IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 623 matching records.
AUTO-POLL // 2026-10-03 01:10 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
NO DATA
NO INTELLIGENCE AGGREGATED TODAY
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 3
NO DATA
--
NO INTEL
FRI
Oct 2

RANSOMWARE
P7
P7
COOL // 46 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
WED
Sep 30

RANSOMWARE
P10
P10
WARM // 59 ARTICLES
TUE
Sep 29

RANSOMWARE
P4
P4
COOL // 68 ARTICLES
MON
Sep 28

RANSOMWARE
P7
P7
COOL // 52 ARTICLES
SUN
Sep 27

RANSOMWARE
P25
P25
ELEVATED // 15 ARTICLES
RESET
2026-09-08 18:07 UTC
Vendor Research

Microsoft’s September 2026 Patch Tuesday addresses 964 CVEs (CVE-2026-81963, CVE-2026-85880)

Tenable Cyber Exposure Alerts · Research Special Operations · indexed 2026-09-08 18:20 UTC

104Critical860Important0Moderate0LowMicrosoft addresses 964 CVEs, smashing July’s release as the largest Patch Tuesday release. This month’s updates include patches for two zero-days that were exploited in the wild.Microsoft patched a record 964 CVEs in its September 2026 Patch Tuesday release, with 104 rated critical and 860 rated as important.This month’s update includes patches for:.NET.NET and Visual StudioASP.NET CoreActive Directory Certificate Services (AD CS)Active Directory Domain Serv…

Cloud SecurityLinuxMicrosoftMobile SecurityNetwork SecurityVulnerabilitiesCVE-2023-21674CVE-2026-81963CVE-2026-85880
P65
2026-09-08 17:57 UTC
Security Journalism

Windows 11 cumulative updates KB5124008 & KB5122880 released

BleepingComputer · Mayank Parmar · indexed 2026-09-08 18:05 UTC

Microsoft has released Windows 11 KB5124008 and KB5122880 cumulative updates for versions 25H2/24H2 and 23H2 to fix security vulnerabilities, bugs, and add new features. [...]

Microsoft
P0
2026-09-08 17:21 UTC
Vendor Research

Claude Mythos 5 is coming to Tenable One, powering the new “Adversary View”

Tenable Blog · Eric Doerr · indexed 2026-09-08 17:30 UTC

Tenable is bringing Anthropic’s Claude Mythos 5 into our enterprise security offerings. Adding frontier adversarial reasoning to the Tenable One Exposure Management Platform will help customers better anticipate how attackers could breach their environments and stay ahead of AI-fueled risk. Tenable One Adversary View, the first innovation planned from this work, will debut in the coming weeks.Key takeawaysClaude Mythos 5 is coming to Tenable One. In addition to using Claude Mythos 5 for researc…

AI SecurityICS / OTMicrosoftVulnerabilities
P0
2026-09-08 15:22 UTC
Security Journalism

August updates trigger 0xc0000409 errors on Windows Server 2016

BleepingComputer · Sergiu Gatlan · indexed 2026-09-08 15:40 UTC

Microsoft says the August 2026 security update may trigger 0xc0000409 errors on Windows Server 2016 systems where the Compatibility Appraiser diagnostic service is enabled. [...]

Microsoft
P5
2026-09-08 14:00 UTC
Vendor Research

GTIG AI Threat Tracker: From Prompting to Autonomy – The Evolution of Adversarial AI

Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-09-08 13:45 UTC

Executive Summary Since the release of our May 2026 report detailing adversarial misuse of artificial intelligence (AI), Google Threat Intelligence Group (GTIG) has observed forward leaning adversaries transition from basic prompting to agentic AI workflows and AI-enabled automation. In these operations, human-in-the-loop latency is dramatically reduced, compressing the traditional window for defenders to respond. In Q2 2026, GTIG observed threat actors compromise a cloud resource, then plan, b…

AI SecurityAPT / Nation-StateCloud SecurityData BreachesDFIRMalwareMicrosoftPhishingRansomwareThreat ActorsThreat IntelligenceVulnerabilities
P35
2026-09-08 11:57 UTC
Security Journalism

Microsoft: Windows Server 2025 changes causing app crashes

BleepingComputer · Sergiu Gatlan · indexed 2026-09-08 12:00 UTC

Microsoft warned customers last week that they may experience application crashes on some Windows Server 2025 due to recent memory management changes. [...]

Microsoft
P0
2026-09-08 11:01 UTC
Vendor Research

CVE-2026-86206, CVE-2026-86207: N-able N-central Authentication Bypass (FIXED)

Rapid7 · Stephen Fewer · indexed 2026-09-08 12:25 UTC

OverviewWhile conducting research into a recent N-able N-central authentication bypass vulnerability (CVE-2026-18577), Rapid7 Labs discovered two new vulnerabilities affecting the latest version of N-central. When chained together, these two vulnerabilities allow a remote unauthenticated attacker to bypass authentication and create a new attacker-controlled System administrator account on an affected server.CVE IDDescriptionCWECVSSv4CVE-2026-86206Semicolon/Forwarded access-control bypassCWE-791…

MicrosoftSecurity ResearchVulnerabilitiesCVE-2026-18577CVE-2026-86206CVE-2026-86207
P15
2026-09-08 10:37 UTC
Security Journalism

N-able Patches Critical Zero-Day in N-central

Security Week · Ionut Arghire · indexed 2026-09-08 10:50 UTC

Administrators are advised to check their deployments for newly created user accounts they don’t recognize. The post N-able Patches Critical Zero-Day in N-central appeared first on SecurityWeek.

MicrosoftVulnerabilities
P25
2026-09-08 07:41 UTC
Other

IT Help Desk Impersonation Lets Hackers Bypass MFA

Security Affairs · Pierluigi Paganini · indexed 2026-09-08 08:15 UTC

Attackers bypass endpoint security by posing as IT staff, stealing Microsoft 365 sessions, draining SaaS data and demanding extortion. Forget installing malware because today’s extortionists just pick up the phone instead of writing code. A widespread threat cluster tracked as PREY-0058 bypasses endpoint security entirely by targeting Microsoft 365 and SaaS environments through pure social […]

MalwareMicrosoft
P0
2026-09-08 05:00 UTC
Other

ZDI-26-622: Microsoft Windows IKEv2 AES-GCM Decryption Integer Underflow Remote Code Execution Vulnerability

Zero Day Initiative · indexed 2026-09-08 21:50 UTC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Windows. Authentication is not required to exploit this vulnerability, but only systems with specific IPsec configurations are vulnerable. The ZDI has assigned a CVSS rating of 8.1. The following CVEs are assigned: CVE-2026-50696.

MicrosoftVulnerabilitiesCVE-2026-50696
P20
2026-09-08 05:00 UTC
Other

ZDI-26-621: Microsoft Windows UMPDDrvRealizeBrush Improper Object Management Local Privilege Escalation Vulnerability

Zero Day Initiative · indexed 2026-09-08 21:50 UTC

This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-62712.

MicrosoftVulnerabilitiesCVE-2026-62712
P15
2026-09-08 05:00 UTC
Other

ZDI-26-620: Microsoft Windows UMPDDrvPlgBlt Improper Object Management Local Privilege Escalation Vulnerability

Zero Day Initiative · indexed 2026-09-08 21:50 UTC

This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-62712.

MicrosoftVulnerabilitiesCVE-2026-62712
P15
2026-09-08 05:00 UTC
Other

ZDI-26-619: Microsoft Windows UMPDDrvStretchBltROP Improper Object Management Local Privilege Escalation Vulnerability

Zero Day Initiative · indexed 2026-09-08 21:50 UTC

This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-62712.

MicrosoftVulnerabilitiesCVE-2026-62712
P15
2026-09-08 05:00 UTC
Other

ZDI-26-618: Microsoft Windows UMPDDrvStretchBlt Improper Object Management Local Privilege Escalation Vulnerability

Zero Day Initiative · indexed 2026-09-08 21:50 UTC

This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-62712.

MicrosoftVulnerabilitiesCVE-2026-62712
P15
2026-09-08 05:00 UTC
Other

ZDI-26-617: Microsoft Windows MIDI Service Incorrect Permission Assignment Local Privilege Escalation Vulnerability

Zero Day Initiative · indexed 2026-09-08 21:50 UTC

This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-66804.

MicrosoftVulnerabilitiesCVE-2026-66804
P15
2026-09-08 04:00 UTC
Security Journalism

AD Rights Management Service (Part 1): Architecture, Deprecation, and Reconnaissance

Huntress · indexed 2026-09-08 13:30 UTC

Active Directory Rights Management Services still ships in Windows Server 2025, years after Microsoft began steering customers to the cloud, and it remains fully supported on-premises. Part 1 maps the AD RMS trust model (the Server Licensor Certificate, the license flow, the SOAP surface) and shows how to discover an RMS deployment, fingerprint an AD RMS-protected file, and trace the path to that certificate's private key.

Microsoft
P0
2026-09-07 15:51 UTC
Security Journalism

Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-07 16:10 UTC

Threat hunters have disclosed details of a widespread data theft and extortion threat cluster that's targeting Microsoft 365 and other software-as-a-service (SaaS) offerings through information technology (IT) help desk vishing, adversary-in-the-middle (AitM) token theft, and residential-proxy sign-ins. The activity, which mainly singles out directors, vice presidents, and other executive staff

Microsoft
P0
2026-09-07 13:42 UTC
Other

Chaotic Eclipse Released GreenSection, A PoC For NVIDIA Memory Corruption Zero-Day

Security Affairs · Pierluigi Paganini · indexed 2026-09-09 08:30 UTC

Chaotic Eclipse released GreenSection, a PoC exploit for an Nvidia Memory Corruption Zero-Day Security researcher Chaotic Eclipse, also known as INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse, released a new zero-day exploit targeting Nvidia. The researcher named the exploit GreenSection, it triggers a Memory Corruption flaw. The researcher disclosed a potential security vulnerability in NVIDIA’s Windows user-mode components. […]

MicrosoftSecurity ResearchVulnerabilities
P25
2026-09-07 13:42 UTC
Other

Chaotic Eclipse Released A PoC For NVIDIA GreenSection Memory Corruption Zero-Day

Security Affairs · Pierluigi Paganini · indexed 2026-09-07 14:40 UTC

Chaotic Eclipse released GreenSection, a PoC exploit for an Nvidia GreenSection Memory Corruption Zero-Day Security researcher Chaotic Eclipse, also known as INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse, released a new zero-day exploit targeting Nvidia. The researcher named the exploit GreenSection, it triggers a Memory Corruption flaw. The researcher disclosed a potential security vulnerability in NVIDIA’s Windows user-mode […]

MicrosoftSecurity ResearchVulnerabilities
P25
2026-09-07 08:31 UTC
Security Journalism

N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-07 09:45 UTC

Every on-premises N-central build below 2026.3.1.14 — including servers updated to Hotfix 3 a day earlier — needs Hotfix 4. N-able's incident notice says the flaw has been exploited in the wild; its release notes say that is unconfirmed. N-able has released its fourth hotfix in five weeks for the N-central remote monitoring and management (RMM) platform, this time for a

MicrosoftVulnerabilities
P35
2026-09-06 08:34 UTC
Security Journalism

Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-06 10:00 UTC

Elastic Security Labs has documented four previously unreported programs associated with REVSTEALER, an emerging Windows information stealer, that remain on an infected machine after the stealer deletes itself. One of them switches off Windows Update and Microsoft Defender before running a cryptocurrency miner. The company named the four programs ProManager, WinUpdate, SoftManager, and

MalwareMicrosoftNetwork Security
P0
2026-09-05 21:14 UTC
Other

OpenAI Announced $1B in Defensive Tools for Water Utilities

Security Affairs · Pierluigi Paganini · indexed 2026-09-05 21:50 UTC

OpenAI pledges $1B in subsidized Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. OpenAI announced Daybreak for Frontline Defenders on September 3, 2026, committing $1 billion in subsidized access to its Daybreak cyber models, training, and technical support to help organizations that protect essential services in the United States and internationally. “A $1 billion […]

Microsoft
P0
2026-09-05 07:55 UTC
Security Journalism

Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordination Channel

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-05 08:55 UTC

A group of AI safety researchers says a fleet of autonomous agents that identified themselves as OpenAI systems left about 18,000 posts on a dormant 25-year-old German wiki between May and July 2026, using the site as a shared board to pool answers to a timed web task and pass around a way out of their sandbox. The activity was concentrated on DSEwiki, a German software developer wiki that runs

AI SecurityMicrosoft
P0
2026-09-04 19:10 UTC
Vendor Research

How to secure edge AI in customer-owned environments

Microsoft Security Blog · Shayak Lahiri · indexed 2026-09-04 20:30 UTC

As AI moves into customer-owned environments, organizations need new ways to verify the systems, software, and AI assets they trust before releasing sensitive data, credentials, and models. The post How to secure edge AI in customer-owned environments appeared first on Microsoft Security Blog.

Microsoft
P0
2026-09-04 16:18 UTC
Security Journalism

In Other News: Microsoft’s Cloud Patches, Hacked Dropbox Accounts, Guardio’s $1.1B Valuation

Security Week · SecurityWeek News · indexed 2026-09-07 17:25 UTC

Noteworthy stories that might have slipped under the radar: Microsoft rolled out patches for cloud services, hackers compromised 5,000 Dropbox accounts, and Guardio is now valued at $1.1 billion. The post In Other News: Microsoft’s Cloud Patches, Hacked Dropbox Accounts, Guardio’s $1.1B Valuation appeared first on SecurityWeek.

Microsoft
P0
2026-09-04 16:07 UTC
Security Journalism

OpenAI Pledges $1 Billion to Bring Frontier AI to Critical Infrastructure Defenders

Security Week · Kevin Townsend · indexed 2026-09-07 17:25 UTC

The Daybreak initiative will provide subsidized AI cyber capabilities, training and technical assistance, though OpenAI has disclosed few details about costs and eligibility. The post OpenAI Pledges $1 Billion to Bring Frontier AI to Critical Infrastructure Defenders appeared first on SecurityWeek.

Microsoft
P0
2026-09-04 15:57 UTC
Security Journalism

Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-04 16:10 UTC

Microsoft is alerting of a "high-volume phishing campaign" that's using invisible Unicode tag characters to bypass email filters. "Instead of using these characters to hide instructions from people while exposing them to AI models, the attacker used them to split financial lure words such as 'funding' to prevent email filters from parsing them," the Microsoft Security Research team said. The

MicrosoftPhishingSecurity Research
P0
6 7 8 9 10