
Vendor Research

Accelerating adoption of AI for cybersecurity at DEF CON 33

Google Online Security Blog · Kimberly Samra · indexed 2026-08-15 14:33 UTC

Posted by Elie Bursztein and Marianna Tishchenko, Google Privacy, Safety and Security TeamEmpowering cyber defenders with AI is critical to tilting the cybersecurity balance back in their favor as they battle cybercriminals and keep users safe. To help accelerate adoption of AI for cybersecurity workflows, we partnered with Airbus at DEF CON 33 to host the GenSec Capture the Flag (CTF), dedicated to human-AI collaboration in cybersecurity. Our goal was to create a fun, interactive environment, …

AI SecurityMicrosoft
P0
2025-09-23 09:20 UTC
Other

Echoes of AI Exposure: Thousands of Secrets Leaking Through Vibe Coded Sites | Wave 15 | Project Resonance

Red Hunt Labs · redhuntAdmin · indexed 2026-09-07 17:30 UTC

1. Introduction The vibe coding revolution has empowered millions to build and deploy websites using natural languages. Entrepreneurs, artists, and small businesses can now bring their ideas to life online without writing a single line of code. But has this convenience come at a hidden security cost? In this post, we present the 15th wave of Project Resonance: A RedHunt Labs Research Initiative, investigating the security posture of websites built on modern “vibe coding” platforms. Our research…

Microsoft
P0
2025-09-17 00:00 UTC
Other

Entra ID actor token validation bug allowing cross-tenant global admin

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A critical vulnerability discovered in Microsoft's Entra ID (formerly Azure AD) allowed for cross-tenant access and potential global admin privilege escalation. The flaw was found in the legacy Azure AD Graph API, which improperly validated the originating tenant for undocumented "Actor tokens." An attacker could use a token from their own tenant to authenticate as any user, including Global Admins, in any other tenant. This vulnerability bypassed security policies like Conditional Access. The …

Cloud SecurityMicrosoftVulnerabilities
P10
2025-09-02 05:00 UTC
Security Journalism

Debunking Microsoft 365 & Identity Myths

Huntress · indexed 2026-09-07 17:30 UTC

Don’t fall for common Microsoft 365 identity security myths. Here, Huntress debunks misconceptions around logins, MFA, Conditional Access, Impossible Travel, and security tuning.

Microsoft
P0
2025-08-27 07:50 UTC
Other

ShadowSilk: A Cross-Border Binary Union for Data Exfiltration

Group-IB · indexed 2026-09-07 17:30 UTC

This blog describes attacks on victims in Central Asia and APAC. Research into the attack has identified a group also called YoroTrooper. We also identified profiles of attackers on hacker forums, their malicious web-panels, test infections of attackers' own machines, and screenshots of attackers' desktops.

Microsoft
P0
2025-07-30 04:00 UTC
Security Journalism

Information to Insights: Intrusion Analysis Methodology

Huntress · indexed 2026-09-07 17:30 UTC

Transform raw Windows event data into actionable insights. Learn expert methodologies for intrusion analysis, authentication events, credential dumping, and RDP activity to stay ahead of threats.

Microsoft
P0
2025-07-21 00:00 UTC
Government

[MàJ] Multiples vulnérabilités dans Microsoft SharePoint (21 juillet 2025)

CERT-FR Alerts · indexed 2026-09-07 17:35 UTC

**[Mise à jour du 23 juillet 2025]** Le 20 juillet 2025, Microsoft a publié des correctifs pour une vulnérabilité de type limitation insuffisante d'un chemin d'accès à un répertoire restreint, aussi appelé *path traversal*, affectant SharePoint Enterprise Server 2016, SharePoint Server 2019 et...

Microsoft
P0
2025-06-03 05:00 UTC
Security Journalism

Infostealers Crash Course: A Tradecraft Tuesday Recap

Huntress · indexed 2026-09-07 17:30 UTC

Cybercriminals are sitting on a pile of stolen credentials, financial information, and sensitive data, thanks to the success of infostealers. Read more to learn how infostealers have grown to become a scourge to defenders, and how businesses can protect themselves.

CybercrimeMalwareMicrosoft
P0
2025-04-02 05:00 UTC
Security Journalism

The Unwanted Guest

Huntress · indexed 2026-09-07 17:30 UTC

Threat actors are enabling the built-in Windows Guest account to maintain persistence. Learn how they gain access and how to detect this activity.

MicrosoftThreat Actors
P0
2025-03-26 09:03 UTC
Other

Unmasking the Classiscam in Central Asia

Group-IB · indexed 2026-09-07 17:30 UTC

Scams like Classiscam automate fake websites to steal financial data, exploiting digitalization’s rise in developing countries, making fraud both effective and hard to detect. In this blog, we dissect the inner working of the scam and its prevalence in Central Asia.

CybercrimeMicrosoft
P0
2025-03-25 00:00 UTC
Other

Entra ID Bug Creates Immutable Users

Cloud Vuln DB · indexed 2026-09-07 17:30 UTC

A bug in Entra ID restricted management administrative units allowed creating immutable users that couldn't be modified or disabled, even by Global Administrators. This could enable an attacker to protect a compromised account from containment. The issue was caused by a timing vulnerability when removing users from restricted AUs and required specific steps to remediate affected accounts.

MicrosoftVulnerabilities
P0
16 17 18 19 20