IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 623 matching records.
AUTO-POLL // 2026-10-02 23:40 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P7 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 2

RANSOMWARE
P7
P7
COOL // 46 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
WED
Sep 30

RANSOMWARE
P10
P10
WARM // 59 ARTICLES
TUE
Sep 29

RANSOMWARE
P4
P4
COOL // 68 ARTICLES
MON
Sep 28

RANSOMWARE
P7
P7
COOL // 52 ARTICLES
SUN
Sep 27

RANSOMWARE
P25
P25
ELEVATED // 15 ARTICLES
SAT
Sep 26

RANSOMWARE
P13
P13
WARM // 20 ARTICLES
RESET
2026-09-17 16:00 UTC
Vendor Research

Improving email security outcomes with real-world Microsoft Defender insights

Microsoft Security Blog · Rob Lefferts · indexed 2026-09-17 18:05 UTC

The latest email security benchmarking reports show strong Microsoft Defender performance across pre-delivery and post-delivery scenarios and reveal where threats and defenses continue to evolve. The post Improving email security outcomes with real-world Microsoft Defender insights appeared first on Microsoft Security Blog.

AppleMicrosoft
P0
2026-09-17 14:16 UTC
Other

SilkParasite Infrastructure Links SpiceRAT to Central Asian Targets

Security Affairs · Pierluigi Paganini · indexed 2026-09-17 14:30 UTC

Hunt.io links SpiceRAT, NodeEdgeRAT and NomadRAT to a four-year SilkParasite campaign targeting governments and critical sectors in Central Asia. Hunt.io and researcher Guy Yasur have traced a tight cluster of SpiceRAT command‑and‑control servers that predate and extend Bitdefender’s August 2026 SilkParasite report. The work doesn’t dissect malware samples; it maps the network side of the […]

MalwareMicrosoft
P0
2026-09-17 08:24 UTC
Security Journalism

Microsoft shares workaround for Windows domain login issues

BleepingComputer · Sergiu Gatlan · indexed 2026-09-17 08:30 UTC

Microsoft shared a temporary fix on Wednesday for a known issue that prevents Windows 11 users from logging in with valid domain credentials after installing the September 2026 security updates. [...]

Microsoft
P5
2026-09-17 07:25 UTC
Other

Chosen Brick, Iran’s Surveillance Malware

Security Affairs · Pierluigi Paganini · indexed 2026-09-17 08:00 UTC

UK, US, and Dutch agencies expose Chosen Brick, Iranian malware used to track and harass dissidents, journalists, and activists via Telegram. The UK, the US, and the Netherlands published a joint advisory warning about a Windows malware family, dubbed Chosen Brick, that Iran’s intelligence services use to track down dissidents, journalists, and activists, and the […]

MalwareMicrosoft
P0
2026-09-17 07:20 UTC
Other

HEAVYGRAM: A Telegram-based Surveillance Backdoor Linked to Handala Hack

Group-IB · indexed 2026-09-17 08:35 UTC

Group-IB Threat Intelligence analyzes HEAVYGRAM, a Telegram-based Windows backdoor attributed with moderate confidence to the Iran-linked threat actor Handala Hack. Active since Fall 2023, it has been used to surveil Iranian dissidents, journalists and government opponents, enabling remote command execution, data exfiltration, and persistence over Telegram command-and-control.

MalwareMicrosoftThreat ActorsThreat Intelligence
P0
2026-09-16 20:39 UTC
Security Journalism

Windows 11 KB5124008 update breaks domain trust for some users

BleepingComputer · Lawrence Abrams · indexed 2026-09-16 20:50 UTC

Microsoft is investigating reports that the Windows 11 KB5124008 security update is breaking domain trust relationships on some enterprise systems, preventing users from logging in with valid domain credentials. [...]

Microsoft
P5
2026-09-16 20:20 UTC
Other

BambooToken: The Malware That Speaks MQTT to Stay Under the Radar

Security Affairs · Pierluigi Paganini · indexed 2026-09-16 21:00 UTC

Lumen exposes BambooToken, a stealthy malware family using MQTT and sideloading to quietly infect targets across Asia and beyond. BambooToken is a new malware family that uses MQTT, a lightweight messaging protocol commonly found in smart devices and industrial systems, to quietly control infected Windows and Linux machines. Most malware connects directly to a command-and-control […]

LinuxMalwareMicrosoft
P0
2026-09-16 14:36 UTC
Security Journalism

One Extension Could Hijack AI Assistants Across Chrome, Comet, Edge, Opera Neon and Claude

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-16 16:25 UTC

Security researchers at Forever Security have shown that one ordinary browser extension could take control of the AI assistants built into five Chromium-based products: Gemini Live in Chrome, Perplexity Comet, Microsoft Edge, Opera Neon and the Claude in Chrome extension. Once the extension was installed, it could access each product's built-in AI with a single click. On Comet, Edge,

MicrosoftSecurity Research
P0
2026-09-16 05:00 UTC
Other

ZDI-26-703: (0Day) Airbyte SharePoint Connector _get_shared_drive_object Server-Side Request Forgery Information Disclosure Vulnerability

Zero Day Initiative · indexed 2026-09-16 15:20 UTC

This vulnerability allows remote attackers to initiate arbitrary server-side requests on affected installations of Airbyte. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.7. The following CVEs are assigned: CVE-2026-92203.

MicrosoftVulnerabilitiesCVE-2026-92203
P5
2026-09-15 16:29 UTC
Security Journalism

Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journalists

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-15 17:45 UTC

Cybersecurity agencies in the United States, the United Kingdom, and the Netherlands have detailed a Windows malware that they say Iran's intelligence service uses to spy on dissidents, journalists, and activists around the world. The malware is controlled via the Telegram messaging app and can copy a target's emails and chat messages, take screenshots, and activate the microphone to record

MalwareMicrosoft
P0
2026-09-15 15:23 UTC
Security Journalism

BambooToken Malware Uses MQTT to Control Windows and Linux Systems

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-15 15:50 UTC

Cybersecurity researchers have disclosed details of a multi-platform campaign that uses the Message Queueing Telemetry Transport (MQTT) protocol as a communication channel to control Windows and Linux systems. The emerging malware family, codenamed BambooToken, is assessed to be active since at least February 2023 and put to use in attacks targeting organizations across Asia and South America.

LinuxMalwareMicrosoftSecurity Research
P0
2026-09-15 13:45 UTC
Security Journalism

What Zero-Day Response Should Be in the Post-Mythos Era

BleepingComputer · Sponsored by Picus Security · indexed 2026-09-15 14:05 UTC

AI is shrinking the time between vulnerability disclosure and exploitation, leaving defenders less time to wait for patches or public exploits. Picus Security explains how exploitability validation, security control testing, and autonomous pentesting can help teams close exposure gaps before attackers arrive. [...]

MicrosoftVulnerabilities
P25
2026-09-15 13:32 UTC
Vendor Research

Australia is replacing the Essential Eight with a new cyber framework. Here’s how exposure management can help you get ahead of it.

Tenable Blog · Ben Mudie · indexed 2026-09-15 13:40 UTC

Australia’s move from the Essential Eight to an outcomes-based cybersecurity model will push organizations from conducting periodic point-in-time, checklist compliance assessments to having continuous evidence of a solid security posture.Key takeawaysThe Australian Signals Directorate (ASD) is moving from the Essential Eight cybersecurity framework to a new outcomes-focused Essentials series covering enterprise IT, cloud, operational technology (OT), and potentially agentic AI.The Essential Eig…

Cloud SecurityICS / OTMicrosoftNetwork SecurityVulnerabilities
P0
2026-09-15 11:12 UTC
Security Journalism

Mass-Scanning Campaign Exploits Vite Flaw to Extract Cloud Credentials From Exposed Dev Servers

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-15 12:25 UTC

Cybersecurity researchers have disclosed details of a mass-scanning campaign that has targeted Vite deployments siphon sensitive data. The first is an automated effort aimed at internet-exposed Vite development servers that's designed to steal cloud credentials, configurations from Amazon Web Services (AWS) and Microsoft Azure instances, and infrastructure state files, per F5 Labs. The

Cloud SecurityMicrosoftSecurity Research
P0
2026-09-15 10:17 UTC
Other

One Exploit Chain, Two Espionage Campaigns: Chrome and Windows Under Fire

Security Affairs · Pierluigi Paganini · indexed 2026-09-15 11:30 UTC

Two China-linked groups ran identical Chrome/Windows zero-day exploits against NGOs, before Chrome’s patch shipped, deploying different backdoors each. Two China-linked threat actors used the same Chrome/Windows zero-day against NGOs starting September 1, 2026, Volexity’s new report lays out the whole chain in detail. On September 1, Volexity detected a spear-phishing campaign by UTA0560 targeting several […]

APT / Nation-StateMalwareMicrosoftPhishingThreat ActorsVulnerabilities
P25
2026-09-15 05:31 UTC
Security Journalism

China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-15 06:25 UTC

A Chinese threat actor has been attributed to a spear-phishing campaign that exploits recently patched security flaws in Google Chrome and Microsoft Windows to deliver a malicious JavaScript backdoor called GRIMWEDGE. Volexity, which is tracking the threat cluster under the moniker UTA0560, said the activity targeted multiple non-governmental organizations (NGOs) on September 1, 2026. "The

Cloud SecurityMalwareMicrosoftPhishingThreat ActorsVulnerabilities
P25
3 4 5 6 7