IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 205 matching records.
AUTO-POLL // 2026-10-02 23:45 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P7 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 2

RANSOMWARE
P7
P7
COOL // 46 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
WED
Sep 30

RANSOMWARE
P10
P10
WARM // 59 ARTICLES
TUE
Sep 29

RANSOMWARE
P4
P4
COOL // 68 ARTICLES
MON
Sep 28

RANSOMWARE
P7
P7
COOL // 52 ARTICLES
SUN
Sep 27

RANSOMWARE
P25
P25
ELEVATED // 15 ARTICLES
SAT
Sep 26

RANSOMWARE
P13
P13
WARM // 20 ARTICLES
RESET
2026-08-13 12:54 UTC
Other

The State of Ransomware Q2 2026

Check Point Research · matthewsu@checkpoint.com · indexed 2026-09-07 17:30 UTC

For the past year, the ransomware conversation has centered on concentration: a handful of dominant RaaS operations controlling most of the damage, and a shrinking pool of active groups fighting over the same territory. The State of Ransomware Q2 2026 report from Check Point Research shows that picture starting to shift. The leaders are still winning, but […] The post The State of Ransomware Q2 2026 appeared first on Check Point Research.

MicrosoftRansomware
P15
2026-08-11 16:35 UTC
Security Journalism

DeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to Disrupt

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-15 14:33 UTC

The ransomware group known as DeadLock has been observed using decentralized infrastructure to facilitate victim communications and data leak operations in a bid to improve operational resilience. "Its recovery ecosystem combines the Session messaging network with blockchain-backed services that store and deliver resources used throughout the extortion process," the Microsoft Threat

Data BreachesMicrosoftRansomware
P15
2026-08-11 09:16 UTC
Security Journalism

Gunra Ransomware Exploits Fortinet FortiOS, FortiProxy Flaws to Breach Networks

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-15 14:33 UTC

Cybersecurity and intelligence agencies from South Korea and the U.S. warned of Gunra ransomware attacks targeting critical infrastructure sectors and organizations across the world. Targets of these attacks include healthcare and public health, financial services, government services and facilities, and professional and nonprofit services. "Gunra is another variant in the ongoing trend of

AppleCloud SecurityNetwork SecurityRansomware
P15
2026-08-10 16:38 UTC
Security Journalism

China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-15 14:33 UTC

Microsoft has disclosed that Storm-1175, a financially motivated threat actor linked to China, has deployed a previously undocumented ransomware strain called StormEncryptor. The use of StormEncryptor marks a shift from the adversary's previous use of Medusa ransomware, the Microsoft Threat Intelligence Team said. "StormEncryptor is written in C++ and appends the file name extension .encrypted

MicrosoftRansomwareThreat ActorsThreat Intelligence
P15
2026-08-10 15:00 UTC
Vendor Research

DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure

Microsoft Security Blog · Microsoft Threat Intelligence · indexed 2026-08-15 18:55 UTC

Microsoft Threat Intelligence examines DeadLock ransomware, an emerging financially motivated operation distinguished by its use of decentralized infrastructure to support victim communications, negotiations, and data leak operations alongside double extortion tactics used to pressure victims. The post DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure appeared first on Microsoft Security Blog.

Data BreachesMicrosoftRansomwareThreat Intelligence
P15
2026-08-04 17:54 UTC
Vendor Research

128 Seconds to disruption: Microsoft Defender stops ransomware at QNET

Microsoft Security Blog · Microsoft Security Research, David Shiran and Ayelet Artzi · indexed 2026-08-15 18:55 UTC

Microsoft Defender automatically isolated a compromised QNET endpoint in 128 seconds, stopping a multi-stage attack before the payload could persist or spread. The post 128 Seconds to disruption: Microsoft Defender stops ransomware at QNET appeared first on Microsoft Security Blog.

MicrosoftRansomware
P15
2026-07-30 14:00 UTC
Vendor Research

Batten Down Your Packages: Mitigation Guidance for Supply Chain Compromise

Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-08-15 18:55 UTC

Written by: Kelli Vanderlee, Stuart Carrera For years, the cybersecurity industry's understanding of software supply chain compromise has been anchored by a few watershed events, including Russian cyber espionage actor ICE RELIC’s (formerly known as APT29) 2020 compromise of SolarWinds and North Korean cyber espionage actor UNC4736's 2023 compromise of 3CX. However, Google Threat Intelligence Group (GTIG) has been tracking growth in threat activity targeting open source software repositories to…

AI SecurityAppleAPT / Nation-StateCybercrimeData BreachesDFIRLinuxMalwareRansomwareThreat ActorsThreat Intelligence
P15
2026-07-27 16:00 UTC
Other

27th July – Threat Intelligence Report

Check Point Research · urias · indexed 2026-09-07 17:30 UTC

For the latest discoveries in cyber research for the week of 27th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Nichirei, a Japan-based frozen-food supplier and logistics company, has experienced a ransomware attack that disrupted shipping operations and affected approximately 5,000 customers. KFC Japan warned of possible shortages. Nichirei confirmed personal data theft, […] The post 27th July – Threat Intelligence Report appeared first on Check Point Researc…

RansomwareThreat Intelligence
P15
2026-07-23 10:00 UTC
Vendor Research

Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel

Cisco Talos Intelligence Blog · Jordyn Dunk · indexed 2026-08-15 14:33 UTC

The Chaos ransomware group uses new malware "msaRAT" that hijacks browsers. The malware doesn't communicate directly with C2 but connects through the browser. It enables arbitrary command execution while hiding the attacker's IP from victims via WebRTC over TURN.

MalwareRansomware
P15
2026-07-20 09:36 UTC
Vendor Research

wp2shell (CVE-2026-63030, CVE-2026-60137): Frequently asked questions about remote code execution chain in WordPress Core

Tenable Cyber Exposure Alerts · Satnam Narang · indexed 2026-08-15 18:55 UTC

An unauthenticated attacker can chain two WordPress Core vulnerabilities, CVE-2026-63030 and CVE-2026-60137, to achieve remote code execution against affected WordPress installations. Multiple security firms have confirmed active in-the-wild exploitation within days of public disclosure, and public proof-of-concept exploits are circulating.Key takeaways:Two WordPress Core vulnerabilities, CVE-2026-63030 and CVE-2026-60137, can be chained together to achieve pre-authentication remote code execut…

Cloud SecurityDFIRMicrosoftNetwork SecurityRansomwareSecurity ResearchThreat ActorsThreat IntelligenceVulnerabilitiesCVE-2026-60137CVE-2026-601377CVE-2026-63030
P70
2026-07-17 18:00 UTC
Security Journalism

It’s Not Safe To Pay SafePa

Huntress · indexed 2026-09-07 17:30 UTC

Huntress has observed Akira ransomware affiliates in action, as well as ReadText34 and INC ransomware being deployed.

Ransomware
P15
2026-07-16 12:00 UTC
Vendor Research

CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions About Active Exploitation of Microsoft SharePoint Server Vulnerabilities

Tenable Cyber Exposure Alerts · Research Special Operations · indexed 2026-08-15 18:55 UTC

Four Microsoft SharePoint Server vulnerabilities are under active exploitation, prompting CISA to issue a hardening alert. An additional high-severity flaw recently patched adds pressure for organizations running on-premises deployments.Key TakeawaysCISA confirmed active exploitation of three on-premises SharePoint Server vulnerabilities (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164), used to gain unauthorized access, establish remote code execution, steal IIS machine keys and deploy malware …

Cloud SecurityMalwareMicrosoftRansomwareThreat ActorsVulnerabilitiesCVE-2026-32201CVE-2026-45659CVE-2026-55040CVE-2026-56164CVE-2026-58644
P95
2026-07-15 13:14 UTC
Vendor Research

CVE-2026-15409, CVE-2026-15410: SonicWall SMA 1000 zero-day vulnerabilities exploited in the wild

Tenable Cyber Exposure Alerts · Scott Caveza · indexed 2026-08-15 18:55 UTC

SonicWall patched two recently exploited zero-day vulnerabilities in its SMA 1000 Series secure remote access appliances which may have been chained for unauthenticated remote code execution.Key takeawaysCVE-2026-15409 and CVE-2026-15410 are a pair of exploited vulnerabilities that may have been chained together to allow for code execution on SonicWall SMA1000 series appliances. Zero-day exploitation of these vulnerabilities has been observed and confirmed by SonicWall. Patches and indicators o…

Cloud SecurityNetwork SecurityRansomwareSecurity ResearchThreat ActorsThreat IntelligenceVulnerabilitiesCVE-2026-15409CVE-2026-15410
P100
2026-07-15 13:00 UTC
Security Journalism

Every Ransomware Attack Has a Backstory

Huntress · indexed 2026-09-07 17:30 UTC

Ransomware is the final act, not the first move. Learn how attackers use access brokers and trusted tools to infiltrate your environment—and how to stop them early.

Ransomware
P15
2026-07-14 13:00 UTC
Security Journalism

5 Modern Threats You Need to Watch

Huntress · indexed 2026-09-07 17:30 UTC

Ransomware, BEC, and social engineering attacks increasingly start with a simple login, not malware. See the five threat patterns IT and security teams need to watch for, and how to catch them early.

MalwareRansomware
P15
2026-07-01 12:00 UTC
Security Journalism

How the RaaS Business Model Actually Works

Huntress · indexed 2026-09-07 17:30 UTC

Ransomware-as-a-Service turned ransomware into a scalable criminal business. Learn how the model works, why it creates so much disruption, and where defenders can shut attacks down before encryption starts.

MicrosoftRansomware
P15
2026-05-11 14:00 UTC
Vendor Research

GTIG AI Threat Tracker: Adversaries Leverage AI for Vulnerability Exploitation, Augmented Operations, and Initial Access

Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-08-15 18:55 UTC

Executive Summary Since our February 2026 report on AI-related threat activity, Google Threat Intelligence Group (GTIG) has continued to track a maturing transition from nascent AI-enabled operations to the industrial-scale application of generative models within adversarial workflows. This report, based on insights derived from Mandiant incident response engagements, Gemini, and GTIG’s proactive research, highlights the dual nature of the current threat environment where AI serves as both a so…

AI SecurityAppleAPT / Nation-StateCloud SecurityDFIRMalwareMicrosoftNetwork SecurityRansomwareSecurity ResearchThreat ActorsThreat IntelligenceVulnerabilities
P60
2026-04-22 20:00 UTC
Security Journalism

What Cybersecurity Leaders Must Prioritize in 2026

Huntress · indexed 2026-09-07 17:30 UTC

The threat landscape has shifted. Here's what cybersecurity leaders need to know about RMM abuse, AI-powered attacks, ransomware, and identity threats in 2026.

Ransomware
P15
2 3 4 5 6