IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 205 matching records.
AUTO-POLL // 2026-10-02 22:50 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P6 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 2

RANSOMWARE
P6
P6
COOL // 45 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
WED
Sep 30

RANSOMWARE
P10
P10
WARM // 59 ARTICLES
TUE
Sep 29

RANSOMWARE
P4
P4
COOL // 68 ARTICLES
MON
Sep 28

RANSOMWARE
P7
P7
COOL // 52 ARTICLES
SUN
Sep 27

RANSOMWARE
P25
P25
ELEVATED // 15 ARTICLES
SAT
Sep 26

RANSOMWARE
P13
P13
WARM // 20 ARTICLES
RESET
2026-10-01 18:08 UTC
Other

Operation KillSwitch: Police Dismantle KillSec Ransomware Group

Security Affairs · Pierluigi Paganini · indexed 2026-10-01 19:00 UTC

Operation KillSwitch: Europol says the KillSec ransomware group, allegedly led by a 16-year-old, was dismantled after attacks on about 1,000 victims. Law enforcement seized control of KillSec ‘s dark web leak site, the Tor website the group used to threaten victims with publishing stolen files unless they paid up. That single action locked down more […]

CybercrimeLaw EnforcementNetwork SecurityRansomware
P15
2026-10-01 16:55 UTC
Security Journalism

Police Arrest 16-Year-Old Suspected of Running KillSec, Seize Ransomware Leak Site and Servers

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-01 17:15 UTC

Police in Spain have arrested a 16-year-old whom investigators suspect of running the KillSec ransomware group. KillSec is accused of stealing data from organizations and threatening to publish it on its leak site unless they paid. The 16-year-old was one of 3 people arrested on September 30, when police also took control of that site. Investigators identified him as KillSec's suspected

Law EnforcementRansomware
P15
2026-10-01 14:17 UTC
Security Journalism

Police Shut Down KillSec Ransomware, Identify Alleged Teen Leader

Security Week · Eduard Kovacs · indexed 2026-10-01 14:20 UTC

Police took control of KillSec’s leak site and secured at least 110 terabytes of data stolen from victims. The post Police Shut Down KillSec Ransomware, Identify Alleged Teen Leader appeared first on SecurityWeek.

Ransomware
P15
2026-09-30 14:16 UTC
Vendor Research

Higher education is under siege, and fragmented security is making it harder to respond

Rapid7 · Rapid7 · indexed 2026-09-30 15:05 UTC

Higher education faces a difficult security equation. Universities hold large volumes of sensitive student, financial, health, and research data while supporting open networks, distributed users, legacy infrastructure, and increasingly complex cloud environments. Attackers have taken notice, and the pressure on security teams continues to grow.In Q2 2025, universities faced an average of 4,388 cyberattacks per organization per week, up 24% from the same period in 2024. Nine in ten universities …

Data BreachesDFIRMalwareMicrosoftRansomwareThreat IntelligenceVulnerabilities
P40
2026-09-29 20:54 UTC
Other

Japanese railway operators Keio Corporation and Tokyo Metro disclose security breaches

Security Affairs · Pierluigi Paganini · indexed 2026-09-29 21:50 UTC

Keio, a major Japanese railway operator, was hit by ransomware, disrupting business systems and forcing the company to shut down its network. Keio Corporation, one of Japan’s major private railway operators, was hit by a ransomware attack over the weekend, disrupting some of its business systems. The company detected a system failure early Saturday and […]

Ransomware
P15
2026-09-28 15:08 UTC
Independent Research

Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation

Krebs on Security · BrianKrebs · indexed 2026-09-28 15:15 UTC

Authorities in the Netherlands have arrested a 23-year-old convicted cybercriminal on suspicion of aiding in data thefts and extortions by the prolific hacker group ShinyHunters. In the days immediately following the suspect's arrest, remaining ShinyHunters members dramatically escalated their attacks, stealing highly sensitive data from the FBI and extorting the Russian ransomware group Cl0p.

DFIRLaw EnforcementRansomwareThreat Actors
P15
2026-09-28 10:46 UTC
Other

Storm-3168, Linked to JADEPUFFER, Abused Stolen Azure Identities

Security Affairs · Pierluigi Paganini · indexed 2026-09-28 11:00 UTC

Microsoft details Storm-3168, the JADEPUFFER-linked actor that used stolen service principals to delete Azure storage in minutes and harvest keys. Microsoft just published the first detailed look at what JADEPUFFER does inside Azure. Sysdig first spotted the group’s activity in July 2026 and called it the first documented agentic ransomware operation. Microsoft tracks the same […]

Cloud SecurityMicrosoftRansomware
P15
2026-09-27 15:05 UTC
Other

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 116

Security Affairs · Pierluigi Paganini · indexed 2026-09-27 15:35 UTC

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Threat Intel | One Kit, Forty Companies: How a Malware-as-a-Service Platform Used GitHub as a Distribution Network for its Campaign Group Policy hijacked: PAYLOAD ransomware weaponizes Active Directory GPO ChainScript: Tracing a Node.js RAT […]

MalwareRansomware
P15
2026-09-27 13:40 UTC
Other

Security Affairs newsletter Round 597 by Pierluigi Paganini – INTERNATIONAL EDITION

Security Affairs · Pierluigi Paganini · indexed 2026-09-27 14:40 UTC

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. OpenAI Agents Accessed US Government Websites Without Authorization Exploit.in Database Reveals the Roots of Today’s Ransomware Ecosystem […]

AI SecurityRansomware
P15
2026-09-27 05:35 UTC
Vendor Research

Frequently asked questions about reported Citrix NetScaler zero-day vulnerabilities

Tenable Blog · Satnam Narang · indexed 2026-09-27 10:00 UTC

CVE-2026-88771 and CVE-2026-88772, two zero-day vulnerabilities in Citrix NetScaler, have been confirmed as exploited in the wild. Citrix released patches on September 27, 2026.Change logUpdate September 27: Citrix published security bulletin CTX697096, confirming CVE-2026-88771 and CVE-2026-88772 as the two zero-day RCE vulnerabilities and releasing patches. Post updated with CVE IDs, CVSS scores, patch versions, and IoC guidance.Click here to review the change log historyUpdate September 27: …

APT / Nation-StateCloud SecurityNetwork SecurityRansomwareThreat ActorsThreat IntelligenceVulnerabilitiesCVE-2023-6549CVE-2025-6543CVE-2026-19489CVE-2026-19490CVE-2026-88771CVE-2026-88772
P95
2026-09-26 14:34 UTC
Other

Exploit.in Database Reveals the Roots of Today’s Ransomware Ecosystem

Security Affairs · Pierluigi Paganini · indexed 2026-09-26 15:40 UTC

Exploit.in data shows how a 2005 cybercrime forum helped shape today’s ransomware ecosystem, with users and practices surviving for decades. Ransomnews researcher Dancho Danchev dug up a database dump of Exploit.in covering its first three years, from February 2005 to May 2008, and the numbers inside it tell a story about Russian cybercrime that enforcement […]

CybercrimeRansomware
P15
2026-09-24 16:00 UTC
Vendor Research

Beyond the ransomware: Tracking Storm-2570’s consistent tradecraft across deployments

Microsoft Security Blog · Microsoft Threat Intelligence · indexed 2026-09-24 18:00 UTC

Storm-2570 is a ransomware affiliate that uses consistent post-compromise tools and techniques across deployments involving Qilin, DragonForce, Anubis, and BERT ransomware, and provides guidance to help defenders detect and disrupt this activity before ransomware deployment. The post Beyond the ransomware: Tracking Storm-2570’s consistent tradecraft across deployments appeared first on Microsoft Security Blog.

MicrosoftRansomware
P15
2026-09-24 14:44 UTC
Security Journalism

3 Cyber Threats That Defined the Summer of 2026

Dark Reading · Arielle Waldman · indexed 2026-09-24 15:45 UTC

This installment of the Reporters' Notebook video series discusses the impact of AI agents breaching Hugging Face, Fairlife's ransomware attack, and Iranian-linked threat actors compromising a dozen US water systems. It was a busy summer.

AI SecurityRansomwareThreat Actors
P15
2026-09-23 08:20 UTC
Security Journalism

Ryuk ransomware member sentenced to 24 months in prison

BleepingComputer · Sergiu Gatlan · indexed 2026-09-23 08:30 UTC

An Armenian man was sentenced to 24 months in prison and 3 years of supervised release for hacking U.S. companies and encrypting their systems in Ryuk ransomware attacks. [...]

Ransomware
P15
1 2 3