IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 623 matching records.
AUTO-POLL // 2026-10-03 01:10 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
NO DATA
NO INTELLIGENCE AGGREGATED TODAY
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 3
NO DATA
--
NO INTEL
FRI
Oct 2

RANSOMWARE
P7
P7
COOL // 46 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
WED
Sep 30

RANSOMWARE
P10
P10
WARM // 59 ARTICLES
TUE
Sep 29

RANSOMWARE
P4
P4
COOL // 68 ARTICLES
MON
Sep 28

RANSOMWARE
P7
P7
COOL // 52 ARTICLES
SUN
Sep 27

RANSOMWARE
P25
P25
ELEVATED // 15 ARTICLES
RESET
2026-09-03 16:00 UTC
Vendor Research

ASCII smuggling crosses over from AI prompt injection to phishing evasion

Microsoft Security Blog · Microsoft Security Research, Noam Kochavi and Sarah Wolstencroft · indexed 2026-09-03 16:45 UTC

Invisible Unicode characters popularized for hiding instructions from AI models are now being used to obfuscate words before email filters parse them. The post ASCII smuggling crosses over from AI prompt injection to phishing evasion appeared first on Microsoft Security Blog.

AI SecurityMicrosoftPhishing
P0
2026-09-03 15:26 UTC
Security Journalism

BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-03 16:45 UTC

Cybersecurity researchers have disclosed details of a sophisticated Python-based Windows malware framework called BraZetsu that fuels an underground marketplace commercializing access to compromised hosts. "Unlike the standard infostealer model, BraZetsu is a comprehensive master toolkit that empowers Initial Access Brokers (IABs) by turning compromised systems into highly valuable commercial

CybercrimeMalwareMicrosoftSecurity Research
P0
2026-09-03 13:50 UTC
Security Journalism

Your Employee’s Password Appeared in an Infostealer Log. Now What?

BleepingComputer · Sponsored by Flare · indexed 2026-09-03 14:00 UTC

Infostealers can expose far more than passwords, including authenticated sessions that may let attackers bypass MFA. Flare explains how defenders can prioritize compromised identities, determine whether stolen access is still usable, and respond before it leads to account takeover. [...]

MalwareMicrosoft
P0
2026-09-03 13:17 UTC
Other

412,000 The Town 2025 Ticket Buyers’ Data Hits the Dark Web

Security Affairs · Pierluigi Paganini · indexed 2026-09-03 14:00 UTC

412,000 The Town 2025 festival buyer records are being sold for $10,000, with Brazil’s data openly marketed for bank fraud, loans and SIM registration. A seller on a Russian-language data-trading forum listed what they’re calling a Ticketmaster database on September 2, claiming over 412,000 Latin American purchase records with a heavy concentration of Brazilian data. […]

CybercrimeMicrosoft
P0
2026-09-03 10:00 UTC
Vendor Research

Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America

Palo Alto Networks Unit 42 · Reese Lewis and Sara McBroom · indexed 2026-09-03 10:20 UTC

Explore how attackers targeting Latin American entities use AI for data exfiltration and how basic OpSec errors allow defenders to disrupt operations. The post Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America appeared first on Unit 42.

Microsoft
P0
2026-09-03 08:55 UTC
Security Journalism

Microsoft Teams, Outlook fail to launch on ARM-based Windows PCs

BleepingComputer · Sergiu Gatlan · indexed 2026-09-03 09:05 UTC

Microsoft is working to fix a known issue that causes crashes and launch failures for Microsoft Teams and New Outlook users after installing updates released since the August 2026 Patch Tuesday. [...]

Microsoft
P0
2026-09-02 22:51 UTC
Vendor Research

Impersonating IT support: how threat actors turn a remote session into enterprise-wide access

Microsoft Security Blog · Microsoft Security Research, Sagar Patil, Arlette Umuhire Sangwa, Jesse Birch and Ravikant Tiwari · indexed 2026-09-03 00:10 UTC

Microsoft Threat Intelligence observed a human-operated intrusion campaign that abuses Microsoft Teams external collaboration to impersonate IT support, gain remote access, and deploy a Node.js-based implant. Learn how attackers move from social engineering to lateral movement using legitimate tools, and how Microsoft Defender helps detect and disrupt the activity. The post Impersonating IT support: how threat actors turn a remote session into enterprise-wide access appeared first on Microsoft …

MicrosoftThreat ActorsThreat Intelligence
P0
2026-09-02 18:27 UTC
Security Journalism

Google, Anthropic, and OpenAI Unveil Cyber AI Models, Safeguards, and Access Programs

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-02 19:30 UTC

Google on Wednesday announced Gemini 3.8 Flash Cyber, which it described as its most capable cybersecurity model, and has made it available to a set of trusted defenders via a new initiative called the Fairwind Program. "The Fairwind Program gives high-priority defenders (like governments, healthcare providers, and telecommunications services) early access to advanced models that help them

Microsoft
P0
2026-09-02 16:41 UTC
Security Journalism

Fake Software Installers Disable Windows Update and Weaken Microsoft Defender

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-02 17:50 UTC

An active malware campaign is using bogus software-download websites to impersonate trusted vendors and distribute malicious installers. "The campaign has targeted users looking to download popular software and has resulted in compromises across multiple organizations and industries, primarily affecting China-based operations of multinational organizations and Chinese-speaking users," Microsoft

MalwareMicrosoft
P0
2026-09-01 22:48 UTC
Vendor Research

Counterfeit installers to system compromise: Tracking a deceptive software download campaign

Microsoft Security Blog · Microsoft Security Research, Microsoft Defender Experts and Parth Jomadkar · indexed 2026-09-01 23:55 UTC

An active campaign is impersonating legitimate software vendors to deliver malware through look-alike download pages and regenerated installer archives. Microsoft Defender Experts shares observed attack techniques, Defender XDR detections, indicators of compromise, and practical mitigations to help organizations identify, block, and respond to this threat. The post Counterfeit installers to system compromise: Tracking a deceptive software download campaign appeared first on Microsoft Security B…

MalwareMicrosoft
P0
2026-09-01 18:55 UTC
Vendor Research

Cybersecurity IR Workshop: The workshop you shouldn’t miss

Microsoft Security Blog · Microsoft Defender Experts Cybersecurity Incident Response · indexed 2026-09-01 20:15 UTC

Cyber resilience starts before a crisis. Gain practical insights from DART to strengthen readiness and response. The post Cybersecurity IR Workshop: The workshop you shouldn’t miss appeared first on Microsoft Security Blog.

Microsoft
P0
2026-09-01 14:00 UTC
Vendor Research

Financially Motivated Threat Actor BREEZE COMET Targets Brazil

Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-09-01 03:50 UTC

Introduction Beginning in 2024 Mandiant investigated a string of compromises affecting Brazilian financial services, retail, and eCommerce organizations. Google Threat Intelligence Group (GTIG) tracks this activity as BREEZE COMET (formerly UNC5669), a financially motivated threat actor specializing in manipulating payment systems and banking software in Brazil to conduct fraudulent transfers. This activity overlaps with operations publicly reported as Plump Spider and SHADOW-AETHER-064. In thi…

AI SecurityCloud SecurityCybercrimeMalwareMicrosoftNetwork SecurityPhishingThreat ActorsThreat Intelligence
P0
2026-09-01 11:30 UTC
Security Journalism

Threat Actors Don’t Want Better Attacks. They Want Repeatable Ones

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-01 11:50 UTC

The most common way into a company last year was to ask. A web page tells the visitor to prove they are not a robot. While they read the instructions, it quietly places a command on their clipboard. Then it talks them through opening a terminal and pasting it in. The technique is called ClickFix, and it was the most common initial access method Microsoft’s team observed last year, accounting

MicrosoftThreat Actors
P0
2026-08-31 18:51 UTC
Security Journalism

Microsoft warns of TerminalFix attacks deploying reverse tunnels

BleepingComputer · Bill Toulas · indexed 2026-08-31 19:05 UTC

A new ClickFix variant dubbed TerminalFix uses fake Cloudflare CAPTCHA prompts on compromised websites to trick victims into running malicious PowerShell commands in Windows Terminal. [...]

Microsoft
P0
2026-08-31 17:18 UTC
Vendor Research

Automate IAM Identity Center governance with continuous discovery and reporting

AWS Security Blog · Jonathan Nguyen · indexed 2026-08-31 17:20 UTC

AWS IAM Identity Center integrates with external identity provider (IdP) to provide customers with a centralized authentication and authorization solution for AWS resources across AWS Organizations. AWS continues to invest into IAM Identity Center with a growing number of AWS services that natively integrate with IAM Identity Center. As your AWS organization scales, maintaining visibility […]

Cloud SecurityMicrosoft
P0
7 8 9 10 11