IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 623 matching records.
AUTO-POLL // 2026-10-02 22:45 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P6 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 2

RANSOMWARE
P6
P6
COOL // 45 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
WED
Sep 30

RANSOMWARE
P10
P10
WARM // 59 ARTICLES
TUE
Sep 29

RANSOMWARE
P4
P4
COOL // 68 ARTICLES
MON
Sep 28

RANSOMWARE
P7
P7
COOL // 52 ARTICLES
SUN
Sep 27

RANSOMWARE
P25
P25
ELEVATED // 15 ARTICLES
SAT
Sep 26

RANSOMWARE
P13
P13
WARM // 20 ARTICLES
RESET
2026-09-30 10:45 UTC
Security Journalism

US-Focused CSuite Phishing Steals Microsoft 365 Sessions and Deploys RMM Tools for Remote Access

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-30 11:45 UTC

ANY.RUN researchers traced a US-focused CSuite phishing campaign across 351 sandbox analyses, with 51% of submissions coming from the United States. Technology, manufacturing, government, and consulting organizations showed the highest exposure. By combining Microsoft 365 session theft with remote-access tool deployment, CSuite can turn a phishing incident into broader account compromise, fraud

CybercrimeMicrosoftPhishing
P0
2026-09-29 21:39 UTC
Vendor Research

Phishing Abuses RMM Tools for Persistent Access

Microsoft Security Blog · Microsoft Security Research, Parasharan Raghavan, Deva Kanna Kannan, Sai Chakri and Microsoft Defender Experts · indexed 2026-09-29 22:40 UTC

Microsoft observed phishing campaigns that abused MSP360 RMM to deploy ScreenConnect, creating redundant remote-access channels for follow-on activity The post Phishing Abuses RMM Tools for Persistent Access appeared first on Microsoft Security Blog.

MicrosoftPhishing
P0
2026-09-29 17:20 UTC
Security Journalism

Russia's Star Blizzard Targets 100+ Organizations With Fake Event Invites to Deliver Backdoor

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-29 18:35 UTC

Russian state hackers known as Star Blizzard have been using fake event invitations to trick people into installing a backdoor on their Windows computers, according to Microsoft. The campaigns, aimed at people and organizations tied to Ukraine, have affected more than 100 organizations since January, mostly in the U.S. and U.K. At least one computer was infected, but the number of breached

MalwareMicrosoft
P0
2026-09-29 16:00 UTC
Vendor Research

​​Beyond source code: A path to the keys to the kingdom

Microsoft Security Blog · Microsoft Defender Experts Cybersecurity Incident Response · indexed 2026-09-29 17:10 UTC

Explore how Storm-3068 turned a compromised identity into broader cloud access and the steps organizations can take to defend their identities, pipelines, and cloud infrastructure. The post ​​Beyond source code: A path to the keys to the kingdom appeared first on Microsoft Security Blog.

Microsoft
P0
2026-09-29 15:00 UTC
Vendor Research

Star Blizzard refines phishing and malware delivery with the RedFlick technique

Microsoft Security Blog · Microsoft Threat Intelligence · indexed 2026-09-29 15:35 UTC

Since January 2026, Microsoft has observed Russian state threat actor Star Blizzard evolve their detection evasion capabilities through large-scale phishing campaigns, the use of accounts on compromised websites, and a novel malware delivery technique, tracked by Microsoft as “RedFlick”. The post Star Blizzard refines phishing and malware delivery with the RedFlick technique appeared first on Microsoft Security Blog.

MalwareMicrosoftPhishingThreat Actors
P0
2026-09-29 14:00 UTC
Vendor Research

Defending Against Active Exploitation of Citrix NetScaler ADC and Gateway Appliances

Google Threat Intelligence / Mandiant · Mandiant · indexed 2026-09-29 14:00 UTC

Introduction In late September 2026, Mandiant Consulting and Google Threat Intelligence Group (GTIG) identified active, in-the-wild exploitation of a zero-day vulnerability (CVE-2026-88772) affecting Citrix NetScaler ADC and NetScaler Gateway appliances. We have observed evidence that organizations in North America and Europe in the government, financial services, technology, education, and legal and professional services sectors were likely impacted by this exploitation campaign, which has bee…

LinuxMalwareMicrosoftNetwork SecurityPhishingThreat ActorsThreat IntelligenceVulnerabilitiesCVE-2026-88771CVE-2026-88772
P30
2026-09-29 09:46 UTC
Security Journalism

Daemon Tools Hackers’ NeedyMantis Malware Dissected by Microsoft

Security Week · Ionut Arghire · indexed 2026-09-29 10:00 UTC

The malware framework uses a modular architecture and a custom executable file format for long-term persistence. The post Daemon Tools Hackers’ NeedyMantis Malware Dissected by Microsoft appeared first on SecurityWeek.

MalwareMicrosoft
P0
2026-09-28 18:35 UTC
Security Journalism

Hackers Use NeedyMantis to Maintain Long-Term Access in Breached Networks

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-28 20:10 UTC

Hackers have used a malware family called NeedyMantis to maintain long-term access to networks they had already breached, Microsoft said in a technical analysis. The malware has been seen in a small number of targeted intrusions at telecommunications organizations, universities, medical nonprofits, intergovernmental organizations, and government contractors. Its use goes back to at least

MalwareMicrosoft
P0
2026-09-28 17:42 UTC
Security Journalism

Bitget Says Attacker Exploited Third-Party Security Product Flaw to Steal $388M

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-28 18:40 UTC

The attacker who stole about $388 million from the cryptocurrency exchange Bitget gained access through a vulnerability in a third-party security product the exchange used, Bitget said on Monday. The attacker exploited the flaw to obtain high-level internal credentials and then, on September 24, used them to send fraudulent withdrawal commands to Bitget's wallet system. Exchanges keep most

CybercrimeMicrosoftVulnerabilities
P0
2026-09-28 15:00 UTC
Vendor Research

NeedyMantis: Unpacking a post-compromise malware family used in targeted operations

Microsoft Security Blog · Microsoft Threat Intelligence · indexed 2026-09-28 16:30 UTC

Microsoft Threat Intelligence identified NeedyMantis, a modular post-compromise malware framework used in targeted intrusions that combines custom loaders, encrypted archives, and extensible components to maintain long-term access and support follow-on operations. The post NeedyMantis: Unpacking a post-compromise malware family used in targeted operations appeared first on Microsoft Security Blog.

MalwareMicrosoftThreat Intelligence
P0
2026-09-28 10:46 UTC
Other

Storm-3168, Linked to JADEPUFFER, Abused Stolen Azure Identities

Security Affairs · Pierluigi Paganini · indexed 2026-09-28 11:00 UTC

Microsoft details Storm-3168, the JADEPUFFER-linked actor that used stolen service principals to delete Azure storage in minutes and harvest keys. Microsoft just published the first detailed look at what JADEPUFFER does inside Azure. Sysdig first spotted the group’s activity in July 2026 and called it the first documented agentic ransomware operation. Microsoft tracks the same […]

Cloud SecurityMicrosoftRansomware
P15
2026-09-28 09:08 UTC
Security Journalism

JADEPUFFER-Linked Attackers Used Compromised Service Principals to Delete Azure Resources

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-28 10:25 UTC

The threat actor known as JADEPUFFER has been observed orchestrating destructive actions within a Microsoft Azure environment using compromised service principals. Microsoft, which is tracking the activity under the name Storm-3168, has called it an evolution of the threat actor's tradecraft. The attack took place in early June 2026 over a period of about 18 hours. "The destructive operations

Cloud SecurityMicrosoftThreat Actors
P0
2026-09-27 15:26 UTC
Other

SECURITY AFFAIRS AI-CYBERSECURITY NEWSLETTER ROUND 1

Security Affairs · Pierluigi Paganini · indexed 2026-09-27 15:35 UTC

Security Affairs AI-CYBERSECURITY newsletter includes a collection of the best articles and research on AI in the international landscape Artificial intelligence is rapidly changing cybersecurity, reshaping both the techniques used by attackers and the tools available to defenders. AI agents can automate tasks, analyze large amounts of data, discover vulnerabilities and accelerate offensive operations. At […]

AI SecurityMicrosoft
P0
2026-09-26 15:50 UTC
Security Journalism

Microsoft pauses KB5002907 update after Office license deactivations

BleepingComputer · Lawrence Abrams · indexed 2026-09-26 15:55 UTC

Microsoft has paused the rollout of the KB5002907 Microsoft 365 update after users report that it deactivated, or in some cases completely removed, perpetual Office 2016 and Office 2019 installations. [...]

Microsoft
P0
2026-09-26 12:00 UTC
Security Journalism

New x47.c Windows Botnet Weaponizes xAI Grok, AI API Draining

Security Week · Ionut Arghire · indexed 2026-09-26 12:10 UTC

The Windows botnet relies on AI to maintain persistence, using xAI Grok to choose from predefined actions. The post New x47.c Windows Botnet Weaponizes xAI Grok, AI API Draining appeared first on SecurityWeek.

MalwareMicrosoft
P0
2026-09-26 08:49 UTC
Security Journalism

SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-26 10:05 UTC

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added two security flaws impacting Microsoft SharePoint and Mikrotik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerabilities in question are as follows - CVE-2026-65660 (CVSS score: 8.8) - A code injection vulnerability in Microsoft Office SharePoint

Cloud SecurityMicrosoftNetwork SecurityVulnerabilitiesCVE-2026-65660
P95
2026-09-25 21:03 UTC
Other

U.S. CISA adds Microsoft SharePoint and Mikrotik RouterOS flaws to its Known Exploited Vulnerabilities catalog

Security Affairs · Pierluigi Paganini · indexed 2026-09-25 22:00 UTC

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Microsoft SharePoint and Mikrotik RouterOS flaws flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2026-65660 is a code-injection vulnerability in Microsoft SharePoint Server that allows an authenticated, low-privileged attacker to execute arbitrary […]

Cloud SecurityMicrosoftNetwork SecurityVulnerabilitiesCVE-2026-65660
P35
2026-09-25 18:02 UTC
Other

Cryptocurrency exchange Bitget Says North Korea-Linked Hackers Stole $351.6 Million

Security Affairs · Pierluigi Paganini · indexed 2026-09-25 18:40 UTC

Bitget says suspected North Korea-linked actors stole $351.6M from hot and warm wallets. Withdrawals were suspended while Mandiant investigates. Cryptocurrency exchange Bitget says suspected North Korea-linked threat actors stole $351.6 million from a limited number of hot and warm wallets. The company detected unauthorized transfers on September 24 and temporarily suspended withdrawals. Bitget said customer […]

MicrosoftThreat Actors
P0
2026-09-25 15:35 UTC
Vendor Research

Storm-3168: Agentic-driven cloud attacks using compromised service principals

Microsoft Security Blog · Microsoft Security Research, Yossi Weizman and Tushar Mudi · indexed 2026-09-25 17:40 UTC

Microsoft details JADEPUFFER-linked Azure reconnaissance, resource deletion, and credential access using compromised service principals, identifying the activity as associated with Storm-3168 and providing guidance for defenders. The post Storm-3168: Agentic-driven cloud attacks using compromised service principals appeared first on Microsoft Security Blog.

Cloud SecurityMicrosoft
P0
2026-09-25 14:00 UTC
Vendor Research

ShinyHunters Renewed Mass Exploitation Campaign Targeting Oracle PeopleSoft

Google Threat Intelligence / Mandiant · Mandiant · indexed 2026-09-26 06:55 UTC

Introduction As an update to the June 2026 post, ShinyHunters Targets Education Sector with Oracle PeopleSoft Exploit, Mandiant and Google Threat Intelligence Group (GTIG) have identified renewed mass exploitation of CVE-2026-35273 by UNC6240 (ShinyHunters), along with expanded global targeting across multiple sectors. In June, the threat actor exploited this vulnerability as a zero-day predominantly against academic institutions. This new wave of activity stems from UNC6240 modifying its explo…

LinuxMicrosoftNetwork SecurityThreat ActorsThreat IntelligenceVulnerabilitiesCVE-2026-35273
P50
1 2 3 4