IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 623 matching records.
AUTO-POLL // 2026-10-02 22:45 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P6 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 2

RANSOMWARE
P6
P6
COOL // 45 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
WED
Sep 30

RANSOMWARE
P10
P10
WARM // 59 ARTICLES
TUE
Sep 29

RANSOMWARE
P4
P4
COOL // 68 ARTICLES
MON
Sep 28

RANSOMWARE
P7
P7
COOL // 52 ARTICLES
SUN
Sep 27

RANSOMWARE
P25
P25
ELEVATED // 15 ARTICLES
SAT
Sep 26

RANSOMWARE
P13
P13
WARM // 20 ARTICLES
RESET
2026-09-25 10:35 UTC
Security Journalism

Bitget Says Suspected North Korean Hackers Stole $351.6M After Backend Compromise

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-25 11:15 UTC

Cryptocurrency exchange Bitget said suspected North Korean threat actors have stolen $351.6 million from its hot and warm wallets. "At 18:31 UTC on September 24, 2026, Bitget's security systems identified unauthorized transfers involving a limited number of hot wallets," Bitget said in a post shared on X. "Bitget's cold wallets and the overwhelming majority of platform assets remain

MicrosoftThreat Actors
P0
2026-09-25 10:30 UTC
Security Journalism

Microsoft: Recent Windows updates cause desktop loading issues

BleepingComputer · Sergiu Gatlan · indexed 2026-09-25 10:35 UTC

Microsoft has confirmed that some users may experience desktop loading issues, including black screens, after installing the August 2026 preview updates and subsequent updates. [...]

Microsoft
P0
2026-09-24 16:00 UTC
Vendor Research

Beyond the ransomware: Tracking Storm-2570’s consistent tradecraft across deployments

Microsoft Security Blog · Microsoft Threat Intelligence · indexed 2026-09-24 18:00 UTC

Storm-2570 is a ransomware affiliate that uses consistent post-compromise tools and techniques across deployments involving Qilin, DragonForce, Anubis, and BERT ransomware, and provides guidance to help defenders detect and disrupt this activity before ransomware deployment. The post Beyond the ransomware: Tracking Storm-2570’s consistent tradecraft across deployments appeared first on Microsoft Security Blog.

MicrosoftRansomware
P15
2026-09-24 15:27 UTC
Security Journalism

Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-24 16:35 UTC

The "third-party[.]com" domain, commonly used as a documentation placeholder, has been observed serving a ClickFix lure to Windows browsers while displaying a harmless decoy to other users. "third-party[.]com has been a generic documentation placeholder for years, the same role example.com plays," Manifold Security's Head of Research, Ax Sharma, said. "Unlike 'example[.]com,' third-party[.]com

Microsoft
P0
2026-09-24 14:29 UTC
Security Journalism

Hacked Ukrainian Sites Serve Fake Cloudflare ClickFix Lures for Psychedelic Stealer

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-24 15:10 UTC

An active ClickFix campaign has been observed compromising legitimate Ukrainian business websites to inject bogus Cloudflare verification pages and trick victims into downloading a previously undocumented information stealer called Psychedelic. "When a visitor interacts with the page, the lure copies a Windows Installer command to the clipboard and instructs the visitor to paste it into the

MalwareMicrosoft
P0
2026-09-24 14:00 UTC
Vendor Research

Proactive Defense: Hardening Code Pipelines and CI/CD Infrastructure

Google Threat Intelligence / Mandiant · Mandiant · indexed 2026-09-24 15:25 UTC

Introduction The landscape of software supply chain security has undergone a significant shift. Recent campaigns demonstrate that sophisticated threat actors are systematically targeting the engineering lifecycle by compromising trusted security and programming tools. These intrusions reveal three key tactics: Attackers target trusted security scanners, utility libraries, and AI developer tools to exploit the elevated privileges granted to these systems within build pipelines. Adversaries targe…

AI SecurityMicrosoftPhishingThreat ActorsVulnerabilities
P0
2026-09-24 13:30 UTC
Security Journalism

Ghost Service Accounts Enable M365 Data Theft in Chile

Dark Reading · Nate Nelson · indexed 2026-09-24 13:35 UTC

Even if the organization locks down employee accounts, forgotten and lost service accounts can still undo the organization's entire M365 environment.

Microsoft
P0
2026-09-24 13:00 UTC
Vendor Research

When Business Email Compromise Starts Rewriting Reality

Rapid7 · Douglas McKee, Director, Vulnerability Intelligence · indexed 2026-09-24 13:20 UTC

Business Email Compromise (BEC) operates on a familiar playbook. Threat actors breach a mailbox, silently monitor operations, map approval chains, and ultimately exploit that access to divert funds or exfiltrate sensitive assets.This dynamic is central to our analysis as we kick off a series around Rapid7's collaborative research with Zimbra; upcoming installments will explore technical details and broader findings based within the Zimbra Collaboration Suite. Our investigation disrupted the tra…

CybercrimeDFIRMicrosoftPhishingThreat ActorsVulnerabilitiesCVE-2022-27925CVE-2022-37042CVE-2023-37580CVE-2024-45519CVE-2025-27915CVE-2026-73570
P70
2026-09-24 12:16 UTC
Security Journalism

Windows 11 KB5124010 update released with 46 changes and fixes

BleepingComputer · Sergiu Gatlan · indexed 2026-09-24 12:25 UTC

Microsoft released the KB5124010 September 2026 non-security preview update for Windows 11 24H2 and 25H2, with 46 changes including Bluetooth improvements and the ability to remap the Copilot key. [...]

Microsoft
P0
2026-09-24 06:32 UTC
Security Journalism

TeamFiltration Campaign Compromises Seven Microsoft 365 Accounts Using Default Passwords

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-24 08:35 UTC

Cybersecurity researchers have disclosed details of an active TeamFiltration campaign codenamed UNK_CondorFiltration that has targeted over 5,700 accounts across 28 Microsoft 365 tenants. According to Proofpoint, the activity has primarily focused on Chilean retail and financial institutions. It originated from 1,487 unique AWS EC2 source IP addresses. "The campaign compromised 7 accounts –

Cloud SecurityMicrosoftSecurity Research
P0
2026-09-24 05:44 UTC
Other

CLOSEDQUORUM, the malware that asks four AI models what to do next

Security Affairs · Pierluigi Paganini · indexed 2026-09-24 05:50 UTC

Cisco Talos finds CLOSEDQUORUM, malware that lets four commercial AI models vote on its next move, with no human operator required. Cisco Talos found malware, dubbed CLOSEDQUORUM, that holds a vote before deciding what to steal from you. Four AI models vote on its next move, without any human interaction. CLOSEDQUORUM is the first Windows […]

MalwareMicrosoft
P0
2026-09-23 22:46 UTC
Security Journalism

Placeholder domain used in dev docs now serves ClickFix attacks

BleepingComputer · Lawrence Abrams · indexed 2026-09-23 22:50 UTC

The "third-party.com" domain, commonly used as a placeholder in developer documentation and code examples, is serving a fake Cloudflare verification page that attempts to trick Windows users into executing PowerShell commands. [...]

Microsoft
P0
2026-09-23 21:03 UTC
Security Journalism

EDR Evasion Stack Helps Process Injection Slip Past Defenses

Dark Reading · Alexander Culafi · indexed 2026-09-23 21:10 UTC

A process parameter-poisoning technique evades EDR by injecting code into process initialization structures without using the Windows APIs that EDR tools typically watch out for.

Microsoft
P0
2026-09-23 18:06 UTC
Security Journalism

Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-23 20:00 UTC

Cybersecurity researchers have disclosed Go-based malware distributed via two Go Modules and two Terraform providers, marking the first time threat actors are using the centralized repository hosted by HashiCorp as a distribution vector for malicious payloads. According to Aikido, the list of Terraform providers and Go modules is below - gocommunity-io/dockerd (222 downloads) kreuzwenker/

MalwareMicrosoftSecurity ResearchThreat Actors
P0
2026-09-23 16:00 UTC
Vendor Research

Reimagining the SOC for the agentic era in Microsoft Defender

Microsoft Security Blog · Rob Lefferts · indexed 2026-09-23 16:40 UTC

We are announcing ISOC in Microsoft Defender: a foundation built for agentic security that brings leading solutions for SIEM and threat protection together. The post Reimagining the SOC for the agentic era in Microsoft Defender appeared first on Microsoft Security Blog.

Microsoft
P0
2026-09-23 14:17 UTC
Security Journalism

This Windows Malware is Built to Let Up to Four AI Models Vote on Its Next Move

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-23 15:25 UTC

A Windows malware called CLOSEDQUORUM is built to take orders from a vote of up to four AI models instead of an attacker's server, Cisco Talos said on September 22. The models can choose to steal Windows credentials, saved browser passwords, and crypto wallet data. Talos has not seen this setup work from start to finish, and the public version of the malware does not work as it is.

MalwareMicrosoft
P0
2026-09-23 13:52 UTC
Security Journalism

Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-23 14:10 UTC

Unknown threat actors have managed to compromise two legitimate MemTensor packages across the npm and Python Package Index (PyPI) repositories to push a platform-specific Go-based implant dubbed sckit designed for Windows, Linux, and macOS. According to reports from Aikido, SafeDep, Socket, and StepSecurity, the libraries in question below - @memtensor/memos-cloud-openclaw-plugin versions

AppleLinuxMalwareMicrosoftThreat Actors
P0
2026-09-23 11:00 UTC
Other

EvilTokens made phishing-as-a-service look easy. Then it got taken down

Security Affairs · Pierluigi Paganini · indexed 2026-09-23 11:10 UTC

Microsoft, Coinbase and law enforcement took down EvilTokens, a phishing kit that compromised 12,000 inboxes through device-code phishing and AI. EvilTokens showed up in February 2026 and moved fast. Within months it had compromised more than 12,000 inboxes across over 10,000 organizations. Microsoft says the EvilTokens platform, operated by Storm-2992, is a phishing-as-a-service kit sold […]

MicrosoftPhishing
P0
2026-09-23 10:00 UTC
Security Journalism

Outerlimit Raises $16 Million to Stop Rogue AI Agents From Causing Harm

Security Week · Kevin Townsend · indexed 2026-09-23 10:10 UTC

Emerging from stealth with $16 million in pre-seed funding, Outerlimit offers a decentralized authorization layer designed to discover, observe, and block harmful autonomous AI actions. The post Outerlimit Raises $16 Million to Stop Rogue AI Agents From Causing Harm appeared first on SecurityWeek.

AI SecurityMicrosoft
P0
2026-09-23 08:29 UTC
Security Journalism

Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-23 08:45 UTC

A Chinese threat actor codenamed UTA0565 has been observed exploiting the recently disclosed Google Chrome-Microsoft Windows exploit chain as zero-days through fake websites. The attacks, detected on September 3 and 4, 2026, involved the chaining of two vulnerabilities in Chrome (CVE-2026-85046, CVE-2026-87491) and one impacting Windows Advanced Local Procedure Call (CVE-2026-85880) to break

MalwareMicrosoftThreat ActorsVulnerabilitiesCVE-2026-85046CVE-2026-85880CVE-2026-87491
P30
2026-09-23 08:25 UTC
Other

Fake LastPass on GitHub Led to an Infostealer That Killed 145 Security Tools

Security Affairs · Pierluigi Paganini · indexed 2026-09-23 08:50 UTC

Attackers spoofed LastPass on GitHub, used a Microsoft-signed driver to disable 145 security products, then deployed an infostealer. Someone impersonated LastPass on GitHub, got users to download a fake authenticator, and ended up killing 145 different antivirus and EDR products using a driver that Microsoft itself had signed. That last part is the one worth […]

MalwareMicrosoft
P0
1 2 3 4 5