IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 205 matching records.
AUTO-POLL // 2026-10-02 23:45 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P7 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Oct 2

RANSOMWARE
P7
P7
COOL // 46 ARTICLES
THU
Oct 1

RANSOMWARE
P8
P8
COOL // 63 ARTICLES
WED
Sep 30

RANSOMWARE
P10
P10
WARM // 59 ARTICLES
TUE
Sep 29

RANSOMWARE
P4
P4
COOL // 68 ARTICLES
MON
Sep 28

RANSOMWARE
P7
P7
COOL // 52 ARTICLES
SUN
Sep 27

RANSOMWARE
P25
P25
ELEVATED // 15 ARTICLES
SAT
Sep 26

RANSOMWARE
P13
P13
WARM // 20 ARTICLES
RESET
2026-04-16 14:00 UTC
Vendor Research

Defending Your Enterprise When AI Models Can Find Vulnerabilities Faster Than Ever

Google Threat Intelligence / Mandiant · Francis deSouza · indexed 2026-08-15 18:55 UTC

Introduction Advances in AI model-powered exploitation have demonstrated that general-purpose AI models can excel at vulnerability discovery, even without being purpose-built for the task. Eventually, capabilities such as these will be integrated directly into the development cycle, and code will be more difficult to exploit than ever; however, this transition creates a critical window of risk. As we harden existing software with AI, threat actors will use it to discover and exploit novel vulne…

AI SecurityAPT / Nation-StateCloud SecurityDFIRMicrosoftRansomwareThreat ActorsVulnerabilities
P60
2026-04-15 14:00 UTC
Vendor Research

The German Cyber Criminal Überfall: Shifts in Europe's Data Leak Landscape

Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-08-15 18:55 UTC

Written by: Jamie Collier, Robin Grunewald Germany has reclaimed its position as a primary focus for cyber extortion in Europe. While data leak site (DLS) posts rose almost 50% globally in 2025, Google Threat Intelligence (GTI) data shows that the surge is hitting German infrastructure harder and faster than its regional neighbors, marking a significant return to the high-pressure levels previously observed in the country during 2022 and 2023. Cyber Criminals Pivoting Back to Germany Germany mo…

CybercrimeData BreachesRansomwareThreat ActorsThreat Intelligence
P15
2026-04-08 11:00 UTC
Security Journalism

Why the Stryker Attack Still Matters. And Five Steps You Can Take Today

Huntress · indexed 2026-09-07 17:30 UTC

The Stryker incident revealed that a "Weaponized Remote Wipe" via compromised MDM is a more permanent and difficult threat than ransomware. Learn concrete steps to secure management platforms and prevent your security shield from becoming a weapon.

Ransomware
P15
2026-01-15 06:07 UTC
Other

DeadLock Ransomware: Smart Contracts for Malicious Purposes

Group-IB · indexed 2026-09-07 17:30 UTC

This blog uncovers DeadLock’s stealthy usage of Polygon smart contracts for proxy address storage, a poorly-documented and under-reported technique that Group-IB analysts have observed increased usage in the wild. Variants of this technique are very wide and offer great alternatives to threat actors for bypassing traditional defenses by abusing decentralized blockchains available worldwide.

MicrosoftRansomwareThreat Actors
P35
2025-12-08 06:00 UTC
Security Journalism

Hardening the Hypervisor | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

Hypervisors are a major target for ransomware attacks. Get expert guidance from Huntress on how to protect your virtualized infrastructure. Learn how to secure access, put runtime controls in place, simplify patching, and improve your recovery plans.

Ransomware
P15
2025-11-05 15:00 UTC
Security Journalism

Gootloader | Threat Detection Overview

Huntress · indexed 2026-09-07 17:30 UTC

Gootloader returns with new obfuscation techniques, including custom WOFF2 fonts and updated persistence mechanisms, while continuing its partnership with Vanilla Tempest for ransomware deployment. Dive in and discover what Huntress is seeing.

Ransomware
P15
2025-10-22 05:00 UTC
Security Journalism

Looking Through a Pinhole at a Qilin Ransomware Attack

Huntress · indexed 2026-09-07 17:30 UTC

Incident analysis is critical, but for newcomers, it can be daunting. Learn how to confirm commands, validate findings, and spot real impact during a Qilin ransomware event.

Ransomware
P15
2025-10-16 05:00 UTC
Security Journalism

Dispelling Ransomware Deployment Myths

Huntress · indexed 2026-09-07 17:30 UTC

Huntress analyzes ransomware activity, uncovering attack patterns and key detection opportunities while dispelling ransomware myths.

Ransomware
P15
2025-08-21 21:00 UTC
Security Journalism

Cephalus Ransomware: Don’t Lose Your Head

Huntress · indexed 2026-09-07 17:30 UTC

In mid-August, Huntress saw two incidents that linked back to a ransomware variant called Cephalus, which included DLL sideloading via a legitimate SentinelOne executable.

Ransomware
P15
2025-08-19 14:00 UTC
Security Journalism

Exposing Data Exfiltration | Huntress

Huntress · indexed 2026-09-07 17:30 UTC

Threat actors often steal data during the course of their attacks. This is particularly true for ransomware threat actors, who do it before deploying file encryption in order to engage in “double extortion” activities. This activity can be difficult to detect, particularly if it’s not dissimilar to legitimate actions taken by system administrators.

RansomwareThreat Actors
P15
2025-08-14 05:00 UTC
Security Journalism

Kawabunga, Dude, You’ve Been Ransomed!

Huntress · indexed 2026-09-07 17:30 UTC

Thanks in large part to our customer base, Huntress sees a great deal of interesting activity, particularly from threat actors (but also from admins). Part of that activity includes not just ransomware variants that Huntress hasn’t seen before, but also variants that may not have been documented via any public means. Further, when these incidents occur, Huntress very often gets a detailed look at the threat actor’s activity, including commands and their timing.

RansomwareThreat Actors
P15
2025-08-13 22:00 UTC
Security Journalism

Active Exploitation of SonicWall VPNs

Huntress · indexed 2026-09-07 17:30 UTC

A likely zero-day vulnerability in SonicWall VPNs is being actively exploited to bypass MFA and deploy ransomware. Huntress advises disabling the VPN service immediately or severely restricting access via IP allow-listing. We're seeing threat actors pivot directly to domain controllers within hours of the initial breach.

Network SecurityRansomwareThreat ActorsVulnerabilities
P40
2025-05-13 05:00 UTC
Security Journalism

Time to Ransom is Money

Huntress · indexed 2026-09-07 17:30 UTC

During ransomware attacks, the average time-to-ransom for attackers is almost 17 hours. Learn more about what this means for businesses.

Ransomware
P15
2025-04-30 06:00 UTC
Other

Ransomware debris: an analysis of the RansomHub operation

Group-IB · indexed 2026-09-07 17:30 UTC

This blog on RansomHub provides an overview into how this Ransomware-as-a-Service (RaaS) group operates, including its extortion tactics, affiliate recruitment strategies, and the features of its affiliate panel.

Ransomware
P15
2025-04-10 05:00 UTC
Security Journalism

Ransomware Initial Access Brokers Exposed

Huntress · indexed 2026-09-07 17:30 UTC

Discover how a seemingly simple brute force attack led to the uncovering of a suspected ransomware-as-a-service operation. This ecosystem appears to be leveraged by initial access brokers, driving an illicit and complex network of cybercrime.

CybercrimeRansomware
P15
3 4 5 6 7